Amazon
20 articles
U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog
U.S.
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in questi...
Hackers Launch Password Spraying Attacks Against AWS Root Accounts at 150+ Organizations
Research has discovered a password-spraying campaign targeting AWS root user accounts across more than 150 organizations. This highlights ongoing efforts by ...
CISA Flags Multiple PaperCut NG/MF Flaws Exploited in the Wild
The U.S.
We invited a direct competitor into Security Hub Extended. Here’s why.
When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we mad...
Automate IAM Identity Center governance with continuous discovery and reporting
AWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution fo...
AWS Console Private Access can block sign-ins to personal accounts
The AWS Management Console now loads inside a network with no path to the public internet. Console Private Access became generally available on August 28 for...
AI Shopping Assistant Vulnerabilities Enable Remote Code Execution on Retailer’s Servers
Security researchers have demonstrated how flaws in the AI shopping assistant of a major unnamed U.S.
D-Link DIR-X1860Z Flaws Enable Unauthenticated Admin Password Reset and Wi-Fi Credential Theft
D-Link has released a security update for the DIR-X1860Z router after researchers discovered vulnerabilities that could enable an unauthenticated attacker on...
AI AppSec tools agree on just 5% of security findings
Software vulnerabilities are turning into exploits within hours, and application security teams carry patch backlogs that go back years. Top types of viable ...
Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, ...
Hack One Robot, Reach the Next: Unitree G1 Security Flaws
A researcher chained two Unitree G1 flaws to gain root access remotely and showed how a compromised robot could attack others nearby. Security researcher Oli...
Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator
An alleged Chinese-speaking actor breached Philippine nuclear and naval targets by exploiting known flaws, stealing sensitive data. A suspected Chinese-speak...
ServiceNow patches three maximum severity flaws that could put enterprise data at risk
Code injection and SQL injection attacks have been around for decades, and they are still tried-and-true ways for attackers to compromise systems. ServiceNow...
CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to exploited vulnerabilities list
The newly cataloged vulnerabilities include CVE-2023-49105, an improper authentication flaw in ownCloud Server affecting versions 10.6.
Two root remote code execution flaws found in Unitree G1 EDU robot
The vulnerabilities, tracked as CVE-2026-76639 and CVE-2026-76640, present distinct attack vectors. CVE-2026-76639 involves a network-adjacent path through c...
CISA urges software vendors to adopt secure by design practices
CISA's review of vulnerabilities from 2024 and 2025 reveals that the most frequently exploited flaws, often found in the Known Exploited Vulnerability (KEV) ...
PaperCut issues emergency patches for actively exploited critical vulnerability
Two flaws in the print management software could enable unauthenticated RCE.