Skip to content
COOEY
LIVE FEED
4274 events · 13 sources · newest first
2026-08-27 News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix...
cisacitrixcve-2019-1068exploithigh-severitykevknown-exploit-vulnerabilitieslinux
2026-08-27 News
<p>CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452.</p> <p>The post <a...
cisacitrixcve-2026-8452exploitgovernments-agenciesnetscalernewspatch
2026-08-27 CISA advisory
<p>CISA has added three new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
bod-26-04cisacisa-advisorycve-2023-49105cve-2026-53362cve-2026-66384cyber-attacksfederal-agencies
2026-08-27 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-078-05.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability...
bound-readcisacisa-advisorycnc-seriescritical-manufacturingcve-2025-2399cwe-1285denial
2026-08-27 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities...
authentication-bypasscisacisa-advisorycommand-injectioncontrol-systemcritical-infrastructurecve-2026-76943cve-2026-78037
2026-08-27 NVD CVE
openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users....
attackbandbypasscve-2026-81707fingerprintidentitykey-substitutionsnvd-cve
2026-08-27 NVD CVE
startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to...
arbitrary-command-executionauthentication-bypassauthentication-middlewarechild-process-execcommit-c2ad42e3eb9b27830db41a3e6f51ca7179d9b168cve-2026-81735file-read-write-toollisten-address-default
2026-08-27 NVD CVE
openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in top-level plugins/ directories and unknown subdirectories to bypass signature verification....
arbitrary-code-executionclicode-executioncryptocryptographic-keyscve-2026-81701malicious-pluginsnvd-cve
2026-08-27 NVD CVE
The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mcp-server/src/http.ts served MCP on the root path with a listener bound to all interfaces and...
api-keyauthenticationclients-secretscode-executioncredentials-exposurecve-2026-81098https-transportmcp-server
2026-08-27 NVD CVE
The mcp-router CLI served its MCP aggregator on every interface and enforced authentication only when the operator asked for it. The serve command in apps/cli/src/commands/serve.ts defaulted its host to the...
aggregatorauthenticationclicommand-line-interfacecve-2026-81094default-configurationloopback-addressmcp-router
2026-08-27 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-04.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities...
cisa-advisory
2026-08-27 NVD CVE
ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor behind the python_code_executor tool, in python_executor_tool.py, inspected...
attribute-lookupauthenticationbearer-tokencode-executioncve-2026-81096debugging-enabledhttps-serverimport-allowlist
2026-08-27 CISA KEV
JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific...
artifactoryauthenticate-usercache-pathcisa-kevcve-2026-66384datum-exfiltrationdirectories-traversaldocker
2026-08-27 NVD CVE
openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate...
attackcve-2026-81702encryptionencryption-vulnerabilitiesfingerprint-validationidentity-managementidentityjsonkey-management
2026-08-27 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-05.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities...
cisa-advisory
2026-08-27 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-128-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability...
cc-links-ie-tsnscisacisa-advisorycommunication-delaycritical-manufacturingcve-2025-3511cwe-1284denial
2026-08-27 CISA KEV
Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat,...
cisa-kevcve-2026-53362ipv6linuxlinux-kernelmultiple-productnetworking-subsystemsprivileges-escalation
2026-08-27 NVD CVE
openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that accepts revoked and expired keys by only checking VALIDSIG status without inspecting REVKEYSIG,...
cryptographic-vulnerabilitiescve-2026-81700expired-keysgpggpgs-runnerhost-processmalicious-pluginsnvd-cve
2026-08-27 CISA KEV
ownCloud Improper Authentication Vulnerability HIGH ◈ 2 sources · orig. NVD CVE
ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key...
attacker-accessesauthentication-bypasscisa-kevcve-2023-49105data-integrityfile-deletionfile-modificationfiles-access
2026-08-27 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities...
argument-injectionbuffer-overflowcisacisa-advisorycritical-infrastructurecritical-manufacturingcve-2018-19518cve-2019-11043
2026-08-27 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability...
brute-forcecisacisa-advisorycritical-manufacturingcve-2026-75112cwe-916encrypted-backupsics-advisories
2026-08-26 News
<p>The National Housing Law Project has been seeking communications about HUD’s pact with DHS and USCIS to share tenant information for immigration enforcement.</p> <p>The post <a...
data-sharingdhfedscoopfoiahudimmigration-enforcementlawsuitnational-housing-law-project
2026-08-26 News
<p>The order says any foreign-produced equipment deemed to pose national security risks can’t be purchased or installed.</p> <p>The post <a...
cisacritical-infrastructurecyber-threatscybersecurity-policydodenergy-infrastructureexecutives-ordersforeign-equipment
2026-08-26 News
<p>The post <a href="https://cyberscoop.com/qtfy-china-espionage-group-infrastructure-seized/">Officials disrupt Chinese espionage operation that hit multiple federal agencies</a> appeared first on <a...
chinese-espionagecyber-attackscyber-intelligencecyber-intrusioncyber-operationscyber-threatscybersecuritydata-breaches
2026-08-26 News
The National Security Agency will welcome back to campus potentially hundreds of former members of the elite group known as Tailored Access Operations (TAO) to celebrate the division’s recent rebranding.
campus-eventsclassified-informationcybersecuritydivision-restructuringelite-unitshacker-reunionintelligence-communitynational-security-agencies
2026-08-26 News
<p>Federal IT leaders across administrations have wanted a single sign-on service. The memo requires the use of Login but does not bar other forms of authentication.</p> <p>The post <a...
access-controlagencies-websitesauthenticationdrafts-memosfederal-agenciesfederal-identityfederal-itfedscoop
2026-08-26 News
<p>After his comments on veterans’ hiring preference, the General Services Administration put him on leave around the beginning of August.</p> <p>The post <a...
fedrampfedscoopgeneral-services-administrationgsanewspete-watermanveteran-hiring
2026-08-26 News
<p>The Anduril alum and Marine Corps veteran joined DHS as its top technology leader in March 2025. He is the latest CIO planning to leave the role amid a slew of other resignations.</p> <p>The post <a...
andurilciodhfedscoopmarines-corpsnewsresignationtechnology-leader
2026-08-26 News
<p><a href="https://breakingdefense.com/2026/08/army-taps-5-vendors-to-build-nuclear-microreactors-with-2-2b-pot/"><img width="1024" height="577"...
armydefense-industrial-basedefense-technologydodenergyinfrastructurenewsnuclear-microreactor
2026-08-26 News
<p>The service tapped five vendors for the effort: Antares Nuclear, BWXT Advanced Technologies, General Atomics Electromagnetic Systems, Radiant Industries and Westinghouse Government Services.</p> <p>The post <a...
antare-nucleararmybwxt-advanced-technologydefense-energydod-energyfort-benningfort-braggfort-campbell
2026-08-26 News
<p>The full hacking suite, seized by authorities, allowed Chinese government funded attackers to intrude highly sensitive networks undetected for more than eight years.</p> <p>The post <a...
chinese-espionagecyber-attackscyber-intelligencecyber-intrusioncyber-operationscyber-threatscybersecuritydata-breaches
2026-08-26 News
<p><a href="https://breakingdefense.com/2026/08/hegseth-stands-by-laneve-nomination-amid-reported-lawmaker-hesitation/"><img width="1024" height="577"...
armychiefdodhegsethlawmakerlvemilitaries-leadershipsnews
2026-08-26 News
The company released a statement and filed documents with the Securities and Exchange Commission (SEC) saying a cybersecurity incident was discovered on Tuesday.
bostons-scientificscyberattackcybersecurity-incidentsdiscovered-incidentfirm-statementmedical-devicesnewssec-filing
2026-08-26 News
<p>The company says the breach stemmed from a systemic failure of alignment and security, and has taken measures to prevent agents from independently orchestrating complex cyberattacks.</p> <p>The post <a...
agents-behavioralignmentbreachcyberattackcyberscoophugging-faceintrusionnews
2026-08-26 News
<p>The communications product company disclosed 22 total Wednesday, all but one of which was rated “critical” at 9.0 or higher.</p> <p>The post <a...
critical-severitycritical-vulnerabilitycvecybersecurityinfrastructurenetwork-securitynetworks-vulnerabilitiesnews
2026-08-26 News
A multibillion-dollar settlement with attorneys general from nearly every U.S. state and territory will mean new privacy and safety protections in Meta products.
attorney-generalchildren-online-safetyconsumers-protectionsdata-protectionlegal-settlementmetanewsonline-safety
2026-08-26 News
<p><a href="https://breakingdefense.com/2026/08/boeing-nabs-whopping-131-billion-f-15-deal/"><img width="974" height="547"...
aircraft-manufacturerboeingboeing-f-15defense-awarddefense-contractdefense-dealdefense-industrydefense-spending
2026-08-26 News
<p>The U.S. Department of Justice (DOJ) and Federal Bureau of Investigation (FBI) seized two hacking platforms used by...</p> <p>The post <a...
china-linkedcritical-infrastructurecyber-threatsdojfbiforeign-adversarieshacking-platformsindustrial-cyber
2026-08-26 News
"We have to stay ready to get ready. We don't know when, if, and how that vulnerability can occur," said Jennifer Franks.
commercial-aviationconnected-systemcybersecurityga-reportincidents-preparednessinfrastructure-securitynetwork-securitynews
2026-08-26 News
<p><a href="https://breakingdefense.com/2026/08/air-force-awards-766-million-for-b-52-radar-modernization/"><img width="1024" height="577"...
air-forceair-force-budgetair-force-contractsb-52boeingdefense-contractdefense-industrydefense-spending
◀ PREV PAGE 03 / 107 NEXT ▶