Skip to content
COOEY
LIVE FEED
4274 events · 13 sources · newest first
2026-08-25 News
The benefits management firm Paylogix told regulators that hackers stole sensitive information on tens of thousands of people from its systems.
cyberattackdata-breachesemployee-benefitsfinancial-datahackerhealth-datanewspaylogix
2026-08-25 News
<p>Joshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that.</p> <p>The post <a...
arrestcybercrimecyberscoopelite-hackinghacking-unitimpersonationjoshua-culvermaverick-young
2026-08-25 News
<p><a href="https://breakingdefense.com/2026/08/us-flexes-new-ship-sinking-weapons-at-summer-naval-exercises/"><img width="1024" height="575"...
airs-launched-weaponsanti-ship-missileb-2-bomberbreaking-defensecruise-missiledecommissioned-vesseldefense-industrymilitary-technology
2026-08-25 News
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We...
breachcritical-infrastructurecyber-actorscybersecurity-enforcementdepartmenteconomic-campaignfinancial-connectiongovernment
2026-08-25 News
<p>Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further.</p> <p>The post <a...
cisa-reds-teamscyber-defensecyber-resiliencecybersecuritycybersecurity-testinggovernment-sectorgovernments-agenciesincident-response
2026-08-25 News
<p>The Quantum-Readiness Task Force follows a June executive order aimed at speeding up post-quantum migration and bolstering industry.</p> <p>The post <a...
cybersecurityencryptionexecutives-ordersfedscoopfinancial-sectornewspost-quantum-cryptographyquantum-computing
2026-08-25 News
<p><a href="https://breakingdefense.com/2026/08/how-a-new-pentagon-memo-resets-industry-requirements-plus-highlights-from-technet/"><img width="1024" height="576"...
breaking-defensecontractor-compliancecontractors-newsdefense-contractingdefense-industrydefense-technologydod-contractorsdod-policies
2026-08-25 News
By: Paul Perez, SVP &#38; Senior Technology Fellow, Office of the CTO &#38; Dell Federal Always-on agents change the economics of AI. Federal agencies need workload placement strategies that account for token demand,...
agentics-aiai-economicsdata-controlfederal-agenciesinference-costsinfrastructure-firstmission-requirementsnews
2026-08-25 News
<p><a href="https://breakingdefense.com/2026/08/saudi-turkish-pakistani-defense-pact-to-boost-turkish-industry-entire-trilateral-ecosystem/"><img width="1024" height="577"...
arms-exportsdefense-agreementdefense-exportsdefense-industrydefense-industry-agreementsdefense-industry-boostdefense-industry-developmentdefense-industry-ecosystem
2026-08-25 News
As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.
affordability-crisisbreach-costscybersecuritydark-readingdefense-spendingnewsrecord-highsmall-businesses
2026-08-25 News
<p>The multi-country sting targeted Black Axe financial networks, seizing millions in assets and uncovering Crime-as-a-Service infrastructure across four continents.</p> <p>The post <a...
assets-seizureblack-axecrimecybercrimecyberscoopfinancial-networkillicit-financeinternational-sting
2026-08-25 News
<p><a href="https://breakingdefense.com/2026/08/navy-establishes-new-defense-industrial-base-office-cao/"><img width="1024" height="577"...
breaking-defensedefense-industrial-basedibdodmagliochettinavynewsoffice
2026-08-25 News
Ukraine will give Britain access to a vast trove of battlefield data collected during the war with Russia, allowing U.K. companies and researchers to use it to train and test artificial intelligence systems.
artificial-intelligencenewsukraineukraine-russiaukraine-russia-conflictukraine-russia-warukraine-russia-war-dataukraine-russia-war-data-access
2026-08-25 News
<p><a href="https://breakingdefense.com/2026/08/hypersonics-rocket-startup-ursa-major-to-go-public-in-2-3b-deal/"><img width="1024" height="577"...
breaking-defensechris-spagnolettidefense-industryhypersonicipomergers-acquisitionsnewsrocket-startup
2026-08-25 News
<p><a href="https://breakingdefense.com/2026/08/uk-provides-ukraine-classified-long-range-scalp-missile-blueprints/"><img width="1024" height="576"...
blueprintbritish-armed-forcesclassifieddefensegeopoliticsinternational-relationslondonmilitary-technology
2026-08-25 News
<p>New data from CYFIRMA rated telecommunications and media sector’s external cyber threat landscape as high, citing sustained activity...</p> <p>The post <a...
aptchina-linkedcyber-activitiescyber-campaignscyber-landscapecyber-riskscyber-threatscyfirma
2026-08-25 News
<p>NTT DATA, vendor of AI, digital business and technology services, and Palo Alto Networks announced a multi-year strategic...</p> <p>The post <a...
aiai-transformationcybersecuritydigital-transformationglobal-alliancenetwork-securitynewsntt-datums
2026-08-25 News
The British government is seeking new powers to ban certain technology vendors from supplying companies working in the country’s critical sectors — potentially doing so in secret.
british-governmentcritical-infrastructurecritical-sectornational-securitynewssecret-powerssupply-chain-securitytech-vendor
2026-08-25 News
The Norwegian Digitalisation Agency said it was working with its IT partner to stabilize systems affected by a distributed denial-of-service attack, with some services gradually coming back online.
availabilitycyber-attacksddos-attacksdistributed-denialgovernmentincident-responsenewsnorway
2026-08-25 News
CISA Warns of Exploited Oracle WebLogic Vulnerability ↗ ◈ 2 sources · orig. thehackernews.com
<p>The vulnerability is tracked as CVE-2026-21962 and it has been widely exploited by threat actors against WebLogic servers.</p> <p>The post <a...
cisacve-2026-21962exploitnewsoraclesecurity-weekvulnerabilityweblogic
2026-08-25 News
<p>Following the July suspension of CMMC Phase II, which paused the planned third-party assessment requirement, contractors facing C3PAO...</p> <p>The post <a...
c3pao-assessmentcmmc-phase-iicompliancecontractorcybersecuritydefense-industrial-basedodnews
2026-08-25 News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV)...
cisacritical-data-accesscve-2026-21962https-protocolkevs-catalogknown-exploit-vulnerabilitiesmaximum-severitynetwork-access
2026-08-25 NVD CVE
DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the upload directory. skill_upload in...
application-packagecode-executioncve-2026-80104db-gptdirectories-traversalfiles-uploadmodule-replacementmultipart-file
2026-08-25 NVD CVE
NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, allowing attackers to inject dangerous JVM flags. Attackers can supply malicious options like...
agentpatharbitrary-code-executionargfilecode-injectioncve-2026-79675javajavaagentjvm
2026-08-25 NVD CVE
Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which are affected by two upstream CVEs. Via CVE-2021-30560 in libxslt, an application transforming XML...
code-executioncrubycve-2021-30560cve-2022-23308cve-2022-51000deniallibxml2libxslt
2026-08-25 NVD CVE
A security vulnerability has been detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. The affected element is the function setSystemConfig of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such...
buffer-overflowcgi-handlercstecgicgicve-2026-79911exploit-disclosurefirmware-vulnerabilitiesiots-securityn600r
2026-08-25 NVD CVE
Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free vulnerability in libxml2 (CVE-2024-25062) in the xmlTextReader module, which underlies...
crubycve-2024-25062cve-2024-58378freejrubylibxml2nokogirinvd-cve
2026-08-25 NVD CVE
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer...
arbitrary-code-executionclipbucketcommand-injectioncrafted-post-requestcve-2026-80138malicious-requestsnvd-cvephp-cli
2026-08-25 NVD CVE
Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to...
cve-2026-16286dangerous-files-typesfiles-uploadnvd-cverepository-managementsecurity-vulnerabilitysoftware-repository-managementsoftware-vulnerabilities
2026-08-25 CISA advisory
CISA Adds One Known Exploited Vulnerability to Catalog ↗ ◈ 3 sources · orig. CISA advisory
<p>CISA has added one new vulnerability to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation....
bod-26-04cisacisa-advisorycode-injectioncve-2026-60004cyber-attacksfederal-agenciesfederal-enterprises
2026-08-25 NVD CVE
Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned...
alluxioauthorization-headerawaw-signature-versions-4cve-2026-79787data-accessdata-deletiondata-modification
2026-08-25 NVD CVE
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of...
adobeadobe-campaign-classicarbitrary-code-executioncvecve-2026-76195nvd-cveos-command-injectionsecurity
2026-08-25 NVD CVE
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of...
adobeadobe-campaign-classicarbitrary-code-executioncvecve-2026-76197nvd-cveos-command-injectionsecurity
2026-08-25 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability...
cisacisa-advisorycommercial-facilitycommunicationcve-2026-75960cvss-31cvss-40cwe-522
2026-08-25 CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities...
authentication-attemptscisacisa-advisorycleartext-transmissionsclient-side-authenticationcritical-infrastructurecross-site-requests-forgerycsrf
2026-08-25 CISA KEV
Gitea Code Injection Vulnerability HIGH ◈ 2 sources · orig. CISA KEV
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the...
cisa-kevcode-injectioncve-2026-60004diffpatch-apiexecutable-git-hookgit-hookgiteamalicious-patches
2026-08-25 NVD CVE
The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to elevate their privileges to that of...
cve-2026-78570nvd-cveplugins-securityplugins-vulnerabilitiesprivileges-escalationsecurity-vulnerabilitytotals-donationsunauthenticated-attacks
2026-08-25 NVD CVE
The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
administrator-privilegescve-2026-78477jawn-themenvd-cveprivileges-escalationsecurity-bulletinthemes-vulnerabilityunauthenticated-attacks
2026-08-25 CISA advisory
<h2><strong>Advisory at a Glance</strong></h2> <table> <tbody> <tr> <th>Title</th> <td>A Tale of Two SOCs: Insights From Two Red Team Assessments</td> </tr> <tr> <th>Original Publication&nbsp;</th> <td><strong>August...
active-directorycisa-advisoriescisa-advisorycloud-securityconditional-accessescredentials-theftcritical-infrastructuredetection-tool
2026-08-25 NVD CVE
The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a...
arbitrary-command-executioncgicommand-injectioncooeys-clubcve-2026-63586http-basic-authenticationnvd-cveroot-privileges-escalation
◀ PREV PAGE 05 / 107 NEXT ▶