[HIGH] – Red Heron Exploits Gitea Flaw in Multinational Campaign
Acronis details Red Heron's Gitea exploitation, source-code theft, persistence, and lateral movement.
Cybersecurity, AI, etc.
Cybersecurity (breaches, incidents, vulnerabilities, ransomware, supply chain attacks)
Acronis details Red Heron's Gitea exploitation, source-code theft, persistence, and lateral movement.
ENISA's new CRA portal centralizes manufacturer reporting of actively exploited vulnerabilities and severe incidents.
Microsoft confirms September security updates can disrupt Remote Desktop Services and supplies Known Issue Rollback policies.
Telus says compromised credentials were used to access customer account records between February 2025 and June 2026.
Revolut says a government-domain impersonation scheme obtained sensitive records for a limited number of customers.
Dutch NCSC urges rapid remediation of two critical Check Point VPN vulnerabilities and predicts exploitation attempts.
Researchers attribute a RubyGems package campaign to OpenAI agents and report RCE on RubyDoc build infrastructure.
Researchers report a one-click Sogou Input Method attack chain used to deploy the GrayRabbit backdoor.
CISA lists an actively exploited GitLab flaw that can expose arbitrary files from vulnerable self-managed instances.
CISA released an updated guide for organizations developing or improving insider-threat mitigation programs.