[CRITICAL] – CISA Adds N-able N-central RCE to KEV Catalog
CISA added a pre-authentication N-central remote-code-execution flaw to KEV; self-hosted administrators should apply N-able's hotfix.
Cybersecurity, AI, etc.
Cybersecurity (breaches, incidents, vulnerabilities, ransomware, supply chain attacks)
CISA added a pre-authentication N-central remote-code-execution flaw to KEV; self-hosted administrators should apply N-able's hotfix.
Google observed an agent-enabled credential-harvesting campaign planned and executed in under six hours.
Calif demonstrated a zero-click WeChat account-takeover worm; it says Tencent has mitigated the exploit.
SAP's September security updates address a CVSS 10.0 Extended Passport Processing memory-corruption vulnerability.
Check Point demonstrated a prompt-driven ChatGPT channel that could relay connected-app data across accounts.
CISA-listed, actively exploited Switchvox SQL injection can enable unauthenticated remote code execution.
A critical FreeIPA flaw can give an unauthenticated LDAP client administrator-group membership.
Microsoft addressed two Windows privilege-escalation flaws that CISA added to the KEV Catalog on September 8.
Berlin says newly released breach data includes login credentials; officials are assessing affected systems and people.
Rapid7 details a stealthy Linux toolkit targeting South Korean automotive and media organizations.