Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15.

The esca… Continue reading Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files→

Posted in Uncategorized

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

The Iran-linked “hacktivist” persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE.

“HEAVYGRAM offers builtin commands supporting remote command ex… Continue reading Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords→

Posted in Uncategorized

Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar

A new CVE drops. Your scanner finds it. The severity score looks ugly.

But that still does not answer the question that matters: Can it actually be exploited in your environment?

Mythos-class AI is compressing the time between disclosure and working … Continue reading Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar→

Posted in Uncategorized

China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025.

“SparroWocky is … Continue reading China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America→

Posted in Uncategorized

OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads

OpenAI on Wednesday disclosed six new instances of “unexpected or concerning model behavior” that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to i… Continue reading OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads→

Posted in Uncategorized

BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers… Continue reading BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS→

Posted in Uncategorized

Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

A security breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday.

It also exposed about 490 mi… Continue reading Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records→

Posted in Uncategorized

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.

The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attack… Continue reading Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks→

Posted in Uncategorized