Breaking news & global coverage. No Filter. Just Facts. 🔴 🌐 rawfeednews.com 𝕏 @rawfeednews
。。。RSS Robot — not a real account。。。 Global News National
。。。RSS Robot — not a real account。。。 Global News Politics
。。。RSS Robot — not a real account。。。 Global News World
I am a retired academic, with an MA & PhD in Social Policy & Administration from the Universities of York & Kent respectively. I am disabled, & am deeply concerned about human, gay and disability rights, the climate emergency and the biodiversity crisis. I was politically homeless, but now favour the Green Party. I like films, classical music, jazz & reading.
Breaking news & global coverage. No Filter. Just Facts. 🔴 🌐 rawfeednews.com 𝕏 @rawfeednews
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Metabase Patches Critical Zero-Day SQL Injection Exploited in the Wild
Metabase patched a critical zero-day SQL injection vulnerability (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) that is actively exploited to gain administrator access and steal database credentials.
If you run self-hosted Metabase (version 1.58 or newer), this is urgent. Your Metabase is under attack. Update immediately to the patched release for your branch (0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5). if you can't patch right now, block all traffic to the /api/session/reset_password endpoint as a stopgap. After patching, check your application and ingress logs for a failed password-reset POST followed straight away by a successful /api/user/current request. Tf you see it, treat the instance as breached: clear the core_session table to log everyone out, rotate all connected database passwords, and check your admin accounts for anything you didn't create. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/metabase-patches-critical-zero-day-sql-injection-exploited-in-the-wild-g-o-s-u-u/gD2P6Ple2L
Breaking news & global coverage. No Filter. Just Facts. 🔴 🌐 rawfeednews.com 𝕏 @rawfeednews
Hello Fediverse! 👋 Lived through martial law. Now I monitor global tensions & anomalies. OSINT, artillery, strategic weapons, WMDs, info warfare. I don't sow panic or propaganda. Inaccuracies? Write me. Peace 🕊️ #OSINT #Monitoring #Security #War #StrategicWeapons #ThreatIntel #OSINT #akert
Hello Fediverse! 👋 Lived through martial law. Now I monitor global tensions & anomalies. OSINT, artillery, strategic weapons, WMDs, info warfare. I don't sow panic or propaganda. Inaccuracies? Write me. Peace 🕊️ #OSINT #Monitoring #Security #War #StrategicWeapons #ThreatIntel #OSINT #akert
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
N-able Patches Critical N-central Authentication Bypass Exploited in the Wild
N-able issued an emergency hotfix for N-central after attackers bypassed previous patches to gain administrative control over MSP servers. The flaw allows remote actors to hijack managed endpoints and establish persistent access via Cloudflare tunnels.
If you are using N-able N-central, this is urgent. Upgrade immediately to version 2026.3.1.7. Attackers are already exploiting the product to take over admin accounts on both on-premises and cloud-hosted servers. After patching, run N-able's provided scan templates on your Windows endpoints to check for signs of compromise (especially unexpected Cloudflare tunnel services), turn on multi-factor authentication, and review all user accounts and policy changes for anything you didn't make yourself. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/n-able-patches-critical-n-central-authentication-bypass-exploited-in-the-wild-7-r-o-r-u/gD2P6Ple2L
Hello Fediverse! 👋 Lived through martial law. Now I monitor global tensions & anomalies. OSINT, artillery, strategic weapons, WMDs, info warfare. I don't sow panic or propaganda. Inaccuracies? Write me. Peace 🕊️ #OSINT #Monitoring #Security #War #StrategicWeapons #ThreatIntel #OSINT #akert
Hello Fediverse! 👋 Lived through martial law. Now I monitor global tensions & anomalies. OSINT, artillery, strategic weapons, WMDs, info warfare. I don't sow panic or propaganda. Inaccuracies? Write me. Peace 🕊️ #OSINT #Monitoring #Security #War #StrategicWeapons #ThreatIntel #OSINT #akert
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack
Arista Networks released an emergency advisory for a CVSS 10.0 OS command injection vulnerability in VeloCloud Orchestrator On-Prem that is currently being exploited in the wild. The flaw allows unauthenticated attackers to gain full control over the orchestrator and all managed SD-WAN edge devices.
Make sure all VeloCloud Orchestrator On-Prem devices are isolated from the internet and accessible only from trusted administrative networks. Then immediately upgrade to a fixed release (5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1) and block the known malicious IPs (8.19.75.217, 206.72.242.124, 206.72.242.162) at your firewall. After patching rotate all credentials and certificates so attackers can't reuse any potentially stolen data. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/arista-patches-critical-velocloud-orchestrator-zero-day-under-active-attack-x-b-e-7-y/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass
CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.
If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-in-fortinet-fortios-ssl-vpn-patch-bypass-h-6-5-r-8/gD2P6Ple2L
Hello Fediverse! 👋 Lived through martial law. Now I monitor global tensions & anomalies. OSINT, artillery, strategic weapons, WMDs, info warfare. I don't sow panic or propaganda. Inaccuracies? Write me. Peace 🕊️ #OSINT #Monitoring #Security #War #StrategicWeapons #ThreatIntel #OSINT #akert
Hello Fediverse! 👋 Lived through martial law. Now I monitor global tensions & anomalies. OSINT, artillery, strategic weapons, WMDs, info warfare. I don't sow panic or propaganda. Inaccuracies? Write me. Peace 🕊️ #OSINT #Monitoring #Security #War #StrategicWeapons #ThreatIntel #OSINT #akert
Hello Fediverse! 👋 Lived through martial law. Now I monitor global tensions & anomalies. OSINT, artillery, strategic weapons, WMDs, info warfare. I don't sow panic or propaganda. Inaccuracies? Write me. Peace 🕊️ #OSINT #Monitoring #Security #War #StrategicWeapons #ThreatIntel #OSINT #akert