BeyondMachines :verified:
beyondmachines1@infosec.exchange
<p>Enabling Good Cybersecurity for Everyone:<br />Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes.<br />Because cybersecurity shouldn't be an enterprise feature.</p><p>Sometimes a bot, sometimes not.</p>
Posts
-
Post #4498932
#AI rules to live by
-
Post #4441260
Metabase Patches Critical Zero-Day SQL Injection Exploited in the Wild Metabase patched a critical zero-day SQL injection vulnerability (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) that is actively exploited to gain administrator access and steal database credentials. **If you run self-hosted Metabase (version 1.58 or newer), this is urgent. Your Metabase is under attack. Update immediately to the patched release for your branch (0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5). if you can't pat...
-
Post #4437302
The state of #AI
-
Post #4429696
PEAR Ransomware Group Claims Breach of Arkansas Oral Surgery Practice Arkansas Oral & Maxillofacial Surgeons suffered a ransomware attack by the PEAR group, which claims to have stolen 2.1 terabytes of sensitive patient and corporate data. The practice confirmed the breach after an investigation and is now providing credit monitoring services to affected individuals. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/pear-ransomware-group-claims-bre...
-
Post #4413644
Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution. **If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers...
-
Post #4412584
Django Patches High-Severity File-Write Flaw in GeoDjango and Three Other Vulnerabilities Django 6.0.8 and 5.2.17 are out, fixing four security issues: most urgently a GeoDjango flaw (CVSS 8.8) that lets any staff user with view permission on a spatial-field model trigger SSRF or file writes, potentially leading to remote code execution. **If you run Django, upgrade now to Django 6.0.8 or 5.2.17. If you're on an older unsupported version like 5.1, 5.0 or 4.2, assume you're vulnerable a...
-
Post #4374431
Cardiovascular Institute of New England Email Breach Exposes Patient and Employee Data The Cardiovascular Institute of New England disclosed a data breach involving unauthorized access to an email account containing personal, financial, and protected health information belonging to patients and employees. The organization is offering potentially affected individuals complimentary credit monitoring and identity restoration services through Epiq. **** #cybersecurity #infosec #incident #databreac...
-
Post #4373118
CHAOS Ransomware Group Claims Data Theft from Radia Inc. The CHAOS ransomware group claims to have stolen 655 gigabytes of sensitive data from Radia Inc., P.S., including patient medical records, corporate financial documents, and employee payroll information. Radia Inc. has not officially confirmed the breach or filed notifications with federal health authorities. **** #cybersecurity #infosec #incident #ransomware https://beyondmachines.net/event_details/chaos-ransomware-group-claims-data-the...
-
Post #4370742
N-able Patches Critical N-central Authentication Bypass Exploited in the Wild N-able issued an emergency hotfix for N-central after attackers bypassed previous patches to gain administrative control over MSP servers. The flaw allows remote actors to hijack managed endpoints and establish persistent access via Cloudflare tunnels. **If you are using N-able N-central, this is urgent. Upgrade immediately to version 2026.3.1.7. Attackers are already exploiting the product to take over admin account...
-
Post #4358943
Liechtenstein Beneficial Ownership Register Breached, 31,000 Entities Exposed Liechtenstein's national register of beneficial owners (VwbP) used for anti-money laundering suffered a data breach on July 30, 2026, exposing the identity and ownership details of approximately 31,000 legal entities. A government crisis team is investigating the breach. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/liechtenstein-beneficial-ownership-register-breached...
-
Post #4355225
#AI Solutions looking for problems, version: IPO is coming!
-
Post #4327272
Redtail Technology Social Engineering Attack Compromises Financial Client Data Redtail Technology suffered a data breach in May 2026 after a social engineering attack against an employee allowed an unauthorized actor to steal client data belonging to J.W. Cole Advisors. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/redtail-technology-social-engineering-attack-compromises-financial-client-data-9-3-4-i-r/gD2P6Ple2L
-
Post #4299555
Blame someone else #catsofmastodon
-
Post #4285011
Lies, Damn Lies, Statistics and AI companies Still waiting for their leadership to be summarily fired after admitting to cybercrime.
-
Post #4280660
ShinyHunters Extortion Group Claims Massive Data Theft from Brinks Home Brinks Home suffered a data breach after the ShinyHunters group used a voice phishing attack to compromise a Microsoft Entra account and allegedly steal 4.9 million records from Salesforce and customer support systems. The company has engaged forensics experts and notified law enforcement. The company says its core alarm monitoring services is secure. **** #cybersecurity #infosec #incident #databreach https://beyondmachine...
-
Post #4279109
Oak Hill Data Breach Exposes Sensitive Information of 1,556 Individuals The Connecticut Institute for the Blind, dba Oak Hill, disclosed a data breach affecting 1,556 individuals after unauthorized actors gained access to network accounts and servers. The incident, detected in October 2025, exposed sensitive medical, financial, and personal information, leading to a federal report and the provision of credit monitoring services. **** #cybersecurity #infosec #incident #databreach https://beyond...
-
Post #4277547
Nuneaton and Bedworth Borough Council Leaks Voter Data via Email Error Nuneaton and Bedworth Borough Council accidentally leaked the personal details and security codes of 2,900 voters after an administrative error included a link to a sensitive spreadsheet in a mass email. The council has since removed the data, notified the Information Commissioner's Office, and contacted affected residents. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/nunea...
-
Post #4271032
IBM Patches Critical Remote Code Execution and Privilege Escalation Flaws in WebSphere IBM issued emergency patches for WebSphere Application Server to fix four vulnerabilities, including two critical flaws with CVSS scores of 9.8. These vulnerabilities allow unauthenticated attackers to execute code, escalate privileges, and perform server-side request forgery. **If you run IBM WebSphere Application Server (traditional 8.5 or 9.0) or WebSphere Liberty, plan a quick patch. Update to packs 9.0....
- Post #4270316
-
Post #4236426
ExfilSquad Threat Group Steals 742,000 Records from UK Education and Police Databases The UK Department for Education and the Police National Legal Database suffered a data breach involving 742,000 records stolen by the ExfilSquad threat group. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/exfilsquad-threat-group-steals-742000-records-from-uk-education-and-police-databases-j-5-e-8-4/gD2P6Ple2L
-
Post #4172434
JetBrains Fixes Critical TeamCity Authentication Bypass Allowing Remote Code Execution JetBrains patched a critical authentication bypass (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated remote code execution. The flaw affects all on-premises versions and could lead to a full takeover of CI/CD pipelines. **If you run TeamCity On-Premises, urgently update to version 2025.11.7 or 2026.1.3 to patch CVE-2026-63077. All on-premises versions are vulnerable to a full server takeov...
-
Post #4160481
GitLab Remote Code Execution Chain Exploits Long-Standing Memory Flaws in Oj Parser GitLab patched a critical remote code execution chain involving two memory corruption flaws in the Oj Ruby JSON parser that allow authenticated users to take over servers via malicious Jupyter notebook diffs. **If you run self-managed GitLab, upgrade immediately to version 18.10.8, 18.11.5, or 19.0.2. There's a working exploit published and any user who can push code to a project can take over the server. I...
-
Post #4159272
Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack Arista Networks released an emergency advisory for a CVSS 10.0 OS command injection vulnerability in VeloCloud Orchestrator On-Prem that is currently being exploited in the wild. The flaw allows unauthenticated attackers to gain full control over the orchestrator and all managed SD-WAN edge devices. **Make sure all VeloCloud Orchestrator On-Prem devices are isolated from the internet and accessible only from trusted ad...
-
Post #4158170
CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices. **If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your For...
-
Post #4144507
State of (in)security - Week 30, 2026 During week 30 of 2026, cybersecurity monitoring recorded 7 advisories and 28 incidents/breaches affecting roughly 80 million individuals. The largest breach is Suno exposing 55.3 million users and AI training source code. Malware/ransomware and unauthorized access are the leading causes of incidents and healthcare and IT/software as the most-targeted industries. **Patch the actively exploited on-premises SharePoint (CVE-2026-50522), self-hosted ServiceNow...
-
Post #4144458
Toss a coin to your trillionaire
-
Post #4141021
Michigan Surgical Center Reports Data Breach Following Ransomware Claims by The Gentlemen Group Michigan Surgical Center LLC disclosed a data breach on July 17, 2026, following ransomware claims by "The Gentlemen" group. The center is offering 24 months of free credit monitoring to affected individuals while investigating the extent of the unauthorized access. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/michigan-surgical-center-reports-...
-
Post #4134235
Lifespark Management Services Discloses Email Data Breach Involving Personal and Health Information Lifespark Management Services disclosed a data breach after an unauthorized party accessed information within its email environment, potentially exposing personal, financial, and protected health information. The company detected suspicious activity in February 2026, hired third-party forensic specialists, and published a data breach notice in July. **** #cybersecurity #infosec #incident #databr...
-
Post #4133175
Tribeca Film Festival Leaks Contact Details of Hollywood Elite in Database Misconfiguration The Tribeca Film Festival exposed over 666,000 records, including the private contact details of A-list celebrities, due to misconfigured databases that lacked password protection. The leak included email addresses, phone numbers, and device information, which could be used for targeted phishing and social engineering attacks. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net...
-
Post #4132075
Handala Hacktivist Group Claims Disruption on SupraNet The Iranian-linked threat actor Handala claimed a disruptive cyberattack against SupraNet Communications, causing widespread internet outages for thousands of businesses and government entities in Wisconsin. **** #cybersecurity #infosec #incident #vulnerability https://beyondmachines.net/event_details/handala-hacktivist-group-claims-disruption-on-supranet-8-r-c-l-0/gD2P6Ple2L