Elektrine lite

← Feed

BeyondMachines :verified:

beyondmachines1@infosec.exchange

<p>Enabling Good Cybersecurity for Everyone:<br />Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes.<br />Because cybersecurity shouldn&#39;t be an enterprise feature.</p><p>Sometimes a bot, sometimes not.</p>

Posts

  • View post

    Vista Del Mar Child and Family Services Reports Data Breach Involving Personal and Health Information Vista Del Mar Child and Family Services disclosed a data breach after an unauthorized actor accessed systems containing personal and protected health information. The organization took its network offline, engaged cybersecurity experts, and is reviewing affected files to identify and notify potentially impacted individuals. **** #cybersecurity #infosec #incident #databreach https://beyondmachi...

  • View post

    Park Place Behavioral Healthcare Data Breach Exposes Personal, Health, and Financial Information Park Place Behavioral Healthcare disclosed a data breach after an unauthorized party accessed its systems and copied files containing personal, health, and financial information. The organization reset account credentials and strengthened remote access controls. Park Place Behavioral Healthcare is offering complimentary credit monitoring and identity theft restoration services to affected individual...

  • View post

    CTOS Digital Discloses Unauthorized Access to Consumer Business Environment CTOS Digital disclosed unauthorized access to an environment supporting its consumer business, where a limited subset of processed consumer information was accessed. The company contained the incident, notified authorities, and temporarily disrupted some credit reporting services while an independent forensic investigation continues. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_de...

  • View post

    Arista Networks Patches Critical VeloCloud Orchestrator Zero-Day Exploited in the Wild Arista Networks disclosed a critical CVSS 10.0 vulnerability (CVE-2026-93952) in VeloCloud Orchestrator On-Prem that is being actively exploited to gain unauthenticated remote access to orchestrator hosts and managed edge devices. **If you run VeloCloud Orchestrator On-Prem, this is urgent. Make sure its web interface is not reachable from the internet and is accessible only from trusted admin networks, then...

  • View post

    BigCommerce Data Breach Linked to Compromised Ribon App Keys Attackers used compromised Ribon application keys to access customer records and inject malicious scripts into BigCommerce storefronts. The breach exposed personal information including names, contact details, and addresses, but not passwords or payment card data. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/bigcommerce-data-breach-linked-to-compromised-ribon-app-keys-a-u-4-1-d/gD2P6Ple2...

  • View post

    War going Agile

  • View post

    Critical Arbitrary File Upload Flaw in Gravity Forms Leads to Remote Code Execution Gravity Forms patched a critical vulnerability (CVE-2026-84434) that allows unauthenticated attackers to upload executable files and gain remote code execution. **If you use Gravity Forms on WordPress, update it to version 3.1.1 or later ASAP. If you can&#39;t update immediately, disable file upload fields on any public forms, then check your upload folders for unexpected PHP files and your logs for suspicious...

  • View post

    ShinyHunters Breaches Clop Ransomware Leak Site in Retaliatory Cyberattack ShinyHunters breached and defaced the Clop ransomware gang&#39;s leak site by exploiting a Grav CMS file upload vulnerability, allegedly stealing Tor private keys and system logs. The attack is a retaliatory move in an ongoing feud over a stolen Oracle E-Business Suite exploit. **** #cybersecurity #infosec #incident #ransomware https://beyondmachines.net/event_details/shinyhunters-breaches-clop-ransomware-leak-site-in-r...

  • View post

    CrowdSec Source Code Leak Linked to TanStack npm Supply Chain Attack CrowdSec suffered a source code leak after attackers exploited a TanStack npm supply chain vulnerability to steal a former employee&#39;s GitHub credentials. The breach exposed 170 private repositories and personal data for 134 users and investors. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/crowdsec-source-code-leak-linked-to-tanstack-npm-supply-chain-attack-6-u-i-d-6/gD2P6Ple2...

  • View post

    Alliance Environmental Group LLC Reports Cyberattack, Data Breach Alliance Environmental Group LLC reported a data breach involving unauthorized network access between April and May 2026, resulting in the acquisition of files containing names and other personal information. The company has secured its systems and is providing credit monitoring services to affected individuals. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/alliance-environmental-gro...

  • View post

    WSO2 Warns of Active Exploitation Targeting Critical Authentication Bypass WSO2 is warning of active exploitation of a critical authentication bypass vulnerability (CVE-2026-5430) that allows attackers to take over administrative accounts and steal sensitive API credentials. The flaw affects multiple middleware products and has been targeted in the wild since mid-September 2026. **If you run WSO2 API Manager, API Control Plane, Traffic Manager, or Universal Gateway, check for affected versions...

  • View post

    Apple Patches Hundreds of Vulnerabilities in September 2026 Security Update Apple&#39;s September 14, 2026 release of iOS 27, macOS Golden Gate 27, Safari 27 and its sibling updates patches over 200 CVEs, concentrated in WebKit, the kernel and drivers, and file-sharing/file-system code (SMB, WebDAV, autofs, disk images). The flaws enable universal XSS, root privilege escalation, kernel memory corruption from hostile servers or crafted volumes, Gatekeeper and sandbox bypasses, and arbitrary code...

  • View post

    The naked truth of #cybersecurity

  • View post

    SonicWall Patches Chained Zero-Day Vulnerabilities in SMA 1000 Series VPNs SonicWall has patched two zero-day vulnerabilities (CVE-2026-83548 and CVE-2026-83549) in its SMA 1000 series VPN appliances that attackers are chaining to achieve unauthenticated remote code execution. **If you run SonicWall SMA 1000 appliances (models 6210, 7210, or 8200v), update immediately to version 12.4.3-03526 or 12.5.0-02952. These devices are actively attacked to take over VPN gateways. After patching review y...

  • View post

    Kiewit Corporation Discloses Data Breach Following Microsoft 365 Account Compromise Kiewit Corporation reported a data breach after an unauthorized party accessed an employee&#39;s Microsoft 365 email account, exposing the personal and health information of employees and contractors. The company disabled the account, hired forensic experts, and is offering credit monitoring to the affected individuals. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/...

  • View post

    AliExpress Silent WebAudio Fingerprinting Uses Bluetooth Hardware AliExpress uses hidden WebAudio graphs to fingerprint devices, which blocks Bluetooth multipoint headphones from switching audio sources. The tracking relies on obfuscated scripts that maintain an active audio pipeline even when muted. **If you shop on AliExpress and your Bluetooth headphones stop switching between devices, this is caused by hidden tracking scripts on the site, not broken hardware. Install uBlock Origin and add...

  • View post

    MANTRA Chain Restores Block Production After Cosmos-EVM Module Exploit MANTRA Chain resumed operations after a 30-hour halt caused by an attacker exploiting a vulnerability in its Cosmos-EVM module&#39;s upstream dependencies. The incident affected two managed wallets but did not compromise user funds. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/mantra-chain-restores-block-production-after-cosmos-evm-module-exploit-z-b-z-7-s/gD2P6Ple2L

  • View post

    #AI rules to live by

  • View post

    Metabase Patches Critical Zero-Day SQL Injection Exploited in the Wild Metabase patched a critical zero-day SQL injection vulnerability (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) that is actively exploited to gain administrator access and steal database credentials. **If you run self-hosted Metabase (version 1.58 or newer), this is urgent. Your Metabase is under attack. Update immediately to the patched release for your branch (0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5). if you can&#39;t pat...

  • View post

    The state of #AI

  • View post

    PEAR Ransomware Group Claims Breach of Arkansas Oral Surgery Practice Arkansas Oral &amp; Maxillofacial Surgeons suffered a ransomware attack by the PEAR group, which claims to have stolen 2.1 terabytes of sensitive patient and corporate data. The practice confirmed the breach after an investigation and is now providing credit monitoring services to affected individuals. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/pear-ransomware-group-claims-bre...

  • View post

    Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution. **If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers...

  • View post

    Django Patches High-Severity File-Write Flaw in GeoDjango and Three Other Vulnerabilities Django 6.0.8 and 5.2.17 are out, fixing four security issues: most urgently a GeoDjango flaw (CVSS 8.8) that lets any staff user with view permission on a spatial-field model trigger SSRF or file writes, potentially leading to remote code execution. **If you run Django, upgrade now to Django 6.0.8 or 5.2.17. If you&#39;re on an older unsupported version like 5.1, 5.0 or 4.2, assume you&#39;re vulnerable a...

  • View post

    Cardiovascular Institute of New England Email Breach Exposes Patient and Employee Data The Cardiovascular Institute of New England disclosed a data breach involving unauthorized access to an email account containing personal, financial, and protected health information belonging to patients and employees. The organization is offering potentially affected individuals complimentary credit monitoring and identity restoration services through Epiq. **** #cybersecurity #infosec #incident #databreac...

  • View post

    CHAOS Ransomware Group Claims Data Theft from Radia Inc. The CHAOS ransomware group claims to have stolen 655 gigabytes of sensitive data from Radia Inc., P.S., including patient medical records, corporate financial documents, and employee payroll information. Radia Inc. has not officially confirmed the breach or filed notifications with federal health authorities. **** #cybersecurity #infosec #incident #ransomware https://beyondmachines.net/event_details/chaos-ransomware-group-claims-data-the...

  • View post

    N-able Patches Critical N-central Authentication Bypass Exploited in the Wild N-able issued an emergency hotfix for N-central after attackers bypassed previous patches to gain administrative control over MSP servers. The flaw allows remote actors to hijack managed endpoints and establish persistent access via Cloudflare tunnels. **If you are using N-able N-central, this is urgent. Upgrade immediately to version 2026.3.1.7. Attackers are already exploiting the product to take over admin account...

  • View post

    Liechtenstein Beneficial Ownership Register Breached, 31,000 Entities Exposed Liechtenstein&#39;s national register of beneficial owners (VwbP) used for anti-money laundering suffered a data breach on July 30, 2026, exposing the identity and ownership details of approximately 31,000 legal entities. A government crisis team is investigating the breach. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/liechtenstein-beneficial-ownership-register-breached...

  • View post

    #AI Solutions looking for problems, version: IPO is coming!

  • View post

    Redtail Technology Social Engineering Attack Compromises Financial Client Data Redtail Technology suffered a data breach in May 2026 after a social engineering attack against an employee allowed an unauthorized actor to steal client data belonging to J.W. Cole Advisors. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/redtail-technology-social-engineering-attack-compromises-financial-client-data-9-3-4-i-r/gD2P6Ple2L

  • View post

    Blame someone else #catsofmastodon