Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone:
Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes.
Because cybersecurity shouldn't be an enterprise feature.
Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Metabase Patches Critical Zero-Day SQL Injection Exploited in the Wild
Metabase patched a critical zero-day SQL injection vulnerability (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) that is actively exploited to gain administrator access and steal database credentials.
If you run self-hosted Metabase (version 1.58 or newer), this is urgent. Your Metabase is under attack. Update immediately to the patched release for your branch (0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5). if you can't patch right now, block all traffic to the /api/session/reset_password endpoint as a stopgap. After patching, check your application and ingress logs for a failed password-reset POST followed straight away by a successful /api/user/current request. Tf you see it, treat the instance as breached: clear the core_session table to log everyone out, rotate all connected database passwords, and check your admin accounts for anything you didn't create. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/metabase-patches-critical-zero-day-sql-injection-exploited-in-the-wild-g-o-s-u-u/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console
Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.
If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/veeam-patches-critical-credential-theft-and-rce-flaws-in-service-provider-console-y-k-8-e-6/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Django Patches High-Severity File-Write Flaw in GeoDjango and Three Other Vulnerabilities
Django 6.0.8 and 5.2.17 are out, fixing four security issues: most urgently a GeoDjango flaw (CVSS 8.8) that lets any staff user with view permission on a spatial-field model trigger SSRF or file writes, potentially leading to remote code execution.
If you run Django, upgrade now to Django 6.0.8 or 5.2.17. If you're on an older unsupported version like 5.1, 5.0 or 4.2, assume you're vulnerable and plan a move to a supported branch. If you use GeoDjango, test your spatial lookups before deploying because the fix intentionally breaks some old behaviour, and check who has staff/view access to models with map or location fields. That level of access is all an attacker needs for the most serious flaw. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/django-patches-high-severity-file-write-flaw-in-geodjango-and-three-other-vulnerabilities-d-x-1-q-e/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
N-able Patches Critical N-central Authentication Bypass Exploited in the Wild
N-able issued an emergency hotfix for N-central after attackers bypassed previous patches to gain administrative control over MSP servers. The flaw allows remote actors to hijack managed endpoints and establish persistent access via Cloudflare tunnels.
If you are using N-able N-central, this is urgent. Upgrade immediately to version 2026.3.1.7. Attackers are already exploiting the product to take over admin accounts on both on-premises and cloud-hosted servers. After patching, run N-able's provided scan templates on your Windows endpoints to check for signs of compromise (especially unexpected Cloudflare tunnel services), turn on multi-factor authentication, and review all user accounts and policy changes for anything you didn't make yourself. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/n-able-patches-critical-n-central-authentication-bypass-exploited-in-the-wild-7-r-o-r-u/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
IBM Patches Critical Remote Code Execution and Privilege Escalation Flaws in WebSphere
IBM issued emergency patches for WebSphere Application Server to fix four vulnerabilities, including two critical flaws with CVSS scores of 9.8. These vulnerabilities allow unauthenticated attackers to execute code, escalate privileges, and perform server-side request forgery.
If you run IBM WebSphere Application Server (traditional 8.5 or 9.0) or WebSphere Liberty, plan a quick patch. Update to packs 9.0.5.29 or 8.5.5.31 for traditional WebSphere, or upgrade Liberty to 26.0.0.9. WebSphere systems may be exposed to the internet by design, so prioritize those systems. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/ibm-patches-critical-remote-code-execution-and-privilege-escalation-flaws-in-websphere-7-h-7-4-3/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
JetBrains Fixes Critical TeamCity Authentication Bypass Allowing Remote Code Execution
JetBrains patched a critical authentication bypass (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated remote code execution. The flaw affects all on-premises versions and could lead to a full takeover of CI/CD pipelines.
If you run TeamCity On-Premises, urgently update to version 2025.11.7 or 2026.1.3 to patch CVE-2026-63077. All on-premises versions are vulnerable to a full server takeover. TeamCity Cloud is already patched and needs no action. If you can't update right away, install the security patch plugin (for versions 2017.1 and later) and restrict access to your TeamCity server to trusted internal networks or a VPN. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/jetbrains-fixes-critical-teamcity-authentication-bypass-allowing-remote-code-execution-c-x-w-3-z/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
GitLab Remote Code Execution Chain Exploits Long-Standing Memory Flaws in Oj Parser
GitLab patched a critical remote code execution chain involving two memory corruption flaws in the Oj Ruby JSON parser that allow authenticated users to take over servers via malicious Jupyter notebook diffs.
If you run self-managed GitLab, upgrade immediately to version 18.10.8, 18.11.5, or 19.0.2. There's a working exploit published and any user who can push code to a project can take over the server. If you're on version 15.2 through 18.9, those are no longer supported and won't get a patch, so you must move to a supported release to be protected. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/gitlab-remote-code-execution-chain-exploits-long-standing-memory-flaws-in-oj-parser-q-z-g-i-b/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack
Arista Networks released an emergency advisory for a CVSS 10.0 OS command injection vulnerability in VeloCloud Orchestrator On-Prem that is currently being exploited in the wild. The flaw allows unauthenticated attackers to gain full control over the orchestrator and all managed SD-WAN edge devices.
Make sure all VeloCloud Orchestrator On-Prem devices are isolated from the internet and accessible only from trusted administrative networks. Then immediately upgrade to a fixed release (5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1) and block the known malicious IPs (8.19.75.217, 206.72.242.124, 206.72.242.162) at your firewall. After patching rotate all credentials and certificates so attackers can't reuse any potentially stolen data. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/arista-patches-critical-velocloud-orchestrator-zero-day-under-active-attack-x-b-e-7-y/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass
CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.
If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-in-fortinet-fortios-ssl-vpn-patch-bypass-h-6-5-r-8/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
State of (in)security - Week 30, 2026
During week 30 of 2026, cybersecurity monitoring recorded 7 advisories and 28 incidents/breaches affecting roughly 80 million individuals. The largest breach is Suno exposing 55.3 million users and AI training source code. Malware/ransomware and unauthorized access are the leading causes of incidents and healthcare and IT/software as the most-targeted industries.
Patch the actively exploited on-premises SharePoint (CVE-2026-50522), self-hosted ServiceNow, Fastjson 1.x Java apps, Oracle systems (July 2026 Critical Patch Update), and WordPress. Then update Firefox and Thunderbird and confirm your Adobe Acrobat Chrome extension is running version 26.5.2.3 or later. #cybersecurity #infosec #knowledge #weeklyreport https://beyondmachines.net/event_details/state-of-in-security-week-30-2026-w-0-e-b-i/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Unexpected "Hi, How Are Things?" Can be a Phishing Indicator
A cold sales email using an innocuous "how are you?" opener, then falsely claiming an existing conversation ("great to hear back from you"), shows the same three techniques phishing attacks rely on: assumed familiarity, conversational bait-and-switch, and presumptive framing that manufactures trust and obligation. Swap the sales pitch for a credential re-authentication request, fake invoice, or malicious attachment and the identical architecture yields stolen credentials, money, or malware.
If a message opens with friendly small talk from someone whose name and role you can't immediately place, don't reply. A two-word answer confirms your inbox is live and lets the sender pretend you were already in conversation. Strip away the pleasantries and judge the actual request on its own. Would you do or respond to any of it without the niceties? #cybersecurity #infosec #scam #phishing #scamawareness https://beyondmachines.net/event_details/hi-how-are-things-is-an-attack-pattern-3-1-2-q-n/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Adobe Acrobat Extension Flaw HermeticReader Allowed Silent WhatsApp Data Theft
Adobe patched a high-severity vulnerability dubbed HermeticReader (CVE-2026-48294) in its Acrobat Chrome extension that allowed malicious websites to silently steal WhatsApp Web chat data and contacts.
If you use the Adobe Acrobat extension in Chrome, open your browser's extensions page and confirm it is running version 26.5.2.3 or later. Adobe already pushed the fix automatically, so most users are covered, but do verify yourself. If you can't confirm the version, remove the extension until you can verify. If you use WhatsApp Web on that browser, log out and re-link your device to invalidate any session an attacker could have touched. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/adobe-acrobat-extension-flaw-hermeticreader-allowed-silent-whatsapp-data-theft-6-w-7-t-g/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
SolarWinds Patches 15 Critical Vulnerabilities in Serv-U Managed File Transfer
SolarWinds released Serv-U 2026.3 to fix 15 critical vulnerabilities and one medium-severity flaw that allow remote code execution, privilege escalation, and account takeover.
If you use SolarWinds Serv-U Managed File Transfer software, update to version 2026.3 ASAP. After updating, turn on multi-factor authentication for all your Active Directory and LDAP users for added protection. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/solarwinds-patches-15-critical-vulnerabilities-in-serv-u-managed-file-transfer-l-j-4-9-9/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Oracle Issues Record-Breaking July 2026 Security Update with 1,449 Patches
Oracle's July 2026 Critical Patch Update addresses a record 1,434 unique vulnerabilities across 334 products, including ten CVSS 10.0 flaws in Fusion Middleware and a critical E-Business Suite RCE exploited in the Estée Lauder data breach.
Apply Oracle's July 2026 Critical Patch Update as soon as possibla. Prioritize the internet-facing systems and the critical (CVSS 9.8 to 10.0) flaws that attackers can exploit remotely without any login. If you can't patch right away, block the network access to the systems and limit user privileges. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/oracle-issues-record-breaking-july-2026-security-update-with-1449-patches-n-s-h-w-j/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Siemens Patches Multiple Vulnerabilities in SIDIS Secured SmartPlug
Siemens released security updates for the SIDIS Secured SmartPlug to fix 12 vulnerabilities, including a critical flaw in wireless authentication components. These flaws allow remote code execution, unauthorized access, and sensitive data disclosure in critical manufacturing environments.
Make sure your SIDIS Secured SmartPlug devices are isolated from the internet and reachable only from trusted networks, behind a firewall separated from your business network. Then update every affected device to version V7.26.0310 or later. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/siemens-patches-multiple-vulnerabilities-in-sidis-secured-smartplug-8-t-0-n-s/gD2P6Ple2L
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.
Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.