Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

BeyondMachines :verified:

@beyondmachines1@infosec.exchange
  • Open on infosec.exchange

Enabling Good Cybersecurity for Everyone:
Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes.
Because cybersecurity shouldn't be an enterprise feature.

Sometimes a bot, sometimes not.

2400 Followers
711 Following
50 Posts
Joined May 22, 2023
Website:
https://beyondmachines.net
Linkedin:
https://www.linkedin.com/company/73905832/
GitHub:
https://github.com/BeyondMachines

Posts

Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · 3d ago
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
#AI rules to live by
21
1
15
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · 6d ago
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

Metabase Patches Critical Zero-Day SQL Injection Exploited in the Wild

Metabase patched a critical zero-day SQL injection vulnerability (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) that is actively exploited to gain administrator access and steal database credentials.

If you run self-hosted Metabase (version 1.58 or newer), this is urgent. Your Metabase is under attack. Update immediately to the patched release for your branch (0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, or 0.63.5). if you can't patch right now, block all traffic to the /api/session/reset_password endpoint as a stopgap. After patching, check your application and ingress logs for a failed password-reset POST followed straight away by a successful /api/user/current request. Tf you see it, treat the instance as breached: clear the core_session table to log everyone out, rotate all connected database passwords, and check your admin accounts for anything you didn't create. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/metabase-patches-critical-zero-day-sql-injection-exploited-in-the-wild-g-o-s-u-u/gD2P6Ple2L

Metabase Patches Critical Zero-Day SQL Injection Exploited in the Wild
BeyondMachines

Metabase Patches Critical Zero-Day SQL Injection Exploited in the Wild

Metabase patched a critical zero-day SQL injection vulnerability (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) that is actively exploited to gain administrator access and steal database credentials.

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 07, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Replying to @david@voidposter.club
@david@voidposter.club Are we rewriting Neuromancer?
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 07, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Replying to @atlovato@mastodon.social
@atlovato@mastodon.social not even fired
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 07, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
The state of #AI
140
6
82
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 07, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
PEAR Ransomware Group Claims Breach of Arkansas Oral Surgery Practice Arkansas Oral & Maxillofacial Surgeons suffered a ransomware attack by the PEAR group, which claims to have stolen 2.1 terabytes of sensitive patient and corporate data. The practice confirmed the breach after an investigation and is now providing credit monitoring services to affected individuals. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/pear-ransomware-group-claims-breach-of-arkansas-oral-surgery-practice-k-d-4-y-9/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 06, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console

Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.

If you run Veeam Service Provider Console version 9.2.1.33875 or any earlier version 9 build, upgrade to version 9.3.0.35057 ASAP. These flaws let attackers take over the console that controls all of your customers' backups. Make sure to lock down the management portal so it's only reachable from a small list of trusted IP addresses, not the open internet. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/veeam-patches-critical-credential-theft-and-rce-flaws-in-service-provider-console-y-k-8-e-6/gD2P6Ple2L

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console
BeyondMachines

Veeam Patches Critical Credential Theft and RCE Flaws in Service Provider Console

Veeam patched four vulnerabilities in its Service Provider Console, including critical flaws (CVE-2026-58073 and CVE-2026-58072) that allow unauthenticated credential theft and remote code execution.

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 06, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

Django Patches High-Severity File-Write Flaw in GeoDjango and Three Other Vulnerabilities

Django 6.0.8 and 5.2.17 are out, fixing four security issues: most urgently a GeoDjango flaw (CVSS 8.8) that lets any staff user with view permission on a spatial-field model trigger SSRF or file writes, potentially leading to remote code execution.

If you run Django, upgrade now to Django 6.0.8 or 5.2.17. If you're on an older unsupported version like 5.1, 5.0 or 4.2, assume you're vulnerable and plan a move to a supported branch. If you use GeoDjango, test your spatial lookups before deploying because the fix intentionally breaks some old behaviour, and check who has staff/view access to models with map or location fields. That level of access is all an attacker needs for the most serious flaw. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/django-patches-high-severity-file-write-flaw-in-geodjango-and-three-other-vulnerabilities-d-x-1-q-e/gD2P6Ple2L

Django Patches High-Severity File-Write Flaw in GeoDjango and Three Other Vulnerabilities
BeyondMachines

Django Patches High-Severity File-Write Flaw in GeoDjango and Three Other Vulnerabilities

Django 6.0.8 and 5.2.17 are out, fixing four security issues: most urgently a GeoDjango flaw (CVSS 8.8) that lets any staff user with view permission on a spatial-field model trigger SSRF or file writ

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 04, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Cardiovascular Institute of New England Email Breach Exposes Patient and Employee Data The Cardiovascular Institute of New England disclosed a data breach involving unauthorized access to an email account containing personal, financial, and protected health information belonging to patients and employees. The organization is offering potentially affected individuals complimentary credit monitoring and identity restoration services through Epiq. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/cardiovascular-institute-of-new-england-email-breach-exposes-patient-and-employee-data-e-e-4-0-3/gD2P6Ple2L
Cardiovascular Institute of New England Email Breach Exposes Patient and Employee Data
BeyondMachines

Cardiovascular Institute of New England Email Breach Exposes Patient and Employee Data

The Cardiovascular Institute of New England disclosed a data breach involving unauthorized access to an email account containing personal, financial, and protected health information belonging to pati

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 04, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
CHAOS Ransomware Group Claims Data Theft from Radia Inc. The CHAOS ransomware group claims to have stolen 655 gigabytes of sensitive data from Radia Inc., P.S., including patient medical records, corporate financial documents, and employee payroll information. Radia Inc. has not officially confirmed the breach or filed notifications with federal health authorities. **** #cybersecurity #infosec #incident #ransomware https://beyondmachines.net/event_details/chaos-ransomware-group-claims-data-theft-from-radia-inc-5-f-v-v-y/gD2P6Ple2L
CHAOS Ransomware Group Claims Data Theft from Radia Inc.
BeyondMachines

CHAOS Ransomware Group Claims Data Theft from Radia Inc.

The CHAOS ransomware group claims to have stolen 655 gigabytes of sensitive data from Radia Inc., P.S., including patient medical records, corporate financial documents, and employee payroll informati

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 04, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

N-able Patches Critical N-central Authentication Bypass Exploited in the Wild

N-able issued an emergency hotfix for N-central after attackers bypassed previous patches to gain administrative control over MSP servers. The flaw allows remote actors to hijack managed endpoints and establish persistent access via Cloudflare tunnels.

If you are using N-able N-central, this is urgent. Upgrade immediately to version 2026.3.1.7. Attackers are already exploiting the product to take over admin accounts on both on-premises and cloud-hosted servers. After patching, run N-able's provided scan templates on your Windows endpoints to check for signs of compromise (especially unexpected Cloudflare tunnel services), turn on multi-factor authentication, and review all user accounts and policy changes for anything you didn't make yourself. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/n-able-patches-critical-n-central-authentication-bypass-exploited-in-the-wild-7-r-o-r-u/gD2P6Ple2L

N-able Patches Critical N-central Authentication Bypass Exploited in the Wild
BeyondMachines

N-able Patches Critical N-central Authentication Bypass Exploited in the Wild

N-able issued an emergency hotfix for N-central after attackers bypassed previous patches to gain administrative control over MSP servers. The flaw allows remote actors to hijack managed endpoints and

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 04, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Replying to @sigi714@ruhr.social
@sigi714@ruhr.social oh so very true https://x.com/_AlexHirsch/status/2083268104742924484
Alex Hirsch (@_AlexHirsch) on X
X (formerly Twitter)

Alex Hirsch (@_AlexHirsch) on X

@sama What if you just talked to your children

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 03, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Liechtenstein Beneficial Ownership Register Breached, 31,000 Entities Exposed Liechtenstein's national register of beneficial owners (VwbP) used for anti-money laundering suffered a data breach on July 30, 2026, exposing the identity and ownership details of approximately 31,000 legal entities. A government crisis team is investigating the breach. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/liechtenstein-beneficial-ownership-register-breached-31000-entities-exposed-y-t-1-h-9/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 03, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
#AI Solutions looking for problems, version: IPO is coming!
12
2
12
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Aug 02, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Redtail Technology Social Engineering Attack Compromises Financial Client Data Redtail Technology suffered a data breach in May 2026 after a social engineering attack against an employee allowed an unauthorized actor to steal client data belonging to J.W. Cole Advisors. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/redtail-technology-social-engineering-attack-compromises-financial-client-data-9-3-4-i-r/gD2P6Ple2L
Redtail Technology Social Engineering Attack Compromises Financial Client Data
BeyondMachines

Redtail Technology Social Engineering Attack Compromises Financial Client Data

Redtail Technology suffered a data breach in May 2026 after a social engineering attack against an employee allowed an unauthorized actor to steal client data belonging to J.W. Cole Advisors.

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 31, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Lies, Damn Lies, Statistics and AI companies Still waiting for their leadership to be summarily fired after admitting to cybercrime.
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 31, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
ShinyHunters Extortion Group Claims Massive Data Theft from Brinks Home Brinks Home suffered a data breach after the ShinyHunters group used a voice phishing attack to compromise a Microsoft Entra account and allegedly steal 4.9 million records from Salesforce and customer support systems. The company has engaged forensics experts and notified law enforcement. The company says its core alarm monitoring services is secure. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/shinyhunters-extortion-group-claims-massive-data-theft-from-brinks-home-y-m-g-2-a/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 31, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Oak Hill Data Breach Exposes Sensitive Information of 1,556 Individuals The Connecticut Institute for the Blind, dba Oak Hill, disclosed a data breach affecting 1,556 individuals after unauthorized actors gained access to network accounts and servers. The incident, detected in October 2025, exposed sensitive medical, financial, and personal information, leading to a federal report and the provision of credit monitoring services. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/oak-hill-data-breach-exposes-sensitive-information-of-1556-individuals-k-1-a-d-t/gD2P6Ple2L
Oak Hill Data Breach Exposes Sensitive Information of 1,556 Individuals
BeyondMachines

Oak Hill Data Breach Exposes Sensitive Information of 1,556 Individuals

The Connecticut Institute for the Blind, dba Oak Hill, disclosed a data breach affecting 1,556 individuals after unauthorized actors gained access to network accounts and servers. The incident, detect

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 31, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Nuneaton and Bedworth Borough Council Leaks Voter Data via Email Error Nuneaton and Bedworth Borough Council accidentally leaked the personal details and security codes of 2,900 voters after an administrative error included a link to a sensitive spreadsheet in a mass email. The council has since removed the data, notified the Information Commissioner's Office, and contacted affected residents. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/nuneaton-and-bedworth-borough-council-leaks-voter-data-via-email-error-6-8-a-m-o/gD2P6Ple2L
1
0
1
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 31, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Replying to @campuscodi@mastodon.social
@campuscodi@mastodon.social Anthropic is still lying Chrome has more critical flaws EU is still playing lawyer Governments are doing banning as usual, some for good reasons some for less good reasons. The world keeps turning:
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 31, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

IBM Patches Critical Remote Code Execution and Privilege Escalation Flaws in WebSphere

IBM issued emergency patches for WebSphere Application Server to fix four vulnerabilities, including two critical flaws with CVSS scores of 9.8. These vulnerabilities allow unauthenticated attackers to execute code, escalate privileges, and perform server-side request forgery.

If you run IBM WebSphere Application Server (traditional 8.5 or 9.0) or WebSphere Liberty, plan a quick patch. Update to packs 9.0.5.29 or 8.5.5.31 for traditional WebSphere, or upgrade Liberty to 26.0.0.9. WebSphere systems may be exposed to the internet by design, so prioritize those systems. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/ibm-patches-critical-remote-code-execution-and-privilege-escalation-flaws-in-websphere-7-h-7-4-3/gD2P6Ple2L

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 31, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 30, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
ExfilSquad Threat Group Steals 742,000 Records from UK Education and Police Databases The UK Department for Education and the Police National Legal Database suffered a data breach involving 742,000 records stolen by the ExfilSquad threat group. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/exfilsquad-threat-group-steals-742000-records-from-uk-education-and-police-databases-j-5-e-8-4/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 28, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

JetBrains Fixes Critical TeamCity Authentication Bypass Allowing Remote Code Execution

JetBrains patched a critical authentication bypass (CVE-2026-63077) in TeamCity On-Premises that allows unauthenticated remote code execution. The flaw affects all on-premises versions and could lead to a full takeover of CI/CD pipelines.

If you run TeamCity On-Premises, urgently update to version 2025.11.7 or 2026.1.3 to patch CVE-2026-63077. All on-premises versions are vulnerable to a full server takeover. TeamCity Cloud is already patched and needs no action. If you can't update right away, install the security patch plugin (for versions 2017.1 and later) and restrict access to your TeamCity server to trusted internal networks or a VPN. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/jetbrains-fixes-critical-teamcity-authentication-bypass-allowing-remote-code-execution-c-x-w-3-z/gD2P6Ple2L

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 28, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

GitLab Remote Code Execution Chain Exploits Long-Standing Memory Flaws in Oj Parser

GitLab patched a critical remote code execution chain involving two memory corruption flaws in the Oj Ruby JSON parser that allow authenticated users to take over servers via malicious Jupyter notebook diffs.

If you run self-managed GitLab, upgrade immediately to version 18.10.8, 18.11.5, or 19.0.2. There's a working exploit published and any user who can push code to a project can take over the server. If you're on version 15.2 through 18.9, those are no longer supported and won't get a patch, so you must move to a supported release to be protected. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/gitlab-remote-code-execution-chain-exploits-long-standing-memory-flaws-in-oj-parser-q-z-g-i-b/gD2P6Ple2L

1
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 28, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack

Arista Networks released an emergency advisory for a CVSS 10.0 OS command injection vulnerability in VeloCloud Orchestrator On-Prem that is currently being exploited in the wild. The flaw allows unauthenticated attackers to gain full control over the orchestrator and all managed SD-WAN edge devices.

Make sure all VeloCloud Orchestrator On-Prem devices are isolated from the internet and accessible only from trusted administrative networks. Then immediately upgrade to a fixed release (5.2.3.14, 6.1.3.4, 6.4.2.4, or 7.0.0.1) and block the known malicious IPs (8.19.75.217, 206.72.242.124, 206.72.242.162) at your firewall. After patching rotate all credentials and certificates so attackers can't reuse any potentially stolen data. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/arista-patches-critical-velocloud-orchestrator-zero-day-under-active-attack-x-b-e-7-y/gD2P6Ple2L

Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack
BeyondMachines

Arista Patches Critical VeloCloud Orchestrator Zero-Day Under Active Attack

Arista Networks released an emergency advisory for a CVSS 10.0 OS command injection vulnerability in VeloCloud Orchestrator On-Prem that is currently being exploited in the wild. The flaw allows unaut

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 28, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass

CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.

If you use Fortinet devices, make sure they are isolated from the internet and accessible only from trusted networks. Then update FortiOS ASAP to version 7.6.2, 7.4.7, or later. This flaw is combined with others, so make sure all your Fortinet devices are up-to-date. And check your devices for indicators of compromise, this flaw allowed hackers to maintain access over patch cycles. #cybersecurity #infosec #attack #activeexploit https://beyondmachines.net/event_details/cisa-warns-of-active-exploitation-in-fortinet-fortios-ssl-vpn-patch-bypass-h-6-5-r-8/gD2P6Ple2L

CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass
BeyondMachines

CISA Warns of Active Exploitation in Fortinet FortiOS SSL-VPN Patch Bypass

CISA reports active explotation of CVE-2025-68686, a flaw in Fortinet FortiOS that allows attackers to bypass security patches and maintain persistent access on compromised devices.

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 27, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

State of (in)security - Week 30, 2026

During week 30 of 2026, cybersecurity monitoring recorded 7 advisories and 28 incidents/breaches affecting roughly 80 million individuals. The largest breach is Suno exposing 55.3 million users and AI training source code. Malware/ransomware and unauthorized access are the leading causes of incidents and healthcare and IT/software as the most-targeted industries.

Patch the actively exploited on-premises SharePoint (CVE-2026-50522), self-hosted ServiceNow, Fastjson 1.x Java apps, Oracle systems (July 2026 Critical Patch Update), and WordPress. Then update Firefox and Thunderbird and confirm your Adobe Acrobat Chrome extension is running version 26.5.2.3 or later. #cybersecurity #infosec #knowledge #weeklyreport https://beyondmachines.net/event_details/state-of-in-security-week-30-2026-w-0-e-b-i/gD2P6Ple2L

State of (in)security - Week 30, 2026
BeyondMachines

State of (in)security - Week 30, 2026

During week 30 of 2026, cybersecurity monitoring recorded 7 advisories and 28 incidents/breaches affecting roughly 80 million individuals. The largest breach is Suno exposing 55.3 million users and AI

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 27, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Toss a coin to your trillionaire
0
1
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 27, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Michigan Surgical Center Reports Data Breach Following Ransomware Claims by The Gentlemen Group Michigan Surgical Center LLC disclosed a data breach on July 17, 2026, following ransomware claims by "The Gentlemen" group. The center is offering 24 months of free credit monitoring to affected individuals while investigating the extent of the unauthorized access. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/michigan-surgical-center-reports-data-breach-following-ransomware-claims-by-the-gentlemen-group-0-w-a-j-3/gD2P6Ple2L
Michigan Surgical Center Reports Data Breach Following Ransomware Claims by The Gentlemen Group
BeyondMachines

Michigan Surgical Center Reports Data Breach Following Ransomware Claims by The Gentlemen Group

Michigan Surgical Center LLC disclosed a data breach on July 17, 2026, following ransomware claims by "The Gentlemen" group. The center is offering 24 months of free credit monitoring to affected indi

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 27, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Lifespark Management Services Discloses Email Data Breach Involving Personal and Health Information Lifespark Management Services disclosed a data breach after an unauthorized party accessed information within its email environment, potentially exposing personal, financial, and protected health information. The company detected suspicious activity in February 2026, hired third-party forensic specialists, and published a data breach notice in July. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/lifespark-management-services-discloses-email-data-breach-involving-personal-and-health-information-u-a-9-1-p/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 27, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Tribeca Film Festival Leaks Contact Details of Hollywood Elite in Database Misconfiguration The Tribeca Film Festival exposed over 666,000 records, including the private contact details of A-list celebrities, due to misconfigured databases that lacked password protection. The leak included email addresses, phone numbers, and device information, which could be used for targeted phishing and social engineering attacks. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/tribeca-film-festival-leaks-contact-details-of-hollywood-elite-in-database-misconfiguration-n-l-x-w-t/gD2P6Ple2L
1
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 27, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Handala Hacktivist Group Claims Disruption on SupraNet The Iranian-linked threat actor Handala claimed a disruptive cyberattack against SupraNet Communications, causing widespread internet outages for thousands of businesses and government entities in Wisconsin. **** #cybersecurity #infosec #incident #vulnerability https://beyondmachines.net/event_details/handala-hacktivist-group-claims-disruption-on-supranet-8-r-c-l-0/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 26, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Cure Dental Confirms Ransomware Breach Exposing Sensitive Patient Data Cure Dental, a Texas-based practice, suffered a ransomware attack by the ThreeAM group that exposed the personal data of 878 individuals. The breach was detected in June 2025, but notifications were sent out over a year later inl July 2026. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/cure-dental-confirms-ransomware-breach-exposing-sensitive-patient-data-8-l-s-3-9/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 26, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Heart Care Centers of Illinois Reports Multi-Month Email Breach Following Phishing Attack Heart Care Centers of Illinois reports a data breach after a phishing attack allowed unauthorized access to an employee email account for over two months in 2024. The breach, discovered in 2026, exposed sensitive patient information including Social Security numbers, financial data, and detailed medical records. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/heart-care-centers-of-illinois-reports-multi-month-email-breach-following-phishing-attack-5-3-r-9-l/gD2P6Ple2L
1
1
1
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 25, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Thialf Ice Skating Stadium Targeted in Ransomware Attack by TheGentlemen Group Thialf, a Dutch ice arena and 2030 Olympic venue, suffered a ransomware attack by TheGentlemen group in July 2026. The breach compromised internal documents, employee data, and financial contracts. **** #cybersecurity #infosec #incident #ransomware https://beyondmachines.net/event_details/thialf-ice-skating-stadium-targeted-in-ransomware-attack-by-thegentlemen-group-u-l-0-r-d/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 25, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Fiesta Insurance Reports Data Breach Affecting 160,000 Individuals Fiesta Insurance Franchise Corporation reports a cybersecurity incident that remained under investigation for over a year, exposing the sensitive personal and financial data of 160,151 individuals. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/fiesta-insurance-reports-data-breach-affecting-160000-individuals-z-r-f-m-m/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 25, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Anatomic and Clinical Laboratory Associates Discloses Data Breach Affecting 170,000 Patients Anatomic and Clinical Laboratory Associates suffered a network server breach that exposed the sensitive medical and personal data of nearly 170,000 patients. The incident was part of a series of healthcare sector attacks involving unauthorized access, email compromises, and ransomware. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/anatomic-and-clinical-laboratory-associates-discloses-data-breach-affecting-170000-patients-1-s-o-n-k/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 24, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

Unexpected "Hi, How Are Things?" Can be a Phishing Indicator

A cold sales email using an innocuous "how are you?" opener, then falsely claiming an existing conversation ("great to hear back from you"), shows the same three techniques phishing attacks rely on: assumed familiarity, conversational bait-and-switch, and presumptive framing that manufactures trust and obligation. Swap the sales pitch for a credential re-authentication request, fake invoice, or malicious attachment and the identical architecture yields stolen credentials, money, or malware.

If a message opens with friendly small talk from someone whose name and role you can't immediately place, don't reply. A two-word answer confirms your inbox is live and lets the sender pretend you were already in conversation. Strip away the pleasantries and judge the actual request on its own. Would you do or respond to any of it without the niceties? #cybersecurity #infosec #scam #phishing #scamawareness https://beyondmachines.net/event_details/hi-how-are-things-is-an-attack-pattern-3-1-2-q-n/gD2P6Ple2L

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 24, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Upbound Group Discloses Data Breach and $13 Million in Fraudulent Contract Losses Upbound Group reported a data breach where hackers stole customer information to create $13 million in fraudulent lease-to-own contracts. The company is working with external experts to enhance security controls and has notified federal law enforcement. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/upbound-group-discloses-data-breach-and-13-million-in-fraudulent-contract-losses-k-e-3-w-h/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 23, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

Adobe Acrobat Extension Flaw HermeticReader Allowed Silent WhatsApp Data Theft

Adobe patched a high-severity vulnerability dubbed HermeticReader (CVE-2026-48294) in its Acrobat Chrome extension that allowed malicious websites to silently steal WhatsApp Web chat data and contacts.

If you use the Adobe Acrobat extension in Chrome, open your browser's extensions page and confirm it is running version 26.5.2.3 or later. Adobe already pushed the fix automatically, so most users are covered, but do verify yourself. If you can't confirm the version, remove the extension until you can verify. If you use WhatsApp Web on that browser, log out and re-link your device to invalidate any session an attacker could have touched. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/adobe-acrobat-extension-flaw-hermeticreader-allowed-silent-whatsapp-data-theft-6-w-7-t-g/gD2P6Ple2L

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 23, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Chick-fil-A Confirms Credential Stuffing Attack Impacting Loyalty Accounts Chick-fil-A suffered a credential stuffing attack in June 2026 where unauthorized parties used stolen third-party credentials to access loyalty accounts and expose personal data. The company responded by forcing logouts, resetting passwords, and restoring account balances for affected customers. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/chick-fil-a-confirms-credential-stuffing-attack-impacting-loyalty-accounts-h-q-w-0-1/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 23, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

SolarWinds Patches 15 Critical Vulnerabilities in Serv-U Managed File Transfer

SolarWinds released Serv-U 2026.3 to fix 15 critical vulnerabilities and one medium-severity flaw that allow remote code execution, privilege escalation, and account takeover.

If you use SolarWinds Serv-U Managed File Transfer software, update to version 2026.3 ASAP. After updating, turn on multi-factor authentication for all your Active Directory and LDAP users for added protection. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/solarwinds-patches-15-critical-vulnerabilities-in-serv-u-managed-file-transfer-l-j-4-9-9/gD2P6Ple2L

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 23, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Progress
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 23, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

Oracle Issues Record-Breaking July 2026 Security Update with 1,449 Patches

Oracle's July 2026 Critical Patch Update addresses a record 1,434 unique vulnerabilities across 334 products, including ten CVSS 10.0 flaws in Fusion Middleware and a critical E-Business Suite RCE exploited in the Estée Lauder data breach.

Apply Oracle's July 2026 Critical Patch Update as soon as possibla. Prioritize the internet-facing systems and the critical (CVSS 9.8 to 10.0) flaws that attackers can exploit remotely without any login. If you can't patch right away, block the network access to the systems and limit user privileges. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/oracle-issues-record-breaking-july-2026-security-update-with-1449-patches-n-s-h-w-j/gD2P6Ple2L

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 22, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Origin Energy Investigates Potential Data Breach After Hacker Claims 2 Million Customer Records Stolen Origin Energy disclosed a potential data breach after a hacker claimed to have stolen records belonging to approximately two million customers and provided samples to media outlets. The company notified Australian cybersecurity, law enforcement, and privacy authorities and is investigating the scope of the unauthorized access. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/origin-energy-investigates-potential-data-breach-after-hacker-claims-2-million-customer-records-stolen-5-4-p-0-x/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 22, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange

Siemens Patches Multiple Vulnerabilities in SIDIS Secured SmartPlug

Siemens released security updates for the SIDIS Secured SmartPlug to fix 12 vulnerabilities, including a critical flaw in wireless authentication components. These flaws allow remote code execution, unauthorized access, and sensitive data disclosure in critical manufacturing environments.

Make sure your SIDIS Secured SmartPlug devices are isolated from the internet and reachable only from trusted networks, behind a firewall separated from your business network. Then update every affected device to version V7.26.0310 or later. #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/siemens-patches-multiple-vulnerabilities-in-sidis-secured-smartplug-8-t-0-n-s/gD2P6Ple2L

0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 22, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
SOC Defense Contractor Reports Email Breach Exposing Medical Records and SSNs SOC, a Day & Zimmermann company, reports a data breach after an unauthorized party gained access to a single corporate email account containing Social Security numbers and medical records. The defense contractor isolated the breach to the affected account and is offering 18 months of credit monitoring via a reimbursement model. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/soc-defense-contractor-reports-email-breach-exposing-medical-records-and-ssns-r-0-d-4-v/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 22, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Suno Data Breach Exposes 55 Million Users and Internal AI Training Source Code Suno suffered a data breach in November 2025 that exposed the personal information of 55.3 million users and internal source code detailing its AI training practices. The incident, reported in July 2026, was caused by a supply chain attack using the Shai-Hulud worm to steal employee credentials. **** #cybersecurity #infosec #incident #databreach https://beyondmachines.net/event_details/suno-data-breach-exposes-55-million-users-and-internal-ai-training-source-code-g-b-1-f-b/gD2P6Ple2L
0
0
0
0
Open post
beyondmachines1
BeyondMachines :verified: @beyondmachines1@infosec.exchange · Jul 22, 2026
BeyondMachines :verified:
@beyondmachines1@infosec.exchange

Enabling Good Cybersecurity for Everyone: Automated cybersecurity tools, learning and expert guidance for individuals and companies of all sizes. Because cybersecurity shouldn't be an enterprise feature. Sometimes a bot, sometimes not.

infosec.exchange
Just another day in the #AI bubble: attacking other companies is now OK. The marketing hype: ChatGPT is as strong as Mythos. The reality: Huggingface got hacked, and OpenAI admitted to hacking them. In my opinion, nothing "escaped". It was allowed to hack with zero restrictions so Scam can flog the value of their statistical parrot. Even if the parrot did "escape", it can't be held accountable. But the legal and natural persons that ran it most definitely can, and MUST. In my opinion, OpenAI must be sued into the ground and management must be summarily fired.
0
0
0
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 23:30:26 UTC