⤷ Title: CVE-2026-4370 (CVSS 10): Critical Juju Flaw Grants Attackers Total Infrastructure Control
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 14:01:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Application Management #Canonical #Cloud Security #CVE_2026_4370 #CVSS 10.0 #Dqlite #infosec #Juju #Kubernetes #Orchestration #Patch Alert #tls
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 14:01:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Application Management #Canonical #Cloud Security #CVE_2026_4370 #CVSS 10.0 #Dqlite #infosec #Juju #Kubernetes #Orchestration #Patch Alert #tls
Daily CyberSecurity
CVE-2026-4370 (CVSS 10): Critical Juju Flaw Grants Attackers Total Infrastructure Control
Juju hits a perfect 10.0 CVSS score (CVE-2026-4370). A TLS flaw on port 17666 lets attackers hijack clusters. Update to 3.6.20 or 4.0.5 now!
⤷ Title: Breaking the Input: Sandbox Escape Hits libinput, Exposing Leading Linux Desktops
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 13:02:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_35093 #CVE_2026_35094 #Fedora #gnome #infosec #kde #KWin #libinput #Linux Security #Lua Vulnerability #Mutter #Patch Alert #Sandbox Escape
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 13:02:48 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_35093 #CVE_2026_35094 #Fedora #gnome #infosec #kde #KWin #libinput #Linux Security #Lua Vulnerability #Mutter #Patch Alert #Sandbox Escape
Daily CyberSecurity
Breaking the Input: Sandbox Escape Hits libinput, Exposing Leading Linux Desktops
Critical 8.8 CVSS flaw in libinput allows sandbox escape via malicious Lua plugins. Affects GNOME, KDE, and Fedora. Update to 1.31.1 or 1.30.3 now!
⤷ Title: The MuPDF Vulnerability Turning “Safe” PDFs into System Hijackers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 12:00:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Artifex #CVE_2026_3308 #heap overflow #infosec #integer overflow #Linux Security #Memory Management #MuPDF #PDF Security #rce #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 12:00:29 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Artifex #CVE_2026_3308 #heap overflow #infosec #integer overflow #Linux Security #Memory Management #MuPDF #PDF Security #rce #Vulnerability
Daily CyberSecurity
The MuPDF Vulnerability Turning "Safe" PDFs into System Hijackers
Artifex MuPDF faces a 7.8 CVSS integer overflow (CVE-2026-3308) allowing RCE via "crafted" PDFs. With no official patch, sandboxing is vital. Update now.
⤷ Title: The EU’s AWS “Master Key”: How a Compromised Trivy Update Leaked 340GB of Data
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 09:40:11 +0000
════════════════════════
⌗ Tags: #Data Leak #API Key Theft #aws security #CERT_EU #CI/CD security #data leak #EU Security #European Commission #infosec #ShinyHunters #supply chain attack #TeamPCP #Trivy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 09:40:11 +0000
════════════════════════
⌗ Tags: #Data Leak #API Key Theft #aws security #CERT_EU #CI/CD security #data leak #EU Security #European Commission #infosec #ShinyHunters #supply chain attack #TeamPCP #Trivy
Daily CyberSecurity
The EU’s AWS "Master Key": How a Compromised Trivy Update Leaked 340GB of Data
A massive supply-chain attack hit the European Commission via a compromised Trivy update. 340GB of data was leaked by ShinyHunters. Rotate your AWS keys!
⤷ Title: The WordPress Killer? Cloudflare Unveils EmDash, the AI-Native CMS Built for the Serverless Epoch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 09:15:52 +0000
════════════════════════
⌗ Tags: #Technology #AI_native #Astro 6.0 #cloudflare #cms #Cybersecurity 2026 #EmDash #open_source #serverless #TypeScript #V8 Isolate #WordPress Alternative
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 09:15:52 +0000
════════════════════════
⌗ Tags: #Technology #AI_native #Astro 6.0 #cloudflare #cms #Cybersecurity 2026 #EmDash #open_source #serverless #TypeScript #V8 Isolate #WordPress Alternative
Daily CyberSecurity
The WordPress Killer? Cloudflare Unveils EmDash, the AI-Native CMS Built for the Serverless Epoch
Cloudflare debuts EmDash, an AI-native, serverless CMS built on Astro 6.0. Say goodbye to WordPress plugin hacks with V8 isolate sandboxing and passkey security.
⤷ Title: OpenSSH 10.3 Patches Command Execution and “scp” Privilege Escalation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 08:00:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2026_35385 #CVE_2026_35386 #infosec #Linux Security #OpenSSH #OpenSSH 10.3 #Patch Alert #privilege escalation #Remote Access #SCP #SSH security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 08:00:11 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Command Injection #CVE_2026_35385 #CVE_2026_35386 #infosec #Linux Security #OpenSSH #OpenSSH 10.3 #Patch Alert #privilege escalation #Remote Access #SCP #SSH security
Daily CyberSecurity
OpenSSH 10.3 Patches Command Execution and "scp" Privilege Escalation
OpenSSH 10.3 fixes critical gaps, including client-side command execution and scp privilege escalation flaws. Update your remote access stacks immediately.
⤷ Title: The Resurrection of the Beam: Google Challenges AirDrop with Android 17’s “Tap to Share”
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 07:23:37 +0000
════════════════════════
⌗ Tags: #Android #AirDrop #Android 17 #Android 4.0 Beam #Google Play Services #NameDrop #NFC #Quick Share #Samsung One UI 9 #Smartphone Ecosystem #Tap to Share #Tech News 2026 #UWB
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 07:23:37 +0000
════════════════════════
⌗ Tags: #Android #AirDrop #Android 17 #Android 4.0 Beam #Google Play Services #NameDrop #NFC #Quick Share #Samsung One UI 9 #Smartphone Ecosystem #Tap to Share #Tech News 2026 #UWB
Daily CyberSecurity
The Resurrection of the Beam: Google Challenges AirDrop with Android 17’s "Tap to Share"
Google’s "Tap to Share" leaked for Android 17! Using NFC and UWB, this new Quick Share feature aims to end AirDrop's dominance. Discover how it works.
⤷ Title: Inside the Rapid Evolution of the BlankGrabber Stealer
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 07:15:56 +0000
════════════════════════
⌗ Tags: #Malware #BlankGrabber #Browser Secrets #Certutil #Cyber Security #data exfiltration #Discord Security #github #info_stealer #Python Malware #Splunk Threat Research #Telegram C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 07:15:56 +0000
════════════════════════
⌗ Tags: #Malware #BlankGrabber #Browser Secrets #Certutil #Cyber Security #data exfiltration #Discord Security #github #info_stealer #Python Malware #Splunk Threat Research #Telegram C2
Daily CyberSecurity
Inside the Rapid Evolution of the BlankGrabber Stealer
Splunk unmasks BlankGrabber: a modular Python info stealer using Discord and GitHub to swipe credentials and Discord tokens. Learn how to stay protected.
⤷ Title: The Apache 2.0 Revolution: Google’s Gemma 4 Shatters the Open-Source Intelligence Ceiling
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 07:15:17 +0000
════════════════════════
⌗ Tags: #Technology #AI 2026 #Apache 2.0 #Edge AI #Gemini 3 Pro #Gemma 4 #google #Hugging Face #LLM #machine_learning #Mixture_of_Experts #open_source
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 07:15:17 +0000
════════════════════════
⌗ Tags: #Technology #AI 2026 #Apache 2.0 #Edge AI #Gemini 3 Pro #Gemma 4 #google #Hugging Face #LLM #machine_learning #Mixture_of_Experts #open_source
Daily CyberSecurity
The Apache 2.0 Revolution: Google’s Gemma 4 Shatters the Open-Source Intelligence Ceiling
Google releases Gemma 4 under the Apache 2.0 license. Featuring multimodal edge models and a 31B "Dense" system, it redefines AI digital sovereignty for 2026.
⤷ Title: The Lobster Craze: How OpenClaw is Triggering a High-Stakes AI Agent Arms Race in China
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 07:10:16 +0000
════════════════════════
⌗ Tags: #Technology #AI Agents #ByteDance #HyperOS #Lobster Husbandry #Mirror Site #OpenAI #OpenClaw #OPPO #Peter Steinberger #Sam Altman #soul.md #WeChat #Xiaomi
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 07:10:16 +0000
════════════════════════
⌗ Tags: #Technology #AI Agents #ByteDance #HyperOS #Lobster Husbandry #Mirror Site #OpenAI #OpenClaw #OPPO #Peter Steinberger #Sam Altman #soul.md #WeChat #Xiaomi
Daily CyberSecurity
The Lobster Craze: How OpenClaw is Triggering a High-Stakes AI Agent Arms Race in China
ByteDance and OpenAI are racing to dominate "Lobster Husbandry." Discover how the OpenClaw agent is transforming WeChat, Xiaomi, and the global AI landscape.
⤷ Title: Microsoft’s Declaration of Independence: The New MAI Models Challenging OpenAI and Google
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 07:00:43 +0000
════════════════════════
⌗ Tags: #Technology #artificial intelligence #Cloud Computing #GPU Efficiency #MAI_Image_2 #MAI_Transcribe_1 #MAI_Voice_1 #Microsoft #Microsoft Foundry #Mustafa Suleyman #OpenAI #Tech News 2026
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 07:00:43 +0000
════════════════════════
⌗ Tags: #Technology #artificial intelligence #Cloud Computing #GPU Efficiency #MAI_Image_2 #MAI_Transcribe_1 #MAI_Voice_1 #Microsoft #Microsoft Foundry #Mustafa Suleyman #OpenAI #Tech News 2026
Daily CyberSecurity
Microsoft’s Declaration of Independence: The New MAI Models Challenging OpenAI and Google
Microsoft CEO Mustafa Suleyman unveils MAI-Transcribe-1, MAI-Voice-1, and MAI-Image-2—proprietary AI built to undercut competitors and secure self-sufficiency.
⤷ Title: Apple Severs All Payment Processing in Russia Following Government Mandates
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 06:49:01 +0000
════════════════════════
⌗ Tags: #Technology #App Store #Apple #Digital Sovereignty #iCloud #in_app purchases #payments #russia #sanctions #Tech News 2026 #VPN Crackdown
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 06:49:01 +0000
════════════════════════
⌗ Tags: #Technology #App Store #Apple #Digital Sovereignty #iCloud #in_app purchases #payments #russia #sanctions #Tech News 2026 #VPN Crackdown
Daily CyberSecurity
Apple Severs All Payment Processing in Russia Following Government Mandates
Apple officially ceases all payment services in Russia as of April 1, 2026. Subscriptions, App Store buys, and iCloud+ renewals are now indefinitely frozen.
⤷ Title: Critical 9.8 CVSS RCE Vulnerabilities Exposed in Progress ShareFile
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 06:18:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_2699 #CVE_2026_2701 #File Transfer Security #infosec #Patch Alert #Progress ShareFile #rce #Remote Code Execution #Storage Zones Controller #Vulnerability #watchTowr
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 06:18:14 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_2699 #CVE_2026_2701 #File Transfer Security #infosec #Patch Alert #Progress ShareFile #rce #Remote Code Execution #Storage Zones Controller #Vulnerability #watchTowr
Daily CyberSecurity
Critical 9.8 CVSS RCE Vulnerabilities Exposed in Progress ShareFile
Progress ShareFile hit by critical 9.8 CVSS RCE flaws (CVE-2026-2699). Unauthenticated attackers can hijack configuration and execute code. Update to v5.12.4!
⤷ Title: Targeting the Cloud: IRGC Claims Strike on Oracle’s Dubai Data Sanctuary
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 04:57:50 +0000
════════════════════════
⌗ Tags: #Technology #Amazon Web Services #Bahrain #Cybersecurity 2026 #Data Center Security #Dubai #infosec #IRGC #Kinetic Strike #Larry Ellison #Middle East #OCI #Oracle Cloud
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 04:57:50 +0000
════════════════════════
⌗ Tags: #Technology #Amazon Web Services #Bahrain #Cybersecurity 2026 #Data Center Security #Dubai #infosec #IRGC #Kinetic Strike #Larry Ellison #Middle East #OCI #Oracle Cloud
Daily CyberSecurity
Targeting the Cloud: IRGC Claims Strike on Oracle’s Dubai Data Sanctuary
Iran's IRGC claims a strike on Oracle's Dubai data center, targeting U.S. tech infrastructure. Dubai officials deny damage as regional tensions escalate.
⤷ Title: The Human Variable: How a Masterful Phishing Ruse Hijacked Axios and 100 Million Users
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 04:55:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #@Jasonsaayman #Axios #Cybersecurity 2026 #malware #npm #Open Source Security #phishing #Remote Access Trojan #supply chain attack #UNC1069
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 04:55:14 +0000
════════════════════════
⌗ Tags: #Cybercriminals #@Jasonsaayman #Axios #Cybersecurity 2026 #malware #npm #Open Source Security #phishing #Remote Access Trojan #supply chain attack #UNC1069
Daily CyberSecurity
The Human Variable: How a Masterful Phishing Ruse Hijacked Axios and 100 Million Users
The Axios npm hijack exposed millions to a RAT. Discover how North Korean-nexus actor UNC1069 used a masterful phishing ruse to bypass 2FA and steal credentials.
⤷ Title: The Cloud in Flames: AWS Bahrain Fire Signals a New Era of Kinetic Strikes on Tech Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 04:48:07 +0000
════════════════════════
⌗ Tags: #Technology #Amazon Web Services #AWS #Bahrain #Cloud Outage #Cybersecurity 2026 #data center fire #geopolitics #Infrastructure Security #IRGC #Middle East
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 04:48:07 +0000
════════════════════════
⌗ Tags: #Technology #Amazon Web Services #AWS #Bahrain #Cloud Outage #Cybersecurity 2026 #data center fire #geopolitics #Infrastructure Security #IRGC #Middle East
Daily CyberSecurity
The Cloud in Flames: AWS Bahrain Fire Signals a New Era of Kinetic Strikes on Tech Infrastructure
A massive fire at an AWS facility in Bahrain highlights a dangerous shift toward kinetic strikes on cloud infrastructure. Is your multi-region strategy ready?
⤷ Title: Smart Home Alert: Critical Flaws Exposed in TP-Link Tapo Security Cameras
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 03:17:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #camera vulnerability #CVE_2026_34121 #CVSS 8.7 #Denial of Service #firmware update #heap overflow #IoT security #Smart Home Security #Tapo C520WS #TP_Link
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 03 Apr 2026 03:17:41 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #camera vulnerability #CVE_2026_34121 #CVSS 8.7 #Denial of Service #firmware update #heap overflow #IoT security #Smart Home Security #Tapo C520WS #TP_Link
Daily CyberSecurity
Smart Home Alert: Critical Flaws Exposed in TP-Link Tapo Security Cameras
TP-Link warns of high-severity flaws (CVSS 8.7) in Tapo C520WS cameras. Attackers can bypass auth or blind your security. Update to firmware 1.2.4 now!
⤷ Title: You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)
════════════════════════
𐀪 Author: Sonny
════════════════════════
ⴵ Time: Thu, 02 Apr 2026 10:00:42 GMT
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Sonny
════════════════════════
ⴵ Time: Thu, 02 Apr 2026 10:00:42 GMT
════════════════════════
⌗ Tags: No_Tags
watchTowr Labs
You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701)
If you squint and look at the CISA KEV list, you might think it's made up exclusively of vulnerabilities in file transfer solutions.
While this would be wrong (and you shouldn’t squint, it’s bad for your eyes), file transfer solutions do play a decent role…
While this would be wrong (and you shouldn’t squint, it’s bad for your eyes), file transfer solutions do play a decent role…
⤷ Title: Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)
════════════════════════
𐀪 Author: Aliz Hammond
════════════════════════
ⴵ Time: Sun, 29 Mar 2026 20:07:28 GMT
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Aliz Hammond
════════════════════════
ⴵ Time: Sun, 29 Mar 2026 20:07:28 GMT
════════════════════════
⌗ Tags: No_Tags
watchTowr Labs
Please, We Beg, Just One Weekend Free Of Appliances (Citrix NetScaler CVE-2026-3055 Memory Overread Part 2)
Today, we woke up with a nagging feeling: what if Citrix had, in fact, patched multiple Memory Overread vulnerabilities as part of CVE-2026-3055?
While we've been using our analysis from Part 1 (please read it first, as this post will be brief) to accurately…
While we've been using our analysis from Part 1 (please read it first, as this post will be brief) to accurately…
⤷ Title: The Sequels Are Never As Good, But We're Still In Pain (Citrix NetScaler CVE-2026-3055 Memory Overread)
════════════════════════
𐀪 Author: Aliz Hammond
════════════════════════
ⴵ Time: Sat, 28 Mar 2026 20:39:56 GMT
════════════════════════
⌗ Tags: No_Tags
════════════════════════
𐀪 Author: Aliz Hammond
════════════════════════
ⴵ Time: Sat, 28 Mar 2026 20:39:56 GMT
════════════════════════
⌗ Tags: No_Tags
watchTowr Labs
The Sequels Are Never As Good, But We're Still In Pain (Citrix NetScaler CVE-2026-3055 Memory Overread)
Sequels? Pain? We're obviously talking about Citrix NetScalers, yet again.
Welcome back to another watchTowr Labs blog post - pull up a chair, we always welcome new members to our group therapy sessions.
If you asked a C programmer what they most dislike…
Welcome back to another watchTowr Labs blog post - pull up a chair, we always welcome new members to our group therapy sessions.
If you asked a C programmer what they most dislike…
⤷ Title: Cloud Security: Tips and Resources for Securing the Cloud
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 14:00:00 +0000
════════════════════════
⌗ Tags: #Blue Team #Blue Team Tools #General InfoSec Tips & Tricks #Informational #InfoSec 101 #Kevin Klingbile #Cloud Security #Green Book #Infosec for Beginners #InfoSec Survival Guide #Resources
════════════════════════
𐀪 Author: BHIS
════════════════════════
ⴵ Time: Wed, 01 Apr 2026 14:00:00 +0000
════════════════════════
⌗ Tags: #Blue Team #Blue Team Tools #General InfoSec Tips & Tricks #Informational #InfoSec 101 #Kevin Klingbile #Cloud Security #Green Book #Infosec for Beginners #InfoSec Survival Guide #Resources
Black Hills Information Security, Inc.
Cloud Security: Tips and Resources for Securing the Cloud - Black Hills Information Security, Inc.
This overview of the basics of Cloud Security includes some tips and resources for getting started in defending the cloud.