Skip to content

Latest alerts

RSS feed

84 Flaws Found in 4G/5G Cores: DoS & Session Hijacking

A study from Nanyang Technological University reports 84 previously unknown vulnerabilities in 4G and 5G core networks. The issues stem from implicit trust between core functions and may enable DoS and session hijacking.

Device code phishing: 6 fast-growing warning signs

Device code phishing has shifted from a niche technique to an industrial-scale phishing-as-a-service threat. Here are six practical reasons security teams should treat it as an urgent 2026 priority.

Chinese hackers use DeepSeek via Telegram

Palo Alto Networks Unit 42 reports that a Chinese-speaking threat actor used DeepSeek via Telegram inside the Hermes Agent framework to carry out largely autonomous attacks. The findings include multiple CVE chains, failed targets, and concrete remediation guidance.

JFrog Artifactory vulnerabilities: patch now

The NCSC reports that JFrog has fixed multiple vulnerabilities in Artifactory. Rapid patching is necessary, including fixes for privilege escalation, SSRF, and path traversal.

Cisco Secure Firewall Management Center Password Fix

Cisco has released an update for a vulnerability in Cisco Secure Firewall Management Center tied to a hard-coded password in the web interface. Applying the patch helps reduce the risk of unauthorized access and potential data exposure.

GitLab security fixes: key vulnerabilities resolved

GitLab security fixes were released for several security issues affecting versions prior to 19.0.5, 19.1.3, and 19.2.1. The fixes help close gaps around access control, input handling, and workflow protection.

VMware vCenter and ESX fixes for critical flaws

The NCSC reports critical vulnerabilities patched in VMware vCenter, ESX, Workstation, and Fusion. Key issues include an authentication bypass, directory traversal, and out-of-bounds memory flaws.