ScanForge Security Digest 2631-02

200 items
71 critical0 high10 news

This week's security digest includes 0 actively exploited vulnerabilities (CISA KEV), 71 critical CVEs, and 0 high-severity CVEs. Review the details below and prioritize patching for any affected systems.

Critical

71
10.0 Vulnerability in the Service Delivery Platform product of Or 11 CVEs
10.0 Vulnerability in the Oracle Unified Directory product of Ora 4 CVEs
10.0 Vulnerability in the Oracle Access Manager product of Oracle 2 CVEs
10.0 In the Linux kernel, the following vulnerability 15 CVEs
9.9 Vulnerability in the Oracle Identity Manager Connector produ 3 CVEs
9.9 Vulnerability in the Oracle WebLogic Server product of Oracl 11 CVEs

Security News

10
Claude uploaded malware to PyPI in Anthropic's botched test Bleeping Computer

One of Anthropic's Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluat

South Korea fines telco giant KT $39 million for customer data breach Bleeping Computer

South Korea's Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53

CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs SecurityWeek

CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozen

JetBrains warns of critical TeamCity remote code execution flaw Bleeping Computer

JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be expl

Minnesota Water Utility Attacks Expose Sector's Cyber-Risks Dark Reading

A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising t

Bank of America to Acquire Cybersecurity Firm MDSec SecurityWeek

The acquisition will add approximately 65 cybersecurity professionals to Bank of America’s operations in the United King

AI Harnesses Burst With Potential Exploit Opps Dark Reading

A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning atta

Okta to Acquire Identity Threat Detection Firm Permiso SecurityWeek

The deal extends Okta's reach beyond identity management and into the realm of security operations, positioning the comp

Content aggregated from NIST/NVD, CISA, CERT/CC, and public security news sources. External articles are linked to their original source.