Security news
Latest security news
Mon, 31 Aug 2026
- [Control Systems] Siemens security advisory (AV26-864)
Serial Number: AV26-864 Date: August 31, 2026 As of August 27, 2026, Siemens is affected by a vulnerability in the following products: Element maps-ng V47 Prior to V47.12.3 Element maps-ng V48 Prior to V48.11.3 Element maps-ng V49 Prior to V49.16.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SSA-682041 CERT Services | Siemens
Canadian Centre for Cyber Security - Dell security advisory (AV26-863)
Serial Number: AV26-863 Date: August 31, 2026 As of August 28, 2026, Dell is affected by vulnerabilities in the following products: Dell PowerEdge Server for Intel Processor Firmware Multiple versions and models Dell AppSync Prior to or equal to 4.6.0.4 and 4.6.1.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. DSA-2026-356: Security Update for Dell PowerEdge Server for Intel® Processor Firmware Vulnerability DSA-2026-165: Security Update for Dell AppSync Vulnerabilities Security Advisories, Notices and Resources | Dell Canada
Canadian Centre for Cyber SecurityDell, Intel - IBM security advisory (AV26-862)
Serial Number: AV26-862 Date: August 31, 2026 As of August 28, 2026, IBM is affected by vulnerabilities in the following products: SPSS Collaboration and Deployment Services Multiple versions IBM SPSS Analytic Server Multiple version IBM MQ Agent Multiple versions IBM Maximo Application Suite - Monitor Component Prior to or equal to 9.2, 9.1 and 9.0 IBM Observability with Instana (Agent) Prior to or equal to 1.0.323 IBM Financial Transaction Manager (FTM) for RedHat OpenShift Multiple versions IBM Engineering Test Management Prior to equal to 7.2, 7.1 and 7.0.3 IBM Control Center Prior to or equal to v6.3.1.0 IBM Concert Software Prior to or equal to 2.3.1 IBM Tivoli System Automation Application Manager 4.1 Versions WebSphere Application Server 8.5 and 9.0 SPSS Collaboration and Deployment Services Multiple versions IBM Sovereign Core Prior to or equal to 1.1 IBM Maximo Application Suite - Cluster Performance Insights Prior to or equal to 9.2 IBM Transformation Advisor Prior to or equal to 5.0.0 IBM Application Modernization Accelerator Prior to or equal to 5.0.0 IBM webMethods Integration (on prem) Prior to or equal to 10.15,11.1 and 12.1 The Cyber Centre encourages users and adm
Canadian Centre for Cyber SecurityIBM
Fri, 28 Aug 2026
- The Vulnpocalypse Is Repricing the Bug Bounty Economy
The surge in AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers.
Dark Reading - CISA: Most exploited vulnerabilities should have been eradicated decades agoHacker News2 outlets
- PaperCut NG/MF Critical Zero-Day Exploited in the Wild
Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the initial time of disclosure, the vulnerability had not been assigned a CVE identifier, and PaperCut had not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the technical details of the exploit path. However on August 28, the vendor assigned CVE-2026-81578 and CVE-2026-82078 for the two vulnerabilities that make up the exploit chain. CVE ID Description CWE CVSSv4 CVE-2026-81578 Authentication Bypass CWE-306 Missing authentication for critical function. 8.8 (High) CVE-2026-82078 Unsafe Dynamic Class Loading in Database Connector CWE-470 Use of Externally-Controlled input to select classes or code ('unsafe reflection'). 9.4 (Critical) PaperCut NG and PaperCut MF are print management platforms commonly deployed within enterprise, education, and other organizational environments. Because the PaperCut Application Server provides web-accessible administrative an
CriticalUsed in attacksRapid7 BlogPaperCut - Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations
Aurora ransomware operators are abusing SpaceX’s Cursor Agent AI tool to conduct tasks such as reconnaissance and exploitation activities
Infosecurity Magazine
Thu, 27 Aug 2026
- “Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend
In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.
Cisco Talos - Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026
This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effects on vulnerability reporting and security research.
Dark Reading
About this news
- 1,264
- Stories
- 35
- Added in the last 24 hours
- 16
- Critical in the last 7 days
- 4
- Reported by several outlets