Serial Number: AV26-916 Date: September 11, 2026 As of September 8, 2026, n8n is affected by a vulnerability in the following product: n8n Prior to 2.37.7 Prior to 2.38.2 Prior to 1.123.76 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Release n8n@1.123.76 Release n8n@2.37.7 Release n8n@2.38.2 Overview - n8n-io/n8n - GitHub
Serial Number: AV26-892 Date: September 8, 2026 As of September 4, 2026, Inductive Automation is affected by a vulnerability in the following product: Ignition Prior to or equal to 8.1.53 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CSAF/csaf_files/OT/white/2026/icsa-26-246-06.json at develop · cisagov/CSAF · GitHub Inductive Automation Ignition | CISA
Serial Number: AV26-882 Date: September 3, 2026 As of September 3, 2026, SUSE is affected by vulnerabilities in the following product: Rancher Prior to 2.15.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Release v2.15.1 · rancher/rancher · GitHub SUSE Update Advisories
Serial Number: AV26-880 Date: September 3, 2026 As of September 3, 2026, n8n is affected by vulnerabilities in the following product: n8n Prior to 1.123.76 Prior to 2.35.4 Prior to 2.36.2 Prior to 2.37.7 Prior to 2.38.2 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Overview · n8n-io/n8n · GitHub
Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDrop: Inside a Self-Propagating npm Worm appeared first on Unit 42 .
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency's initial response provide important lessons that all security teams should absorb.
From LinkedIn to X, GitHub to Instagram, there are plenty of opportunities to share work-related information. But posting could also get your company into trouble.