Aggregator
FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289)
A newly discovered vulnerability (CVE-2026-28289) in the open-source help desk platform FreeScout could allow attackers to take over vulnerable servers by sending a specially crafted email to a FreeScout mailbox. CVE-2026-28289 exploitation FreeScout is a free, open-source help desk and shared inbox system used by businesses or teams to manage customer support conversations in one place. It is built with PHP (Laravel) and MySQL, and it’s designed to be self-hosted – either on-premises, on a … More →
The post FreeScout vulnerability enables unauthenticated, zero-click RCE via email (CVE-2026-28289) appeared first on Help Net Security.
Google changes Play Store policies after settling Epic Games dispute
Google is making changes to the Play Store after settling its legal fight with Epic Games, focusing on three areas: more billing options, lower fees with new programs for developers, and a program for registered app stores. The rollout begins in the European Economic Area, the United Kingdom and the United States by June 30, 2026. Australia follows in September, while Japan and South Korea receive the changes by the end of 2026. The rest … More →
The post Google changes Play Store policies after settling Epic Games dispute appeared first on Help Net Security.
【安全圈】思科修复最高危 Secure FMC 漏洞
【安全圈】汽车胎压传感器或成隐私泄露隐患,可悄无声息追踪车主行程
【安全圈】Telegram日益成为访问权限、恶意软件和窃取日志的交易平台
【安全圈】官方提醒:警惕发票陷阱!境外黑客借邮箱植入木马
Не болтай – компьютер выдаст. Рассказываем, как физические процессы превращают любую технику в предателя
An OT Incident Scoring System Inspired by Natural Disasters
Hurricanes, tornados, earthquakes - and now operational technology cyber incidents - all can receive a numerical score based on their severity, although a new effort promoting an "OT Incident Impact Score" faces an uphill climb to get the traction it needs to succeed.
AI Should Be the First Defense for Stablecoin Payment Fraud
Stablecoins can remove chargebacks and make transactions irreversible in fraud cases. This trend is forcing banks to analyze risks before a payment executes. AI models must work within milliseconds while maintaining accuracy and minimizing friction for legitimate users.
Agentic AI Emerges as the Next Frontier for State Government IT
Reputation aside, most pen pushers in state governments don't actually like pushing paper. They also don't care to force citizens to fill out forms in triplicate. Two decades of promises to minimize those chores may be on the cusp of gloriously coming true with the advent of agentic AI.
Fig Security Raises $30M to Modernize SOC Infrastructure
Fig Security has raised $30 million in Series A funding to help organizations modernize their SOC infrastructure. The startup said CISOs lack visibility into complex SecOps pipelines spanning SIEMs, data lakes and automation tools, which can lead to silent failures that undermine threat detection.
Where Multi-Factor Authentication Stops and Credential Abuse Starts
Zero-Click FreeScout Bug Enables Remote Code Execution
62 people indicted by Taiwanese prosecutors over ties to cyber scam company Prince Group
Cisco Secure Firewall Management Vulnerability Enables Remote Code Execution
Cisco has issued an urgent security advisory for a critical vulnerability affecting its Secure Firewall Management Center (FMC) software. This flaw, rated with the maximum possible CVSS score of 10.0, allows remote, unauthenticated attackers to execute arbitrary code and gain complete root-level control over the affected system. The vulnerability exists in the web-based management interface […]
The post Cisco Secure Firewall Management Vulnerability Enables Remote Code Execution appeared first on Cyber Security News.