State CIO Tim Galluzi on Identity Modernization, AI and Resident Services The State of Nevada is accelerating its cybersecurity and digital modernization efforts after a major ransomware attack exposed the importance of resilience, workforce readiness and strong governance, said State CIO Tim Galluzi.
Individual Vulnerability Severity Not Always a Good Measure of Risk Exposure A mainstay of IT security programs across the world, the Common Vulnerability Scoring System, may have terminal flaws when applied to the mirror universe of operational technology - a place where ordinary assumptions about risk don't apply.
Program Offers Up to $100K for Security Upgrades and $50K for Assessments New York is rolling out new cybersecurity regulations for water and wastewater utilities, requiring operators to conduct risk assessments and deploy security controls while offering $2.5 million in grants to strengthen defenses against rising cyberthreats targeting critical infrastructure.
House Democrats Demand Probe Into Former CISA Head Gottumukkala Poly Failures Five U.S. Democratic lawmakers called for an investigation into a series of escalating controversies surrounding Cybersecurity and Infrastructure Security Agency leadership, following allegations that ex-Acting Director Madhu Gottumukkala bypassed established intelligence protocols.
A vulnerability categorized as critical has been discovered in Oracle Linux 8/9/10. This impacts an unknown function of the component dtprobed. Such manipulation leads to denial of service.
This vulnerability is listed as CVE-2026-21991. The attack must be carried out locally. There is no available exploit.
A vulnerability was found in frdel/agent0ai agent-zero 0.9.7. It has been rated as critical. This affects the function handle_pdf_document of the file python/helpers/document_query.py. This manipulation causes server-side request forgery.
This vulnerability is tracked as CVE-2026-4308. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in frdel/agent0ai agent-zero 0.9.7-10. It has been declared as critical. The impacted element is the function get_abs_path of the file python/helpers/files.py. The manipulation results in path traversal.
This vulnerability is identified as CVE-2026-4307. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Forgejo up to 13.0.3. It has been classified as problematic. The affected element is an unknown function of the component File Attachment Handler. The manipulation leads to denial of service.
This vulnerability is referenced as CVE-2025-68971. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability was found in Mattermost up to 10.11.10/11.2.2/11.3.0 and classified as problematic. Impacted is an unknown function of the component Websocket Message Handler. Executing a manipulation can lead to improper validation of specified type of input.
The identification of this vulnerability is CVE-2026-2454. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability has been found in ZwickRoell Test Data Management up to 3.0.7 and classified as critical. This issue affects some unknown processing of the file /server/node_upgrade_srv.js. Performing a manipulation of the argument firmware results in path traversal.
This vulnerability was named CVE-2026-29522. The attack needs to be approached locally. There is no available exploit.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in kubectl-mcp-server 1.2.0. This vulnerability affects unknown code of the file minimal_wrapper.py. Such manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2025-69902. The attack can be launched remotely. No exploit exists.
A vulnerability, which was classified as problematic, has been found in Mattermost up to 10.11.10/11.3.x. This affects an unknown part of the component API Endpoint. This manipulation causes incorrect authorization.
This vulnerability is handled as CVE-2026-26230. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability classified as problematic was found in Mattermost up to 10.11.10/11.3.x. Affected by this issue is some unknown functionality of the component Private Channel Handler. The manipulation results in operation on a resource after expiration.
This vulnerability is known as CVE-2026-1629. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
A vulnerability classified as problematic has been found in Mattermost up to 11.2.2/11.3.0. Affected by this vulnerability is an unknown functionality of the component Playbook Run API. The manipulation leads to incorrect authorization.
This vulnerability is traded as CVE-2026-26304. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.