UNIX CONSULTINGIT security, defense and AI compliance Back to site

Cybersecurity watch

Latest cybersecurity signals

This watch aggregates institutional sources, security vendors, research teams and specialist media. Each page adds a short editorial read to help CISOs, DPOs, IT leaders, SMBs, mid-market and enterprise accounts identify topics to prioritize.

Tracked sources CISA Microsoft MSRC Cisco Security Advisories SANS ISC BleepingComputer SecurityWeek The Hacker News Google Project Zero Cloudflare Security GitHub Security Lab

Hackers build AI frameworks for widescale credential theft

BleepingComputer

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of... Unix Consulting read: This signal relates to AI usage, assistants, models or data handled by these systems. It should be read through a governance lens: which data enters...

Microsoft: Windows Server 2025 changes causing app crashes

BleepingComputer

Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent... Unix Consulting read: This signal deserves fast qualification: affected asset, exposure, potential impact, urgency and internal owner. The value comes from turning the...

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

The Hacker News

A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end... Unix Consulting read: This signal relates to AI usage, assistants, models or data handled by these systems. It should be read through a governance lens: which data enters...

MikroTik Patches Critical Flaws Chained to Hack Routers

SecurityWeek

Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. The... Unix Consulting read: This signal should be mapped against the application inventory, internet exposure and patch-management process. The key point is not only the...

Mathspace Data Breach Exposes Over 1 Million People

SecurityWeek

Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance. The post... Unix Consulting read: This signal deserves fast qualification: affected asset, exposure, potential impact, urgency and internal owner. The value comes from turning the...

N-able Patches Critical Zero-Day in N-central

SecurityWeek

Administrators are advised to check their deployments for newly created user accounts they don’t recognize. The post N-able... Unix Consulting read: This signal should be mapped against the application inventory, internet exposure and patch-management process. The key point is not only the...

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

The Hacker News

Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves... Unix Consulting read: This signal relates to AI usage, assistants, models or data handled by these systems. It should be read through a governance lens: which data enters...

220 million traveler records exposed in Vietnam-linked APIS leak

BleepingComputer

Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing... Unix Consulting read: This signal relates to AI usage, assistants, models or data handled by these systems. It should be read through a governance lens: which data enters...

Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

SANS ISC

Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication... Unix Consulting read: This signal should be mapped against the application inventory, internet exposure and patch-management process. The key point is not only the...

numbat - AI agent observability, (Fri, Sep 4th)

SANS ISC

This signal relates to AI usage, assistants, models or data handled by these systems. It should be read through a governance lens: which data enters the tool, which access is granted and which traces remain auditable. Review handled data, connectors and...

Cisco IOS XR Software Security Hardening Release: September 2026

Cisco Security Advisories

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has... Unix Consulting read: This signal should be mapped against the application inventory, internet exposure and patch-management process. The key point is not only the...

CISA Adds One Known Exploited Vulnerability to Catalog

CISA

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active... Unix Consulting read: This signal should be mapped against the application inventory, internet exposure and patch-management process. The key point is not only the...

Chromium: CVE-2026-84359 Information leak in Skia

Microsoft MSRC

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see... Unix Consulting read: This signal should be mapped against the application inventory, internet exposure and patch-management process. The key point is not only the...

Chromium: CVE-2026-84358 Improper privilege management in Downloads

Microsoft MSRC

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see... Unix Consulting read: This signal should be mapped against the application inventory, internet exposure and patch-management process. The key point is not only the...

Chromium: CVE-2026-84357 Improper input validation in Omnibox

Microsoft MSRC

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see... Unix Consulting read: This signal should be mapped against the application inventory, internet exposure and patch-management process. The key point is not only the...

Chromium: CVE-2026-84356 UI misrepresentation in FullScreen

Microsoft MSRC

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see... Unix Consulting read: This signal should be mapped against the application inventory, internet exposure and patch-management process. The key point is not only the...

Tycon Systems TPDIN-Monitor-WEB3

CISA

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle... Unix Consulting read: This signal should be mapped against the application inventory, internet exposure and patch-management process. The key point is not only the...

Pyramid Solutions NetStaX EtherNet/IP Stack

CISA

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential... Unix Consulting read: This signal should be mapped against the application inventory, internet exposure and patch-management process. The key point is not only the...

IXON VPN Client

CISA

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the... Unix Consulting read: This signal should be mapped against the application inventory, internet exposure and patch-management process. The key point is not only the...

View full archive