MikeTrendsTrends right now

search

compromised running

Trends

  1. 1
    Hackers obtain counterfeit TLS certificates for Google and othersโ—Hackers obtain counterfeit TLS certificates for Google and other large servicesMmastodon1044 min ago

    Hackers have issued unauthorized TLS certificates for Google and other major services after compromising three domain registries, according to Ars Technica. The forged certificates could let attackers impersonate trusted websites, intercept traffic, or run convincing phishing sites, since browsers normally rely on certificates to verify a site's identity. The incident raises fresh concerns over the security of the certificate issuance chain and how quickly affected certificates can be revoked.

  2. 2
    Multisig Wallets Pushed as Answer to Single-Key Riskโ–ผA single private key is a single point of failure. If you've ever run a system with one database and... # blockchain # sMmastodonBusinessCrypto118 h ago

    Developers and security commentators are highlighting that relying on a single private key creates a single point of failure, drawing parallels to running production systems on one database. The discussion promotes multisig wallets, where transactions require multiple of a set number of keys โ€” an m-of-n scheme โ€” to approve movement of funds. The argument is aimed at developers and newcomers to blockchain security.

  3. 3
    Citrix NetScaler Zero-Days CVE-2026-88771 and CVE-2026-88772 Raise Alarmโ–ผCitrix NetScaler Zero-Days (CVE-2026-88771 and CVE-2026-88772): A Skeleton Key at the Network Edge If your organisationMmastodonTechnologyCybersecurity11 d ago

    Security researchers are warning about two zero-day vulnerabilities in Citrix NetScaler, tracked as CVE-2026-88771 and CVE-2026-88772, described as a 'skeleton key' at the network edge. Organisations running internet-facing NetScaler appliances are being urged to assume possible compromise if the devices were exposed in the past month. Administrators are advised to patch immediately and review access logs.

  4. 4
    Runner completes 10K session split by strength stationsโ–ผโœ…๐Ÿƒโ€โ™‚๏ธ๐Ÿ‹๏ธ10K Running ( 7K Compromised ) Started with 7 x 1K runs with 6 fitness stations in between. This is called comproMmastodonHealthFitness22 d ago

    A fitness enthusiast completed a 10-kilometre run broken into seven 1-kilometre segments, with six strength stations in between โ€” wall balls, lunges and farmer carries. The format, known as compromised running, adds fatigue to each interval before finishing with an easy 3K treadmill jog. The whole workout took nearly 100 minutes. Compromised running is drawing attention as a hybrid training style mixing endurance and strength in a single session.

  5. 5
    Critical Command Injection Flaw Disclosed in Fortra BoKS Privileged Access Managerโ–ผCVE-2026-9862: Critical OS Command Injection Vulnerability in Fortra BoKS Core Privileged Access Manager Threatens System Securityโœ‰newsTechnologyCybersecurity2 d ago

    A critical vulnerability tracked as CVE-2026-9862 has been disclosed in Fortra's BoKS Core Privileged Access Manager, an OS command injection flaw that could let attackers run arbitrary commands on affected systems. Security teams are being urged to patch or restrict exposure, given that privileged access management tools sit at the heart of enterprise infrastructure and a compromise would hand attackers keys to entire environments.

  6. 6
    Storm-3168 attackers exploit Azure via compromised service principalsโ–ผActive Exploitation Alert: Storm-3168 (JADEPUFFER) Agentic Attack Targets Azure via Compromised Service Principalsโœ‰newsEnvironmentWeather2 d ago

    Security firm Rescana has issued an alert about active exploitation by the threat group Storm-3168, also tracked as JADEPUFFER, which is using compromised Azure service principals to attack Microsoft Azure environments. The campaign is described as an agentic attack, meaning the attackers deploy automated tooling to move through cloud infrastructure. Organizations running Azure are being urged to review service principal credentials and permissions.

  7. 7
    HPE AOS-Switch hit by high-severity buffer overflow flawโ—๐Ÿšจ EUVD-2026-93874 ๐Ÿ“Š Score: 9.1/10 (CVSS v3.1) ๐Ÿ“ฆ Product: AOS-Switch (AOS-S) ๐Ÿข Vendor: Hewlett Packard Enterprise (HPE) ๐Ÿ“…MmastodonTechnologyCybersecurity010 h ago

    A newly catalogued vulnerability, EUVD-2026-93874, has been assigned a CVSS score of 9.1 and affects Hewlett Packard Enterprise's AOS-Switch (AOS-S) software. The flaw involves buffer overflow issues in an affected interface, and successful exploitation could allow an unauthenticated remote attacker to compromise systems. Administrators running HPE network switches are being urged to review their exposure and apply patches or mitigations as they become available.

  8. 8
    Developer runs AI coding mentor entirely on budget Android phoneโ—Most people think building an AI coding mentor on a budget Android phone means cutting corners. They're wrong. ConstrainMmastodonBusinessStartups46 d ago

    A developer reports stress-testing KODA, an AI coding mentor built to run on a low-cost Android phone, against nine industry benchmark challenges from Anthropic, OpenAI, DeepSeek and SpaceX/Grok. The argument is that tight hardware constraints force ruthless optimization rather than compromise, and that capable AI coding assistance does not require expensive infrastructure or flagship devices.

  9. 9

    Advice columnist Annie fields a letter about an ongoing household dispute over thermostat settings, which the writer frames as a 'cold war' between family members or housemates. The column offers guidance on compromise and communication in shared living situations. Readers of the long-running advice feature follow such domestic conflicts for both entertainment and practical takeaways.

  10. 10
    Wind Waker recompilation project sparks emulation debateโ—This Zelda: Wind Waker Recomp is making me question my commitment to authenticity.โœ‰newsCultureGaming15 h ago

    A fan-made recompilation of The Legend of Zelda: The Wind Waker is drawing attention for running the GameCube game natively on PC with improved performance and features. The project has reignited debate among fans about whether playing through such ports compromises the value of experiencing games on original hardware.

  11. 11
    Roundcube Webmail SQL Injection Flaw Actively Exploitedโ–ผRoundcube Webmail SQL Injection Vulnerability CVE-2026-48842 Under Active Exploitation Roundcube Webmail high-severity SMmastodonTechnologyCybersecurity22 d ago

    A high-severity SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is under active exploitation. The flaw resides in the virtuser_query plugin and allows unauthenticated attackers to compromise servers running the popular open-source webmail software. Security administrators are being urged to patch affected installations immediately and check systems for signs of compromise.

  12. 12
    Dell Patches Critical Flaws in Container Storage Modulesโ–ผDell CSM Flaws Allow Unauthenticated Admin Access and Root on Kubernetes Nodes Dell patched 37 vulnerabilities in its CoMmastodonTechnologyCybersecurity14 d ago

    Dell has released fixes for 37 vulnerabilities in its Container Storage Modules, including six critical flaws. The most serious allow unauthenticated attackers to steal storage administrator credentials and gain root access on Kubernetes nodes. Administrators running Dell storage with Kubernetes are urged to apply the patches promptly to avoid credential theft and full system compromise.

  13. 13
    Microsoft's X account hacked in crypto pump-and-dump schemeโ—# Microsoft โ€™s # X account hacked in # crypto pump-and-dump scheme https://www. bleepingcomputer.com/news/secu rity/micrMmastodonBusinessCrypto03 d ago

    Microsoft's X account was compromised and used to promote a cryptocurrency pump-and-dump scheme, according to security outlet BleepingComputer. The hijacked account was used to push a fraudulent token to Microsoft's large follower base, raising fresh concerns about the security of major corporate accounts on the platform.

  14. 14
    DIVD reports compromise via chained Zammad vulnerabilitiesโ—DIVD reported a compromise involving two chained Zammad vulnerabilities, with session hijacking, remote code execution,MmastodonTechnologyCybersecurity25 d ago

    The Dutch Institute for Vulnerability Disclosure has reported a security compromise involving two chained vulnerabilities in the open-source ticketing system Zammad. The attack combined session hijacking, remote code execution, privilege escalation and data exfiltration, showing how separate flaws in a single service can be combined into a full intrusion path. Security professionals are circulating the report as a case study in chained exploits and the importance of patching interconnected components.

  15. 15
    Senators Reach Construction Permitting Deal Ahead of Electionsโ–ผSenators clinch construction permitting deal before election jet-setโœ‰newsWorldElections6 d ago

    A group of US senators has clinched a deal on construction permitting reform, reaching agreement just before lawmakers leave Washington for the election campaign period. The agreement would streamline approval processes for building projects, a long-stalled issue. With congressional time running out before the elections, the timing of the breakthrough is drawing attention to whether the deal can advance further.

  16. 16
    Microsoft details Zimbra flaw allowing code execution via emailโ—Zimbra CVE-2026-73570 lets one crafted email run code. Microsoft details the Zimbra command injection attacks: web shellMmastodonTechnologyCybersecurity16 d ago

    Microsoft researchers have detailed attacks exploiting a Zimbra command injection vulnerability, CVE-2026-73570, in which a single crafted email is enough to run code on the mail server. The documented attacks involve deploying web shells, gaining root access, and stealing cryptographic keys. Security teams running Zimbra are being urged to patch and review their servers for signs of compromise.

  17. 17
    Citrix NetScaler Flaw Used to Create Superuser Accountsโ—๐Ÿ”’ Security News Digest - 2026-10-01 ๐Ÿ“Š 10 updates from 3 sources: ๐Ÿ”น The Hacker News: Citrix NetScaler Post-Exploitation PMmastodonTechnologyCybersecurity15 d ago

    Security reports detail post-exploitation activity targeting Citrix NetScaler appliances, where attackers deploy payloads that create superuser accounts and disguise web shells as CSS-like URLs to evade detection. The technique raises concerns for organisations running NetScaler gateways, as compromised devices may grant persistent privileged access. Administrators are advised to review devices for unexpected accounts and unusual URL patterns.

  18. 18
    Sisi: Egypt backs diplomacy on Ethiopian dam, water security non-negotiableโ–ผAl-Sisi: Egypt committed to diplomacy on Ethiopian dam, but water security is non-negotiableโœ‰newsWorldDiplomacy6 d ago

    Egyptian President Abdel Fattah Al-Sisi said Egypt remains committed to a diplomatic solution over Ethiopia's Grand Renaissance Dam, but stressed that the country's water security is a red line that cannot be compromised. His remarks underline the ongoing tension between Cairo and Addis Ababa over the Nile dam, which Egypt sees as a threat to its freshwater supply.

  19. 19
    Critical stored XSS flaw reported in Kiteworks Coreโ—๐Ÿšจ CVE-2026-102147 โ€” CVSS 9.3 CRITICAL A stored cross-site scripting (XSS) weakness in Kiteworks Core could allow an unauMmastodonTechnologyCybersecurity06 d ago

    Security researchers are flagging CVE-2026-102147, a critical vulnerability in Kiteworks Core carrying a CVSS score of 9.3. The flaw is a stored cross-site scripting weakness that could let an unauthenticated attacker plant crafted content which then executes arbitrary JavaScript in the session of an administrator who views it, potentially giving attackers privileged access. Organizations running Kiteworks are urged to review the advisory and apply patches.

  20. 20
    US senators reach deal on energy permitting billโ—US senators hit deal on energy project permitting bill, vote seen after Novemberโœ‰newsEnvironmentEnergy6 d ago

    A bipartisan group of US senators has reached an agreement on a bill to reform permitting for energy projects, with a vote expected after November. The legislation aims to speed up approvals for power lines, pipelines and other infrastructure. Details of the compromise and its chances of passing remain to be seen, and the proposal is likely to draw scrutiny from both environmental groups and industry.

  21. 21
    Cisco Patches Exploited SD-WAN Zero-Day Vulnerabilityโ—Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerabilityโœ‰newsTechnologyCybersecurity5 d ago

    Cisco has released patches for a zero-day vulnerability in its Catalyst SD-WAN software that was being actively exploited, according to a report by SecurityWeek. The flaw allowed attackers to compromise affected SD-WAN devices. Administrators are urged to apply the updates promptly, and details about the exploitation campaign remain limited.

  22. 22
    Questions raised over Seventh-day Adventist Church's UN tiesโ—Does the Adventist Church have close ties to the UN?โœ‰newsWorldReligion6 d ago

    Adventist Today is examining whether the Seventh-day Adventist Church maintains close institutional ties to the United Nations. The question touches on a long-running debate within the denomination, where some members worry that official engagement with UN bodies, including its status as an NGO, could compromise the church's independence, while others see advocacy work as consistent with its humanitarian mission. The publication invites readers to weigh the evidence behind the claim.