CVE Alert: CVE-2026-107701 - ntharim - dot-access - https://www.redpacketsecurity.com/cve-alert-cve-2026-107701-ntharim-dot-access/
RedPacket Security
CVE Alert: CVE-2026-107701 - ntharim - dot-access - RedPacket Security
dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to
CVE Alert: CVE-2026-84245 - IBM - Guardium Data Protection - https://www.redpacketsecurity.com/cve-alert-cve-2026-84245-ibm-guardium-data-protection/
RedPacket Security
CVE Alert: CVE-2026-84245 - IBM - Guardium Data Protection - RedPacket Security
IBM Guardium Data Protection 12.2 is vulnerable to a local privilege escalation in the cp_wrapper component. A low-privileged local user could exploit this
CVE Alert: CVE-2026-84250 - IBM - Guardium Data Protection - https://www.redpacketsecurity.com/cve-alert-cve-2026-84250-ibm-guardium-data-protection/
RedPacket Security
CVE Alert: CVE-2026-84250 - IBM - Guardium Data Protection - RedPacket Security
IBM Guardium Data Protection 12.2 is vulnerable due to weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component. A local
CVE Alert: CVE-2026-84275 - IBM - Guardium Data Protection - https://www.redpacketsecurity.com/cve-alert-cve-2026-84275-ibm-guardium-data-protection/
RedPacket Security
CVE Alert: CVE-2026-84275 - IBM - Guardium Data Protection - RedPacket Security
IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the GIM file-upload functionality. An unauthenticated attacker could exploit this
CVE Alert: CVE-2026-84271 - IBM - Guardium Data Protection - https://www.redpacketsecurity.com/cve-alert-cve-2026-84271-ibm-guardium-data-protection/
RedPacket Security
CVE Alert: CVE-2026-84271 - IBM - Guardium Data Protection - RedPacket Security
IBM Guardium Data Protection 12.2 is vulnerable to a signature verification bypass in the patch installer. An attacker with local access could exploit this
CVE Alert: CVE-2026-82344 - IBM - Guardium Data Protection - https://www.redpacketsecurity.com/cve-alert-cve-2026-82344-ibm-guardium-data-protection/
RedPacket Security
CVE Alert: CVE-2026-82344 - IBM - Guardium Data Protection - RedPacket Security
IBM Guardium Data Protection 12.0, 12.1 is vulnerable to a heap-based buffer overflow in the S-TAP TrafficTap TDS login reassembly functionality. An
CVE Alert: CVE-2026-18740 - IBM - Security Verify Access - https://www.redpacketsecurity.com/cve-alert-cve-2026-18740-ibm-security-verify-access/
RedPacket Security
CVE Alert: CVE-2026-18740 - IBM - Security Verify Access - RedPacket Security
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote authenticated attacker to perform
CVE Alert: CVE-2026-17189 - IBM - Security Verify Access - https://www.redpacketsecurity.com/cve-alert-cve-2026-17189-ibm-security-verify-access/
RedPacket Security
CVE Alert: CVE-2026-17189 - IBM - Security Verify Access - RedPacket Security
IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 is vulnerable to cross-site scripting. This vulnerability
CVE Alert: CVE-2026-107781 - dromara - skyeye - https://www.redpacketsecurity.com/cve-alert-cve-2026-107781-dromara-skyeye/
RedPacket Security
CVE Alert: CVE-2026-107781 - dromara - skyeye - RedPacket Security
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains a server-side request forgery and missing authorization vulnerability in the
CVE Alert: CVE-2026-107782 - winsiderss - System Informer - https://www.redpacketsecurity.com/cve-alert-cve-2026-107782-winsiderss-system-informer/
RedPacket Security
CVE Alert: CVE-2026-107782 - winsiderss - System Informer - RedPacket Security
System Informer before 4.0.26241.138 contains an incorrect authorization vulnerability in the phsvc helper that allows local attackers to reach privileged
CVE Alert: CVE-2026-11318 - Zuler Technology - DeskIn - https://www.redpacketsecurity.com/cve-alert-cve-2026-11318-zuler-technology-deskin/
RedPacket Security
CVE Alert: CVE-2026-11318 - Zuler Technology - DeskIn - RedPacket Security
Deskin through 3.3.4.3 contains a privilege escalation vulnerability in the com.deskin.service.installer XPC service that allows local unprivileged attackers
[SILENTRANSOMGROUP] - Ransomware Victim: O'Hagan Meyer - https://www.redpacketsecurity.com/silentransomgroup-ransomware-victim-o-hagan-meyer/
RedPacket Security
[SILENTRANSOMGROUP] - Ransomware Victim: O'Hagan Meyer - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
CyrusOne - 373,460 breached accounts - https://www.redpacketsecurity.com/cyrusone-373-460-breached-accounts/
RedPacket Security
CyrusOne - 373,460 breached accounts - RedPacket Security
In August 2026, data centre operator CyrusOne was the target of a ShinyHunters "pay or leak" extortion attempt. The group subsequently published data
ccTLD Hijacking: Attackers Obtain Unauthorized Google HTTPS Certificates - https://www.redpacketsecurity.com/attackers-hijack-three-cctlds-to-obtain-google-certificates/
RedPacket Security
ccTLD Hijacking: Attackers Obtain Unauthorized Google HTTPS Certificates - RedPacket Security
The incidents involved the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) namespaces, according to an update published by Google’s Chrome Secure Web
MATCHBOIL Malware: UAC-0099 Adds Evasion and Persistence Features - https://www.redpacketsecurity.com/russia-aligned-uac-0099-evolves-matchboil-malware/
RedPacket Security
MATCHBOIL Malware: UAC-0099 Adds Evasion and Persistence Features - RedPacket Security
In research published on October 8, ESET documented MATCHBOIL samples compiled or observed between April 2024 and April 2026. The researchers found that each
AI Cyberattack on South Korean Banks: Suspected China-Based Actor Used ARTEX - https://www.redpacketsecurity.com/chinese-hacker-deployed-ai-in-campaign-against-south-korean-banks/
RedPacket Security
AI Cyberattack on South Korean Banks: Suspected China-Based Actor Used ARTEX - RedPacket Security
An AI cyberattack on South Korean banks exposed how a suspected China-based threat actor combined an agentic penetration-testing tool with large language
Atlassian Products: Critical Flaw Exploited in the Wild - https://www.redpacketsecurity.com/critical-flaw-in-multiple-atlassian-products-exploited-in-the-wild/
RedPacket Security
Atlassian Products: Critical Flaw Exploited in the Wild - RedPacket Security
A critical flaw in multiple Atlassian products is being exploited in the wild. No further details were provided in the source material.
ASOS Data Breach: Stolen Employee Credentials Exposed Customer Information - https://www.redpacketsecurity.com/asos-confirms-data-breach-linked-to-stolen-employee-credentials/
RedPacket Security
ASOS Data Breach: Stolen Employee Credentials Exposed Customer Information - RedPacket Security
The ASOS data breach involved an attacker using stolen employee login credentials to access information on third-party platforms. The retailer says payment
Post-Quantum Cryptography: Europol and GAO Urge Organizations to Act - https://www.redpacketsecurity.com/europol-and-us-spending-watchdog-sound-the-alarm-over-quantum-threats/
RedPacket Security
Post-Quantum Cryptography: Europol and GAO Urge Organizations to Act - RedPacket Security
Post-quantum cryptography is moving up the security agenda. Reports from Europol and the US Government Accountability Office (GAO) urge organizations to
FortiBleed Lockout Threat: FBI and Secret Service Warn Fortinet Users - https://www.redpacketsecurity.com/fbi-and-secret-service-warn-of-fortibleed-lockout-threat/
RedPacket Security
FortiBleed Lockout Threat: FBI and Secret Service Warn Fortinet Users - RedPacket Security
A warning published by the FBI and US Secret Service on October 6 cited SOCRadar figures showing that FortiBleed has compromised 86,644 devices in 194
Cloud Security: Practical Controls for a Changing Environment - https://www.redpacketsecurity.com/cloud-security-practical-controls-for-a-changing-environment/
RedPacket Security
Cloud Security: Practical Controls for a Changing Environment - RedPacket Security
Cloud security is the practice of protecting cloud-hosted data, services, identities and infrastructure from unauthorised access, disruption and misuse. It