Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution – PATCH: NOW
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. * Adobe Bridge is a powerful asset management tool that allows creative professionals to preview, organize, edit, and publish multiple creative assets efficiently across the Creative Cloud ecosystem. * Adobe Format Plugins are software add-ons used …
Continue reading Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution – PATCH: NOWTue, 28 Jul 2026 17:52:42 +0000
Large-Scale Exploitation Campaign Targeting Website Content Management Systems
This Australian Signals Directorate (ASD) Australian Cyber Security Centre (ACSC) Alert is relevant to website owners and website managers. It is being provided to assist agencies and organizations in guarding against the persistent malicious actions of cybercriminals. A large-scale exploitation campaign is targeting various vulnerabilities in content management systems (CMS) globally, including in Australia, with …
Continue reading Large-Scale Exploitation Campaign Targeting Website Content Management SystemsTue, 28 Jul 2026 17:50:56 +0000
ID.me Phishing Campaign
The NJCCIC received reports of a phishing campaign impersonating ID.me, which is a US-based digital identity network that allows users to provide proof of their legal identity online to access government services, healthcare portals, and retailer discounts. The phishing email is sent from a “.ar” top-level domain (TLD) for Argentina with a subject line of …
Continue reading ID.me Phishing CampaignTue, 28 Jul 2026 17:49:58 +0000
Understanding Browser Push Notifications:A Gateway to Online Scams
Websites often ask for permission to send you “push notifications.” When used correctly, this feature is highly convenient. If you use a communication tool like Microsoft Teams or a news website in your browser, a small pop-up in the corner of your screen can alert you to a new message or breaking news, even if …
Continue reading Understanding Browser Push Notifications:A Gateway to Online ScamsTue, 28 Jul 2026 17:48:35 +0000
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
United States Federal and international partner agencies, released this Joint Cybersecurity Advisory to provide network defenders with vital tools and resources to combat the threat posed by Russian Government-sponsored activity targeting poorly configured and vulnerable devices across critical sectors. Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising …
Continue reading Improve Router Hygiene to Protect Against Russian State-Sponsored TargetingTue, 28 Jul 2026 17:47:17 +0000
Trusted Technologies Create Pathways Into Critical Infrastructure Networks
Critical infrastructure organizations are increasingly dependent on third-party vendors for a variety of remote services, including security and operational technologies that support essential functions. Yet the privileged access that providers rely on can also create opportunities for threat actors to infiltrate these sensitive networks. Recent incidents involving Itron and Fortinet illustrate how trusted relationships can …
Continue reading Trusted Technologies Create Pathways Into Critical Infrastructure NetworksTue, 28 Jul 2026 17:46:27 +0000
Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
Move to phishing-resistant authentication before SMS and voice retire We are notifying all Microsoft Entra ID tenants of an important change to authentication security: The AI era demands stronger, phishing-resistant authentication. Passkeys are becoming the default authentication experience in Microsoft Entra, and Microsoft-provided SMS and voice authentication will retire on February 1, 2027. For more …
Continue reading Passkeys by default and retirement of Microsoft-provided SMS and voice authenticationTue, 28 Jul 2026 17:44:05 +0000
Isolating Vital Operational Technology and Enabling Systems During Crisis
The Cybersecurity and Infrastructure Security Agency (CISA) and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration with the Federal Bureau of Investigation (FBI) and international partners, published Joint Guidance CI Fortify – Advice for isolating vital systems. This guidance, aligned with CISA’s CI Fortify initiative, is designed to help critical infrastructure …
Continue reading Isolating Vital Operational Technology and Enabling Systems During CrisisTue, 28 Jul 2026 17:36:29 +0000
Building Assurance Through HIPAA Security Conference
The U.S. Department of Health and Human Services Office for Civil Rights (OCR) and the National Institute of Standards and Technology (NIST) Information Technology Laboratory (ITL) are excited to announce their 2026 Conference, “Safeguarding Health Information: Building Assurance Through HIPAA Security 2026”. DATES: September 2 – 3, 2026 LOCATION: NIST Gaithersburg Campus, 100 Bureau Drive, …
Continue reading Building Assurance Through HIPAA Security ConferenceTue, 28 Jul 2026 13:29:02 +0000
Register Today! NIST Workshop | Securing AI Data Center: Architecture, Security Posture, and Emerging Standards
Securing AI Data Center: Architecture, Security Posture, and Emerging Standards Workshop Remember to register for the Secure AI Data Center Workshop before Tuesday, July 21, 2026. The agenda is now available. Data centers are the computing infrastructure that powers the training and inference of artificial intelligence (AI), and they have become a critical element of …
Continue reading Register Today! NIST Workshop | Securing AI Data Center: Architecture, Security Posture, and Emerging StandardsTue, 28 Jul 2026 12:35:11 +0000