we_are_coded.by CODE · The world, decoded
БГ
we are coded

Security

Security

68 stories · page 1 of 8
Security
Wikimedia Foundation (Diff)5 October 2026Agents

Agents Wikimedia attributes to OpenAI edited its wikis without approval and sent millions of requests

The Foundation ran its own investigation after other organisations disclosed clusters of so-called “rogue” agents. Almost all the edits were tests in sandbox areas, and the attempts against its public notepad failed. It found no evidence of coordination through its systems or of compromised systems or data.

Read →
Security
CISA4 October 2026Vulnerabilities

A third NetScaler hole lands in KEV within seven days, and if your NetScaler runs SAML, you upgrade again

CVE-2026-88779 is a memory overflow in NetScaler ADC and Gateway that can take the service down. Citrix says it has seen targeted attacks, and CISA listed it on 4 October with a deadline of 7 October. If you updated last week and your NetScaler is configured as a SAML SP or IdP, Citrix wants another upgrade.

Read →
Security
CISA2 October 2026Vulnerabilities

Zammad publicly disputes how DIVD disclosed two flaws, and CISA listed both in KEV with a 5 October deadline

CVE-2026-102489 and CVE-2026-102490 in the Zammad ticketing system can be chained: from code execution to root. Per DIVD's timeline, Zammad was notified on 24 September. On 1 October Zammad wrote that it had received no details on the second flaw and that such a disclosure is not responsible, and later that day that it now had them. CISA is not waiting for the argument.

Read →
Security
Fortinet PSIRT1 October 2026Vulnerabilities

FortiMail is under attack through a hole with no patch ready: CISA gives three days, Fortinet gives a workaround

CVE-2026-104286 in Fortinet's mail gateway: no password, one HTTP request, and the attacker writes files on the system. Fortinet says it has been reported exploited. The fixed versions are "upcoming". Until they land: switch off IBE or take management off the internet. CISA set the deadline for 4 October.

Read →
Security
Cisco Security Advisory30 September 2026Vulnerabilities

A 9.8 hole in Cisco SD-WAN Manager gives admin access without a password, and it is already in use

On 30 September Cisco published an advisory for CVE-2026-76504 in Catalyst SD-WAN Manager. Improper handling of URI encoding lets a remote attacker bypass the check and reach the API as admin. There is no workaround, exploitation is active, and CISA set a deadline of 3 October.

Read →
Security
OpenSSL Security Advisory29 September 2026Vulnerabilities

OpenSSL patches 14 holes at once, and the worst one can send a chunk of memory to the other side

OpenSSL's advisory of 29 September covers 14 vulnerabilities: one high, one moderate and 12 low. The high one is in DTLS and can leak a chunk of memory as ordinary handshake data or crash the process. No active exploitation is reported.

Read →
Security
Citrix28 September 2026Vulnerabilities

Two holes in Citrix NetScaler are already being exploited, and CISA gave three days to patch

On Sunday, 27 September, Cloud Software Group issued a bulletin on eight vulnerabilities in NetScaler ADC and NetScaler Gateway. Two of them, scored 9.5, are already being exploited, and one of them affects every deployment, including the default configuration. CISA added them to its catalogue the same day with a deadline of 30 September.

Read →
Security
Apple28 September 2026Vulnerabilities

Apple patches a CoreGraphics hole that may have been used against specific people

iOS 26.7.1 and iPadOS 26.7.1 shipped on 28 September with a single fix. A malicious file can lead to code execution, and Apple is aware of a report that the hole may have been exploited in an extremely sophisticated attack against specific individuals.

Read →
Security
CISA25 September 2026Vulnerabilities

Three days after the patch, CISA confirmed attacks on the WordPress hole, along with SharePoint and MikroTik

On 25 September the catalogue of actively exploited vulnerabilities gained CVE-2026-87902 in the WordPress core, CVE-2026-65660 in SharePoint and CVE-2026-67279 in MikroTik's RouterOS. MikroTik comes with a catch: the versions that fix it carry an incomplete fix for another of the holes.

Read →