AVEVA’s Patch Cannot Secure the Files You Forgot

Four PIMBoards flaws have a vendor fix, but old project files, backups and passwords still need separate handling after the software update.

Four PIMBoards flaws have a vendor fix, but old project files, backups and passwords still need separate handling after the software update.

Apple’s 14 September security rollout spans 273 unique CVEs across ten advisories. The headline number is real, but one familiar flaw in CISA’s exploited catalogue changes how defenders should prioritise the work.

Researchers showed how a false lost-phone report can block a home alarm’s cellular backup. The attack needs an IMEI, local radio access and a vulnerable modem.

A critical LiteSpeed Enterprise flaw can let a low-privilege website user cross a shared server's account boundary, bypass CageFS and potentially gain root access.

Six Mistral Vibe flaws expose a gap between the command an AI coding agent approves and the action its shell actually performs. The real boundary is the developer's machine.

A GoAnywhere MFT user with Secure Folders and Secure Mail access could escape their assigned folder and read other server files. Fortra has a fix.

Cisco says attackers are exploiting a critical flaw in Secure Email Gateway. A crafted message can pass through the appliance and become root-level commands, with no login or user click.

A specific Traefik HTTP/3 and NTLM configuration could let one client reuse a backend connection authenticated as someone else. Fixed releases and a public test are available.

AWS tested 12 general-purpose AI models on vulnerable code and safe lookalikes. None met its simultaneous false-alarm and missed-bug target.

A researcher exported Mirth Connect's configuration database into a public web folder in a controlled test. Two separate flaws reach exposed message channels without a login.