Το υπουργείο Άμυνας των Ηνωμένων Αραβικών Εμιράτων ανακοίνωσε ότι συστήματα αντιαεροπορικής άμυνας ενεργοποιήθηκαν και αντιμετωπίζουν επιθέσεις… The post Επιθέσεις με πυραύλους και drones από το Ιράν κατά των ΗΑΕ appeared first on DEFENCE ReDEFiNED.
Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE
The Apache Software Foundation has released security updates addressing multiple vulnerabilities in Apache HTTP Server. A critical vulnerability tracked as CVE-2026-23918 with a CVSS score of 8.8 involves a double free error in HTTP/2 protocol handling that could enable remote code execution.
As US eyes smaller military footprint in Europe, new unit trains for drone warfare
The U.S. Army is establishing a new unit in Germany dedicated to training personnel in drone warfare operations, concurrent with Pentagon efforts to reduce troop levels in the country.
As US eyes smaller military footprint in Europe, new unit trains for drone warfare
The U.S. Army is establishing a new unit in Germany to provide training on drone warfare operations, despite Pentagon plans to reduce overall troop levels in the country.
DAEMON Tools Supply Chain Attack Compromises Official Installers with Malware
Kaspersky has identified a supply chain attack that compromised DAEMON Tools installers to distribute malware. The affected installers are distributed through the legitimate DAEMON Tools website and are signed with digital certificates belonging to DAEMON Tools developers, according to researchers Igor Kuznetsov and Georgy Kucherin.
China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions
A China-nexus advanced persistent threat group tracked as UAT-8302 by Cisco Talos has conducted attacks against government entities in South America since late 2024 and government agencies in southeastern Europe in 2025. Post-exploitation activities involve the deployment of custom malware families.
The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed
Many AI tools, workflow automation, and productivity applications connected to Google or Microsoft accounts generate persistent OAuth tokens that lack expiration dates and automatic cleanup processes. In most organizations, these tokens go unmonitored. Traditional perimeter controls and multi-factor authentication do not detect or prevent their use. When attackers obtain these tokens, they can bypass password requirements to gain access.
The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed
Many AI tools, workflow automation, and productivity applications connected to Google or Microsoft accounts create persistent OAuth tokens that lack expiration dates, automatic cleanup mechanisms, and oversight in most organizations. These tokens operate outside perimeter security controls and are not blocked by multi-factor authentication. When attackers obtain such tokens, they can gain access without needing a password.
MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks
Threat actors are actively exploiting a critical security vulnerability in MetInfo, an open-source content management system, according to VulnCheck research. CVE-2026-29014 is a code injection flaw with a CVSS score of 9.8 that allows arbitrary code execution. The vulnerability affects MetInfo CMS versions 7.9, 8.0, and 8.1 and involves an unauthenticated PHP code issue.
We Scanned 1 Million Exposed AI Services. Here’s How Bad the Security Actually Is
While the software industry has made significant improvements in product security over recent decades, the rapid pace of AI adoption is threatening that progress. Companies are quickly deploying self-hosted large language model infrastructure, motivated by AI’s potential to increase productivity and competitive pressure to deliver faster results. However, this acceleration is compromising security measures.
