TGViewer
Channel Public Channel
News Vulnerability Management and more

News Vulnerability Management and more

@avleonovnews

Latest news about vulnerability assessment, IT compliance management, security automation and other beautiful stuff. It updates automatically from RSS feeds. Discussion group for this channel: @avleonovchat
You can also watch my main channel @avleonovcom
Subscribers
1.45K
Photos
0
Videos
0
Links
185
Recent Posts 20 shown
Post #28605 14
🟢 AI Makes Finding Bugs Cheaper
#SecurityWeeklyVideo

"AI can reduce the cost of finding software vulnerabilities. Microsoft reported an average model cost of $3.61 per successful case in the example discussed here, along with 21.5 minutes per successful case. That changes the economics of vulnerability discovery. Companies already know their own software better than outside researchers, so inexpensive AI-assisted testing could make proactive bug hunting much more practical. If finding certain vulnerabilities becomes this inexpensive, how much responsibility should companies take for finding them before anyone else does? Subscribe to our..."

https://www.youtube.com/shorts/Qc1gIQu2qrE
YouTube AI Makes Finding Bugs Cheaper AI can reduce the cost of finding software vulnerabilities. Microso...
Post #28604 15
🟢 FBI disrupts Chinese hacking tools used to breach critical infrastructure
#BleepingComputerNews

"The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide.
The seizures targeted infrastructure supporting the two hacking platforms allegedly operated by China-based Integrity Technology Group (Integrity Tech), which U.S. authorities say has contracts with the Chinese government.
According to the U.S. Department of Justice, the tools were used to scan for vulnerabilities and breach critical infrastructure networks in..."

https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-hacking-tools-used-to-breach-critical-infrastructure/
BleepingComputer FBI disrupts Chinese hacking tools used to breach critical infrastructure The FBI has seized seven domains used by Chinese state-sponsored hackers known as Flax Typhoon to operate two hacking tools, MicroScan and FishHub, used in attacks that breached critical infrastructure and other organizations worldwide.
Post #28603 12
🟠 Routers on Trial, AI Found More Bugs - PSW #947
#SecurityWeeklyVideo

"In the security news this week: \- BPFDoor \- OpenSSH compresses a little too much \- AI can find bugs. Who gets them fixed? \- TP-Link and the courts \- Cisco NX-API \- ClingSTUN \- LineageOS, Android TV, and a Raspberry PI \- Dell’s updater has a privilege problem \- SonicWall SSRF \- U-Boot’s LogoFAIL like \- Exploit-DB isn’t dead \- MFA passes. The attacker still gets in. \- LakeShark and cool gadgets \- Kasa cameras and an exposed debug interface \- SharePoint hardening is back on the checklist \- Google pauses open-source bug bounty submissions \- NetScaler’s latest vulnerability needs..."

https://www.youtube.com/watch?v=uYsGmtKSzNE
YouTube Routers on Trial, AI Found More Bugs - PSW #947 In the security news this week: - BPFDoor - OpenSSH compresses a little too much - AI can find bugs. Who gets them fixed? - TP-Link and the courts - Cisco NX-API - ClingSTUN - LineageOS, Android TV, and a Raspberry PI - Dell’s updater has a privilege…
Post #28602 17
Post #28601 26
Post #28600 34
🔴 Cisco warns of critical flaws allowing Nexus switch takeover
#BleepingComputerNews

"Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches.
If remote code execution cannot be achieved, an attacker could exploit the vulnerabilities to crash processes and force the vulnerable device to reload, resulting in a denial-of-service condition.
The issues affect the NX-API, Next Generation OAM (NGOAM), and MPLS OAM features in Nexus 3000 and Nexus 9000 Series switches.
All vulnerabilities relate to
The issues impact Nexus 3000 and Nexus..."

https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-flaws-allowing-nexus-switch-takeover/
BleepingComputer Cisco warns of critical flaws allowing Nexus switch takeover Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches.
Post #28599 32
🟢 Fighting GenAI with GenAI: The New Email Security Landscape
#TheRegisterNews

"The use of phishing emails as a means of stealing information or implanting damaging malware dates back to the mid-1990s.
Although almost as old as the Internet, it remains the instrument of choice for threat actors wanting to pose as trusted organizations or individuals for the purposes of corporate infiltration. In fact its use is on the rise: according to the most recent figures from the Federal Bureau of Investigation (FBI), some 26 percent of all cybercrime complaints filed with them are now phishing-related.
The bad news doesn’t stop there. Phishing is mutating in alarming new ways,..."

https://www.theregister.com/security/2026/10/08/sponsored-fighting-genai-with-genai-the-new-email-security-landscape/5301063
theregister SPONSORED: Fighting GenAI with GenAI: The New Email Security Landscape Old attack, new protections
Post #28598 35
🟡 More Vulnerabilities Don’t Mean More Risk
#SecurityWeeklyVideo

"A dramatic increase in reported vulnerabilities can look like a dramatic increase in organizational risk. But the two measurements are not necessarily equivalent. For nontechnical leaders, a rising vulnerability count can create the impression that security is getting worse. In reality, organizations have never been able to patch everything. Understanding the environment and identifying what is critical are essential to prioritizing risk. If vulnerability counts keep climbing, what should senior leaders use to understand actual cyber risk? Subscribe to our podcasts:..."

https://www.youtube.com/shorts/M01M8uIFRpE
YouTube More Vulnerabilities Don’t Mean More Risk A dramatic increase in reported vulnerabilities can look like a dra...
Post #28597 41
Post #28596 51
🟡 Critical Flaw in Multiple Atlassian Products Exploited in the Wild
#InfosecurityMagazineNews

"A critical vulnerability affecting eight Atlassian products, including Jira and Confluence, is being exploited in the wild, said..."

https://www.infosecurity-magazine.com/news/critical-vulnerability-atlassian/
Infosecurity Magazine Critical Flaw in Multiple Atlassian Products Exploited in the Wild A critical vulnerability affecting eight Atlassian products, including Jira and Confluence, is being exploited in the wild, said VulnCheck
Post #28595 50
Post #28594 56
🟡 Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland
#BleepingComputerNews

"On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities.
The day's highlight was the Samsung Galaxy S26 flagship getting hacked three times by KAIST Hacking Lab's Kyeongmin Kim, PetoWorks, and Mobile Hacking Lab's Dimitrios Valsamaras and Ken Gannon.
Jack Dates of RET2 Systems demoed a Sonos Era 300 exploit chain in under a minute, and Out of Bounds team's HaeJung Yang was awarded $40,000 for hacking Dynamo in the AI Infrastructure category.
PetoWorks, Yves Bieri of Xint, Kyeongmin Kim, _McCaulay,..."

https://www.bleepingcomputer.com/news/security/samsung-galaxy-s26-hacked-three-more-times-at-pwn2own-ireland/
BleepingComputer Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland ​​​On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities.
Post #28592 49
Post #28591 52
🟢 Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
#TheHackersNews

"Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts.
The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have been flagged as malicious.
- The attack is designed to infect Windows systems through three separate pathways -
- A loader for Overlord, an open-source RAT written in Go that uses Solana transactions..."

https://thehackernews.com/2026/10/eight-malicious-npm-packages-downloaded.html
Post #28590 49
Post #28589 47
🟠 SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
#TheHackersNews

"SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions.
SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being used in attacks.
The most serious flaw, tracked as CVE-2026-102255, is a server-side request forgery (SSRF) bug in WorkPlace, the portal that SMA1000 users log in to. It exists due to an unintended access..."

https://thehackernews.com/2026/10/sonicwall-patches-cvss-100-pre.html
Post #28588 50
🔴 Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
#TheHackersNews

"A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available.
The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network message to that server can run commands as the user the LMCache process runs as.
The server can be reached from another machine only when an operator sets it to listen on a routable address, rather than the..."

https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html
Post #28587 51
🟢 PoeLLM malware infects exposed AI servers in cryptomining attacks
#BleepingComputerNews

"A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads.
The malware features an uncommon method to retrieve command-and-control (C2) addresses by extracting keywords in a poem hosted on GitHub.
Researchers at Lumen's Black Lotus Labs (BLL) tracking the botnet malware say it has compromised more than 2,100 servers, with peak activity reaching as many as 800 infected systems active on a single day.
PoeLLM has been active since at least April, but its activity has increased significantly since then, with at..."

https://www.bleepingcomputer.com/news/security/poellm-malware-infects-exposed-ai-servers-in-cryptomining-attacks/
BleepingComputer PoeLLM malware infects exposed AI servers in cryptomining attacks A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads.
Post #28586 44
🟢 Your Data Is Already Vulnerable
#SecurityWeeklyVideo

"Quantum readiness is not only about adopting quantum technology. The more immediate issue is that sensitive data is already exposed today. For banks, capital markets, energy companies, and other critical organizations, resilience means understanding existing vulnerabilities and improving visibility before a future quantum threat becomes the focus. Preparing for quantum without addressing current exposure can leave a major gap in the security strategy. How should organizations balance fixing today’s vulnerabilities with preparing for tomorrow’s quantum risks? Subscribe to our podcasts:..."

https://www.youtube.com/shorts/4QjVIgKkp60
YouTube Your Data Is Already Vulnerable Quantum readiness is not only about adopting quantum technology. Th...
Older posts →

About this channel

How can I read @avleonovnews without a Telegram account?
TGViewer shows the public web preview Telegram publishes for News Vulnerability Management and more: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does News Vulnerability Management and more have?
News Vulnerability Management and more (@avleonovnews) has 1.45K subscribers on Telegram, refreshed roughly every 30 minutes.
Does News Vulnerability Management and more know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →