The U.S. Cybersecurity and Infrastructure Security Agency expanded its Known Exploited Vulnerabilities catalog to include issues in Smartbedded Meteobridge, Samsung devices, Juniper ScreenOS, Jenkins, and GNU Bash. The KEV designation signals confirmed in-the-wild exploitation and elevates patching priorities for federal agencies and any organization that maps risk to KEV.
Source: Security Affairs
500% spike in scans against Palo Alto Networks login portals
Threat intel firm GreyNoise observed a nearly 500% increase in IPs scanning Palo Alto Networks login portals on October 3, the highest level in three months. The targeted, structured probing suggests credential-stuffing and attack staging against exposed management interfaces; defenders should audit exposure, enforce MFA, and monitor for authentication anomalies.
Source: The Hacker News
Discord discloses vendor breach exposing user IDs and limited billing data
Discord confirmed a data breach at a third-party support vendor that exposed government-issued photo IDs, names, email addresses, and limited billing details for users who interacted with customer support. The incident underscores third-party risk and the sensitivity of support workflows that collect identity documents.
Source: HackRead
Study: Hundreds of free iOS/Android VPN apps leak data and over-collect permissions
Zimperium analyzed 800 free VPN apps and found critical security flaws—including the Heartbleed bug—excessive system permissions, and opaque data practices. For enterprises, these “privacy” apps can increase attack surface in BYOD environments and exfiltrate sensitive data under the guise of protection.
Source: HackRead
‘CometJacking’ turns Perplexity’s Comet AI browser into a one-click data thief
Researchers detailed a prompt-injection technique that embeds malicious instructions in a link, causing Perplexity’s Comet AI browser to exfiltrate sensitive data from the session, including connected services like email and calendar. The attack highlights risks with agentic browsing and the need for stricter permissions and link sanitization.
Source: The Hacker News
NIST flags security weaknesses and propaganda risks in DeepSeek AI models
A new NIST study warns that DeepSeek models have notable security shortcomings and tend to amplify Chinese Communist Party narratives, while also lagging U.S. models on cost and performance. The findings raise supply-chain and content integrity concerns for organizations considering non-domestic AI systems in sensitive workflows.
Source: CyberNews
DoD’s CMMC finalized—what it could mean for state and local agencies
With the Cybersecurity Maturity Model Certification now finalized, analysis explores how federal contractor requirements may cascade to state and local governments through grants and procurement. Agencies are advised to leverage funding to mature controls and prepare for third-party assessments aligned to CMMC tiers.
Source: GovTech
You May Also Be Interested In...
Using .LNK files as lolbinsExclusive: Event startup Partiful wasn't stripping GPS locations from user-uploaded photos
Anker offered Eufy camera owners $2 per video for AI training