Recent Advisories

Severity ID Title Vendor Product Date Type
NONE IMPERVABLOG:FF2...

Using Bedrock with Claude Code? Your AWS Credentials Are Shared With Every Subprocess_IMPERVABLOG:FF2E6468F47434CB67407AB7F1141DBF

Many developers today are using Claude Code, with a growing portion running it through Amazon Bedrock. For enterprise teams, Bedrock offers major a...

N/A N/A IMPERVABLOG
NONE SCHNEIER:FF87AA...

Upcoming Speaking Engagements_SCHNEIER:FF87AADC60454183463850A4B99FDCE2

This is a current list of where and when I am scheduled to speak: * I’m giving a virtual talk on “The Security of Trust in the Age of AI,” hoste...

N/A N/A SCHNEIER
NONE QUALYSBLOG:855C...

Achieve Federal-Grade M365 Security: Governing with Qualys SSPM and SCuBA_QUALYSBLOG:855C96831EB1A034498C12E814C39899

**Qualys SaaS Security Posture Management (SSPM) introduces native support for the Secure Cloud Business Applications (SCuBA) compliance framework,...

N/A N/A QUALYSBLOG
NONE MSSECURE:C7FCC0...

Defense in depth for autonomous AI agents_MSSECURE:C7FCC0B6AA7826584F18F54114B7939D

**Designing Secure Autonomous AI Agents with Defense in Depth** AI agents are moving beyond assistance and into action. Instead of generating cont...

N/A N/A MSSECURE
CRITICAL 9.8 THN:067F4AFF97E...

ThreatsDay Bulletin: PAN-OS RCE, Mythos cURL Bug, AI Tokenizer Attacks, and 10+ Stories_THN:067F4AFF97EE5175ED3AA056125B2626

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjImYNT-qC7frGzEXeok3KDX_JNMKote6V1FVXIpkAoSEER2z1YyT8dpFq5RtRhBQ0cweEPbBIuioDWFf5rw_...

N/A N/A THN
NONE AKAMAIBLOG:51A9...

The Internet Has a Front Door — The Edge Is Now Intelligent_AKAMAIBLOG:51A95497B6837A2A03D0FE3ABFCF1546

Recent improvements in the capabilities of the edge network have created a smarter, more connected edge. These changes call for a reassessment of e...

N/A N/A AKAMAIBLOG
NONE QUALYSBLOG:9876...

FedRAMP High Authorized: Qualys TotalCloud CNAPP – From Compliance to Defense_QUALYSBLOG:9876D026285E975FEB7911F38A4BE347

**Qualys TotalCloud![™](https://s.w.org/images/core/emoji/17.0.2/72x72/2122.png) has achieved FedRAMP High Authorization, marking a major milestone...

N/A N/A QUALYSBLOG
NONE THN:E4F2C1ED390...

Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike_THN:E4F2C1ED39097CE159F8ED709A409925

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhEld5BcqD9rYWVjx7o_XlV5pN_9djvilow0iIYP-LlFEzGReX8fTPZ0gKi9zMGVLTT8qddHu5FyBMaZpQroE...

N/A N/A THN
NONE HACKREAD:CEBC2B...

FamousSparrow Targeted Oil and Gas Industry via MS Exchange Server Exploit_HACKREAD:CEBC2B71D643C2824DE566505C3FC5DA

Bitdefender Labs reveals how the China-linked FamousSparrow hacking group targeted an Azerbaijani energy firm using ProxyNotShell, Deed RAT,…

N/A N/A HACKREAD
NONE HACKREAD:3AEE54...

China-Linked Twill Typhoon Uses Fake Apple and Yahoo Sites for Espionage_HACKREAD:3AEE544DD9E3429EEE8313A3FF885E63

A new Darktrace report reveals how Chinese hackers use fake Apple and Yahoo sites and the FDMTP malware framework to spy on organisations.

N/A N/A HACKREAD