MalwareTips Newswire

Security updates, independent AV tests and useful news for the MalwareTips community.
Everything in one placeAll security news, as it happensMalwareTips articles, community discussions and the security industry, newest first.
Industry
CISA Advisories
CISA AdvisoriesSecurity updates

MikroTik RouterOS

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. The following versions of MikroTik RouterOS are affected: RouterOS <7.24 (CVE-2026-84411) CVSS Vendor Equipment Vulnerabilities v3 9.8 MikroTik MikroTik RouterOS Integer Underflow (Wrap or Wraparound) Background Critical Infrastructure Sectors: Communications, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: Latvia Vulnerabilities Expand All + CVE-2026-84411 The web management service in affected RouterOS versions contains an integer underflow in its HTTP request body handling that is reachable before authentication. This can be leveraged by an unauthenticated network attacker to achieve arbitrary code execution as root, or to cause a denial of service, using a single crafted request. View CVE Details Affected Products MikroTik RouterOS Vendor: MikroTik Product Version: MikroTik RouterOS: <7.24 Product Status: known_affected Remediations Vendor fix MikroTik recommends users update RouterOS to version 7.23 or later. The upgrade can be downloaded from the MikroTik website. https://mikrotik.com/download Relevant CWE: CWE-191 Integer Underflow (Wrap or Wraparound) Metrics CVSS Version Base Score Base Severity Vector String 3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments An anonymous researcher reported thi
Industry
CISA Advisories
CISA AdvisoriesSecurity updates

Baicells Nova 430H

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition. The following versions of Baicells Nova 430H are affected: Nova 430H eNodeB (model pBS3101SH) <=BaiBLQ_3.0.12 (CVE-2026-96274) CVSS Vendor Equipment Vulnerabilities v3 7.4 Baicells Technologies Baicells Nova 430H Uncaught Exception Background Critical Infrastructure Sectors: Communications, Information Technology Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-96274 In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling association for the cell. This results in a temporary service disruption until the eNodeB and core network re-establish connectivity. View CVE Details Affected Products Baicells Nova 430H Vendor: Baicells Technologies Product Version: Baicells Technologies Nova 430H eNodeB (model pBS3101SH): <=BaiBLQ_3.0.12 Product Status: known_affected Remediations No fix planned Baicells has not responded to requests to work with CISA to mitigate this vulnerability. Users of affected versions of Nova 430H eNodeB are invited to contact Baicells customer support for additional information (https://www.baicells.com/contact-us). Relevant
Forum
Newswire
Industry
Image from Help Net Security for Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)
Help Net SecuritySecurity updates

Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950)

Apple has shipped iOS and macOS security updates to fix an actively exploited zero-day vulnerability (CVE-2026-86950) in the operating systems’ Core Graphics framework. “Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27,” the company said, but refrained from providing additional details about the attacks or targets. About CVE-2026-86950 Core Graphics handles “path-based drawing, transformations, color … More → The post Apple squashes zero-day bug exploited in “extremely sophisticated” attack (CVE-2026-86950) appeared first on Help Net Security.
Industry
Industry
Image from Help Net Security for Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider
Help Net SecurityMalware & threats

Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider

Hackers stole patient data from Qbusoft, a Polish medical software maker, weeks after a breach at another provider exposed records of nearly 19 million people in the country. The data comes from Medyc, a platform the company sells to medical offices and clinics to manage patient registration, records and prescriptions. In August, attackers stole data on nearly 19 million people from MyDr, a Warsaw-based company whose software is used by about 12,000 healthcare facilities. The … More → The post Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider appeared first on Help Net Security.
Industry
Industry
Image from Help Net Security for Cloudflare’s EmDash 1.0 makes sandboxed plugins ask for access first
Help Net SecurityMalware & threats

Cloudflare’s EmDash 1.0 makes sandboxed plugins ask for access first

Cloudflare released EmDash 1.0, a free, open source content management system that locks each sandboxed plugin in its own isolated runtime. A plugin starts with access to its own private storage. It cannot reach the site’s content, media, users, secrets, environment, filesystem, or network until it declares what it needs and a site administrator approves the request. The people this protects are site owners who run code they did not write. Cloudflare pitches EmDash as … More → The post Cloudflare’s EmDash 1.0 makes sandboxed plugins ask for access first appeared first on Help Net Security.
Industry
Industry
Image from Help Net Security for GitHub’s AI agent found 24 Android app vulnerabilities
Help Net SecurityMalware & threats

GitHub’s AI agent found 24 Android app vulnerabilities

GitHub Security Lab researcher Kevin Stubbings built custom AI-driven audit workflows, called taskflows, on top of the lab’s open source Taskflow Agent, and used them to find and report more than 20 vulnerabilities in Android apps. Two of the disclosed bugs show what’s at stake. In OsmAnd, a navigation app with over 10 million downloads on the Play Store, an exported activity called MapActivity accepted intent extras that should have stayed restricted to an internal … More → The post GitHub’s AI agent found 24 Android app vulnerabilities appeared first on Help Net Security.
Industry
Industry
Image from The Hacker News for OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
The Hacker NewsMalware & threats

OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot

OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions. "An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions:
Industry
Image from Help Net Security for Cybersecurity jobs available right now: September 29, 2026
Help Net SecurityMalware & threats

Cybersecurity jobs available right now: September 29, 2026

Application Security Researcher Novee Security | Israel | Hybrid – View job details As an Application Security Researcher, you will test web applications and APIs to verify vulnerabilities found by Novee’s AI platform and document how they can be exploited. You will help customers reproduce and fix findings, investigate missed or inaccurate results, and work with research and engineering teams to improve detection. You will also develop new testing methods and support complex customer deployments. … More → The post Cybersecurity jobs available right now: September 29, 2026 appeared first on Help Net Security.
Industry
Industry
Industry
SANS ISC
SANS ISCSecurity updates

Apple Emergency Patch for iOS 26/macOS26/macOS15 (CVE-2026-86950), (Mon, Sep 28th)

Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today&&#x23;x26;&#x23;39;s update for the current "27" branch does not address security issues, but fixes some functional issues that got caught after the release two weeks ago. A 27.1 version was also expected to support the new foldable iPhone and will likely include specific features geared to the soon to be available device. &#xd;
Industry
Industry
Industry
Industry
Industry
Industry
Image from Security Affairs for AI Accounts Are Becoming the New Target for Infostealers
Security AffairsMalware & threats

AI Accounts Are Becoming the New Target for Infostealers

Infostealers are exposing corporate AI accounts, sessions and API keys, giving attackers access to sensitive data, compute and connected systems. SOCRadar analyzed stealer log data from the last 90 days and found 482 companies with exposed AI accounts and credentials. Of those, 295 appeared in active logs during that period, suggesting the exposure is recent […]
Forum
Back
Top