Cussins Enterprises LLC
Technology is a paint brush on the canvas of life.
What can we paint for you?
Cybersecurity News
Awareness of what is happening is the 1st to a secure system.Threat Post
| WP HTTP Error: cURL error 52: Empty reply from server |
Beeping Computer
| https://www.bleepingcomputer.com/feed/ is invalid XML, likely due to invalid characters. XML error: XML_ERR_NAME_REQUIRED at line 1, column 1342 |
Motherboard
| WP HTTP Error: A valid URL was not provided. |
Data Breeches
Poland reports a second medical data cyberattack in recent weeksOn September 26, 2026Source: DataBreaches.NetBy DissentCategories: Hack, Health Data, Non-U.S. Polish healthcare entities have been the victims of cyberattacks recently. First, it was the MyDr s… Read more |
Pentagon data breach of military personnel raises national security concernsOn September 26, 2026Source: DataBreaches.NetBy DissentCategories: Government Sector, Hack, Of Note, U.S. Sean Lyngaas and Davis Winkie report: A data breach at the Pentagon’s vast HR system has exposed Soc… Read more |
Some Supabase customers are publicly exposing reams of people’s data to the webOn September 26, 2026Source: DataBreaches.NetBy DissentCategories: Exposure Zack Whittaker reports today’s nominee for the “No need to hack when it’s leaking… Read more |
Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failingsOn September 26, 2026Source: DataBreaches.NetBy DissentCategories: Breach Incidents Suzanne Smiley reports another update on litigation stemming from the American Medical Collection Ag… Read more |
AI breach puts cyber insurance notification rules under scrutinyOn September 25, 2026Source: DataBreaches.NetBy DissentCategories: Commentaries and Analyses, Miscellaneous, cyber insurance, cyberinsurance Roxanne Libatique writes: An OpenAI agent accessed Australian government health data in June 2026. T… Read more |
DIVD Dutch Institute for Vulnerability Disclosure investigating agentic AI-powered attackOn September 25, 2026Source: DataBreaches.NetBy DissentCategories: Artificial Intelligence, Miscellaneous, Non-U.S. A Dutch non-profit that has helped so many over the years has discovered it become the victim of wha… Read more |
OpenAI agent breached Australian government health website, Albanese saysOn September 24, 2026Source: DataBreaches.NetBy DissentCategories: Artificial Intelligence, Breach Incidents Alexander Martin reports: An OpenAI agent gained “unauthorized access” to “non-public files” from an… Read more |
Stevens Point servers go offline, city officials not sure if caused by a cyberattackOn September 24, 2026Source: DataBreaches.NetBy DissentCategories: Government Sector Brandi Makuski reports: Stevens Point officials are investigating a possible cyberattack after sever… Read more |
Kosovar National Pleads Guilty to Operating Cybercrime Marketplace Offering Tools and Products to CybercriminalsOn September 24, 2026Source: DataBreaches.NetBy DissentCategories: Miscellaneous, Rydox From the DOJ: Ardit Kutleshi, 28, a Kosovar national, pleaded guilty to charges related to his creat… Read more |
Two Maryland hospitals still dealing with system issues after cyberattackOn September 24, 2026Source: DataBreaches.NetBy DissentCategories: Health Data, Malware, U.S. On September 22, WYPR reported: Luminis Health says it’s making considerable progress on restoring s… Read more |
Cyberscoop
Army soldier sentenced for spree of attacks on AT&T, Snowflake and other major companiesOn September 25, 2026Source: CyberScoopBy Matt KapkoCategories: Cybercrime, Cybersecurity, AT&T, cybercrime, Department of Justice (DOJ), extortion, guilty, hacking, Justice Department, Snowflake, Ticketmaster Cameron Wagenius was involved in some of the most high-profile attacks of 2024 while on active duty.… Read more |
Supreme Court permits states to use SAVE database for citizenship checksOn September 25, 2026Source: CyberScoopBy djohnsonCategories: Cybersecurity, Election Security, Government, Policy, election, election security, SAVE database, U.S. Supreme Court, voter registration Three justices wrote in a dissent that longstanding privacy laws protecting sensitive personal data… Read more |
House and Senate members propose legislation for CISA to step up cyber defenses for biotechOn September 24, 2026Source: CyberScoopBy Tim StarksCategories: Policy, Government, Healthcare, Amgen, biotechnology, Boston Scientific, Congress, critical infrastructure, cyber strategy, Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security (DHS), maggie hassan, National Infrastructure Protection Plan, Ro Khanna, Todd Young Biotechnology doesn’t have its own critical infrastructure designation, so the bipartisan group of l… Read more |
New bill would create federal investigative body for AI-driven hacksOn September 24, 2026Source: CyberScoopBy djohnsonCategories: AI, Cybersecurity, Government, Policy, Technology, AI hacking, Anthropic, Artificial Intelligence (AI), Congress, legislation, Meta, OpenAI, oversight A new Democratic bill in Congress would establish a federal Cybersecurity and AI Board of Investigat… Read more |
Phone-hacking company that won U.S. security agency contracts hid Russian ownership, DOJ allegesOn September 24, 2026Source: CyberScoopBy Tim StarksCategories: Government, Privacy, Access Now, cellphones, Department of Defense (DOD), Department of Homeland Security (DHS), Department of Justice (DOJ), Homeland Security Investigations, Oxygen, Russia, Secret Service, U.S. courts The Justice Department said two leaders of the company have been arrested and face conspiracy to com… Read more |
Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacksOn September 24, 2026Source: CyberScoopBy Tim StarksCategories: Exclusive, Government, Threats, Policy, Mark Warner, NTIA, telecommunications, Senate Intelligence Committee, Senate Commerce Committee, standards, Salt Typhoon, Ted Cruz The legislation from Senate Intelligence Vice-Chairman. Mark Warner, D-Va., and Senate Commerce Chai… Read more |
How tax policy can stop threat actors from breaching US water systemsOn September 24, 2026Source: CyberScoopBy Greg OttoCategories: Uncategorized, Commentary, critical infrastructure, op-ed, cybersecurity funding, tax code New federal programs take years to launch and fund. State and local governments need cybersecurity s… Read more |
CISA outlines improvement plan for CVE programOn September 24, 2026Source: CyberScoopBy Tim StarksCategories: Government, Technology, Threats, Policy, National Institute of Standards and Technology (NIST), CVE, National Vulnerability Database, OWASP, Cybersecurity and Infrastructure Security Agency (CISA), VulnCheck, Chris Butera, Sonatype The white paper is the latest step in trying to create a “Quality Era” for the Common Vulnerabilitie… Read more |
Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attackOn September 23, 2026Source: CyberScoopBy Tim StarksCategories: Government, Threats, Policy, Federal IT, Inspector general, Binding Operational Directive, multi-factor authentication (MFA), Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), Cloud, SCuBa The DHS inspector general said CISA lacks the power to compel agencies to implement its Binding Oper… Read more |
Pentagon cyber chief: The demand far exceeds supplyOn September 23, 2026Source: CyberScoopBy Greg OttoCategories: AI, Government, Artificial Intelligence (AI), Cyber Command, DefenseTalks, Department of Defense (DOD) At DefenseTalks on Tuesday, Katie Sutton said the Pentagon now receives far more requests to use cyb… Read more |
Krebs On Security
The Hacker News
![]() Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web ShellsOn September 26, 2026Source: The Hacker NewsByGoogle is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSof… Read more Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.
The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution.
The vulnerability was first exploited as a zero-day |
![]() Zero Trust for AI Agents Starts With Fixing Zero VisibilityOn September 26, 2026Source: The Hacker NewsByThe way we talk about AI agents is shifting, and the way we implement them requires an even more fun… Read more The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to |
![]() Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted LinkOn September 26, 2026Source: The Hacker NewsByDetails have emerged about a high-severity security flaw in the Elementor Website Builder WordPress… Read more Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site.
The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions |
![]() SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the WildOn September 26, 2026Source: The Hacker NewsByThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws… Read more The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerabilities in question are as follows -
CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint |
![]() Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber AttackOn September 26, 2026Source: The Hacker NewsByKiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary mea… Read more Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack.
"Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief |
![]() Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud MalwareOn September 25, 2026Source: The Hacker NewsByTwo actions-cool GitHub Actions have been disabled for a second time after the repositories became a… Read more Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign.
The affected GitHub Actions are listed below -
actions-cool/issues-helper
actions-cool/maintain-one-comment
Visiting either of the repositories now shows the message: "Access to this |
![]() PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer PersistenceOn September 25, 2026Source: The Hacker NewsByCybersecurity researchers have flagged a new version of PamStealer that ensures that the main payloa… Read more Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.
The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method.
"Where earlier variants embedded their payload key material |
![]() The SOC Doesn't Need to Start Over with Every AlertOn September 25, 2026Source: The Hacker NewsBySecurity leaders keep debating whether AI will produce an entirely new class of cyberattack. The nea… Read more Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry.
The routine version looks like this. An attacker lands on a low-privilege cloud account, and the first try at privilege escalation goes nowhere. That dead end used to cost hours of documentation reading, |
![]() Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend CompromiseOn September 25, 2026Source: The Hacker NewsByCryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million… Read more Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.
"At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain |
![]() Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the WildOn September 25, 2026Source: The Hacker NewsByThe Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability… Read more The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.
The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.
The issue stems from a preg_replace() backslash |
How Can We Help?



















