Top 10 Device Control & USB Security Tools for 2026 Evaluated
A new evaluation ranks the top 10 device control and USB security tools for 2026, assessing their effectiveness in preventing malware and data exfiltration.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 6,130 stories synthesized.
A new evaluation ranks the top 10 device control and USB security tools for 2026, assessing their effectiveness in preventing malware and data exfiltration.
Nearly 10% of internet-facing LiteLLM servers accepted the default 'sk-1234' admin key, granting attackers full administrative access.
Threat actors are increasingly using commercial AI models like Claude and GPT-4 to expedite post-compromise activities, targeting government and financial organizations in Latin America.
A dental practice left patient records vulnerable for years due to an unmanaged administrator account created by a former contractor.
The EU's Cyber Resilience Act now requires businesses selling connected products in member states to report serious security incidents within 24 hours to ENISA, with significant fines for non-compliance.
GitGuardian's new Honeytoken service offers real-time detection of credential theft attempts on developer machines, aiming to intercept stolen credentials before they can be exploited.
Key findings • 25 CVEs disclosed together for Drupal between September 9-10, 2026. • All advisories direct users to the official Drupal security page for details. • The batch includes CVE…
A use-after-free vulnerability in Adobe Acrobat Reader DC's font parsing component enables remote attackers to disclose sensitive information, requiring user interaction.
A critical out-of-bounds read vulnerability in Adobe Acrobat Pro DC allows remote attackers to disclose sensitive information on affected systems.
A critical remote code execution vulnerability (CVE-2026-19397) in ASUS Control Center Express Agent allows unauthenticated attackers to execute arbitrary code on affected systems.
A critical information disclosure vulnerability in Adobe Acrobat Reader DC's JBIG2 file parsing allows remote attackers to expose sensitive data with user interaction.
A critical use-after-free vulnerability in Adobe Acrobat Reader DC, tracked as CVE-2026-81976, enables remote code execution with a CVSS score of 7.8.
A new vulnerability in Adobe Acrobat Reader DC allows remote attackers to disclose sensitive information by exploiting a flaw in JPEG2000 file parsing.
A critical vulnerability in OpenAI Codex, tracked as CVE-2026-19591, allows remote code execution when users interact with specially crafted malicious folders.
A critical integer overflow vulnerability in Adobe Acrobat Pro DC's JPEG parsing component allows remote code execution, requiring user interaction with a malicious file or webpage.
A critical integer overflow vulnerability in Adobe Photoshop's DCM JPEG image parsing allows remote code execution, requiring only user interaction with a malicious file or webpage.
A Time-Of-Check Time-Of-Use vulnerability in TrendAI's Apex One Security Agent allows local attackers to escalate privileges, potentially leading to arbitrary code execution.
A stack-based buffer overflow in PAPPL's IPP processing allows local attackers to escalate privileges on affected systems.
A critical heap-based buffer overflow vulnerability in PAPPL, tracked as ZDI-26-656, allows unauthenticated remote attackers to execute arbitrary code with a CVSS score of 9.8.
OPAQUE has introduced the Weight Custody Manifest (WCM), an open standard designed to cryptographically bind AI model weights to specific hardware, preventing unauthorized decryption and use.
Hardware wallet manufacturer Trezor has alerted customers to phishing attempts following a breach of its email service provider, while cryptocurrency exchange Liquid has halted network operations after a massive $320 million Bitcoin withdrawal.
Key findings • Two actively-exploited Mikrotik vulnerabilities, CVE-2026-67277 and CVE-2026-86060, added to CISA KEV. • Inclusion in KEV confirms active exploitation by threat actors in the w…
GitLab has issued urgent patch releases (19.3.2, 19.2.6, 19.1.8) to address a critical path traversal flaw (CVE-2026-85706) and other high-severity vulnerabilities affecting both Community and Enterprise Editions.
The first alpha release of OpenSSL 4.1.0 brings support for Datagram Transport Layer Security (DTLS) 1.3 and performance enhancements for post-quantum cryptography algorithms.