all articles

CVE-2024-30896 InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states that InfluxDB allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. The supplier indicates that the organizations feature is operating as intended and that users may choose to add users to non-default organizations. A future release of InfluxDB 2.x will remove the ability to retrieve tokens from the API.
CVE-2026-54411 Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.

Cybersecurity

darkreading (https://www.darkreading.com/rss.xml)
Latest:
The Hacker News (https://feeds.feedburner.com/TheHackersNews)
Latest:
BleepingComputer (https://www.bleepingcomputer.com/feed/)
Latest:
MSRC Security Update Guide (https://api.msrc.microsoft.com/update-guide/rss)
Latest:
CVE-2024-30896 InfluxDB OSS 2.x through 2.7.11 stores the administrative operator token under the default organization which allows authorized users with read access to the authorization resource of the default organization to retrieve the operator token. InfluxDB OSS 1.x, Enterprise, Cloud, Cloud Dedicated and Clustered are not affected. NOTE: The researcher states that InfluxDB allows allAccess administrators to retrieve all raw tokens via an "influx auth ls" command. The supplier indicates that the organizations feature is operating as intended and that users may choose to add users to non-default organizations. A future release of InfluxDB 2.x will remove the ability to retrieve tokens from the API.
CVE-2026-54411 Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences. The comparison uses strncmp() (or strncasecmp() when PAM_ICASE_ARG is set) preceded by a length-equality check, so the time to reject a candidate depends on the index of the first differing byte and on whether the candidate's length matches the stored password, leaking the password length and individual prefix bytes. The vulnerable path is reached when the administrator configures pam_userdb with crypt=none, with an unrecognized crypt method, or without a crypt= argument, causing the module to store and compare credentials in plaintext.
Schneier on Security (https://www.schneier.com/blog/atom.xml)
Latest:
All CISA Advisories (https://www.cisa.gov/cybersecurity-advisories/all.xml)
Latest:
CISA News (https://www.cisa.gov/news.xml)
Latest:
Krebs on Security (https://krebsonsecurity.com/feed/)
Latest:
CISA Blog (https://www.cisa.gov/blog.xml)
Latest:
Threatpost (https://threatpost.com/feed/)
Latest:

Threat Intelligence

SANS Internet Storm Center, InfoCON: green (https://isc.sans.edu/rssfeed_full.xml)
Latest:
Unit 42 (https://unit42.paloaltonetworks.com/feed/)
Latest:
Threat Intelligence (https://feeds.feedburner.com/threatintelligence/pvexyqv7v0v)
Latest:
Blog (https://www.crowdstrike.com/blog/feed/)
Latest:

OSINT

Open Source Intelligence (https://www.reddit.com/r/OSINT.rss)
Latest:
bellingcat (https://www.bellingcat.com/feed/)
Latest:

US Breaking News

U.S. Home | Mail Online (https://www.dailymail.co.uk/ushome/index.rss)
Latest:
U.S. News Today on Fox News (https://moxie.foxnews.com/google-publisher/us.xml)
Latest:
WSJ.com : U.S. News (https://feeds.content.dowjones.io/public/rss/RSSUSnews)
Latest:

World Breaking News

BBC News (http://feeds.bbci.co.uk/news/world/rss.xml)
Latest:
WSJ.com: World News (https://feeds.content.dowjones.io/public/rss/RSSWorldNews)
Latest:
Latest World News on Fox News (https://moxie.foxnews.com/google-publisher/world.xml)
Latest:
World news | Mail Online (https://www.dailymail.co.uk/news/worldnews/index.rss)
Latest:

US Politics

Latest Political News on Fox News (https://moxie.foxnews.com/google-publisher/politics.xml)
Latest:
LegiScan US Congress State Feed (https://legiscan.com/gaits/feed/d7f65c53fb3f1a3600e3527ccd716bf8.rss)
Latest:

Business

WSJ.com: US Business (https://feeds.content.dowjones.io/public/rss/WSJcomUSBusiness)
Latest:

World Politics

Foreign Policy (https://foreignpolicy.com/feed/)
Latest:
Atlantic Council (https://www.atlanticcouncil.org/feed/)
Latest:

Department of Defense

Contracts - U.S. Dept. of War (https://www.defense.gov/DesktopModules/ArticleCS/RSS.ashx?ContentType=400&Site=945&max=10)
Latest:
Department of War News Feed (https://www.defense.gov/DesktopModules/ArticleCS/RSS.ashx?max=10&ContentType=1&Site=945)
Latest:
Department of War Featured Stories Feed (https://www.defense.gov/DesktopModules/ArticleCS/RSS.ashx?ContentType=800&Site=945&max=10)
Latest:
News Releases - U.S. Dept. of War (https://www.defense.gov/DesktopModules/ArticleCS/RSS.ashx?ContentType=9&Site=945&max=10)
Latest:
Advisories - U.S. Dept. of War (https://www.defense.gov/DesktopModules/ArticleCS/RSS.ashx?ContentType=2&Site=945&max=10)
Latest:
Transcripts - U.S. Dept. of War (https://www.defense.gov/DesktopModules/ArticleCS/RSS.ashx?ContentType=13&Site=945&max=10)
Latest:

War Monitoring

Defense One - All Content (https://www.defenseone.com/rss/all/)
Latest:

Espionage

NSA News (https://www.nsa.gov/DesktopModules/ArticleCS/RSS.ashx?ContentType=1&Site=1282&max=20)
Latest:
The Cipher Brief Open Source Report (https://feeds.libsyn.com/90836/rss)
Latest:

Space

NASA (https://www.nasa.gov/news-release/feed/)
Latest:
r/SpaceX, the premier SpaceX discussion community (https://www.reddit.com/r/spacex.rss)
Latest:

Indiana

IndyPolitics.Org (https://indypolitics.org/feed/)
Latest:
LegiScan Indiana State Feed (https://legiscan.com/gaits/feed/47313d91ae8ca0755b31856c7c8b5cf0.rss)
Latest:

Italy

🦉📚 welcome!

select a feed group to get started