left cover bg
circles

Security Daily.

Friday, September 25, 2026

Automatically Curated Security Digest

Collected

13 Articles

Across

2 Trusted Sources

Published

Last Updated 11:48 AM UTC

Coverage

BleepingComputer
CISA
Top Story

Eufy Omni C20, Omni X10 Pro

CISAHigh

Why it matters

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to run system level commands or execute arbitrary code. The following versions of Eufy Omni C20, Omni X10 Pro are affected:…

Read Original

13

Articles

2

Sources

2

CVEs

4

Alerts

0

Research

3m

Read Time

Feed Status

CISA5
NIST NVD
BleepingComputer15
PortSwigger Research1

Automated Security Digest — This page is an automatically curated cybersecurity digest generated from publicly available security feeds. All articles remain the property of their respective publishers. Click any item to read the original article.

Last generated: Sep 25, 2026, 11:48 AM

Security Alerts

4

Critical alerts and advisories from official agencies.

CISASecurity AlertsHigh

Eufy Omni C20, Omni X10 Pro

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to run system level commands or execute arbitrary code. The following versions of Eufy Omni C20, Omni X10 Pro are affected: Omni C20 <1.6.4 (CVE-2026-93289, CVE-2026-93290, CVE-2026-93291)…

CVE-2026-93289CVE-2026-93290CVE-2026-93291
Read Original
CISASecurity Alerts

Botslab G980H Dashcams

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to bypass authentication controls, gain unauthorized access to sensitive data and privileged device functionality, modify device configuration, disrupt device operation. The following…

Read Original
CISASecurity AlertsInfo

Siemens Mendix Runtime (Update A)

View CSAF Summary This advisory is revoked. Re-investigation confirmed the reported behavior is expected platform configuration and does not expose the protected attribute. The following versions of Siemens Mendix Runtime are affected: Siemens Mendix Runtime vers:all/*…

Read Original
CISASecurity AlertsCritical

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization…

CVE-2026-5430CVE-2026-71362
Read Original

Cybersecurity News

9

Latest news from trusted cybersecurity publications.

BleepingComputerCybersecurity News

Rydox marketplace admin pleads guilty, faces 22 years in prison

A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. [...]

Read Original
BleepingComputerCybersecurity News

Microsoft: Recent Windows updates cause desktop loading issues

Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. [...]

Read Original
BleepingComputerCybersecurity News

Hackers steal $351.6 million in Bitget crypto exchange hack

​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. [...]

Read Original
BleepingComputerCybersecurity News

MacSync malware uses public iCloud calendars to deliver new payloads

A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]

Read Original
BleepingComputerCybersecurity News

New Carbonato malware uses AI agents to hijack exposed Docker hosts

A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]

Read Original
BleepingComputerCybersecurity News

Exposed GitLab project email addresses let attackers push code

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]

Read Original
BleepingComputerCybersecurity News

FedRAMP VDR & VER: Daily Scans Are Only the Beginning

FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward…

Read Original
BleepingComputerCybersecurity NewsCritical

Hackers now exploit critical Roundcube flaw in code injection attacks

A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]

Read Original
BleepingComputerCybersecurity News

Windows 11 KB5124010 update released with 46 changes and fixes

Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. [...]

Read Original

Share This Digest