Friday Squid Blogging: Rotting Squid on a Beached California Boat
Bruce Schneierschneier.com
Vulnerabilities, security writing, standards and rules as they were filed.
Bruce Schneierschneier.com
| Name | By | Where | When |
|---|---|---|---|
| My Talk at DEF CON | Bruce Schneier | schneier.com | 5d ago |
| Cliff Stoll’s DEF CON Talk | Bruce Schneier | schneier.com | 5d ago |
| AIs Compress Exploit Timeline | Bruce Schneier | schneier.com | 6d ago |
| Revised Medical Criteria for Evaluating Cardiovascular Disorders | federalregister.gov | ||
| CVE-2026-49363An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. | nist.gov | Sep 10 | |
| CVE-2026-49364An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. | nist.gov | Sep 10 | |
| CVE-2026-57822When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The permitted types allow to craft a payload causing excessive computation and pinning the processing thread, leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.3.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. | nist.gov | Sep 10 | |
| CVE-2026-57967An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. | nist.gov | Sep 10 | |
| Continuation of the National Emergency With Respect to Persons Who Commit, Threaten To Commit, or Support Terrorism | federalregister.gov | ||
| CVE-2026-49362An unauthenticated remote attacker can create arbitrary durable queues via the CORE protocol, leading to unauthorized broker state manipulation and potential denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue. | nist.gov | Sep 10 | |
| CVE-2026-76562The Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sbm_description' parameter in all versions up to, and including, 1.18 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | nist.gov | Sep 10 | |
| CVE-2026-4657The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the control_selectors meta field in all versions up to, and including, 2.0.4. This is due to the plugin registering the control_selectors meta field with show_in_rest enabled but without a sanitize_callback, and subsequently outputting this unsanitized data directly into <style> tags on the frontend without proper escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | nist.gov | Sep 10 | |
| CVE-2026-15820The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | nist.gov | Sep 10 | |
| Indiana: Approval of State Coal Combustion Residuals Permit Program | federalregister.gov | ||
| CVE-2026-15823The Builderall Cheetah For Wp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disable() function in versions up to, and including, 3.0.2. The wp_ajax_ba_cheetah_disable AJAX handler is registered without any capability or nonce verification, and the target post_id is sourced directly from user-controlled $_POST['ba_cheetah_data']['post_id']. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disable the page builder layout on arbitrary posts by setting the _ba_cheetah_enabled post meta to false, including on posts owned by other users. | nist.gov | Sep 10 | |
| CVE-2026-18386The WP BackItUp Community Edition plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.0 via the 'backup_file' parameter parameter. This makes it possible for authenticated attackers, with administrator-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. The basename() normalization present in the handler only executes when the traversed target path does not exist, providing no protection against reads of existing files. | nist.gov | Sep 10 | |
| CVE-2026-18594The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with custom-level access and above, to import forged CSV submission records into any Contact Form 7 form managed by the plugin. | nist.gov | Sep 10 | |
| CVE-2026-15796The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bg_video_service_url' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | nist.gov | Sep 10 | |
| Native American Graves Protection and Repatriation Review Committee; Notice of Public Meeting | federalregister.gov | ||
| CVE-2026-14873The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity prior to updating their details like arbitrary user passwords, including administrator passwords, to a known plugin-configured custom value, enabling full account takeover of the site. This makes it possible for authenticated attackers, with subscriber-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account. | nist.gov | Sep 10 | |
| CVE-2026-15019The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The product ownership check only verifies that some free, virtual, downloadable product exists on the site — not that the requested file path belongs to that product's configured downloads — making exploitation viable on any WooCommerce site with at least one such product. | nist.gov | Sep 10 | |
| CVE-2026-19584Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. This allows a malicious user with NOTEBOOK_EDITOR permission to plant a VQL query which will be evaluated at elevated permissions if the notebook's backup is subsequently restored. | nist.gov | Sep 10 | |
| CVE-2026-84062BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who can log in to the product may be caused. | nist.gov | Sep 10 | |
| Medicare Program; Medicare Appeals; Adjustment to the Amount in Controversy Threshold Amounts for Calendar Year 2027 | federalregister.gov | ||
| CVE-2026-84063BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product, potentially allowing arbitrary PHP code to be executed may be caused. | nist.gov | Sep 10 | |
| CVE-2026-87870The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Parameters (interval, format, emailTo) in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level privileges and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The REST endpoint is registered without a permission_callback and only validates a nonce without checking user capabilities. | nist.gov | Sep 10 | |
| CVE-2026-19583Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the CLIENT_EVENTS type. This allows any user who can schedule client monitoring artifacts to also schedule otherwise restricted artifacts (such as Linux.Sys.BashShell). | nist.gov | Sep 10 | |
| CVE-2026-18351The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validation in the is_file_type_valid() function, which uses the attacker-controlled 'type' parameter as regex keys in the MIME allowlist, allowing blacklist bypass via a crafted extension that sanitize_file_name() later normalizes to a PHP extension. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. | nist.gov | Sep 10 | |
| Medicare Program; Public Meeting for New Revisions to the Healthcare Common Procedure Coding System (HCPCS) Level II Coding | federalregister.gov | ||
| CVE-2026-87933A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched remotely. The exploit has been made public and could be used. The pull request to fix this issue awaits acceptance. | nist.gov | Sep 10 | |
| CVE-2026-87925A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Performing a manipulation of the argument pro_name[] results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet. | nist.gov | Sep 10 | |
| CVE-2026-87926A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a manipulation of the argument msg can lead to cross site scripting. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet. | nist.gov | Sep 10 | |
| CVE-2026-87931A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The manipulation leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way. | nist.gov | Sep 10 | |
| Agency Information Collection Activities; Submission to the Office of Management and Budget for Review and Approval; Comment Request; EIB 00-02, Annual Competitiveness Report Survey of Exporters and Lenders | federalregister.gov | ||
| Driver’s License Data for Sale | Bruce Schneier | schneier.com | Sep 9 |
| Claude Fable Solves a Historical Cipher | Bruce Schneier | schneier.com | Sep 9 |
| AIs as Modern Genies | Bruce Schneier | schneier.com | Sep 8 |
| Stealing AI Reasoning Traces | Bruce Schneier | schneier.com | Sep 8 |
| Racial Nondiscrimination in Private Schools; Hearing | federalregister.gov | ||
| Automobile Camouflage to Hide from Flock Cameras | Bruce Schneier | schneier.com | Sep 7 |
| Friday Squid Blogging: Squid on a Stick at the New York State Fair | Bruce Schneier | schneier.com | Sep 4 |
| RFC 10042: Post-Quantum/Traditional Hybrid Key Exchange with the Module-Lattice-Based Key-Encapsulation Mechanism for Use in SSH | rfc-editor.org | Aug 31 | |
| RFC 10034: RTP Payload Format for Visual Volumetric Video-Based Coding (V3C) | rfc-editor.org | Aug 28 | |
| Notice Pursuant to the National Cooperative Research and Production Act of 1993-1EdTech Consortium, Inc. (F/K/A IMS Global Learning Consortium, Inc.) | federalregister.gov | ||
| RFC 10037: Registration Data Access Protocol (RDAP) Extension for DNS Time-to-Live (TTL) Values | rfc-editor.org | Aug 28 | |
| RFC 10038: Distributing the Segment Routing over IPv6 (SRv6) Locator Using DHCPv6 | rfc-editor.org | Aug 28 | |
| RFC 10035: YANG Library: Addition of the augmented-by List | rfc-editor.org | Aug 26 | |
| RFC 10017: OAuth 2.0 for Browser-Based Applications | rfc-editor.org | Aug 21 | |
| Commission Information Collection Activities (Ferc-555); Comment Request; Extension | federalregister.gov | ||
| RFC 10036: Incremental Forwarding of HTTP Messages | rfc-editor.org | Aug 21 |