What broke this week · Area

Advisories as they were published, beside the people writing about them and the rules the internet just agreed on. This is the filing, not the fix: nothing here tells you whether you are affected.

Latest

My Talk at DEF CONBruce Schneierschneier.comCliff Stoll’s DEF CON TalkBruce Schneierschneier.comAIs Compress Exploit TimelineBruce Schneierschneier.comCVE-2026-0306A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enables a local user to bypass configured DLP policy enforcement controls and exfiltrate sensitive data. This Prisma Access Agent on macOS, Linux, iOS, Android and Chrome OS is not affected.nist.govCVE-2026-0307Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. This GlobalProtect app on iOS, Android and ChromeOS is not impacted.nist.govCVE-2026-0308A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store or execute a JavaScript payload using the web interface. This issue is applicable to PAN-OS software on PA-Series and VM-Series firewalls and on Panorama (virtual and M-Series). Cloud NGFW and Prisma® Access are not affected by this vulnerability.nist.govCVE-2026-0305An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to access sensitive configuration data and credentials. The Prisma Access Agent on macOS, Windows, iOS, Android and Chrome OS is not affected.nist.govCVE-2026-49363An unauthenticated remote attacker connecting with the CORE protocol can discover cluster node details by sending a SUBSCRIBE_TOPOLOGY request prior to authentication. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.nist.govCVE-2026-49364An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during the initial cluster connection handshake. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.nist.govCVE-2026-57822When the broker is processing message-based management requests, sent by an authenticated messaging client that is authorized with MANAGE permission to perform management-via-messaging, the parameter processing can trigger Java deserialization of certain method parameters that the broker will not utilise. The permitted types allow to craft a payload causing excessive computation and pinning the processing thread, leading to denial of service. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.3.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.nist.govCVE-2026-57967An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and assume ongoing execution of the previously authenticated session. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.nist.govCVE-2026-67593A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis broker before the connection authentication and authorization stage or at any time thereafter. This issue affects Apache Artemis: from 2.50.0 through 2.56.0; Apache ActiveMQ Artemis: from 1.0.0 through 2.44.0. Users are recommended to upgrade to version 2.57.0, which fixes the issue.nist.gov

More

  1. CVE-2026-75880nist.gov
  2. CVE-2026-49362nist.gov
  3. CVE-2026-76562nist.gov
  4. CVE-2026-4657nist.gov
  5. CVE-2026-15820nist.gov
  6. CVE-2026-15823nist.gov
  7. CVE-2026-18386nist.gov
  8. CVE-2026-18594nist.gov
  9. CVE-2026-15796nist.gov
  10. CVE-2026-14873nist.gov
  11. CVE-2026-15019nist.gov
  12. CVE-2026-19584nist.gov
  13. CVE-2026-84062nist.gov
  14. CVE-2026-84063nist.gov
  15. CVE-2026-87870nist.gov
  16. CVE-2026-19583nist.gov
  17. CVE-2026-18351nist.gov
  18. CVE-2026-87933nist.gov
  19. CVE-2026-87925nist.gov
  20. CVE-2026-87926nist.gov
  21. CVE-2026-87931nist.gov
  22. Driver’s License Data for SaleBruce Schneierschneier.com
  23. Claude Fable Solves a Historical CipherBruce Schneierschneier.com
  24. Supreme Court forces TV stations to sell more election ads at steep discountsarstechnica.com
  25. Top chipmakers embrace ASML’s $400M machines, agree to crucial chipmaking changearstechnica.com
  26. Godzilla Minus Zero IMAX trailer teases King Ghidoraharstechnica.com
  27. “This is the AI men actually use”: Meta ads pushed apps nudifying real teensarstechnica.com
  28. Update to Google’s AI weather model improves forecast accuracyarstechnica.com
  29. AIs as Modern GeniesBruce Schneierschneier.com
  30. Google complies with EU rules for travel searches, says the new results stinkarstechnica.com