Data & infrastructure
-
Researchers detail closed ChatGPT cross-account channel
Check Point has disclosed a now-closed ChatGPT cross-account channel that used shared internal package infrastructure to relay hidden tasks and data between isolated execution environments.
-
Microsoft fixes two exploited Windows zero-days
Microsoft’s September Patch Tuesday fixes two exploited privilege-escalation zero-days amid its largest monthly security release, although third-party counts differ slightly by methodology.
-
UK space strategy puts resilience first
The UK will develop a resilient national satellite communications system as a £7.8 billion space strategy brings infrastructure, defence, procurement, and economic security under one plan.
-
SAP fixes critical enterprise software flaws
SAP’s September security release includes a CVSS 10.0 memory-corruption flaw and three other critical vulnerabilities across NetWeaver, cloud application components, and SAP GUI for Java.
-
Rogue ScreenConnect clients propagate malicious scripts
Huntress has observed modified ScreenConnect clients deploying malicious scripts and propagating the same activity to newly connected systems, while ConnectWise separately prepares a file-transfer fix.
-
NetScaler bypass draws exploitation attempts
Exploit attempts against a critical NetScaler authentication bypass are being observed after public proof-of-concept code appeared, increasing pressure on operators still running vulnerable appliances.
-
N-central flaw draws exploitation warning
Dutch authorities say exploitation attempts have been observed against a maximum-severity N-central vulnerability, while N-able says it has no confirmed production exploitation.
-
Telia fault disrupts Sweden’s SE-Alert test
Sweden’s first regional test of its new mobile emergency-warning system failed to reach all Telia subscribers, exposing an operator dependency before a planned nationwide exercise.
-
HPE fixes critical AOS-CX code execution flaws
HPE has patched critical vulnerabilities in Aruba AOS-CX that could allow an unauthenticated remote attacker to execute code with elevated privileges on enterprise switches.
-
EU defence officials resist cloud sovereignty rules
European defence officials are pushing back against parts of the EU’s proposed cloud sovereignty regime, warning that strict restrictions on non-European providers could undermine military capability and interoperability.










