Cyber Security

Articles on SystemTek’s website that relate to cyber security.

NewsSecurity Vulnerabilities

SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability (CVE-2026-66148)

– This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall GMS Virtual Appliance.

Read More
NewsSecurity Vulnerabilities

SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability (CVE-2026-66150)

– This vulnerability allows local attackers to escalate privileges on affected installations of SonicWall Email Security.

Read More
NewsSecurity Vulnerabilities

Apache Tomcat allowed bypass of EncryptInterceptor (CVE-2026-29146)

– Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor.

Read More
NewsSecurity News

Cyberattack on UK Department for Education and Police Exposes Sensitive Information

– A cyberattack has compromised systems used by the UK Department for Education (DfE) and a police legal database, with hackers claiming to have stolen more than 740,000 records containing sensitive information.

Read More
NewsSecurity Vulnerabilities

WatchGuard FireWare OS cli Token Parser Stack-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2026-13053)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS.

Read More
NewsSecurity News

NordVPN introduces transaction monitoring for bank accounts

– NordVPN’s Dark Web Monitor already alerts users when their personal data, such as passwords or card details, shows up in a breach.

Read More
NewsSecurity Vulnerabilities

Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability (CVE-2026-18267)

– This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices.

Read More
NewsSecurity Vulnerabilities

Apple macOS CoreAudio Out-Of-Bounds Write Remote Code Execution Vulnerability (CVE-2026-43673)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS.

Read More
NewsSecurity Vulnerabilities

WordPress Gallery PhotoBlocks Plugin Cross Site Scripting vulnerability (CVE-2026-66448)

– This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

Read More
NewsSecurity News

UK and Allies Uncover Russian ‘Zero-Click’ Phishing Attack

– Russian state-supported cyber actors have targeted Western organisations with a malicious campaign which uses a zero-click exploit coined “beehive” (or “Ulej”) to steal emails, the UK has warned. 

Read More