Cyber Security

Articles on SystemTek’s website that relate to cyber security.

NewsSecurity Vulnerabilities

Cortex XSOAR: Improper Verification of Cryptographic Signature in Microsoft Teams integration (CVE-2026-0234)

CVE number = CVE-2026-0234 An improper verification of cryptographic signature vulnerability exists in Cortex XSOAR and Cortex XSIAM platforms during

Read More
NewsSecurity Vulnerabilities

Ongoing campaign exploiting vulnerabilities in Cisco VPN devices

– An attacker attributed to ArcaneDoor campaign has exploited CVE-2025-20333, CVE-2025-20362, and CVE-2025-20363 to install a sophisticated bootkit for persistent stealthy access to affected devices.

Read More
NewsSecurity Vulnerabilities

DriveLock Directory Traversal Information Disclosure Vulnerability (CVE-2026-5492)

– This vulnerability allows remote attackers to disclose sensitive information on affected installations of DriveLock.

Read More
NewsSecurity NewsSecurity Vulnerabilities

Supply Chain Compromise Impacts Axios Node Package Manager​

– The Cybersecurity and Infrastructure Security Agency (CISA) released an alert to provide guidance in response to the software supply chain compromise of the Axios node package manager (npm). Axios is an HTTP client for JavaScript that developers commonly use in Node.js and browser environments. 

Read More
NewsSecurity Vulnerabilities

Fortinet FortiWeb cat_cgi_paths Out-Of-Bounds Write Remote Code Execution Vulnerability (CVE-2026-40688)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiWeb. Authentication is required to exploit this vulnerability.

Read More
NewsSecurity Vulnerabilities

Samsung MagicINFO 9 Server Incorrect Default Permissions Local Privilege Escalation Vulnerability (CVE-2026-25203)

CVE number = CVE-2026-25203 This vulnerability allows local attackers to escalate privileges on affected installations of Samsung MagicINFO 9 Server.

Read More
NewsSecurity Vulnerabilities

Critical severity vulnerability affecting CPython (CVE-2026-6100)

– Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used.

Read More
NewsSecurity Vulnerabilities

Apache dolphinscheduler sensitive information disclosure (CVE-2023-48796)

– Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache DolphinScheduler.

Read More
NewsSecurity News

SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks

– Forest Blizzard, a threat group associated with the Russian military, has been exploiting poorly secured home and small-office internet devices—such as routers—by taking control of them and altering their configurations.

Read More
NewsSecurity Vulnerabilities

Labcenter Electronics Proteus PDSPRJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability (CVE-2026-5495)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Labcenter Electronics Proteus.

Read More