Cyber Security

Articles on SystemTek’s website that relate to cyber security.

NewsSecurity Vulnerabilities

Apple macOS CoreAudio Out-Of-Bounds Write Remote Code Execution Vulnerability (CVE-2026-43673)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Apple macOS.

Read More
NewsSecurity Vulnerabilities

WordPress Gallery PhotoBlocks Plugin Cross Site Scripting vulnerability (CVE-2026-66448)

– This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.

Read More
NewsSecurity News

UK and Allies Uncover Russian ‘Zero-Click’ Phishing Attack

– Russian state-supported cyber actors have targeted Western organisations with a malicious campaign which uses a zero-click exploit coined “beehive” (or “Ulej”) to steal emails, the UK has warned. 

Read More
NewsSecurity Vulnerabilities

Microsoft Windows WMI Providers Incorrect Authorization Local Privilege Escalation Vulnerability (CVE-2026-50325)

– This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows.

Read More
NewsSecurity Vulnerabilities

ASUS Business Manager Service Client-Side Authentication Local Privilege Escalation Vulnerability (CVE-2026-8921)

– This vulnerability allows local attackers to escalate privileges on affected installations of ASUS Business Manager.

Read More
NewsSecurity Vulnerabilities

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVE-2026-14266)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip.

Read More
NewsSecurity Vulnerabilities

Cisco Identity Services Engine Path Traversal Vulnerability (CVE-2026-20146)

– A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files.

Read More
Uncategorized

JetBrains YouTrack Authentication Bypass via Direct Database Access Leading to Administrative Access Vulnerability (CVE-2026-62422)

CVE number = CVE-2026-62422 In JetBrains YouTrack before versions 2026.1.13757,2025.3.148033,2025.2.148048,2025.1.148120,2024.3.148430,2024.2.148429 Authentication bypass via direct database access leading to administrative access

Read More
NewsSecurity News

UK and Allies urge critical sectors to improve defences against Russian intelligence targeting

– Organisations in critical infrastructure sectors are being supported to better understand and defend against malicious activity, as the UK and international partners today call out techniques used by Russian Intelligence Services

Read More
NewsSecurity Vulnerabilities

JuiceFS – Authentication Bypass via pprof and metrics Endpoints (CVE-2026-59092)

– JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper handler registration on the shared http.DefaultServeMux.

Read More