<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: BeyondMachines</title>
    <description>The latest articles on DEV Community by BeyondMachines (@beyondmachines).</description>
    <link>https://dev.to/beyondmachines</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Forganization%2Fprofile_image%2F11918%2F48c4d1b8-9bad-45fc-9717-af1f9d280297.png</url>
      <title>DEV Community: BeyondMachines</title>
      <link>https://dev.to/beyondmachines</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/beyondmachines"/>
    <language>en</language>
    <item>
      <title>Palo Alto Networks PAN-OS Authentication Bypass Exploited in the Wild</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Sun, 31 May 2026 10:01:08 +0000</pubDate>
      <link>https://dev.to/beyondmachines/palo-alto-networks-pan-os-authentication-bypass-exploited-in-the-wild-5fad</link>
      <guid>https://dev.to/beyondmachines/palo-alto-networks-pan-os-authentication-bypass-exploited-in-the-wild-5fad</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Palo Alto Networks patched a high-severity authentication bypass vulnerability (CVE-2026-0257) in PAN-OS and Prisma Access that is being exploited to gain unauthorized VPN access. The flaw allows attackers to forge session cookies when encryption certificates are shared with HTTPS services.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you use Palo Alto Networks PAN-OS or Prisma Access with GlobalProtect, ASAP, your devices are already under attack. Review the advisory and upgrade to the respective patched version (12.1.7, 11.2.12, 11.1.15, or 10.2.18-h6). If you can't patch right away, disable the authentication override feature or generate a separate certificate just for cookie encryption that isn't shared with the HTTPS service.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/palo-alto-networks-pan-os-authentication-bypass-exploited-in-the-wild-f-1-o-b-b/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Critical Samba Printing Vulnerability Enables Remote Code Execution</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Sun, 31 May 2026 09:01:07 +0000</pubDate>
      <link>https://dev.to/beyondmachines/critical-samba-printing-vulnerability-enables-remote-code-execution-28gl</link>
      <guid>https://dev.to/beyondmachines/critical-samba-printing-vulnerability-enables-remote-code-execution-28gl</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Samba patched a critical remote code execution vulnerability (CVE-2026-4480) in its printing subsystem caused by improper sanitization of the %J substitution parameter. The flaw allows unauthenticated attackers to run arbitrary shell commands by submitting crafted print job descriptions.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you run Samba file/print servers, immediately upgrade to versions 4.22.10, 4.23.8, or 4.24.3 to patch CVE-2026-4480, or as a quick fix remove the %J parameter from the "print command" line in your smb.conf file. Also disable guest access to printing and make sure your Samba servers are only reachable from trusted internal networks, never directly from the internet.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/critical-samba-printing-vulnerability-enables-remote-code-execution-o-j-r-w-v/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Zcash Foundation Issues Emergency Zebra 4.5.0 Update to Fix Critical Consensus Flaw</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Sun, 31 May 2026 08:01:07 +0000</pubDate>
      <link>https://dev.to/beyondmachines/zcash-foundation-issues-emergency-zebra-450-update-to-fix-critical-consensus-flaw-2ppd</link>
      <guid>https://dev.to/beyondmachines/zcash-foundation-issues-emergency-zebra-450-update-to-fix-critical-consensus-flaw-2ppd</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;The Zcash Foundation released Zebra 4.5.0 to address 13 vulnerabilities, including a critical consensus flaw (GHSA-gf9r-m956-97qx) that could cause a chain split and high-severity issues leading to permanent node halts.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you're running a Zebra Zcash node, upgrade to version 4.5.0 ASAP to patch 13 vulnerabilities, including a critical flaw that could split you off from the rest of the network. Until you upgrade, your node is at risk of crashing, getting stuck, or disagreeing with other nodes about the state of the blockchain.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/zcash-foundation-issues-emergency-zebra-4-5-0-update-to-fix-critical-consensus-flaw-s-h-g-l-8/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Critical WP Maps Pro Vulnerability Allows Unauthenticated Administrator Takeover</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Sat, 30 May 2026 15:01:08 +0000</pubDate>
      <link>https://dev.to/beyondmachines/critical-wp-maps-pro-vulnerability-allows-unauthenticated-administrator-takeover-2n9h</link>
      <guid>https://dev.to/beyondmachines/critical-wp-maps-pro-vulnerability-allows-unauthenticated-administrator-takeover-2n9h</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;WP Maps Pro versions 6.1.0 and earlier contain a critical vulnerability (CVE-2026-8732) that allows unauthenticated attackers to create administrator accounts and take full control of WordPress sites.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you use the WP Maps Pro WordPress plugin, this is urgent. Update to version 6.1.1 immediately to patch this critical flaw that lets attackers create admin accounts on your site. Also, audit your WordPress user list for any suspicious admin accounts (especially ones tied to &lt;a href="mailto:support@flippercode.com"&gt;support@flippercode.com&lt;/a&gt;) and remove them.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/critical-wp-maps-pro-vulnerability-allows-unauthenticated-administrator-takeover-e-g-t-g-s/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>MyPillow Internal Data Allegedly Leaked Following a Claimed Play Ransomware Attack</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Sat, 30 May 2026 10:01:08 +0000</pubDate>
      <link>https://dev.to/beyondmachines/mypillow-internal-data-allegedly-leaked-following-a-claimed-play-ransomware-attack-1cof</link>
      <guid>https://dev.to/beyondmachines/mypillow-internal-data-allegedly-leaked-following-a-claimed-play-ransomware-attack-1cof</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;MyPillow allegedly suffered a data breach after the Play ransomware group claimed a breach and leaked 9.8 GB of sensitive internal data, including Social Security numbers and financial records.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/mypillow-internal-data-allegedly-leaked-following-a-claimed-play-ransomware-attack-a-l-t-q-x/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Google Chrome 148 Update Addresses 151 Vulnerabilities Including 22 Critical Flaws</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Sat, 30 May 2026 09:01:08 +0000</pubDate>
      <link>https://dev.to/beyondmachines/google-chrome-148-update-addresses-151-vulnerabilities-including-22-critical-flaws-29h9</link>
      <guid>https://dev.to/beyondmachines/google-chrome-148-update-addresses-151-vulnerabilities-including-22-critical-flaws-29h9</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Google released Chrome 148 to patch 151 vulnerabilities, including 22 critical-severity flaws primarily consisting of use-after-free and memory safety issues that could lead to sandbox escapes and remote code execution.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;Another huge patch for Chrome and Chromium based browsers (Edge, Opera, Brave, Vivaldi...). Don't delay, it has 22 critical flaws and over a hundred of others. Don't debate the severity, it's pointless. Updating the browser is easy, all your tabs reopen after the patch.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/google-chrome-148-update-addresses-151-vulnerabilities-including-22-critical-flaws-u-y-h-f-n/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Oracle Releases May 2026 Monthly Critical Security Patch Update, Fixes 35 Vulnerabilities</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Sat, 30 May 2026 08:01:07 +0000</pubDate>
      <link>https://dev.to/beyondmachines/oracle-releases-may-2026-monthly-critical-security-patch-update-fixes-35-vulnerabilities-44do</link>
      <guid>https://dev.to/beyondmachines/oracle-releases-may-2026-monthly-critical-security-patch-update-fixes-35-vulnerabilities-44do</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Oracle's May 2026 Critical Security Patch Update addresses 35 vulnerabilities, including 11 critical flaws with CVSS scores up to 10.0. Some vulnerabilities allow unauthenticated remote attackers to compromise systems.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you are using Oracle products, review this advisory in detail. Prioritize patching of unauthenticated exploiuts in Oracle REST Data Services, Oracle Payments, Hospitality OPERA 5, and Oracle Database Server Net Service, then internet-facing systems and the rest of the critical flaws, then everything else.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/oracle-releases-may-2026-monthly-critical-security-patch-update-fixes-35-vulnerabilities-o-g-h-8-4/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Brisbane Accounting Firm Kennedy McLaughlin Confirms Cyber Incident Following Qilin Ransomware Claim</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Fri, 29 May 2026 19:01:08 +0000</pubDate>
      <link>https://dev.to/beyondmachines/brisbane-accounting-firm-kennedy-mclaughlin-confirms-cyber-incident-following-qilin-ransomware-claim-4gde</link>
      <guid>https://dev.to/beyondmachines/brisbane-accounting-firm-kennedy-mclaughlin-confirms-cyber-incident-following-qilin-ransomware-claim-4gde</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Kennedy McLaughlin &amp;amp; Associates, an Australian accounting firm, confirmed a data breach after the Qilin ransomware group published stolen client financial records and internal company data.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/brisbane-accounting-firm-kennedy-mclaughlin-confirms-cyber-incident-following-qilin-ransomware-claim-b-d-7-9-2/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Juventus Discloses Third-Party Data Breach Exposing Event Photography Archives</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Fri, 29 May 2026 11:01:08 +0000</pubDate>
      <link>https://dev.to/beyondmachines/juventus-discloses-third-party-data-breach-exposing-event-photography-archives-56a0</link>
      <guid>https://dev.to/beyondmachines/juventus-discloses-third-party-data-breach-exposing-event-photography-archives-56a0</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Juventus Football Club reported a data breach at a third-party photographic supplier that exposed an archive of event images captured between 2023 and 2025.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/juventus-discloses-third-party-data-breach-exposing-event-photography-archives-z-c-n-r-2/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Everest Ito Group Discloses Data Breach Compromising Social Security Numbers</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Fri, 29 May 2026 10:01:08 +0000</pubDate>
      <link>https://dev.to/beyondmachines/everest-ito-group-discloses-data-breach-compromising-social-security-numbers-1na0</link>
      <guid>https://dev.to/beyondmachines/everest-ito-group-discloses-data-breach-compromising-social-security-numbers-1na0</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Everest Ito Group, LLP reports a data breach that exposed the names and Social Security numbers of an undisclosed number of individuals.The firm id offering two years of identity monitoring services.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/everest-ito-group-discloses-data-breach-compromising-social-security-numbers-h-d-7-u-e/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Pick n Pay Legacy Delivery App Breach Exposes Historical Customer Data</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Fri, 29 May 2026 09:01:10 +0000</pubDate>
      <link>https://dev.to/beyondmachines/pick-n-pay-legacy-delivery-app-breach-exposes-historical-customer-data-56of</link>
      <guid>https://dev.to/beyondmachines/pick-n-pay-legacy-delivery-app-breach-exposes-historical-customer-data-56of</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Pick n Pay confirmed a data breach of its legacy delivery app, exposing personal details and partial payment information of users registered before 2022. The 639MB database is being sold on the dark web.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/pick-n-pay-legacy-delivery-app-breach-exposes-historical-customer-data-a-m-5-6-s/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Critical Unpatched RCE Vulnerability Discovered in Gogs Git Service</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Fri, 29 May 2026 08:01:07 +0000</pubDate>
      <link>https://dev.to/beyondmachines/critical-unpatched-rce-vulnerability-discovered-in-gogs-git-service-6k3</link>
      <guid>https://dev.to/beyondmachines/critical-unpatched-rce-vulnerability-discovered-in-gogs-git-service-6k3</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Gogs is reported to have a critical unpatched authenticated RCE vulnerability (CVSS 9.4) that allows users to execute arbitrary code via malicious branch names during rebase operations. The flaw enables full server compromise, data theft, and supply chain attacks on Linux, Windows, and macOS deployments.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you're running Gogs, disable open user registration (&lt;code&gt;DISABLE_REGISTRATION = true&lt;/code&gt;) and block repository creation (&lt;code&gt;MAX_CREATION_LIMIT = 0&lt;/code&gt;) in your &lt;code&gt;app.ini&lt;/code&gt; config file, since no patch is available. Audit server logs for &lt;code&gt;--exec&lt;/code&gt; related errors and unexpected API tokens with the &lt;code&gt;msf_&lt;/code&gt; prefix, and consider isolating Gogs behind a VPN or internal network until a fix is released.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/critical-unpatched-rce-vulnerability-discovered-in-gogs-git-service-w-x-e-r-d/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
  </channel>
</rss>
