<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: BeyondMachines</title>
    <description>The latest articles on DEV Community by BeyondMachines (beyondmachines).</description>
    <link>https://dev.to/beyondmachines</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Forganization%2Fprofile_image%2F11918%2F48c4d1b8-9bad-45fc-9717-af1f9d280297.png</url>
      <title>DEV Community: BeyondMachines</title>
      <link>https://dev.to/beyondmachines</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/beyondmachines"/>
    <language>en</language>
    <item>
      <title>Apple Patches Hundreds of Vulnerabilities in September 2026 Security Update</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 15 Sep 2026 20:01:14 +0000</pubDate>
      <link>https://dev.to/beyondmachines/apple-patches-hundreds-of-vulnerabilities-in-september-2026-security-update-1e5d</link>
      <guid>https://dev.to/beyondmachines/apple-patches-hundreds-of-vulnerabilities-in-september-2026-security-update-1e5d</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Apple's September 14, 2026 release of iOS 27, macOS Golden Gate 27, Safari 27 and its sibling updates patches over 200 CVEs, concentrated in WebKit, the kernel and drivers, and file-sharing/file-system code (SMB, WebDAV, autofs, disk images). The flaws enable universal XSS, root privilege escalation, kernel memory corruption from hostile servers or crafted volumes, Gatekeeper and sandbox bypasses, and arbitrary code execution from images and 3D models.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you use any Apple devices: iPhone, iPad, Mac, Apple Watch, Apple TV or Vision Pro, update them ASAP to the latest version (iOS/iPadOS 27 or 26.7, macOS Golden Gate 27, Tahoe 26.7 or Sequoia 15.8, tvOS/watchOS/visionOS 27, and Safari 27). The September releases patch a huge number of issues. Until you've updated, be extra careful about visiting unfamiliar websites, opening files or images from strangers, and connecting to unknown file-sharing servers or Wi-Fi networks.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/apple-patches-hundreds-of-vulnerabilities-in-september-2026-security-update-j-s-p-c-n/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Communauto Insider Incident Exposes Customer Records Through Unauthorized Script</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 15 Sep 2026 17:01:13 +0000</pubDate>
      <link>https://dev.to/beyondmachines/communauto-insider-incident-exposes-customer-records-through-unauthorized-script-3kac</link>
      <guid>https://dev.to/beyondmachines/communauto-insider-incident-exposes-customer-records-through-unauthorized-script-3kac</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Communauto disclosed a security incident after an employee used an unauthorized automated script to access and download customer records, potentially affecting a few thousand users. The company blocked the access, notified police, and stating it has found no evidence that the information has been publicly disclosed or misused.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/communauto-insider-incident-exposes-customer-records-through-unauthorized-script-0-7-s-q-y/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Japan Digital Agency VPN Breach Potentially Exposes 246,000 Personnel Records</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 15 Sep 2026 16:01:13 +0000</pubDate>
      <link>https://dev.to/beyondmachines/japan-digital-agency-vpn-breach-potentially-exposes-246000-personnel-records-1po1</link>
      <guid>https://dev.to/beyondmachines/japan-digital-agency-vpn-breach-potentially-exposes-246000-personnel-records-1po1</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Japan's Digital Agency disclosed a data breach after an attacker exploited a known VPN vulnerability to gain unauthorized access to its Government Solution Service. Approximately 246,000 records containing names, email addresses, phone numbers, and addresses may have been exposed.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/japan-digital-agency-vpn-breach-potentially-exposes-246000-personnel-records-l-u-u-m-r/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>State of (in)security - Week 37, 2026</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 15 Sep 2026 13:01:13 +0000</pubDate>
      <link>https://dev.to/beyondmachines/state-of-insecurity-week-37-2026-4gk2</link>
      <guid>https://dev.to/beyondmachines/state-of-insecurity-week-37-2026-4gk2</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Week 37 of 2026 saw 13 advisories and 31 incidents (up from 27 the prior week), affecting roughly 5.6 million known individuals. The largest is the Veradigm third-party credential-theft breach at 3.5 million. Unauthorized access, ransomware/malware, and third-party compromise are the leading causes and healthcare by far the hardest-hit sector. Critical patches landed across Microsoft, Google, Adobe, Fortinet, SAP, Ivanti and others, alongside five flaws under active exploitation including zero-days in N-able N-central, GitLab, Cisco Secure FMC, Fortinet CAPWAP, and Adobe Commerce/Magento.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;Patch the actively exploited flaws first: Adobe Commerce, Windows, Chrome, GitLab, Cisco Secure FMC, Fortinet, Check Point and N-able N-central. Where you can't patch straight away, take management and admin interfaces off the public internet.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/state-of-in-security-week-37-2026-6-e-g-b-g/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Hawaii Family Dental Reports Data Breach Impacting 45,000 Patients</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 15 Sep 2026 12:01:14 +0000</pubDate>
      <link>https://dev.to/beyondmachines/hawaii-family-dental-reports-data-breach-impacting-45000-patients-4p8k</link>
      <guid>https://dev.to/beyondmachines/hawaii-family-dental-reports-data-breach-impacting-45000-patients-4p8k</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Hawaii Family Dental suffered a cyberattack in July 2026 that compromised the personal and health information of 45,853 patients. The Qilin ransomware group claimed responsibility for the breach, which was caused by a compromised account.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/hawaii-family-dental-reports-data-breach-impacting-45000-patients-v-1-4-q-4/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>ConnectWise Patches Critical ScreenConnect Flaw Exploited in Worm Attacks</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 15 Sep 2026 11:01:14 +0000</pubDate>
      <link>https://dev.to/beyondmachines/connectwise-patches-critical-screenconnect-flaw-exploited-in-worm-attacks-3813</link>
      <guid>https://dev.to/beyondmachines/connectwise-patches-critical-screenconnect-flaw-exploited-in-worm-attacks-3813</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;ConnectWise fixed a critical vulnerability (CVE-2026-84869) in ScreenConnect that allows unauthorized file execution and worm-like propagation across remote sessions.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you use ConnectWise ScreenConnect, update to version 26.6.5 right away and then reinstall every host client. The update only takes effect once the clients are reinstalled, and this flaw is already being exploited to spread from machine to machine. If you can't patch, turn off the TransferFiles permission for all user roles as a mitigating measures. Don't forget to check integrated tools like ConnectWise Automate for their own patched versions.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/connectwise-patches-critical-screenconnect-flaw-exploited-in-worm-attacks-n-t-h-f-x/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Community Health Care Inc. Reports Data Breach After Phishing Attack</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 15 Sep 2026 10:01:27 +0000</pubDate>
      <link>https://dev.to/beyondmachines/community-health-care-inc-reports-data-breach-after-phishing-attack-13e6</link>
      <guid>https://dev.to/beyondmachines/community-health-care-inc-reports-data-breach-after-phishing-attack-13e6</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;A phishing attack compromised a single Community Health Care Inc. employee email account, exposing Social Security numbers, contact details, insurance data, and medical records for 808 patients.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/community-health-care-inc-reports-data-breach-after-phishing-attack-j-e-3-9-3/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Swiss Bitcoin Pay Shuts Down Infrastructure Following Internal System Breach</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 15 Sep 2026 09:01:14 +0000</pubDate>
      <link>https://dev.to/beyondmachines/swiss-bitcoin-pay-shuts-down-infrastructure-following-internal-system-breach-egp</link>
      <guid>https://dev.to/beyondmachines/swiss-bitcoin-pay-shuts-down-infrastructure-following-internal-system-breach-egp</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Swiss Bitcoin Pay took its servers offline after a malicious actor gained access to internal systems and potentially compromised customer data including IBANs and hashed passwords. The company says that user funds are safe due to the non-custodial nature of the platform.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/swiss-bitcoin-pay-shuts-down-infrastructure-following-internal-system-breach-u-v-0-h-z/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Next Level Medical Reports Ransomware Attack, Data Theft</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 15 Sep 2026 08:01:13 +0000</pubDate>
      <link>https://dev.to/beyondmachines/next-level-medical-reports-ransomware-attack-data-theft-4b96</link>
      <guid>https://dev.to/beyondmachines/next-level-medical-reports-ransomware-attack-data-theft-4b96</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Next Level Medical LLC suffered a ransomware attack by the Pear group, resulting in the alleged theft of three terabytes of sensitive patient and employee data. The organization is investigating the breach.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/next-level-medical-reports-ransomware-attack-data-theft-o-t-b-z-n/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Surfshark Reports Security Incident Involving Misconfigured Test Server and Unauthorized Access</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Mon, 14 Sep 2026 10:01:14 +0000</pubDate>
      <link>https://dev.to/beyondmachines/surfshark-reports-security-incident-involving-misconfigured-test-server-and-unauthorized-access-po</link>
      <guid>https://dev.to/beyondmachines/surfshark-reports-security-incident-involving-misconfigured-test-server-and-unauthorized-access-po</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Surfshark disclosed unauthorized access to an internal test server and isolated proxy server caused by a misconfiguration. The incident exposed limited internal engineering materials and build-related credentials, but no user data or VPN services were affected.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/surfshark-discloses-unauthorized-access-to-internal-engineering-systems-f-z-4-6-9/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Storm Ransomware Group Claims Penfold Motors Data Breach</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Mon, 14 Sep 2026 09:01:14 +0000</pubDate>
      <link>https://dev.to/beyondmachines/storm-ransomware-group-claims-penfold-motors-data-breach-1dd0</link>
      <guid>https://dev.to/beyondmachines/storm-ransomware-group-claims-penfold-motors-data-breach-1dd0</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Penfold Motors confirmed a data breach involving an external software provider after Storm claimed responsibility for the attack. Exposed information includes customer contact details, vehicle information, VINs, and tax invoices. Penfold stated there is no evidence that bank account details or other high-risk personal information were affected.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/storm-ransomware-group-claims-penfold-motors-data-breach-a-1-l-9-g/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>VLC Media Player Flaws Allow Heap Corruption and Sensitive Data Disclosure</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Sun, 13 Sep 2026 17:01:13 +0000</pubDate>
      <link>https://dev.to/beyondmachines/vlc-media-player-flaws-allow-heap-corruption-and-sensitive-data-disclosure-5haj</link>
      <guid>https://dev.to/beyondmachines/vlc-media-player-flaws-allow-heap-corruption-and-sensitive-data-disclosure-5haj</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;VideoLAN reports two vulnerabilities in VLC Media Player (CVE-2026-56711 and CVE-2026-73324) that allow attackers to corrupt heap memory or leak sensitive data via crafted PNG files and RTSP streams.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you use VLC Media Player (any version from 3.0.0 to 3.0.23), update it to the latest patched version as soon as VideoLAN releases it. Until you've updated, don't open media files, playlists, or RTSP streaming links that come from people or websites you don't know and trust.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/vlc-media-player-flaws-allow-heap-corruption-and-sensitive-data-disclosure-6-k-q-2-9/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
  </channel>
</rss>
