<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: BeyondMachines</title>
    <description>The latest articles on DEV Community by BeyondMachines (beyondmachines).</description>
    <link>https://dev.to/beyondmachines</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Forganization%2Fprofile_image%2F11918%2F48c4d1b8-9bad-45fc-9717-af1f9d280297.png</url>
      <title>DEV Community: BeyondMachines</title>
      <link>https://dev.to/beyondmachines</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/beyondmachines"/>
    <language>en</language>
    <item>
      <title>CISA Reports Actively Exploited Gitea Critical RCE Vulnerability</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 26 Aug 2026 17:01:20 +0000</pubDate>
      <link>https://dev.to/beyondmachines/cisa-reports-actively-exploited-gitea-critical-rce-vulnerability-9od</link>
      <guid>https://dev.to/beyondmachines/cisa-reports-actively-exploited-gitea-critical-rce-vulnerability-9od</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Gitea patched a critical remote code execution vulnerability (CVE-2026-60004) that attackers are actively exploiting to install crypto-miners on self-hosted instances. The flaw allows users with write access to inject malicious Git hooks via the diffpatch API, potentially exposing database credentials and system secrets.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;Update self-hosted Gitea instances to version 1.27.1 immediately. Now it's urgent, since hackers are actively attacking you. If you can't patch right away, disable public registration to prevent new outsiders from obtaining repository write access. This does not protect against existing users who already have the required permissions.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/cisa-reports-actively-exploited-gitea-critical-rce-vulnerability-2-1-9-j-5/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>LACMA Discloses Year-Old Data Breach Exposing Social Security and Medical Records</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 26 Aug 2026 11:01:42 +0000</pubDate>
      <link>https://dev.to/beyondmachines/lacma-discloses-year-old-data-breach-exposing-social-security-and-medical-records-2jn2</link>
      <guid>https://dev.to/beyondmachines/lacma-discloses-year-old-data-breach-exposing-social-security-and-medical-records-2jn2</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;The Los Angeles County Museum of Art (LACMA) reports a data breach from July 2025 that exposed the Social Security numbers, medical records, and financial information of an undisclosed number of individuals. The museum has notified law enforcement and is offering one year of identity theft protection to those affected.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/lacma-discloses-year-old-data-breach-exposing-social-security-and-medical-records-o-p-j-c-y/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Zscaler Patches Critical Unauthenticated RCE in Client Connector for Windows</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 26 Aug 2026 10:01:42 +0000</pubDate>
      <link>https://dev.to/beyondmachines/zscaler-patches-critical-unauthenticated-rce-in-client-connector-for-windows-iok</link>
      <guid>https://dev.to/beyondmachines/zscaler-patches-critical-unauthenticated-rce-in-client-connector-for-windows-iok</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Zscaler fixed a critical vulnerability (CVE-2026-59568) that allowed unauthenticated remote code execution and privilege escalation as well as three other flaws in its Client Connector for Windows&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you use Zscaler Client Connector on Windows, update every endpoint to the latest patched version. Anything released before June 2026 (including 4.7.0.364, 4.8.0.232/284/291, and 4.9.0.448/455) is at risk of remote takeover. Don't assume your automated update policy reached every machine; manually verify the version on all devices. Check endpoint logs for odd processes launched by Zscaler components or unexpected new listening services.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/zscaler-patches-critical-unauthenticated-rce-in-client-connector-for-windows-x-x-2-j-a/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Critical Remote Code Execution Vulnerability Discovered in JSONata Library</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 26 Aug 2026 09:01:43 +0000</pubDate>
      <link>https://dev.to/beyondmachines/critical-remote-code-execution-vulnerability-discovered-in-jsonata-library-1ajl</link>
      <guid>https://dev.to/beyondmachines/critical-remote-code-execution-vulnerability-discovered-in-jsonata-library-1ajl</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;JSONata patched a critical vulnerability (CVE-2026-77413) that allows attackers to execute arbitrary code by exploiting a missing prototype check. The flaw enables full system takeover if an application processes malicious JSONata expressions.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If your applications or systems use the JSONata library, upgrade ASAP to version 1.8.8 (for 1.x) or 2.2.0 (for 2.x). Anything older can let an attacker run commands on your server. Until you can update, stop accepting JSONata expressions from users or treat any that you do accept as untrusted code.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/critical-remote-code-execution-vulnerability-discovered-in-jsonata-library-1-8-z-n-u/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>New Zealand Sotheby’s International Realty Investigates Third-Party CRM Data Breach</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 26 Aug 2026 08:01:42 +0000</pubDate>
      <link>https://dev.to/beyondmachines/new-zealand-sothebys-international-realty-investigates-third-party-crm-data-breach-m7d</link>
      <guid>https://dev.to/beyondmachines/new-zealand-sothebys-international-realty-investigates-third-party-crm-data-breach-m7d</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;New Zealand Sotheby’s International Realty suffered a data breach after the threat actor "2019" gained unauthorized access to a third-party CRM platform, potentially exposing the contact details of thousands of clients. The company has contained the incident and is working with the NCSC and forensic experts to investigate the extent of the data exposure.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/new-zealand-sothebys-international-realty-investigates-third-party-crm-data-breach-b-x-s-8-z/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>GitPython Patches Critical RCE Vulnerability in Config Parser</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 25 Aug 2026 15:01:42 +0000</pubDate>
      <link>https://dev.to/beyondmachines/gitpython-patches-critical-rce-vulnerability-in-config-parser-17fm</link>
      <guid>https://dev.to/beyondmachines/gitpython-patches-critical-rce-vulnerability-in-config-parser-17fm</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;GitPython version 3.1.59 patches a critical remote code execution vulnerability (CVE-2026-78676) caused by improper handling of multi-line configuration values. The flaw allows attackers to inject malicious Git directives that execute arbitrary code during routine repository operations.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you use GitPython in any application or CI/CD pipeline, update it to version 3.1.59 or later. Еvery version up to 3.1.58 is vulnerable to CVE-2026-78676. Until you can update, don't let GitPython read or write config files from cloned repos, shared configs, or workspace caches you don't fully control. Тreat any repository from an outside source as untrusted.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/gitpython-patches-critical-rce-vulnerability-in-config-parser-g-q-0-2-o/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Hackers Exploit miniOrange SAML SSO Vulnerabilities to Hijack WordPress Admin Accounts</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 25 Aug 2026 14:01:42 +0000</pubDate>
      <link>https://dev.to/beyondmachines/hackers-exploit-miniorange-saml-sso-vulnerabilities-to-hijack-wordpress-admin-accounts-2642</link>
      <guid>https://dev.to/beyondmachines/hackers-exploit-miniorange-saml-sso-vulnerabilities-to-hijack-wordpress-admin-accounts-2642</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Attackers are exploiting two vulnerabilities in the miniOrange SAML SSO plugin to bypass authentication and gain administrative access to WordPress sites.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you use the miniOrange SAML 2.0 SSO plugin on WordPress, check your version manually and download the latest release from the miniOrange store right away. The plugin has flaws that are actively exploited. The dashboard won't warn you about updates if you're on a paid edition. If you can't update immediately, deactivate the plugin and review your admin login history for logins from unfamiliar IP addresses, since attackers may already have created or hijacked admin accounts.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/hackers-exploit-miniorange-saml-sso-vulnerabilities-to-hijack-wordpress-admin-accounts-n-f-p-m-y/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Integrative Emergency Services Discloses Data Breach Via Unauthorized Email Access</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 25 Aug 2026 13:01:17 +0000</pubDate>
      <link>https://dev.to/beyondmachines/integrative-emergency-services-discloses-data-breach-via-unauthorized-email-access-3obj</link>
      <guid>https://dev.to/beyondmachines/integrative-emergency-services-discloses-data-breach-via-unauthorized-email-access-3obj</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Integrative Emergency Services suffered a data breach after attackers accessed an employee email account for four hours, potentially viewing patient medical records and identifiers. The company secured the account and is now providing retraining to staff and a dedicated support line for affected individuals.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/integrative-emergency-services-discloses-data-breach-via-unauthorized-email-access-p-d-w-5-s/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>The Asthma Center Discloses Data Breach Impacting Patient Medical Records</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 25 Aug 2026 12:01:17 +0000</pubDate>
      <link>https://dev.to/beyondmachines/the-asthma-center-discloses-data-breach-impacting-patient-medical-records-3dla</link>
      <guid>https://dev.to/beyondmachines/the-asthma-center-discloses-data-breach-impacting-patient-medical-records-3dla</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Allergic Disease Associates, P.C., doing business as The Asthma Center, suffered a data breach where attackers accessed its systems for three weeks and downloaded files containing patient medical and personal information. The organization has secured its network, is notifying affected individuals and offering guidance on credit monitoring and fraud prevention.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/the-asthma-center-discloses-data-breach-impacting-patient-medical-records-k-j-5-m-3/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>ReliaQuest Blocks Data Theft Attempt Following ShinyHunters Social Engineering Attack</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 25 Aug 2026 11:01:17 +0000</pubDate>
      <link>https://dev.to/beyondmachines/reliaquest-blocks-data-theft-attempt-following-shinyhunters-social-engineering-attack-4l4b</link>
      <guid>https://dev.to/beyondmachines/reliaquest-blocks-data-theft-attempt-following-shinyhunters-social-engineering-attack-4l4b</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;ReliaQuest successfully blocked a data theft attempt by the ShinyHunters group after an employee was tricked into providing credentials via a vishing and phishing attack. Device-trust controls prevented the attackers from accessing internal applications or customer data.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/reliaquest-blocks-data-theft-attempt-following-shinyhunters-social-engineering-attack-i-j-u-g-c/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Grafton City Hospital Reports Data Breach Following Email Account Compromise</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 25 Aug 2026 10:01:17 +0000</pubDate>
      <link>https://dev.to/beyondmachines/grafton-city-hospital-reports-data-breach-following-email-account-compromise-9mn</link>
      <guid>https://dev.to/beyondmachines/grafton-city-hospital-reports-data-breach-following-email-account-compromise-9mn</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Grafton City Hospital disclosed a data breach resulting from a compromised email account discovered on May 6, 2026. The incident potentially exposed personal and medical information, leading the hospital to enhance security and offer credit monitoring to affected individuals.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/grafton-city-hospital-reports-data-breach-following-email-account-compromise-n-9-2-p-v/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>State of (in)security - Week 34, 2026</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 25 Aug 2026 09:01:17 +0000</pubDate>
      <link>https://dev.to/beyondmachines/state-of-insecurity-week-34-2026-3p33</link>
      <guid>https://dev.to/beyondmachines/state-of-insecurity-week-34-2026-3p33</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;During the week of Aug. 17–24, 2026, there were 16 advisories and 34 incidents (advisories up from 9, incidents down from 42 the prior week), affecting roughly 20 million known individuals. The largest incident is a ClarityCheck leak of about 9 million biometric facial images. Ransomware/malware, third-party compromise, and unauthorized access were the leading causes, and healthcare, IT, and finance the hardest-hit industries. Active exploitation was reported of flaws in MLflow, Citrix NetScaler, GitLab, Zimbra, Microsoft Entra ID and IKE, plus mass patch releases from Oracle (943 fixes), Atlassian (172), and Mozilla (58).&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;Update your browser now: Chrome to 151.0.7922.169/.170 (or the matching Edge/Brave/Opera/Vivaldi release) and restart it, since these sandbox-escape flaws are exactly what web-based attacks target first. If you administer servers, patch anything internet-facing that's under active attack: NetScaler, Citrix, Zimbra, Windows IKEv2, Atlassian, GitLab and keep every management interface off the public internet, reachable only from trusted networks.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/state-of-in-security-week-34-2026-6-z-z-0-h/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
  </channel>
</rss>
