<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: BeyondMachines</title>
    <description>The latest articles on DEV Community by BeyondMachines (@bsp_beyondmachines).</description>
    <link>https://dev.to/bsp_beyondmachines</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2445503%2F3faf5e64-542b-44d9-9bb9-e5bdaa993b59.png</url>
      <title>DEV Community: BeyondMachines</title>
      <link>https://dev.to/bsp_beyondmachines</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/bsp_beyondmachines"/>
    <language>en</language>
    <item>
      <title>Oracle Releases Massive August 2026 Security Update Fixing 943 Vulnerabilities</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 19 Aug 2026 20:01:23 +0000</pubDate>
      <link>https://dev.to/beyondmachines/oracle-releases-massive-august-2026-security-update-fixing-943-vulnerabilities-mif</link>
      <guid>https://dev.to/beyondmachines/oracle-releases-massive-august-2026-security-update-fixing-943-vulnerabilities-mif</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Oracle's August 2026 update patches 943 vulnerabilities, including critical remote code execution flaws in WebLogic and E-Business Suite that allow unauthenticated attackers to take over systems.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you are using Oracle products, review this advisory in detail. Prioritize patching of internet-facing systems, as more than 650 vulnerabilities allow remote attackers to compromise your systems without any authentication. Patch Oracle Fusion Middleware first: it accounts for nine of the flaws scored CVSS 10.0 and 219 network-accessible vulnerabilities requiring no credentials. Oracle Communications should follow, where 122 of 168 patches address unauthenticated remote issues.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/oracle-releases-massive-august-2026-security-update-fixing-943-vulnerabilities-h-3-w-o-n/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Researcher Reports ClarityCheck Data Leak Exposing 9 Million Biometric Facial Images</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 19 Aug 2026 17:01:23 +0000</pubDate>
      <link>https://dev.to/beyondmachines/researcher-reports-claritycheck-data-leak-exposing-9-million-biometric-facial-images-m3m</link>
      <guid>https://dev.to/beyondmachines/researcher-reports-claritycheck-data-leak-exposing-9-million-biometric-facial-images-m3m</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;ClarityCheck, a U.S. reverse image search service, exposed over 9 million biometric facial images due to an unsecured and unencrypted cloud database. The leak included photos of adults and children, raising significant concerns about the long-term privacy risks of persistent biometric data.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/researcher-reports-claritycheck-data-leak-exposing-9-million-biometric-facial-images-1-p-e-u-q/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Quest Apartment Hotels Data Breach Reportedly Exposes 1.7 Million Guest Records</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 19 Aug 2026 15:01:23 +0000</pubDate>
      <link>https://dev.to/beyondmachines/quest-apartment-hotels-data-breach-reportedly-exposes-17-million-guest-records-m6f</link>
      <guid>https://dev.to/beyondmachines/quest-apartment-hotels-data-breach-reportedly-exposes-17-million-guest-records-m6f</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Quest Apartment Hotels disclosed a data breach involving unauthorized access to a historical customer database through a vulnerability involving a third-party service provider. The incident reportedly affected approximately 1.7 million guests, the company has contained the breach and notified Australian cybersecurity and privacy authorities.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/quest-apartment-hotels-data-breach-reportedly-exposes-1-7-million-guest-records-z-5-5-t-o/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Cameron Regional Medical Center Disclosed Ransomware Attack</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 19 Aug 2026 14:01:23 +0000</pubDate>
      <link>https://dev.to/beyondmachines/cameron-regional-medical-center-disclosed-ransomware-attack-2dl1</link>
      <guid>https://dev.to/beyondmachines/cameron-regional-medical-center-disclosed-ransomware-attack-2dl1</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Cameron Regional Medical Center disclosed a ransomware attack involving potential unauthorized access to sensitive patient information. The Anubis ransomware group claimed responsibility and alleged it stole patient and employee data. CRMC continues to investigate the scope of the incident.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/cameron-regional-medical-center-disclosed-ransomware-attack-3-1-b-n-p/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Forrestall CPAs LLC Notifies Clients of Network Intrusion and Data Exfiltration</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 19 Aug 2026 13:01:24 +0000</pubDate>
      <link>https://dev.to/beyondmachines/forrestall-cpas-llc-notifies-clients-of-network-intrusion-and-data-exfiltration-5ckg</link>
      <guid>https://dev.to/beyondmachines/forrestall-cpas-llc-notifies-clients-of-network-intrusion-and-data-exfiltration-5ckg</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Forrestall CPAs LLC suffered a data breach where an unauthorized person accessed and stole client files between December 22 and December 30, 2025. The is providing identity monitoring services to affected individuals and has reported the incident to law enforcement.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/forrestall-cpas-llc-notifies-clients-of-network-intrusion-and-data-exfiltration-4-0-5-7-r/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Arkansas Oral Surgery Practice Suffers Ransomware Attack</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 19 Aug 2026 12:01:23 +0000</pubDate>
      <link>https://dev.to/beyondmachines/arkansas-oral-surgery-practice-suffers-ransomware-attack-5ek1</link>
      <guid>https://dev.to/beyondmachines/arkansas-oral-surgery-practice-suffers-ransomware-attack-5ek1</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Arkansas Oral &amp;amp; Maxillofacial Surgeons suffered a ransomware attack claimed by the PEAR group, resulting in the alleged theft of 2.1 terabytes of sensitive patient and corporate data. The breach exposed Social Security numbers, medical records, and financial information. The practice is offering credit monitoring services to affected individuals.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/arkansas-oral-surgery-practice-suffers-ransomware-attack-x-g-f-c-h/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Lennar Mortgage Discloses Data Breach Following Social Engineering Attack</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 19 Aug 2026 11:01:24 +0000</pubDate>
      <link>https://dev.to/beyondmachines/lennar-mortgage-discloses-data-breach-following-social-engineering-attack-4bkj</link>
      <guid>https://dev.to/beyondmachines/lennar-mortgage-discloses-data-breach-following-social-engineering-attack-4bkj</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Lennar Mortgage and Lennar Corporation suffered a data breach after attackers used social engineering tactics to access internal systems between May and June 2026. The incident exposed sensitive personal and financial information, including Social Security numbers and government IDs, affecting over 60,000 individuals in Texas alone.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/lennar-mortgage-discloses-data-breach-following-social-engineering-attack-h-8-l-4-e/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>RansomHub Group Claims 100GB Data Theft in 3C Care Systems Ransomware Attack</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 19 Aug 2026 10:01:23 +0000</pubDate>
      <link>https://dev.to/beyondmachines/ransomhub-group-claims-100gb-data-theft-in-3c-care-systems-ransomware-attack-3kge</link>
      <guid>https://dev.to/beyondmachines/ransomhub-group-claims-100gb-data-theft-in-3c-care-systems-ransomware-attack-3kge</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;3C Care Systems, a healthcare IT provider, was targeted by the RansomHub ransomware group in an attack that compromised 100GB of sensitive patient data. The breach affected multiple healthcare clients, including the Midwest Spine and Brain Institute, leading to the exposure of PII and PHI.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/ransomhub-group-claims-100gb-data-theft-in-3c-care-systems-ransomware-attack-2-y-a-i-c/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Unauthenticated RCE Vulnerability Patched in Forminator Forms Plugin</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 19 Aug 2026 09:01:23 +0000</pubDate>
      <link>https://dev.to/beyondmachines/unauthenticated-rce-vulnerability-patched-in-forminator-forms-plugin-36p1</link>
      <guid>https://dev.to/beyondmachines/unauthenticated-rce-vulnerability-patched-in-forminator-forms-plugin-36p1</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;WPMU DEV patched a critical vulnerability (CVE-2026-15748) in the Forminator Forms plugin that allowed unauthenticated attackers to upload and execute PHP files. The flaw can lead to full remote code execution and site compromise.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you use the Forminator Forms plugin on your WordPress site, update it to version 1.56.2 or later ASAP away: attackers can take over the whole site without logging in. After updating, check your upload folders for any unfamiliar PHP files. If you can't update yet, delete any forms that use both File Upload and Select fields.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/unauthenticated-rce-vulnerability-patched-in-forminator-forms-plugin-q-r-9-h-5/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Attackers Exploit a Critical MLflow Vulnerability</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Wed, 19 Aug 2026 08:01:24 +0000</pubDate>
      <link>https://dev.to/beyondmachines/attackers-exploit-a-critical-mlflow-vulnerability-33j5</link>
      <guid>https://dev.to/beyondmachines/attackers-exploit-a-critical-mlflow-vulnerability-33j5</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Attackers are actively exploiting a critical flaw in MLflow (CVE-2026-64849) to steal cloud credentials and gain remote code execution.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you run MLflow, update it to version 3.15.0 or later ASAP, and make sure the server is not reachable from the internet. Then check your audit logs for any odd requests to cloud metadata services. If you see any (or aren't sure), rotate your cloud credentials and keys as a precaution.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/attackers-exploit-a-critical-mlflow-vulnerability-3-u-3-k-6/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Hacker Claims Large-Scale Azure Exfiltration Campaign Exposing 3.6 Million Records From Global Enterprises</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 18 Aug 2026 12:01:46 +0000</pubDate>
      <link>https://dev.to/beyondmachines/hacker-claims-large-scale-azure-exfiltration-campaign-exposing-36-million-records-from-global-1hae</link>
      <guid>https://dev.to/beyondmachines/hacker-claims-large-scale-azure-exfiltration-campaign-exposing-36-million-records-from-global-1hae</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;A threat actor known as "TheHatman" is selling 3.6 million employee records allegedly stolen from the Azure tenants of several Fortune 500 companies, including McDonald's and Vodafone. The breach likely involved compromised credentials from infostealer infections and techniques like MFA fatigue to exfiltrate internal corporate directories.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/hacker-claims-large-scale-azure-exfiltration-campaign-exposing-3-6-million-records-from-global-enterprises-h-8-d-f-a/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>GitLab Issues Emergency Patch for Critical GraphQL Flaw Allowing Remote Project Deletion</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Tue, 18 Aug 2026 11:01:46 +0000</pubDate>
      <link>https://dev.to/beyondmachines/gitlab-issues-emergency-patch-for-critical-graphql-flaw-allowing-remote-project-deletion-2626</link>
      <guid>https://dev.to/beyondmachines/gitlab-issues-emergency-patch-for-critical-graphql-flaw-allowing-remote-project-deletion-2626</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;GitLab issued an emergency security update to fix a critical GraphQL code injection vulnerability (CVE-2026-19478) that allows unauthenticated attackers to remotely delete or modify public projects and user data.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you run a self-managed GitLab server (version 18.2 through 19.2.3), update it ASAP to 19.2.4, 19.1.6, 19.0.8, or 18.11.11. The patch is quick and won't take your system offline. Before you patch, check your logs for unusual GraphQL activity so you know nobody has already deleted or altered your projects or user data.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/gitlab-issues-emergency-patch-for-critical-graphql-flaw-allowing-remote-project-deletion-k-u-c-h-x/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
  </channel>
</rss>
