<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: BeyondMachines</title>
    <description>The latest articles on DEV Community by BeyondMachines (@bsp_beyondmachines).</description>
    <link>https://dev.to/bsp_beyondmachines</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F2445503%2F3faf5e64-542b-44d9-9bb9-e5bdaa993b59.png</url>
      <title>DEV Community: BeyondMachines</title>
      <link>https://dev.to/bsp_beyondmachines</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/bsp_beyondmachines"/>
    <language>en</language>
    <item>
      <title>State of (in)security - Week 24, 2026</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Mon, 15 Jun 2026 18:01:04 +0000</pubDate>
      <link>https://dev.to/beyondmachines/state-of-insecurity-week-24-2026-4c0j</link>
      <guid>https://dev.to/beyondmachines/state-of-insecurity-week-24-2026-4c0j</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;During week 24 of 2026, there were 20 advisory/vulnerability events (including actively exploited zero-days in Check Point VPN, Langflow, Ivanti Sentry, Google Chrome, and Microsoft Defender, plus critical flaws patched by Microsoft, SAP, Fortinet, Veeam, and others) and 18 incidents affecting over 11.6 million individuals. The largest incident was a Kyushu Electric Power subsidiary breach exposing 10.9 million customer records. Incidents were driven mainly by malware/ransomware and third-party compromises, hitting education and healthcare hardest, with notable breaches at Novo Nordisk, Lincoln Financial, Oracle PeopleSoft (ShinyHunters), and multiple NHS trusts via the Synnovis ransomware attack.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;This week prioritize Microsoft and Oracle products. Oracle has an actively exploited flaw that has been used to compromise multiple organizations.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/state-of-in-security-week-24-2026-m-2-x-c-8/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Caldwell Sutter Capital Discloses Data Breach Following Third-Party Vendor Cyberattack</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Mon, 15 Jun 2026 17:01:05 +0000</pubDate>
      <link>https://dev.to/beyondmachines/caldwell-sutter-capital-discloses-data-breach-following-third-party-vendor-cyberattack-1745</link>
      <guid>https://dev.to/beyondmachines/caldwell-sutter-capital-discloses-data-breach-following-third-party-vendor-cyberattack-1745</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Caldwell Sutter Capital disclosed a data breach affecting 663 individuals after a cyberattack on its third-party software provider, FoxTrot LLC, exposed Social Security numbers and financial account details.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/caldwell-sutter-capital-discloses-data-breach-following-third-party-vendor-cyberattack-b-x-x-b-0/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Maine Attorney General Disables Breach Portal Following Fraudulent Reports</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Mon, 15 Jun 2026 16:01:05 +0000</pubDate>
      <link>https://dev.to/beyondmachines/maine-attorney-general-disables-breach-portal-following-fraudulent-reports-1i5f</link>
      <guid>https://dev.to/beyondmachines/maine-attorney-general-disables-breach-portal-following-fraudulent-reports-1i5f</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;The Maine Attorney General Office disabled its public breach reporting portal after unknown actors submitted fraudulent notifications impersonating VRChat and Discord.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/maine-attorney-general-disables-breach-portal-following-fraudulent-reports-o-e-n-a-a/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Paylogix Insurtech Platform Breached by Akira Ransomware Group</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Sun, 14 Jun 2026 09:01:14 +0000</pubDate>
      <link>https://dev.to/beyondmachines/paylogix-insurtech-platform-breached-by-akira-ransomware-group-4c2j</link>
      <guid>https://dev.to/beyondmachines/paylogix-insurtech-platform-breached-by-akira-ransomware-group-4c2j</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Paylogix, a New York insurance tech company, suffered a data breach in November 2025 that the Akira ransomware group later claimed involved the theft of 185 GB of sensitive data.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/paylogix-insurtech-platform-breached-by-akira-ransomware-group-m-k-x-r-6/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>HDFC Asset Management Company Discloses Data Breach Affecting Investor PII</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Sun, 14 Jun 2026 08:01:14 +0000</pubDate>
      <link>https://dev.to/beyondmachines/hdfc-asset-management-company-discloses-data-breach-affecting-investor-pii-54hb</link>
      <guid>https://dev.to/beyondmachines/hdfc-asset-management-company-discloses-data-breach-affecting-investor-pii-54hb</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;HDFC Asset Management Company suffered a data breach after an anonymous attacker gained access to its IT systems, potentially exposing investor PII such as PAN and bank details. The firm has advised investors to reset passwords and monitor for SIM-swap fraud.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/hdfc-asset-management-company-discloses-data-breach-affecting-investor-pii-5-e-9-d-w/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Ubiquiti Patches Critical Command Injection Flaws in UniFi OS</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Sat, 13 Jun 2026 18:01:15 +0000</pubDate>
      <link>https://dev.to/beyondmachines/ubiquiti-patches-critical-command-injection-flaws-in-unifi-os-1kdl</link>
      <guid>https://dev.to/beyondmachines/ubiquiti-patches-critical-command-injection-flaws-in-unifi-os-1kdl</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Ubiquiti patched five vulnerabilities in UniFi OS and UID Enterprise Agent, including three critical command injection and privilege escalation flaws with CVSS scores of 9.9. These vulnerabilities allow attackers with network access to take full control of networking hardware or steal sensitive data.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;Make sure all your UniFi OS devices and UID Enterprise Agents are isolated from the internet and reachable only from trusted networks. Prioritize fixing any devices that are currently internet-facing. Then update everything to the fixed versions right away: UID Enterprise Agent 1.61.4, UniFi OS 5.1.15 (or 5.1.16 for UNAS storage appliances), and Express 4.0.15.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/ubiquiti-patches-critical-command-injection-flaws-in-unifi-os-y-b-9-z-4/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Norfolk and Norwich University Hospital Patient Data Stolen in Synnovis Ransomware Attack</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Sat, 13 Jun 2026 08:01:14 +0000</pubDate>
      <link>https://dev.to/beyondmachines/norfolk-and-norwich-university-hospital-patient-data-stolen-in-synnovis-ransomware-attack-18cd</link>
      <guid>https://dev.to/beyondmachines/norfolk-and-norwich-university-hospital-patient-data-stolen-in-synnovis-ransomware-attack-18cd</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Norfolk and Norwich University Hospital suffered a data breach after the Qilin ransomware group attacked its third-party provider, Synnovis, leaking sensitive medical records of tens of thousands of patients.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/norfolk-and-norwich-university-hospital-patient-data-stolen-in-synnovis-ransomware-attack-5-7-j-e-o/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Elmwood Home Care Ransomware Attack Exposes Patient Medical and Personal Data</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Fri, 12 Jun 2026 15:01:14 +0000</pubDate>
      <link>https://dev.to/beyondmachines/elmwood-home-care-ransomware-attack-exposes-patient-medical-and-personal-data-236l</link>
      <guid>https://dev.to/beyondmachines/elmwood-home-care-ransomware-attack-exposes-patient-medical-and-personal-data-236l</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Elmwood Home Care reported a ransomware attack by the Lockbit 5.0 group, resulting in the theft of sensitive personal and medical data from its systems between January and February 2026.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/elmwood-home-care-ransomware-attack-exposes-patient-medical-and-personal-data-r-g-g-7-g/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Palo Alto Networks Patches High-Severity Flaw in Cortex XSOAR and XSIAM</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Fri, 12 Jun 2026 14:01:16 +0000</pubDate>
      <link>https://dev.to/beyondmachines/palo-alto-networks-patches-high-severity-flaw-in-cortex-xsoar-and-xsiam-1m44</link>
      <guid>https://dev.to/beyondmachines/palo-alto-networks-patches-high-severity-flaw-in-cortex-xsoar-and-xsiam-1m44</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Palo Alto Networks patched nine vulnerabilities across PAN-OS, Cortex XSOAR/XSIAM, Prisma Access Agent, GlobalProtect, and Prisma Browser, the most severe being CVE-2026-0274, an unauthenticated credential-validation flaw in the CommvaultSecurityIQ integration that allows access and modification of protected resources by default.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;Make sure your firewall and security management interfaces are isolated from the internet and reachable only from trusted internal networks, since most of these Palo Alto flaws are far more dangerous when those interfaces are exposed. Then update all affected products right away, especially the Cortex XSOAR/XSIAM CommvaultSecurityIQ integration.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/palo-alto-networks-patches-high-severity-flaw-in-cortex-xsoar-and-xsiam-g-w-d-i-j/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Splunk Patches Critical Unauthenticated File Manipulation Vulnerability</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Fri, 12 Jun 2026 12:01:15 +0000</pubDate>
      <link>https://dev.to/beyondmachines/splunk-patches-critical-unauthenticated-file-manipulation-vulnerability-2lgl</link>
      <guid>https://dev.to/beyondmachines/splunk-patches-critical-unauthenticated-file-manipulation-vulnerability-2lgl</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Splunk patched a critical vulnerability (CVE-2026-20253, CVSS 9.8) in Splunk Enterprise and Cloud Platform that allows unauthenticated attackers to create or truncate arbitrary files via a PostgreSQL sidecar service.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you run Splunk Enterprise, update immediately to version 10.4.0, 10.2.4, or 10.0.7. And make sure to isolate the system from the internet and untrusted networks. If you use Splunk Cloud Platform, Splunk is already patching your instances, but verify you're on a fixed version (10.4.2604.3 or 10.2.2510.14 or higher) since there are no other ways to block this attack.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/splunk-patches-critical-unauthenticated-file-manipulation-vulnerability-8-g-w-0-w/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Critical Vertiv UPS Management Card Flaws Threaten Data Center Power Stability</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Fri, 12 Jun 2026 11:01:15 +0000</pubDate>
      <link>https://dev.to/beyondmachines/critical-vertiv-ups-management-card-flaws-threaten-data-center-power-stability-3mm1</link>
      <guid>https://dev.to/beyondmachines/critical-vertiv-ups-management-card-flaws-threaten-data-center-power-stability-3mm1</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Vertiv patched two critical vulnerabilities (CVE-2025-46412 and CVE-2025-41426) in its UPS management cards that allow attackers to bypass authentication and execute remote code to shut down data center power.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;Make sure your Vertiv Liebert UPS network cards (IS-UNITY-DP and RDU101) are isolated from the internet and reachable only from trusted internal networks or via VPN. Then apply the firmware updates ASAP. Review your UPS logs for any unexpected configuration changes or strange web requests.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/critical-vertiv-ups-management-card-flaws-threaten-data-center-power-stability-r-p-7-m-q/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
    <item>
      <title>Microsoft Defender Zero-Days GreatXML and RoguePlanet Bypass BitLocker and Escalate Privileges</title>
      <dc:creator>BeyondMachines</dc:creator>
      <pubDate>Fri, 12 Jun 2026 10:01:14 +0000</pubDate>
      <link>https://dev.to/beyondmachines/microsoft-defender-zero-days-greatxml-and-rogueplanet-bypass-bitlocker-and-escalate-privileges-43le</link>
      <guid>https://dev.to/beyondmachines/microsoft-defender-zero-days-greatxml-and-rogueplanet-bypass-bitlocker-and-escalate-privileges-43le</guid>
      <description>&lt;h3&gt;
  
  
  Summary
&lt;/h3&gt;

&lt;p&gt;Microsoft is dealing with multiple zero-day exploits, including GreatXML and RoguePlanet, which allow attackers to bypass BitLocker encryption and escalate privileges to SYSTEM by targeting Microsoft Defender.&lt;/p&gt;

&lt;h3&gt;
  
  
  Take Action:
&lt;/h3&gt;

&lt;p&gt;If you use Windows BitLocker encryption, switch it from TPM-only to TPM+PIN mode right away, so your drive requires a PIN at startup and can't be unlocked through the recovery environment. Keep an eye out for Microsoft patches for these two flaws (RoguePlanet and GreatXML), and limit physical access to your machines since the BitLocker bypass needs someone to physically touch the device.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;&lt;a href="https://beyondmachines.net/event_details/microsoft-defender-zero-days-greatxml-and-rogueplanet-bypass-bitlocker-and-escalate-privileges-4-d-3-b-0/9uoJWdGwxq" rel="noopener noreferrer"&gt;Read the full article on BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;This article was originally published on &lt;a href="https://beyondmachines.net" rel="noopener noreferrer"&gt;BeyondMachines&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>infosec</category>
    </item>
  </channel>
</rss>
