Category: Uncategorized

  • US ambassador’s Israel comments condemned by Arab and Muslim nations

    US ambassador’s Israel comments condemned by Arab and Muslim nations


    The statement said it was signed by the UAE, Egypt, Jordan, Indonesia, Pakistan, Turkey, Saudi Arabia, Qatar, Kuwait, Oman, Bahrain, Lebanon, Syria and the State of Palestine, as well as the Organisation of Islamic Cooperation, the Arab League and the Gulf Cooperation Council.



    Source link

  • CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog

    CISA Adds Two Actively Exploited Roundcube Flaws to KEV Catalog


    Ravie LakshmananFeb 21, 2026Vulnerability / Patch Management

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Roundcube webmail software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

    The vulnerabilities in question are listed below –

    • CVE-2025-49113 (CVSS score: 9.9) – A deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php. (Fixed in June 2025)
    • CVE-2025-68461 (CVSS score: 7.2) – A cross-site scripting vulnerability via the animate tag in an SVG document. (Fixed in December 2025)
    Cybersecurity

    Dubai-based cybersecurity company FearsOff, whose founder and CEO, Kirill Firsov, was credited with discovering and reporting CVE-2025-49113, said attackers have already “diffed and weaponized the vulnerability” within 48 hours of public disclosure of the flaw. An exploit for the vulnerability was subsequently made available for sale on June 4, 2025.

    Firsov also noted that the shortcoming can be triggered reliably on default installations, and that it had been hidden in the codebase for over 10 years.

    There are no details on who is behind the exploitation of the two Roundcube flaws. But multiple vulnerabilities in the email software have been weaponized by nation-state threat actors like APT28 and Winter Vivern.

    Federal Civilian Executive Branch (FCEB) agencies are to remediate identified vulnerabilities by March 13, 2026, to secure their networks against the active threat.



    Source link

  • Homeland Security suspends TSA PreCheck and Global Entry airport security programs

    Homeland Security suspends TSA PreCheck and Global Entry airport security programs


    WASHINGTON (AP) — The U.S. Department of Homeland Security is suspending the TSA PreCheck and Global Entry airport security programs as a partial government shutdown continues.

    The programs are designed to help speed registered travelers through security lines. Suspending them could cause headaches for fliers.

    Homeland Security Secretary Kristi Noem said in a statement that “shutdowns have serious real world consequences.” She also said that “TSA and CBP are prioritizing the general traveling population at our airports and ports of entry and suspending courtesy and special privilege escorts.”

    Advertisement

    Advertisement

    The partial government shutdown began Feb. 14 after Democrats and the White House were unable to reach a deal on legislation to fund the Department of Homeland Security. Democrats have been demanding changes to immigration operations that are core to President Donald Trump’s deportation campaign.

    Democrats on the House Committee on Homeland Security criticized the decision about airport security.

    They said on social media that the administration was “kneecapping the programs that make travel smoother and secure” and accused them of “ruining your travel on purpose.”


    [ad_2]
    Source link