Latest News

Vulnerabilities

SAP's April 2026 Patch Day Tackles 9.9-Severity ABAP SQL Injection Flaw

SAP released 20 security notes on its April 2026 patch day, led by CVE-2026-27681, a critical 9.9-rated SQL injection vulnerability in Business Planning and Consolidation and Business Warehouse that enables arbitrary code execution.

Vulnerabilities

CVE-2026-5194: Critical wolfSSL Flaw Lets Attackers Pass Off Forged Certificates

A critical cryptographic validation bug in the widely deployed wolfSSL library allows improperly weak digests to be accepted during certificate verification, potentially letting attackers impersonate malicious servers. The flaw was patched in wolfSSL 5.9.1 on April 8, 2026.

Analysis

OT Environments Can't Back Up Post-Quantum Cryptography Attestations

Operational technology asset owners are being required to attest to post-quantum cryptographic readiness, but the frameworks, tools, and visibility needed to make those attestations meaningful simply don't exist in most OT environments.

← Prev 1 3536373839 53 Next →