433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (813) 563-2652

Cisco Unified Communications Manager Static SSH Credentials Vulnerability

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static user credentials for the root account that are reserved for use during development. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and execute arbitrary commands as the root user. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cucm-ssh-m4UBdpE7 Security Impact Rating: Critical CVE: CVE-2025-20309
http://news.poseidon-us.com/TLhT3r

Qantas data breach could affect 6 million customers

Qantas has suffered a cyber incident that has lead to a data breach. “The incident occurred when a cyber criminal targeted a call centre and gained access to a third-party customer servicing platform,” the Australian airline announced today, but said that all of its systems remain secure and its operations haven’t been affected. What is known about the cyber incident? Qantas does not say which call center was affected, but the Australian Frequent Flyer reports … More → The post Qantas data breach could affect 6 million customers appeared first on Help Net Security.
http://news.poseidon-us.com/TLh9pZ

American Airlines CIO on redefining CX with tech

On a recent podcast, Ganesh Jayaram discussed the carrier’s revamped app and self-service capabilities as it turns to AI to avoid missed connections.
http://news.poseidon-us.com/TLh76H

Exabeam Nova Advisor Agent equips security leaders with a real-time strategic planning engine

Exabeam announced a major expansion of its integrated multi-agent AI system Exabeam Nova that now equips security leaders with a real-time strategic planning engine and boardroom communication tool. The Exabeam Nova Advisor Agent is the AI capability designed to turn security data into a strategy that CISOs can defend in the boardroom. Translating complex security metrics into business-relevant terms has been a long-standing challenge, making it difficult to demonstrate risk reduction, prove the value of … More → The post Exabeam Nova Advisor Agent equips security leaders with a real-time strategic planning engine appeared first on Help Net Security.
http://news.poseidon-us.com/TLgtnB

Scamnetic KnowScam 2.0 helps consumers detect every type of scam

Scamnetic releaseed KnowScam 2.0, its flagship product for scam protection and digital identity verification. KnowScam 2.0 builds on everything users already trust — now with major upgrades, including an enhanced three-point scoring system, the new Auto Scan feature for Microsoft Outlook and Android RCS, and a new deepfake detection and ID verification feature in IDeveryone for instant identification. “KnowScam 2.0 marks a major leap forward in proactive scam protection by combining broader platform coverage, automated … More → The post Scamnetic KnowScam 2.0 helps consumers detect every type of scam appeared first on Help Net Security.
http://news.poseidon-us.com/TLgtmw

Cybersecurity essentials for the future: From hype to what works

Cybersecurity never stands still. One week it’s AI-powered attacks, the next it’s a new data breach, regulation, or budget cut. With all that noise, it’s easy to get distracted. But at the end of the day, the goal stays the same: protect the business. CISOs are being asked to juggle more, with tighter resources, more boardroom time, and threats that keep changing. Here are five areas that deserve your attention now and going forward. Get … More → The post Cybersecurity essentials for the future: From hype to what works appeared first on Help Net Security.
http://news.poseidon-us.com/TLgtls

How FinTechs are turning GRC into a strategic enabler

In this Help Net Security interview, Alexander Clemm, Corp GRC Lead, Group CISO, and BCO at Riverty, shares how the GRC landscape for FinTechs has matured in response to tighter regulations and global growth. He discusses the impact of frameworks like DORA and the EU AI Act, and reflects on building a culture where compliance supports, rather than slows, business progress. How has the GRC landscape evolved for FinTechs in the last few years, particularly … More → The post How FinTechs are turning GRC into a strategic enabler appeared first on Help Net Security.
http://news.poseidon-us.com/TLgtkx

Secretless Broker: Open-source tool connects apps securely without passwords or keys

Secretless Broker is an open-source connection broker that eliminates the need for client applications to manage secrets when accessing target services like databases, web services, SSH endpoints, or other TCP-based systems. Secretless Broker features “We created Secretless Broker to solve the “last mile” problem in secret delivery. While many tools handle secret storage and retrieval, there was still a gap in how those secrets were used securely by applications. The tool was designed to close … More → The post Secretless Broker: Open-source tool connects apps securely without passwords or keys appeared first on Help Net Security.
http://news.poseidon-us.com/TLgtkr

Product showcase: Protect your data with Apricorn Aegis Secure Key 3NXC

The Apricorn Aegis Secure Key 3NXC is a 256-bit AES XTS hardware-encrypted flash drive with a USB-C connector. It is available in storage capacities ranging from 4GB to 512GB and holds FIPS 140-2 Level 3 validation. The device is OS-agnostic, meaning it can work with any device that has a USB-C port, whether it’s a phone, tablet, Windows PC, or Mac. Apricorn Aegis Secure Key 3NXC setup Before setting it up, the device must be … More → The post Product showcase: Protect your data with Apricorn Aegis Secure Key 3NXC appeared first on Help Net Security.
http://news.poseidon-us.com/TLgtdn