433 Central Ave., 4th Floor, St. Petersburg, FL 33701 | info@poseidon-us.com | Office: (813) 786-3120

Cisco RoomOS Security Hardening Release: July 2026

As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.   These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-roomos-AqNMbEq Security Impact Rating: High CVE: CVE-2026-20150,CVE-2026-20153,CVE-2026-20156,CVE-2026-20157,CVE-2026-20158,CVE-2026-20187
http://news.poseidon-us.com/TTYC0h

Cisco Identity Services Engine Path Traversal Vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system. Cisco plans to release software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-traversal-xNt7wb2Y Security Impact Rating: Medium CVE: CVE-2026-20146
http://news.poseidon-us.com/TTYBz8

LabubaRAT malware infiltrates Windows systems while posing as NVIDIA software

LabubaRAT, a previously undocumented Rust-based remote access tool (RAT) masquerading as NVIDIA software that enables post-compromise operations on Windows systems, has been uncovered by Blackpoint Cyber. According to researchers, LabubaRAT creates “a reusable foothold for hands-on activity.” Once deployed, it can profile the host, identify installed security tools, receive operator commands, transfer files, capture screenshots, and proxy network traffic through the affected system. Blackpoint Cyber named the malware LabubaRAT after discovering a “LabubaPanel” title and … More → The post LabubaRAT malware infiltrates Windows systems while posing as NVIDIA software appeared first on Help Net Security.
http://news.poseidon-us.com/TTYBt4

Threat actor impersonated hundreds of brands on GitHub to push infostealer malware

A financially motivated threat actor is impersonating hundreds of brands on GitHub and pushing a smash-and-grab infostealer masquerading as legitimate downloads of popular software, Arctic Wolf threat researchers have warned. “The 292 impersonated repositories span security tooling, fintech and personal finance, cryptocurrency wallets and exchanges, developer and productivity tools, secure email providers, macOS utilities, and gaming software, including ‘cheat’ tools,” they said. How the attack works Among these repositories was one impersonating Arctic Wolf, which … More → The post Threat actor impersonated hundreds of brands on GitHub to push infostealer malware appeared first on Help Net Security.
http://news.poseidon-us.com/TTYBkK

Socure rolls out Remote Verifier for higher-risk identity checks

Socure has launched Remote Verifier in RiskOS, a new identity verification tool that helps organizations verify identities requiring additional review while reducing manual effort. Socure’s AI-powered document verification solution instantly verifies more than 99% of identities on the first try, compared to an industry average of 64%. The Remote Verifier is designed for individuals who do not initially pass Socure’s document verification check. With verification accuracy, the company anticipates fewer than 1% of individuals will … More → The post Socure rolls out Remote Verifier for higher-risk identity checks appeared first on Help Net Security.
http://news.poseidon-us.com/TTYBkD

Xint Pulse offers on-demand black-box penetration testing for web applications

Xint.io has launched Xint Pulse, a black-box autonomous penetration testing tool that provides product security teams with on-demand security assessments of their applications. Unlike the company’s enterprise platform, which is designed for continuous testing, Xint Pulse is intended for timely, one-off penetration tests. But with Xint Pulse, organizations of all sizes, from startups to large enterprises, can now perform a scan of their applications with the same Xint technology that was named Best Automated Pentesting … More → The post Xint Pulse offers on-demand black-box penetration testing for web applications appeared first on Help Net Security.
http://news.poseidon-us.com/TTYBk7

F5 Insight for ADSP enhances BIG-IP operations with guided updates and AI audit trails

F5 has announced new fleet management capabilities for F5 Insight for ADSP that help enterprises reduce risk exposure across F5 BIG-IP environments as frontier AI compresses vulnerability response timelines. The new F5 Insight workflows give security and operations teams fleet-wide visibility, guided update management, enterprise authentication, role-based access controls, and a tamper-evident AI audit trail. This enables customers to move from identifying risk to taking accountable action across large, distributed application delivery and security fleets. … More → The post F5 Insight for ADSP enhances BIG-IP operations with guided updates and AI audit trails appeared first on Help Net Security.
http://news.poseidon-us.com/TTYBhw

Recorded FutureがGartner® サイバー脅威インテリジェンス・テクノロジー部門のMagic Quadrant™のリーダーの1社に位置づけられました。

Gartnerがサイバー脅威インテリジェンスのマジック・クアドラントのリーダーの1社と評価 — 能動的サイバー防御法施行を前に、日本企業が今すべきこと
http://news.poseidon-us.com/TTYBC7

DOJ’s top FOIA official is stepping down

Glendening took over the OIP role last year after longtime Director Bobak Talebian was fired as part of a wave of DOJ terminations.
http://news.poseidon-us.com/TTY9KC

DOJ’s top FOIA official is stepping down

Glendening took over the OIP role last year after longtime Director Bobak Talebian was fired as part of a wave of DOJ terminations.
http://news.poseidon-us.com/TTY9K4