EPA proposes $19M cybersecurity boost for water systems.

AI security, infra resilience, rising threatsโ€”critical shift.

Is it enough?

Source: https://www.epa.gov/system/files/documents/2026-04/00_fy-2027-bib_combined_final.pdf

Follow @technadu & share your take.

#Infosec #Cybersecurity #CriticalInfrastructure

Someone planted backdoors in dozens of WordPress plug-ins used in thousands of websites | TechCrunch

Dozens of WordPress plug-ins were allegedly hijacked to push malware after they were sold to a new corporate owner.

TechCrunch

That Chrome still has a user base is a bit astounding to me.

It has capability by design... and that capability is sort of like a friend who keeps gossiping about what you do.

๐Ÿ™„

https://thehackernews.com/2026/04/108-malicious-chrome-extensions-steal.html?m=1

#chrome #telegram #google #infosec #privacy

108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users

108 Chrome extensions routed stolen Google and Telegram data to shared C2 infrastructure, impacting 20,000 users.

The Hacker News

๐ŸšจNew ransom group blog post!๐Ÿšจ

Group name: akira
Post title: Fletcher Chrysler Products
Info: https://cti.fyi/groups/akira.html

#ransomware #cti #threatintelligence #cybersecurity #infosec

wolfSSL Patches Critical Certificate Forgery Vulnerability Affecting Billions of Devices

wolfSSL version 5.9.1 patched a critical flaw (CVE-2026-5194) that allows attackers to use forged certificates to impersonate trusted servers.

**If you use devices or software built on wolfSSL (common in IoT, routers, industrial controllers, and embedded systems), make sure they are isolated from the internet and accessible from trusted networks only, then check with your device vendor for firmware updates that include wolfSSL version 5.9.1 to patch CVE-2026-5194. Be aware that older or unsupported devices may never get this fix, so network isolation and monitoring are your only protection for those.**
#cybersecurity #infosec #advisory #vulnerability
https://beyondmachines.net/event_details/wolfssl-patches-critical-certificate-forgery-vulnerability-affecting-billions-of-devices-d-z-4-g-0/gD2P6Ple2L

wolfSSL Patches Critical Certificate Forgery Vulnerability Affecting Billions of Devices

wolfSSL version 5.9.1 patched a critical flaw (CVE-2026-5194) that allows attackers to use forged certificates to impersonate trusted servers.

BeyondMachines

๐Ÿšจ EUVD-2026-22915

๐Ÿ“Š Score: 6.5/10 (CVSS v3.1)
๐Ÿ“ฆ Product: Mattermost, Mattermost, Mattermost (+2 more)
๐Ÿข Vendor: Mattermost
๐Ÿ“… Updated: 2026-04-15

๐Ÿ“ Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid ma...

๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-22915

#cybersecurity #infosec #euvd #cve #vulnerability

๐Ÿšจ EUVD-2026-22913

๐Ÿ“Š Score: n/a
๐Ÿ“ฆ Product: Apache SkyWalking
๐Ÿข Vendor: Apache Software Foundation
๐Ÿ“… Updated: 2026-04-15

๐Ÿ“ The SkyWalking OAP /debugging/config/dump endpoint may leak sensitive configuration information of MySQL/PostgreSQL.

This issue affects Apache SkyWalking: from 9.7.0 through 10.3.0.

Users are recommended to upgrade to version 10.4.0, which fi...

๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-22913

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

๐Ÿšจ EUVD-2026-22911

๐Ÿ“Š Score: 6.1/10 (CVSS v3.1)
๐Ÿ“ฆ Product: Product Pricing Table by WooBeWoo
๐Ÿข Vendor: woobeewoo
๐Ÿ“… Updated: 2026-04-15

๐Ÿ“ The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the updateLabel() and remo...

๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-22911

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

ASN: AS22369
Location: Parsippany, US
Added: 2026-04-09T09:05

#shodansafari #infosec