SysBlue Cyber Solutions
Sysblue is an information security consulting and managed cybersecurity services firm with headquarters in Romania.
We help clients solve information security challenges based on risk, not fear.
15/09/2026
CenterPoint Energy confirms customer data stolen in cyberattack.
CenterPoint Energy disclosed a breach compromising some customers’ personal information after an attacker leaked data allegedly stolen from the utility company.
An investigation started after the company discovered an online post from a threat actor claiming to have stolen 7.49 million records.
CenterPoint Energy confirms customer data stolen in cyberattack CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company.
14/09/2026
Microsoft: September updates cause RDS failures on Windows Server.
Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems.
According to a release health update on Friday, this known issue impacts Windows Server 2012 and later, as well as Windows 10 and Windows 11 devices.
Microsoft: September updates cause RDS failures on Windows Server Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems.
13/09/2026
Hackers exploit Tencent app flaw to deploy GrayRabbit malware.
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor.
Researchers at cybersecurity company Gen Digital warn that the security issue is a one-click remote code ex*****on (RCE) flaw.
Hackers exploit Tencent app flaw to deploy GrayRabbit malware Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor.
12/09/2026
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent.
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
Although no public proof-of-concept (PoC) exploit has been reported, the agency is urging organizations to install the security updates addressing the two issues as soon as possible.
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.
11/09/2026
Florida confirms DMV database breached via stolen police account.
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach after the ShinyHunters extortion gang claimed to have compromised the system.
The disclosure comes after the ShinyHunters extortion group claimed it breached the DAVID database and stole more than 200,000 driver records.
Florida confirms DMV database breached via stolen police account The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee.
10/09/2026
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key.
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide.
LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential.
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key Wiz found 294 of 3,074 LiteLLM gateways accepted sk-1234, exposing provider keys and enabling cloud IAM access in tests.
09/09/2026
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime syndicates.
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto U.S. authorities disrupted Xinbi Guarantee and froze $52.8 million in crypto tied to the scam marketplace and its merchant network.
07/09/2026
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released.
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code ex*****on — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild.
Security firm TantoSec has published a working exploit chain targeting vulnerabilities in Telerik UI for ASP.NET AJAX that can allow an unauthenticated attacker to execute remote code on the server hosting a vulnerable application.
https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html?m=1
ASP.NET Core, an open-source web development framework | .NET Build web apps and services that run on Windows, Linux, and macOS using C #, HTML, CSS, and JavaScript. Get started for free on Windows, Linux, or macOS.
06/09/2026
Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5.
Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or attacker identity.
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication Attackers gain full administrative control of MikroTik routers through internet-exposed SSH without authentication, CERT Polska says.
05/09/2026
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Store.
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5.
Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early because stores are being compromised right now," the company said.
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Sansec says attackers exploit an unpatched Magento and Adobe Commerce flaw to run server code without authentication and install persistent backdoors.
Click here to claim your Sponsored Listing.
Category
Website
Address
București
Bucharest
030171