Skip to content

The digital town square for the concert band community.

Connect with local ensembles, trade repertoire insights, and keep the pulse of the wind band world.

  • ๐Ÿ”’ Security News Digest - 2026-04-23

    World infosec securitynews
    1
    0 Votes
    1 Posts
    0 Views
    Security FeedS
    Security News Digest - 2026-04-23 29 updates from 9 sources: Security Boulevard: What is Bring Your Own Encryption (BYOE)? https://securityboulevard.com/2026/04/what-is-bring-your-own-encryption-byoe/ darkreading: 'Zealot' Shows What AI's Capable of in Staged Cloud Attack https://www.darkreading.com/cyber-risk/zealot-shows-ai-execute-full-cloud-attacks Unit 42: AIใฏใ‚ฏใƒฉใ‚ฆใƒ‰ใ‚’ๆ”ปๆ’ƒใงใใ‚‹ใฎใ‹?่‡ชๅพ‹ๅž‹ใ‚ฏใƒฉใ‚ฆใƒ‰ๆ”ปๆ’ƒๅž‹ใƒžใƒซใƒใ‚จใƒผใ‚ธใ‚งใƒณใƒˆ ใ‚ทใ‚นใƒ†ใƒ ใฎๆง‹็ฏ‰ใ‹ใ‚‰ๅพ—ใ‚‰ใ‚ŒใŸๆ•™่จ“ https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/ Unit 42: Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System https://unit42.paloaltonetworks.com/autonomous-ai-cloud-attacks/ SecurityWeek: AI Can Autonomously Hack Cloud Systems With Minimal Oversight: Researchers https://www.securityweek.com/ai-can-autonomously-hack-cloud-systems-with-minimal-oversight-researchers/ Security Boulevard: Supply Chain Resilience for UK SMEs: Practical Steps to Reduce Third-Party Risk https://securityboulevard.com/2026/04/supply-chain-resilience-for-uk-smes-practical-steps-to-reduce-third-party-risk/๐Ÿฆ  Malwarebytes: Apple fixes iOS bug that kept deleted notifications, including chat previews https://www.malwarebytes.com/blog/news/2026/04/apple-fixes-ios-bug-that-kept-deleted-notifications-including-chat-previews Security Boulevard: Apple fixes iOS bug that kept deleted notifications, including chat previews https://securityboulevard.com/2026/04/apple-fixes-ios-bug-that-kept-deleted-notifications-including-chat-previews/ SecurityWeek: Luxury Cosmetics Giant Rituals Discloses Data Breach https://www.securityweek.com/luxury-cosmetics-giant-rituals-discloses-data-breach/ BleepingComputer: CISA orders feds to patch BlueHammer flaw exploited as zero-day https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-microsoft-defender-flaw-exploited-in-zero-day-attacks/ SecurityWeek: The Behavioral Shift: Why Trusted Relationships Are the Newest Attack Surface https://www.securityweek.com/the-behavioral-shift-why-trusted-relationships-are-the-newest-attack-surface/ Security Boulevard: Telco Privacy Violation? Fine! No, Telco Privacy Violation, Fine. Supreme Court to Determine if FCC Can Charge Telcos for Data Breaches https://securityboulevard.com/2026/04/telco-privacy-violation-fine-no-telco-privacy-violation-fine-supreme-court-to-determine-if-fcc-can-charge-telcos-for-data-breaches/ The Hacker News: Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them? https://thehackernews.com/2026/04/project-glasswing-proved-ai-can-find.html SecurityWeek: Rilian Raises $17.5 Million for AI-Native Security Orchestration https://www.securityweek.com/rilian-raises-17-5-million-for-ai-native-security-orchestration/ Security Boulevard: Threat on the Horizon โ€“ AI and Cybersecurity https://securityboulevard.com/2026/04/threat-on-the-horizon-ai-and-cybersecurity/ Security News | TechCrunch: Surveillance vendors caught abusing access to telcos to track peopleโ€™s phone locations, researchers say https://techcrunch.com/2026/04/23/surveillance-vendors-caught-abusing-access-to-telcos-to-track-peoples-phone-locations-researchers-say/ Security Boulevard: How Branded SSO Interfaces Improve User Trust And Experience https://securityboulevard.com/2026/04/how-branded-sso-interfaces-improve-user-trust-and-experience/ The Hacker News: [Webinar] Mythos Reality Check: Beating Automated Exploitation at AI Speed https://thehackernews.com/2026/04/webinar-mythos-reality-check-beating.html BleepingComputer: New GopherWhisper APT group abuses Outlook, Slack, Discord for comms https://www.bleepingcomputer.com/news/security/new-gopherwhisper-apt-group-abuses-outlook-slack-discord-for-comms/ Security Boulevard: Managing AI Agents: Balancing Security and Productivity https://securityboulevard.com/2026/04/managing-ai-agents-balancing-security-and-productivity/ BleepingComputer: UK warns of Chinese hackers using proxy networks to evade detection https://www.bleepingcomputer.com/news/security/uk-warns-of-chinese-hackers-using-botnets-of-hijacked-consumer-devices-to-evade-detection/ SecurityWeek: Chinese Cybersecurity Firmโ€™s AI Hacking Claims Draw Comparisons to Claude Mythos https://www.securityweek.com/chinese-cybersecurity-firms-ai-hacking-claims-draw-comparisons-to-claude-mythos/ Security Boulevard: District Administration | How Cloud Monitoring Protects Districts From New Cyber Threats https://securityboulevard.com/2026/04/district-administration-how-cloud-monitoring-protects-districts-from-new-cyber-threats/ Security Boulevard: Why Chrome Zero-Days Keep Winning and What Enterprises Need to Change โ€“ Blog | Menlo Security https://securityboulevard.com/2026/04/why-chrome-zero-days-keep-winning-and-what-enterprises-need-to-change-blog-menlo-security/ Security Boulevard: Copperhelm Emerges to Launch Autonomous Cloud Security Platform https://securityboulevard.com/2026/04/copperhelm-emerges-to-launch-autonomous-cloud-security-platform/ The Record from Recorded Future News: Medical data of 500,000 Britons put up for sale on Chinese website https://therecord.media/medical-data-on-500000-britons-put-on-sale-alibaba BleepingComputer: Microsoft: Some Teams users canโ€™t join meetings after Edge update https://www.bleepingcomputer.com/news/microsoft/microsoft-some-teams-users-cant-join-meetings-after-edge-update/ The Record from Recorded Future News: House Republicans unveil data privacy law that would override state protections https://therecord.media/house-republicans-unveil-data-privacy-law-override-state-measures The Record from Recorded Future News: Trumpโ€™s pick for CISA director withdraws from consideration https://therecord.media/trump-pick-to-lead-cisa-withdraws-from-consideration#InfoSec #SecurityNews
  • 0 Votes
    1 Posts
    0 Views
    TechNaduT
    Tropic Trooper abuses GitHub + VS Code for covert C2 and persistence.AdaptixC2 + custom beacon listener in play.Trusted platforms = new attack surface.https://www.technadu.com/tropic-trooper-deploys-adaptixc2-and-custom-beacon-listener/626720/#Infosec #APT #ThreatIntel
  • 0 Votes
    1 Posts
    0 Views
    FelixC
    Sniffnet: comfortably monitor your Internet traffic https://sniffnet.net/ #bot #cybersecurity #infosec
  • 0 Votes
    2 Posts
    0 Views
    ANY.RUNA
    IOCs: URL patterns: hxxps://<redirector_site>/*#<8 digits>Family=<base64-victim email> hxxps://<phishing_domain>/?v=<hexadec_chars>&session=<session_id>&cid=<client_id>&iat=<digits>&loc=<location_code>&build=<build_version> Domains: kjcleaningservices[.]com[.]au starllamerchantservices[.]club lavor[.]sbsechosign[.]co[.]it dspconsulting[.]eu
  • 0 Votes
    1 Posts
    0 Views
    pentest-tools.comP
    We shipped an MCP server for Pentest-Tools.com. Connect Claude, Cursor, VS Code, Gemini CLI, or any MCP-compatible client and drive scans, finding triage, and report generation through natural language.Every tool call needs explicit approval before it runs. JSON-Schema validated.Python package is open source, self-hosting supported: https://github.com/pentesttoolscom/pentesttools-pypiDocs and ready-made configs: https://pentest-tools.com/docs/ai/mcp/overview#infosec #pentesting #MCP #opensource
  • 0 Votes
    1 Posts
    0 Views
    TechNaduT
    Apple fixes iOS flaw exposing deleted messages via notification logs (CVE-2026-28950).Even encrypted apps were impacted.Patch now.https://www.technadu.com/apple-patches-bug-exposing-deleted-chat-messages-via-logged-notifications/626706/#Infosec #iOS #Privacy
  • 0 Votes
    5 Posts
    0 Views
    PatrickP
    @AAKL unknown they seem rather tight lipped about it
  • 0 Votes
    1 Posts
    0 Views
    Shodan SafariS
    ASN: AS25472Location: Kallithรฉa, GRAdded: 2026-04-20T00:41#shodansafari #infosec
  • New.

    World infosec threatresearch
    1
    0 Votes
    1 Posts
    0 Views
    AAA
    New.Socket: Malicious Checkmarx Artifacts Found in Official KICS Docker Repository and Code Extensions https://socket.dev/blog/checkmarx-supply-chain-compromise @SocketSecurity #infosec #threatresearch
  • 0 Votes
    1 Posts
    0 Views
    Lenny ZeltserL
    AI is making commodity software nearly free to produce, exposing security vendors without real moats. Feature lists stopped being a reliable signal of which products will hold their position as commoditization sorts the market. If you were anxious about "SaaSpocalypse," here's a practical way to understand and handle it:A seven-dimension rubric from Ben Vierck scores software products from 1 to 3 across each dimension. Three cybersecurity-specific dynamics raise scores for products with compounding defensibility. For example, an EDR platform with a shared data layer can score 20 out of 21 because its dimensions reinforce each other. Enterprise buyers generate telemetry that sharpens detection, which strengthens the compliance posture that attracts the next buyer.Product managers and founders can apply the rubric to their own product, while buyers can apply it to their vendor shortlist. A low score names a dimension that needs investment, or a vendor likely to be bundled, absorbed, or replaced. Running the exercise honestly identifies the gaps worth examining.https://zeltser.com/scoring-security-product-strategy#cybersecurity #infosec #productmanagement #AI #securityleadership
  • 0 Votes
    1 Posts
    0 Views
    Yazoul - Cybersecurity AlertsM
    THREAT INTEL | STERIMED Actor "qilin" claims Undisclosed๏ธ Unverified claimhttps://www.yazoul.net/intel/claim/2026-04-22-sterimed-ransomware-attack-by-qilin-april-2026#DarkWeb #DataBreach #ThreatIntel #CyberSecurity #InfoSec
  • ๐Ÿšจ New security advisory:

    World infosec zeroday threatintel
    1
    0 Votes
    1 Posts
    0 Views
    Yazoul - Cybersecurity AlertsM
    New security advisory:CVE-2026-34275 affects multiple systems.โ€ข Impact: Remote code execution or complete system compromise possibleโ€ข Risk: Attackers can gain full control of affected systemsโ€ข Mitigation: Patch immediately or isolate affected systemsFull breakdown:https://www.yazoul.net/advisory/cve/cve-2026-34275-oracle-e-biz-unauth-takeover#InfoSec #ZeroDay #ThreatIntel
  • ๐Ÿ”’ Security News Digest - 2026-04-22

    World infosec securitynews
    1
    0 Votes
    1 Posts
    0 Views
    Security FeedS
    Security News Digest - 2026-04-22 15 updates from 7 sources: Security Boulevard: SnowFROC 2026: Secure Defaults, Real Trust, and a Better Layer on Top https://securityboulevard.com/2026/04/snowfroc-2026-secure-defaults-real-trust-and-a-better-layer-on-top/ BleepingComputer: Inside Caller-as-a-Service Fraud: The Scam Economy Has a Hiring Process https://www.bleepingcomputer.com/news/security/inside-caller-as-a-service-fraud-the-scam-economy-has-a-hiring-process/ Security News | TechCrunch: UK government says 100 countries have spyware that can hack peopleโ€™s phones https://techcrunch.com/2026/04/22/uk-government-says-100-countries-have-spyware-that-can-hack-peoples-phones/ SecurityWeek: After Bluesky, Mastodon Targeted in DDoS Attack https://www.securityweek.com/after-bluesky-mastodon-targeted-in-ddos-attack/ darkreading: DPRK Fake Job Scams Self-Propagate in 'Contagious Interview' https://www.darkreading.com/cyberattacks-data-breaches/dprk-fake-job-scams-self-propagate-contagious-interview Security Boulevard: North Korea Stole 100,000 Identities to Infiltrate Global Companies https://securityboulevard.com/2026/04/north-korea-stole-100000-identities-to-infiltrate-global-companies/ Security Boulevard: News alert: BreachLockโ€™s integrated attack validation platform debuts in Gartner AEV category https://securityboulevard.com/2026/04/news-alert-breachlocks-integrated-attack-validation-platform-debuts-in-gartner-aev-category/ Security Boulevard: [un]prompted 2026 โ€“ 8 Minutes to Admin. We Caught It in the Wild. Welcome to VibeHacking. https://securityboulevard.com/2026/04/unprompted-2026-8-minutes-to-admin-we-caught-it-in-the-wild-welcome-to-vibehacking/ BleepingComputer: Spain dismantles major $4.7M manga piracy platform, arrests four https://www.bleepingcomputer.com/news/security/spain-dismantles-major-47m-manga-piracy-platform-arrests-four/ Security Boulevard: How to Attend Tech Conferences and Events for Free: The Complete Guide for Cybersecurity and AI Professionals https://securityboulevard.com/2026/04/how-to-attend-tech-conferences-and-events-for-free-the-complete-guide-for-cybersecurity-and-ai-professionals/ The Hacker News: Harvester Deploys Linux GoGra Backdoor in South Asia Using Microsoft Graph API https://thehackernews.com/2026/04/harvester-deploys-linux-gogra-backdoor.html The Record from Recorded Future News: French police arrest suspected hacker behind dozens of data breaches https://therecord.media/french-hacker-cyberattacks-arrest Security Boulevard: CyberStrong Product Update: Whatโ€™s New in Release 4.14 https://securityboulevard.com/2026/04/cyberstrong-product-update-whats-new-in-release-4-14/ Security News | TechCrunch: Cosmetics giant Rituals confirms data breach of customer membership records https://techcrunch.com/2026/04/22/cosmetics-giant-rituals-confirms-data-breach-of-customer-membership-records/ Security Boulevard: Is Your Network Ready for AI? A Practical Evaluation Framework https://securityboulevard.com/2026/04/is-your-network-ready-for-ai-a-practical-evaluation-framework/#InfoSec #SecurityNews
  • One more for the lost generation.

    World infosec cybercrime
    1
    0 Votes
    1 Posts
    0 Views
    AAA
    One more for the lost generation. This suspect is 20-years-old, The Record: French police arrest suspected hacker behind dozens of data breaches https://therecord.media/french-hacker-cyberattacks-arrest @therecord_media #infosec #cybercrime
  • Headline of the day:

    World mozilla firefox claude anthropic infosec
    2
    0 Votes
    2 Posts
    0 Views
    James_inthe_boxJ
    @AAKL @SecurityWeek ๐Ÿฅฑ
  • 0 Votes
    1 Posts
    0 Views
    VladyslavN
    Cybersecurity is everyone's responsibility, not just IT's. The weakest link in any system is the human factor, and most breaches start with a single click. #cybersecurity #infosec #tech
  • 0 Votes
    1 Posts
    0 Views
    Yazoul - Cybersecurity AlertsM
    THREAT INTEL | Complete Aircraft Group๐ŸŸ  Actor "everest" claims Undisclosed๏ธ Unverified claimhttps://www.yazoul.net/intel/claim/2026-04-20-complete-aircraft-group-ransomware-claim-by-everest-apr-2026#DarkWeb #DataBreach #ThreatIntel #CyberSecurity #InfoSec
  • 0 Votes
    1 Posts
    0 Views
    BeyondMachines :verified:B
    Critical RCE Vulnerability in SGLang AI Framework via Malicious GGUF ModelsSGLang disclosed a critical RCE vulnerability CVE-2026-5760 caused by unsandboxed Jinja2 template rendering in its reranking endpoint. Attackers can exploit this by tricking users into loading malicious GGUF model files that run arbitrary Python code.**If you run SGLang for serving LLMs, treat it as unsafe right now: restrict the API to trusted internal networks only, run it in a non-privileged container, and do not load any GGUF models from public repositories like Hugging Face until the maintainers release a patch. As a temporary fix, have your team manually patch the source to use Jinja2's ImmutableSandboxedEnvironment instead of the default environment.**#cybersecurity #infosec #advisory #vulnerabilityhttps://beyondmachines.net/event_details/critical-rce-vulnerability-in-sglang-ai-framework-via-malicious-gguf-models-l-4-1-8-t/gD2P6Ple2L
  • 0 Votes
    1 Posts
    0 Views
    r1cksecR
    KslDump extracts credentials from PPL-protected LSASS using only Microsoft-signed componentshttps://github.com/andreisss/KslDump#infosec #cybersecurity #redteam #pentest
  • 0 Votes
    1 Posts
    0 Views
    ThreatNoirT
    ๏ธ CRITICAL: ๏ธ A threat actor operating under the alias spider321 has shared samples of an alleged databa...Threat actor spider321 publicly disclosed a database containing ~90,000 records of US law enforcement personnel with full names, emails, phone numbers, IP addresses, and home zip codes. This PII exposes officers to direct targeting, harassment, and social engineering attacks. The breach significantโ€ฆhttps://threatnoir.com/focus#infosec #cybersecurity