ex-aws-sns-signingcerturl-spoofing-cve-2026-47074
CVE-2026-47074: ex_aws_sns verify_message/1 fails to validate SigningCertURL, allowing unauthenticated SNS message signature spoofing; affects versions 2.0.1 to before 2.3.5.
CVE-2026-47074: ex_aws_sns verify_message/1 fails to validate SigningCertURL, allowing unauthenticated SNS message signature spoofing; affects versions 2.0.1 to before 2.3.5.
Data centre projects now fall under the Infrastructure Planning regime, creating new consent requirements and governance obligations for developers.
A high‑severity NeuVector vulnerability (CVE‑2025‑66001) published 49 minutes ago shows TLS verification for OpenID Connect isn’t enforced by default, risking MITM exposure; immediate configuration checks, patched guidance and ISO 27001‑aligned controls will reduce the danger.
The 2026 amendments clarify which business customers fall under the redress scheme for heat network operators.
A critical deserialisation vulnerability (CVE-2025-47552) in the DZS Video Gallery WordPress plugin allows object injection in versions through 12.37; patch or remove the plugin now and map the risk to ISO 27001 controls.
The UK’s £210m Cyber Action Plan targets public‑service resilience and software supply‑chain risk — a timely reminder to strengthen ISO 27001 controls, test continuity plans and lock down supplier security now.
Emergency Prescott airspace restrictions require immediate changes to drone operations and related activities.
Donec ullamcorper nulla non metus auctor fringilla. Cras justo odio, dapibus ac facilisis in, egestas eget
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.