ex-aws-sns-signingcerturl-spoofing-cve-2026-47074
CVE-2026-47074: ex_aws_sns verify_message/1 fails to validate SigningCertURL, allowing unauthenticated SNS message signature spoofing; affects versions 2.0.1 to before 2.3.5.
CVE-2026-47074: ex_aws_sns verify_message/1 fails to validate SigningCertURL, allowing unauthenticated SNS message signature spoofing; affects versions 2.0.1 to before 2.3.5.
Overview of the amendment to packaging obligations and how organisations should respond.
An authenticated OS command injection in QNO’s VPN Firewall (CVE‑2025‑15389) lets attackers run shell commands; organisations should prioritise patching, restrict management interfaces, enforce MFA and apply ISO 27001 controls immediately.
The 2025 Regulations revoke and replace the 2024 framework, expanding the IBCS and creating new governance and claims handling obligations for NHS bodies and related organisations.
A critical MapSVG plugin vulnerability (CVE-2025-68562, severity 9.9) allows web‑shell uploads; immediate inventory, patching and containment are essential, plus ISO 27001 controls to prevent recurrence.
Consolidation of medicines legislation in UK health and safety law and what it means for organisations handling medicinal products and how to respond.
A high‑severity CVE in WELLTEND’s BPMFlowWebkit (CVE-2025-15227) allows unauthenticated absolute path traversal to download arbitrary system files; immediate triage, patching or mitigations plus ISO 27001 risk management are essential.
Donec ullamcorper nulla non metus auctor fringilla. Cras justo odio, dapibus ac facilisis in, egestas eget
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.