Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article compares AWS KMS and AWS CloudHSM for cryptographic key management. AWS KMS is a fully managed service suitable for most cloud-based key management needs, while AWS CloudHSM provides dedicated HSM instances for legacy applications and strict compliance requirements.
CISA, the Australian Cyber Security Centre (ACSC), the FBI, and international partners released 'CI Fortify — Advice for isolating vital systems,' urging critical infrastructure organizations to prepare plans for disconnecting OT from corporate and internet-facing networks during cyberattacks. The guidance covers identifying minimum systems for critical service delivery, documenting all connections, and determining isolation points.
CVE-2026-61511 is a critical pre-authentication remote code execution vulnerability in vBulletin forum software affecting versions up to 5.7.5 and 6.2.1. The flaw resides in the runMaths() function, which fails to sanitize user input before passing it to PHP's eval().
AWS announces the availability of the latest IRAP Phase 1a report on AWS Artifact. The report adds four new services assessed at the PROTECTED level, bringing the total to 167.
AWS has released its 2026 Phase 1a IRAP (Information Security Registered Assessors Program) report on AWS Artifact for Australian customers. An independent assessor certified by the Australian Signals Directorate (ASD) completed the evaluation in June 2026, adding four new AWS services—Amazon Bedrock AgentCore, AWS Parallel Computing Service, AWS Resilience Hub, and AWS Security Incident Response—to the PROTECTED level assessment.