• Council accelerates construction to address port access closures

    Council accelerates construction to address port access closures

    THE DALLES — Owners, employees and patrons of the Bargeway Pub & Catering packed The Dalles City Council meeting on April 27, addressing business impacts tied to the ongoing closure of Webber Street, which has significantly halted traffic in the…

    Read More

  • Candidates for Oregon House, Senate speak

    Candidates for Oregon House, Senate speak

    THE DALLES — All the candidates for Wasco County positions, from county commission to U.S. Senate, were invited to a forum at The Dalles Senior Center on April 28. Most attended, though three candidates ended up answering the moderator’s questions…

    Read More

  • Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE

    Critical Apache HTTP/2 Flaw (CVE-2026-23918) Enables DoS and Potential RCE

    The Apache Software Foundation (ASF) has released security updates to address several security vulnerabilities in the HTTP Server, including a severe vulnerability that could potentially lead to remote code execution (RCE). The vulnerability, tracked as CVE-2026-23918 (CVSS score: 8.8), has been described as a case of “double free and possible RCE” in the HTTP/2 protocol…

    Read More

  • China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions

    China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions

    A sophisticated China-nexus advanced persistent threat (APT) group has been attributed to attacks targeting government entities in South America since at least late 2024 and government agencies in southeastern Europe in 2025. The activity is being tracked by Cisco Talos under the moniker UAT-8302, with post-exploitation involving the deployment of custom-made malware families that have…

    Read More

  • The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed

    The Back Door Attackers Know About — and Most Security Teams Still Haven’t Closed

    Every AI tool, workflow automation, and productivity app your employees connected to Google or Microsoft this year left something behind: a persistent OAuth token with no expiration date, no automatic cleanup, and in most organizations, no one watching it. Your perimeter controls don’t see it. Your MFA doesn’t stop it. And when an attacker gets…

    Read More

  • We Scanned 1 Million Exposed AI Services. Here’s How Bad the Security Actually Is

    We Scanned 1 Million Exposed AI Services. Here’s How Bad the Security Actually Is

    While the software industry has made genuine strides over the past few decades to deliver products securely, the furious pace of AI adoption is putting that progress at risk. Businesses are moving fast to self-host LLM infrastructure, drawn by the promise of AI as a force multiplier and the pressure to deliver more value faster.…

    Read More

  • ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows

    ScarCruft Hacks Gaming Platform to Deploy BirdCall Malware on Android and Windows

    The North Korea-aligned state-sponsored hacking group known as ScarCruft has compromised a video game platform in a supply chain espionage attack, trojanizing its components with a backdoor called BirdCallto likely target ethnic Koreans residing in China. While prior versions of the backdoor have primarily targeted Windows users only, the supply chain attack is assessed to…

    Read More

  • Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API

    Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API

    A critical security vulnerability in Weaver (Fanwei) E-cology, an enterprise office automation (OA) and collaboration platform, has come under active exploitation in the wild. The vulnerability (CVE-2026-22679, CVSS score: 9.8) relates to a case of unauthenticated remote code execution affecting Weaver E-cology 10.0 versions prior to 20260312. The issue resides in the “/papi/esearch/data/devops/

    Read More

  • Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

    Phishing Campaign Hits 80+ Orgs Using SimpleHelp and ScreenConnect RMM Tools

    An active phishing campaign has been observed targeting multiple vectors since at least April 2025, with legitimate Remote Monitoring and Management (RMM) software as a way to establish persistent remote access to compromised hosts. The activity, codenamed VENOMOUS#HELPER, has impacted over 80 organizations, most of which are in the U.S., according to Securonix. It shares…

    Read More

  • Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass

    Progress Patches Critical MOVEit Automation Bug Enabling Authentication Bypass

    Progress Software has released updates to address two security flaws in MOVEit Automation, including a critical bug that could result in an authentication bypass. MOVEit Automation (formerly Central) is a secure, server-based managed file transfer (MFT) solution used to schedule and automate file movement workflows in enterprise environments without requiring any custom scripts.  The

    Read More