惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

酷 壳 – CoolShell
酷 壳 – CoolShell
H
Hacker News: Front Page
P
Palo Alto Networks Blog
T
ThreatConnect
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
T
True Tiger Recordings
P
Privacy & Cybersecurity Law Blog
B
Blog
IT之家
IT之家
Last Week in AI
Last Week in AI
F
Full Disclosure
Hacker News: Ask HN
Hacker News: Ask HN
C
Comments on: Blog
Microsoft Azure Blog
Microsoft Azure Blog
C
Cybersecurity and Infrastructure Security Agency CISA
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
N
News and Events Feed by Topic
NISL@THU
NISL@THU
腾讯CDC
雷峰网
雷峰网
Security Latest
Security Latest
李成银的技术随笔
M
Microsoft Research Blog - Microsoft Research
L
LangChain Blog
L
Lohrmann on Cybersecurity
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
Check Point Blog
Y
Y Combinator Blog
Recent Announcements
Recent Announcements
博客园 - Franky
N
News | PayPal Newsroom
V
V2EX
A
About on SuperTechFans
The Register - Security
The Register - Security
月光博客
月光博客
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google Online Security Blog
Google Online Security Blog
MyScale Blog
MyScale Blog
Cisco Talos Blog
Cisco Talos Blog
Vercel News
Vercel News
WordPress大学
WordPress大学
C
Cyber Attacks, Cyber Crime and Cyber Security
The Hacker News
The Hacker News
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
爱范儿
爱范儿
A
Arctic Wolf
L
LINUX DO - 最新话题
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More

The Register - Security

Even Claude agrees: hole in its sandbox was real and dangerous GitHub says internal repos exfiltrated after poisoned VS Code extension attack London's police asked Big Tech for comms data over 700,000 times last year Microsoft shuts down illegal code-signing operation used by ransomware crims to mask their malware America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames Clear your calendar, Drupal user: You have a critically urgent patch to install Clear your calendar, Drupal user: You have a critically urgent patch to install Do fear the Reaper - stealer swipes macOS users' passwords, wallets, then backdoors them Shai-Hulud copycat hits another npm package Linux kernel flaw opens root-only files to unprivileged users TanStack weighs invitation-only pull requests after supply chain attack NGINX Rift attackers waste no time targeting exposed servers Poland directs officials to ditch Signal in favor of 'secure' state-developed alternative F-35 software delays leave UK buying time with US glide bombs Mozilla warns UK: Breaking VPNs will not magically fix Britain's age-check mess Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’ OpenAI caught in TanStack npm supply chain chaos after employee devices compromised MPs want social media treated more like unsafe toys than harmless apps Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Cops arrest man suspected of being Dream Market kingpin Dirty Frag gets a sequel as Fragnesia hands Linux attackers root-level access To gain root access at this company, all an intruder had to do was ask nicely To gain root access at this company, all an intruder had to do was ask nicely AI models are getting better at replacing cybersecurity pros on certain tasks Cisco to fire 4,000 staff and generously give them free training – on Cisco Welcome to the vulnpocalypse, as vendors use AI to find bugs and patches multiply like rabbits AWS patched Quick auth bypass, says customers weren't using control AWS to Quick admins: The access control didn't work, but you weren't using it anyway, so what's the problem? Bug hunter tracks down three massive MCP flaws and one vendor won't fix theirs Disgruntled researcher releases two more Microsoft zero-days Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Vietnam to develop domestic cloud so it can ditch risky overseas operators for government workloads Doozy of a Patch Tuesday includes 30 critical Microsoft CVEs Foxconn confirms cyberattack after Nitrogen claims Apple, Nvidia data theft US bank reports itself after AI customer data mishap Cache-poisoning caper turns TanStack npm packages toxic Apple, Google drag cross-platform texting into the encrypted age Japan’s PM orders cybersecurity review to stop Mythos going full CyberZilla Double Canvas breach acknowledged as ShinyHunters sets new pay-or-leak deadline Cookie thieves caught stealing dev secrets via fake Claude Code installers Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator Best Western Hotels confirms web app data breach Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged Checkmarx tackles another TeamPCP intrusion as Jenkins plugin sabotaged Taiwan's train cyber-trauma reveals a global system that’s coming off the tracks Worm rubs out competitor's malware, then takes control 'Dirty Frag' Linux flaw one-ups CopyFail with no patches and public root exploit Meta U-turns on encryption push for Instagram as DMs go plaintext Hackers ate my homework: Educational SaaS Canvas down after cyberattack Hackers ate my homework: Educational SaaS Canvas down after cyberattack Meta fights Ofcom over how many billions count as billions Mozilla boasts Mythos boosted Firefox bug cull Anthropic response to 1-click pwn: Shouldn't have clicked 'ok' 60% of MD5 password hashes are crackable in under an hour The network password was a key plot point in one of the most famous movies of all time Arctic Wolf cuts 250 jobs in AI push 1 in 8 workers say selling company logins is justifiable Iran cyberspies LARPing as ransomware crims in espionage ops UK age-gating plans risk breaking the internet, privacy groups warn India orders infosec red alert in case Mythos sparks crime spree India orders infosec red alert in case Mythos sparks crime ServiceNow clears agents for landing with new AI control tower Attackers are cashing in on fresh 'CopyFail' Linux flaw 'CopyFail' attackers start cashing in on Linux flaw Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking Real estate giant confirms vishing incident as ShinyHunters and Qilin both come knocking ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Romance scammers turn sweet talk into £102M payday Romance scammers turn sweet talk into £102M payday NHS to close-source hundreds of GitHub repos over AI, security concerns Microsoft's bad obsession is showing up in shabby services and slipshod software. Here's proof Singapore boffins get diverse SIEMs singing in harmony Singapore boffins get diverse SIEMs singing in harmony with agentic rule translation Kids say they can beat age checks by drawing on a fake mustache Kids say they can beat age checks by drawing on a fake mustache AI-BOMs replace SBOMs as way to track AI agents and bots Shadow IT has given way to shadow AI. Enter AI-BOMs If the vote you rocked, your personal info can be grokked If the vote you rocked, your personal info can be grokked Five Eyes spook shops warn rapid rollouts of agentic AI are too risky Five Eyes spook shops warn agentic is too wonky for rapid rollout Brace for the patch tsunami: AI is unearthing decades of buried code debt Brace for the patch tsunami: AI is unearthing decades of buried code debt First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed First reports come in of victims of critical cPanel vuln as 'millions' of sites potentially exposed OpenAI locks GPT-5.5-Cyber behind velvet rope despite slamming Anthropic for doing exactly that OpenAI locks GPT-5.5-Cyber behind velvet rope despite slamming Anthropic for doing exactly that Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays down Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays down Passport to £££: Home Office adds £216M to travel doc contract before a single bid's been placed Home Office adds £216M to travel doc contract before bids The never-ending supply chain attacks worm into SAP npm packages, other dev tools The never-ending supply chain attacks worm into SAP npm packages, other dev tools Bot her emails: most modern phishing campaigns are AI-enabled Bot her emails: most modern phishing campaigns are AI-enabled FBI cyber boss: China's hacker-for-hire ecosystem 'out of control' FBI: China's hacker-for-hire ecosystem 'out of control'
CISA tells feds to patch 13-year-old Apache ActiveMQ bug under active attack
Carly Page · 2026-04-18 · via The Register - Security

CISA is sounding the alarm on a newly-exploited Apache ActiveMQ bug, ordering federal agencies to patch within two weeks as attackers circle a flaw that's been quietly lurking for more than a decade.

The US cybersecurity agency added the bug, tracked as CVE-2026-34197, to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, triggering a Binding Operational Directive (BOD) 22-01 deadline that gives Federal Civilian Executive Branch agencies until April 30 to fix their systems or get ready to explain why not.

The bug sits in Apache ActiveMQ, an open source message broker used to shuttle data between applications and services, and allows an authenticated user to execute arbitrary code via the broker's Jolokia management API – effectively turning a messaging workhorse into a remote command runner.

It was disclosed just over a week ago by Horizon3 researcher Naveen Sunkavally, who used Anthropic's Claude AI assistant to help dig it out. According to Horizon3, the issue has been sitting in the codebase for 13 years, unnoticed until now. Patches are available in ActiveMQ versions 5.19.5 and 6.2.3.

"CVE-2026-34197 is a remote code execution vulnerability in Apache ActiveMQ Classic that has been hiding in plain sight for 13 years," Sunkavally said. "An attacker can invoke a management operation through ActiveMQ's Jolokia API to trick the broker into fetching a remote configuration file and running arbitrary OS commands."

While the bug technically requires authentication, Horizon3 notes that many deployments still rely on default credentials – the ever-reliable "admin:admin" –  making initial access trivial. Worse, on certain versions (6.0.0 through 6.1.1), an older flaw, CVE-2024-32114, can expose the Jolokia API without authentication entirely, turning this into a no-credentials-needed remote code execution chain.

"The vulnerability requires credentials, but default credentials are common in many environments," Sunkavally said. "On some versions… no credentials are required at all… In those versions, CVE-2026-34197 is effectively an unauthenticated RCE."

That combination is exactly the sort of thing that lands a bug on CISA's KEV list, which is reserved for vulnerabilities already being exploited in the wild. And there's plenty of exposed surface to aim at: threat monitoring outfit ShadowServer is tracking more than 8,000 ActiveMQ instances reachable from the public internet.

This isn't ActiveMQ's first run-in with attackers, either. The platform has featured in its fair share of compromises, from cryptominers to botnet infrastructure. As Sunkavally pointed out, none of this is especially novel, which puts the onus squarely on admins to move quickly. ®