Every story tagged Network Security, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.
155 stories · open in the command center
The UK and Germany are deepening cyber cooperation to share intelligence and coordinate disruption of Russian-backed attacks, signaling that state-sponsored threats to critical infrastructure, businesses, and public trust are becoming a more central business risk. For CIOs and technology leaders, the strategic takeaway is that geopolitics is increasingly shaping security posture: IT organizations should expect greater emphasis on cross-border threat intelligence, resilience, and rapid response, even though this pact currently lacks clear operational detail, funding, or agency ownership.
TP-Link is facing a growing mix of regulatory, legal, and national-security pressure in the U.S., including an FCC router ban that is blocking sale of newer models and coordinated state lawsuits alleging deceptive claims about its China ties and security posture. For CIOs and technology leaders, this highlights how vendor-origin risk, supply-chain traceability, and geopolitical scrutiny can quickly turn networking hardware into a procurement, compliance, and business-continuity issue that affects both refresh planning and enterprise security posture.
A multi-state lawsuit against TP-Link highlights growing regulatory and national-security scrutiny of widely deployed networking gear, with allegations that the company overstated security protections and understated China-linked supply-chain and data-access risks. For CIOs, the business impact is immediate: vendors in critical network infrastructure may face legal, reputational, and procurement disruption, while IT organizations will need stronger third-party risk management, device inventory, and assurance processes for routers and smart-home equipment. Strategic takeaway: treat network hardware as a supply-chain and sovereignty issue, not just a price/performance decision.
Authentication bypass vulnerabilities exist in the web management interface of AOS-S. Successful exploitation could allow an unauthenticated remote attacker to gain unauthorized access to the affected system.
A format string vulnerability in an affected service interface of HPE Networking ClearPass Policy Manager could allow an unauthenticated remote attacker to corrupt process memory. Successful exploitation could allow an attacker to execute arbitrary code.
NetBSD’s racoon2 IKE daemon was materially hardened with fixes for NAT traversal, IPv6, packet fragmentation, and configuration handling, making it more reliable for IPsec/L2TP VPN services behind NAT and with modern clients such as Windows, iOS, and Android. For IT organizations, the strategic value is lower operational risk and fewer brittle workarounds: the daemon now behaves more predictably, supports IPv6 by default, and is backed by automated tests that reduce regression risk in security infrastructure.
This project shows that effective network-level ad blocking can run on extremely low-cost hardware by shifting blocklists from RAM into flash as compact hashes, reducing memory requirements and eliminating the need for PSRAM. For CIOs and technology leaders, the strategic takeaway is that edge appliances and embedded devices can now deliver practical security and filtering services at materially lower cost, power, and operational complexity—an example of how software architecture choices can unlock cheaper infrastructure without sacrificing capability.
HPE Networking is positioning inline segmentation in Juniper switches as a lower-complexity way to implement Zero Trust by using group policy tags to segment LAN traffic without the overhead of VXLAN or similar architectures. For CIOs, the business case is faster, less disruptive security modernization that can reduce risk and operational complexity; for IT organizations, it offers an incremental path to stronger segmentation without a wholesale network redesign.
This threat shows how exposed IoT fleets can be converted into covert proxy infrastructure, creating operational risk, potential compliance exposure, and reputational damage for organizations that lack strong device governance. For CIOs and technology leaders, it underscores the need to treat IoT as part of the core attack surface, with tighter patching, segmentation, monitoring, and third-party traffic controls to detect abuse that can hide inside legitimate public services like STUN.
This article highlights the diversity and creativity of user-agent strings seen in honeypot traffic, showing how scanners often advertise their intent, include contact details, reuse public lists, or even attempt parser exploits like Shellshock. For CIOs and technology leaders, the business impact is that simple web telemetry can reveal active reconnaissance, attacker tooling, and weak hygiene in external-facing environments—making user-agent analysis a low-cost source of threat intelligence that can improve detection, prioritization, and exposure management. IT organizations should treat these strings as an operational signal to strengthen logging, enrich SIEM detections, and monitor for repeated or unusual scanning patterns that may precede exploitation.
A critical missing-authentication flaw in the ait.core.server telemetry and command broker (ait-server) could allow attackers to access sensitive command and telemetry functions without credentials, creating a high-risk path to unauthorized control, disruption, or broader system compromise. For CIOs and technology leaders, this is an urgent operational and governance issue: any exposed instance should be treated as a potential entry point, requiring immediate visibility into where the software is deployed, accelerated remediation, and tighter segmentation around affected systems.
A high-severity vulnerability in Next.js image optimization affects versions 16.0.0 through 16.3.8, putting internet-facing applications at risk of operational disruption and potential abuse of a core web delivery feature. For CIOs and technology leaders, this is both a security and availability issue: organizations should treat their Next.js estate as part of the critical application stack, prioritize remediation, and verify that dependent customer-facing services can be upgraded without breaking performance or release schedules.
Cloudflare’s new OHTTP Gateway lowers the operational and latency barriers to deploying Oblivious HTTP, making privacy-preserving application traffic more practical for enterprises and digital products. For CIOs and IT leaders, this expands the ability to reduce exposure of user IPs and request metadata while simplifying compliance and privacy-by-design initiatives through a managed edge service. Strategically, it gives organizations a clearer path to adopt emerging privacy infrastructure without building and scaling their own gateway layer.
A federal court blocked Utah’s anti-VPN age-verification law, finding that it effectively demands perfect geolocation that current technology cannot deliver. For CIOs and technology leaders, the ruling is a reminder that regulatory requirements built on technically impossible assumptions can create broad compliance, privacy, and operational risk—potentially forcing platforms to over-verify all users or restrict access entirely. IT organizations should expect continued pressure from state-level internet regulation and plan for stronger coordination between engineering, legal, privacy, and policy teams when deploying geolocation or identity controls.
Researchers have uncovered Linux backdoors that closely mimic legitimate Korean and Taiwanese mail security appliances, making them exceptionally difficult to detect and increasing the risk of long-term stealth compromise in enterprises, telecoms, and public-sector environments. For CIOs and technology leaders, this is a reminder that edge appliances and Linux-based security controls are now high-value attack surfaces, and IT organizations need stronger integrity monitoring, behavioral baselining, and threat hunting beyond signature-based defenses.
RUSI warns that the EU’s inconsistent approach to foreign technology procurement is leaving member states exposed to security, operational, and supply-chain risks from Chinese vendors such as Huawei and ZTE. For CIOs and technology leaders, the strategic implication is that vendor risk can no longer be treated as a country-by-country compliance issue: organizations operating across the EU may soon face tighter, more harmonized scrutiny, potential forced replacement timelines, and higher costs as governments move to reduce dependency on high-risk suppliers. IT leaders should prepare for a shift toward security-led sourcing decisions, with greater pressure to diversify vendors and reassess telecom and critical infrastructure dependencies.
`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte residue exits the loop with that tail unexamined; the residue is not negative, so the function returns `NX_SUCCESS`. Its zero-length rejection never sees those bytes. Every consumer then re-walks the same area, reading a two-byte option header at the residue and subtracting `nx_icmpv6_option_length << 3` with no zero check and no remaining-length check. Three outcomes follow, selected by bytes the attacker controls. **Zero length byte.** The walker subtracts zero and advances zero. All four handlers loop forever — `_nx_icmpv6_process_ra` (`nx_icmpv6_process_ra.c:245, :528`), `_nx_icmpv6_process_ns` (`:251, :329`), `_nx_icmpv6_process_na` (`:147, :156`) and `_nx_icmpv6_process_redirect` (`:247, :350`). The walk runs in the IP thread, which is the highest-priority thread and does not yield inside the loop, so...
Any host on the LAN can send two mDNS records and make the responder write past the end of its transmit packet. The string table stores each name in a slot rounded up to a multiple of four: ```c /* addons/mdns/nxd_mdns.c:11436, 11443, 11447 */ memory_len = ((memory_len & 0xFFFFFFFC) + 8) & 0xFFFFFFFF; ... len = *((USHORT*)(p - 2)); /* slot size, not string length */ if ((len == memory_len) && ... _nx_mdns_name_match(start, memory_ptr, memory_size) ...) ``` The lookup that decides whether an incoming name is already stored compares the rounded slot size, so names of 12, 13, 14 and 15 characters share one bucket. A second name in the bucket is answered with the pointer to the first, and the record then carries a string up to three bytes longer than the length the caller accounted for. `_nx_mdns_packet_rr_add` (nxd_mdns.c:8911) sizes its only bound check from that stale length, and `_nx_mdns_name_string_encode` writes the real string....
hey, `_nx_snmp_utility_object_id_get` in the NetX Duo SNMP addon does not validate the claimed OID data length against the actual buffer size when the OID uses BER multibyte length encoding, so a remote attacker can send a crafted SNMP packet with a multibyte OID length larger than the available buffer, causing the parser to read past the packet buffer boundary into adjacent heap memory. the OOB bytes are decoded as OID component values and written into the agents internal OID string buffer, corrupting agent state. on systems with memory protection the OOB read poses the risk of crashing the SNMP agent thread, causing denial of service. on bare metal embedded systems without memory protection the read silently succeeds and corrupts the agents internal state with heap data.
Buffer overflow vulnerability exists in the affected interface of HPE Networking Instant ON that could allow an unauthenticated remote attacker to run arbitrary code on the underlying host. Successful exploitation could allow an attacker to execute arbitrary code as a privileged user on the underlying operating system.
Citrix disclosed two critical NetScaler zero-days affecting default configurations of ADC and Gateway products, with evidence of active exploitation before patches were released. For CIOs and technology leaders, this is a reminder that internet-facing infrastructure can become a fast-moving enterprise-wide risk, making rapid patching, emergency isolation, and stronger vulnerability intelligence critical to protecting network access and business continuity.
Microsoft says a previously unseen malware framework, NeedyMantis, is being used by a China-based threat actor to maintain long-term, stealthy access after initial compromise, with targeting that includes telecoms, universities, healthcare nonprofits, intergovernmental organizations, and government contractors. For CIOs and technology leaders, the key implication is that perimeter defenses and initial intrusion detection are no longer enough; IT teams need stronger post-breach visibility, endpoint and identity monitoring, and controls that can detect DLL sideloading, encrypted loaders, and suspicious remote command-and-control activity. The business risk is prolonged dwell time and potential espionage or deeper lateral movement into sensitive systems, which can increase operational disruption, data exposure, and recovery costs.
An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access to the AP to execute arbitrary shell commands on the underlying operating system.
Citrix has disclosed eight NetScaler vulnerabilities, including three critical flaws already being actively exploited, creating immediate risk of remote code execution, denial of service, and security-control bypass. For CIOs and technology leaders, the business impact is potential outage, exposure of externally facing access infrastructure, and emergency change management pressure, making asset visibility, rapid remediation, and compensating controls a board-level priority.
Citrix has confirmed that two critical, actively exploited NetScaler zero-day remote code execution vulnerabilities put internet-facing ADC and Gateway deployments at immediate risk of compromise. For CIOs and IT leaders, this is a high-priority operational issue that can lead to unauthorized access, service disruption, and emergency response costs, making rapid patching, exposure assessment, and mitigation planning essential.
Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec tracks the HTTP method of each still-unanswered pipelined request; the first 32 entries are bit-packed into a single long, but every additional entry is appended to methodOverflowQueue, an ArrayDeque with no size limit and no rejection path. A remote, unauthenticated attacker who pipelines HTTP/1.1 requests on a single connection while withholding reads on their own end (preventing responses from being flushed) can grow this queue without bound, causing unbounded heap growth and denial of service. Affected versions are 4.2.0.Final through 4.2.17.Final and all releases up to and including 4.1.137.Final; the issue is fixed in 4.2.18.Final and 4.1.138.Final.
Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled resource consumption vulnerability in the QPACK encoder-stream instruction decoder (QpackEncoderHandler, installed on the peer-initiated unidirectional QPACK encoder stream, type 0x02). The handler accepts an attacker-declared string-literal length of up to Integer.MAX_VALUE (~2 GiB) for the Name Length and Value Length fields of the "Insert With Literal Name" instruction (RFC 9204 §4.3.3), with no per-instruction or per-literal length cap and no cumulation-size limit; the existing HTTP/3 limits (maxHeaderListSize, maxUnknownFramePayloadLength, DEFAULT_MAX_FIELD_SECTION_SIZE) are not applied to this handler. A remote, unauthenticated peer with an established HTTP/3 connection to a default Netty HTTP/3 server can declare a very large literal length and then trickle fewer bytes than declared, causing the ByteToMessageDecoder MERGE cumulator to retain and grow the per-con...
A critical CVE in the D-Link DIR-895L firmware (CVSS 9.9) indicates a high-risk vulnerability in the router’s tunnel_set_params function that could expose network infrastructure to compromise. For CIOs and technology leaders, this underscores the operational and security risk of relying on vulnerable edge devices, where exploitation could enable unauthorized access, traffic interception, or broader network disruption. IT organizations should treat affected routers as urgent remediation items, prioritizing patching, exposure reduction, and segmentation controls to limit blast radius.
The UK’s creation of No. III Space Effects Squadron signals that satellite protection is becoming a core national resilience and security capability, not just a military niche. For CIOs and technology leaders, the broader implication is that critical services—from navigation and telecom to grid synchronization and emergency response—are increasingly dependent on contested space assets, making cyber, spectrum, and infrastructure resilience strategic priorities for IT organizations.
In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid unneeded actions on subflow reset Once in a blue moon, the mptcp receive path can recursively call mptcp_data_ready() via state change under unlucky error conditions, and then try to hold the data lock again. Break the recursion loop explicitly checking for the exceptional condition. Add a new flag instead of using an existing one like 'closing', to exit early in subflow_state_change(), and explicitly flush the RX queue at reset time. This avoids unneeded processing to check for available data -- calling get_mapping_status() and more on a dying subflow -- but also in error reporting and worker scheduling. Note that we must consume the currently peeked skb before invoking mptcp_dss_corruption to avoid consuming it again after the eventual reset has freed it.