π ADVISORIES
-
U.S. Coast Guard Creates Office for Maritime Cybersecurity Policy
The U.S. Coast Guard has established a central office for maritime cybersecurity policy.- The office covers U.S. ports, vessels, maritime facilities, and the Marine Transportation System.
- It will oversee cybersecurity policy for maritime information and operational technology.
- CG-MCP will develop domestic policy, contribute to international standards, and coordinate compliance and enforcement.
- The Marine Transportation System includes roughly 360 commercial sea and river ports.
- The office will act as the Coast Guardβs primary cybersecurity liaison with industry and government agencies.
π Coverage: securityweek.com Β· π via SecurityWeek
-
OpenAI Limits Astra Cyber Access Over Potential Critical Capabilities
OpenAI says its upcoming Astra model may have critical cybersecurity capabilities.- OpenAIβs upcoming Astra model is affected; advanced cyber access will initially be limited to select Daybreak Blue partners.
- Astra may identify and develop functional zero-day exploits against hardened real-world critical systems.
- The model may execute end-to-end cyberattacks against hardened targets with little or no human guidance.
- Astra can chain multiple exploits to penetrate targets more deeply; WIRED reports it scored 100% on ExploitBench.
π Source: openai.com Β· π Coverage: wired.com Β· π via @metacurity@infosec.exchange
π CVEs & KEV
-
CVE-2026-84304 β grpc grpc-go β CVSS 8.7 β gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame FragmentationgRPC...
-
CVE-2026-83551 β AWS sagemaker-python-sdk β CVSS 8.5 β Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@r...
-
CVE-2026-19953 β CPANSec URI β CVSS 6.5 β URI versions before 5.36 for Perl encode non-NFC host names to non-standard p...
-
CVE-2026-84303 β grpc grpc-go β CVSS 6.3 β gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC ...