ZeroHour

Search: “network security”

350 stories

Palo Alto Networks security advisory (AV26-905)

Canada's Cyber Centre relayed Palo Alto Networks advisories covering PAN-OS, Cloud NGFW, Prisma Access, and Prisma Browser vulnerabilities, including PAN-OS CVE-2026-0310 buffer overflow.

The Canadian Centre for Cyber Security issued advisory AV26-905, noting that as of September 10, 2026, multiple Palo Alto Networks products are affected by vulnerabilities. Affected products include Cloud NGFW on AWS and Azure, multiple PAN-OS versions, Prisma Access, and Prisma Browser prior to 151.26.5.170. The advisory references CVE-2026-0310, a PAN-OS buffer overflow via XML processing (PAN-SA-2026-0012), and the September 2026 Chromium monthly vulnerability update. Administrators are encouraged to review the vendor links and apply available updates.

SonicWall security advisory (AV26-884)

Canada's Cyber Centre issued advisory AV26-884 warning that SonicWall Network Security Manager On-Prem 4.3.0 and earlier are affected by multiple vulnerabilities.

The Canadian Centre for Cyber Security published advisory AV26-884 on September 4, 2026, flagging SonicWall Network Security Manager (NSM) On-Prem across VMware, Hyper-V, Azure, and KVM deployments, versions 4.3.0 and earlier, as affected by multiple vulnerabilities. The advisory does not list CVE identifiers, exploit details, or in-the-wild exploitation. Administrators are encouraged to review the referenced links and apply updates as they become available.

Canadian Centre for Cyber Security · 7d agoAdvisory

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Google announced Android 17 will enforce OS-wide Encrypted Client Hello with ECH GREASE, plus Certificate Transparency by default and carrier 2G disablement.

Google announced Android 17 network security protections headlined by OS-wide support for Encrypted Client Hello (ECH), with ECH GREASE enabled by default so connections to non-ECH servers look identical. Google's Jigsaw noted OkHttp has integrated ECH, letting third-party Android apps adopt the standard. The release also enforces Local Network Protection permission prompts, enables Certificate Transparency by default, and lets carriers turn off 2G by default to prevent downgrade attacks, rogue base stations, and SMS blasters. ECH was previously added to Chrome 117 and Firefox 118 at the browser level only.

The Hacker News · 18d agoAdvisory