Favicon for changeflow.com

Rakuten Symphony NGDU managing multiple radio carriers O-RAN 847 units

USPTO granted Patent US12598046B2 to Rakuten Symphony, Inc. covering a Near-Real Time Distributed Unit (NGDU) designed to manage multiple radio carriers in Open Radio Access Network (O-RAN) architectures. The patent describes technology for mapping CPRI ports connecting radio units to distributed units, enabling efficient communication management across O-RAN networks.

Routine Notice Telecommunications
Favicon for changeflow.com

Mutable Digital Asset Storage Units for Decentralised Peer-to-Peer Verification

The USPTO granted Patent US12598058B2 to British Telecommunications Public Limited Company covering methods for managing mutable digital asset storage units in a decentralised peer-to-peer storage network using cryptographic verification. The patent includes 19 claims relating to selection criteria rules, cryptographic processing functions, and version management of storage units across peer computing systems.

Routine Notice Intellectual Property
Favicon for changeflow.com

Similarity Calculation System with Homomorphic Encryption

USPTO granted patent US12598057B2 to NEC Corporation on April 7, 2026, covering a similarity calculation system using homomorphic encryption. The system enables secure distance calculations between vectors where one vector remains encrypted on a similarity calculation apparatus while the other is input from a terminal. The invention uses weighted distance tables and additive homomorphic encryption to compute ciphertext sums of element distances.

Routine Rule Intellectual Property
DHS Press Releases
Favicon for www.dhs.gov

DHS Requests Kentucky Not to Release Criminal Illegal Alien Detained for Sexual Assault

ICE has lodged a detainer requesting Kentucky authorities not release a criminal illegal alien who was arrested for sexually assaulting a teenager in his church office while working as a pastor. The individual has prior arrests for theft, forgery, and reckless driving. DHS is invoking federal immigration authority to ensure the individual remains detained pending removal proceedings.

Priority review Enforcement Immigration
Favicon for wid.cert-bund.de

MariaDB DoS Vulnerability - CVSS 6.5 Medium Severity

CERT-Bund issued advisory WID-SEC-2026-0972 disclosing a medium-severity denial-of-service vulnerability in MariaDB database systems. Affected versions include MariaDB prior to 11.4.10, 11.8.6, and 12.2.2, with a CVSS base score of 6.5. Remote authenticated attackers can exploit this vulnerability to conduct DoS attacks against affected installations on Linux, UNIX, and Windows platforms.

Priority review Guidance Cybersecurity
Favicon for wid.cert-bund.de

sudo Vulnerability Enables Privilege Escalation - CVSS 7.4

CERT-Bund issued security advisory WID-SEC-2026-0971 regarding a vulnerability in sudo (CVSS Base Score 7.4) affecting Linux and UNIX systems. The vulnerability enables local attackers to escalate privileges. Affected products include Microsoft Azure Linux azl3 and Open Source sudo. Mitigation measures are available.

Urgent Guidance Cybersecurity
Favicon for wid.cert-bund.de

OpenClaw Multiple Vulnerabilities - CVSS 5.3 (Medium)

CERT-Bund issued a security advisory identifying multiple vulnerabilities in OpenClaw, a personal AI assistant for Linux. The vulnerabilities carry a CVSS Base Score of 5.3 (medium) and allow remote anonymous attackers to manipulate data, bypass security mechanisms, or cause denial of service. Affected versions include OpenClaw prior to version 2026.4.2.

Priority review Guidance Cybersecurity
Favicon for wid.cert-bund.de

Apache Traffic Server vulnerabilities allow DoS, request smuggling

CERT-Bund published security advisory WID-SEC-2026-0978 disclosing multiple vulnerabilities (CVSS Base Score 7.5, CVSS Temporal Score 6.5) in Apache Traffic Server. The vulnerabilities affect versions prior to 9.1.13 and 10.1.2 running on Linux and UNIX systems, including Debian Linux and Fedora Linux. Remote attackers can exploit these vulnerabilities to conduct Denial of Service or HTTP Request Smuggling attacks. Mitigations are available.

Priority review Notice Cybersecurity
Favicon for wid.cert-bund.de

Keycloak vulnerabilities CVSS 8.1, affects Linux

Keycloak vulnerabilities CVSS 8.1, affects Linux

Routine Notice
Favicon for wid.cert-bund.de

OpenSSH Multiple Vulnerabilities - Remote Code Execution and Privilege Escalation

CERT-Bund issued security advisory WID-SEC-2026-0979 warning of multiple vulnerabilities in OpenSSH versions prior to 10.3. The vulnerabilities carry a CVSS Base Score of 7.5 (high) and enable remote attackers to execute arbitrary code, escalate privileges, or bypass security mechanisms on affected systems running Linux, UNIX, and Windows. Mitigation measures are available but immediate patching is required.

Urgent Guidance Cybersecurity
Favicon for wid.cert-bund.de

Checkmk Critical Vulnerabilities - Privilege Escalation and XSS

CERT-Bund issued security advisory WID-SEC-2026-0983 identifying critical vulnerabilities in Checkmk IT monitoring software. Multiple security flaws including privilege escalation and Cross-Site Scripting (XSS) were discovered affecting versions below 2.6.0b1, 2.5.0b3, 2.4.0p25, and 2.3.0p46. The vulnerabilities carry a CVSS Base Score of 9.0 (critical) and enable remote attackers to elevate privileges and execute XSS attacks on affected systems running Linux and UNIX.

Urgent Guidance Cybersecurity
Favicon for wid.cert-bund.de

OpenBSD Vulnerability Enables Unspecified Remote Attack

CERT-Bund issued a security advisory regarding a high-severity vulnerability (CVSS 7.3) in OpenBSD versions 7.7 and 7.8 that enables remote attacks by unauthenticated threat actors. The vulnerability allows remote code execution without user interaction. Organizations running affected OpenBSD systems should review and apply available mitigations immediately.

Priority review Guidance Cybersecurity
Favicon for wid.cert-bund.de

Dell PowerScale OneFS Multiple Vulnerabilities, CVSS 6.6, Privilege Escalation

CERT-Bund issued security advisory WID-SEC-2026-0984 regarding multiple vulnerabilities in Dell PowerScale OneFS with CVSS Base Score 6.6 (medium). Affected organizations running Dell PowerScale NAS platforms below versions 9.10.1.7, 9.13.0.1, and 9.13.0.2 face risks of information disclosure and privilege escalation. Mitigation measures are available.

Priority review Guidance Cybersecurity
Favicon for wid.cert-bund.de

Critical FortiClient EMS Vulnerability Enables Remote Code Execution

CERT-Bund issued a critical security advisory regarding a vulnerability in Fortinet FortiClient EMS software. The vulnerability, affecting versions prior to 7.4.7, carries a CVSS Base Score of 9.8 (critical) and enables remote anonymous attackers to execute arbitrary code without authentication. Organizations using FortiClient EMS are advised to apply available mitigations immediately or update to the patched version.

Urgent Guidance Cybersecurity
Favicon for wid.cert-bund.de

Multiple Exynos vulnerabilities allow DoS, code execution

CERT-Bund issued security advisory WID-SEC-2026-0981 regarding multiple high-severity vulnerabilities in Samsung Exynos chipsets (CVSS Base Score 8.6). Attackers can exploit these vulnerabilities to conduct denial of service attacks and potentially execute arbitrary code remotely. Affected products include Samsung Exynos mobile chipsets and processors.

Priority review Guidance Cybersecurity
Favicon for wid.cert-bund.de

Critical Cisco Smart Software Manager On-Prem Remote Code Execution Vulnerability

CERT-Bund issued a critical security advisory regarding CVE-2026-0964 affecting Cisco Smart Software Manager On-Prem (versions prior to 9-202601). The vulnerability carries a CVSS Base Score of 9.8 (critical) and enables remote, unauthenticated attackers to execute arbitrary code with administrator privileges. Organizations running the affected product are at immediate risk of complete system compromise.

Urgent Guidance Cybersecurity
Favicon for wid.cert-bund.de

Linux Kernel Multiple Vulnerabilities - CVSS 7.3 DoS Bypass

CERT-Bund issued a security advisory regarding multiple vulnerabilities in the Linux Kernel affecting Microsoft Azure Linux azl3. The vulnerabilities carry a CVSS Base Score of 7.3 (high) and CVSS Temporal Score of 6.6 (medium), with remote attack capability confirmed. An attacker could exploit these flaws to execute denial of service attacks or bypass security mechanisms. Mitigation measures are available.

Priority review Guidance Cybersecurity
Favicon for wid.cert-bund.de

Microsoft Azure critical vulnerabilities, CVSS 10.0, privilege escalation

Microsoft Azure critical vulnerabilities, CVSS 10.0, privilege escalation

Routine Notice
DHS Press Releases
Favicon for www.dhs.gov

Haitian Illegal Alien Arrested for Murder of Mother at Florida Gas Station

DHS announced that ICE assisted Fort Myers Police Department in locating and arresting Rolbert Joachim, a Haitian national with a 2022 removal order, in connection with the alleged murder of a woman at a Florida gas station on April 3, 2026. Surveillance footage reportedly showed Joachim striking the victim multiple times in the head with a hammer after allegedly smashing her car windshield. The arrest highlights ongoing immigration enforcement operations conducted jointly with local law enforcement.

Routine Notice Immigration
DHS Press Releases
Favicon for www.dhs.gov

ICE Arrests Criminal Illegal Alien Facing Kidnapping Charges

DHS announced ICE Enforcement and Removal Operations (ERO) arrested Carlos Corte-Corte, an Ecuadorian national illegally present in the US, following his arrest on local charges for kidnapping and cruelty towards a child in Patchogue, New York. The individual was taken into ICE custody after being processed for removal proceedings.

Routine Notice Immigration
Favicon for changeflow.com

System for data archival in a blockchain network and a method thereof

The USPTO granted patent US12596674B2 to National Payments Corporation of India for a blockchain data archival system. The invention enables archiver nodes and non-archiver nodes to maintain, query, and retrieve transaction data across a distributed blockchain network using specialized archival ledgers and data management modules.

Routine Notice Intellectual Property
Favicon for changeflow.com

Systolic Parallel Galois Hash Computing Device Patent Grant

USPTO granted Patent US12596530B2 to Secturion Systems, Inc. for a systolic parallel Galois hash computing device. The invention comprises multiple circuits processing data packets using multipliers and exclusive-OR gates to compute Galois hashes, applicable in FPGA and integrated circuit implementations. The patent includes 19 claims covering the hardware architecture for cryptographic hash operations in networking applications.

Routine Notice Intellectual Property
Favicon for changeflow.com

Round trip time (RTT) measurement based upon sequence number

The USPTO granted Cisco Technology, Inc. Patent US12596568B2 covering systems and methods for measuring packet round trip time (RTT) in networks using sequence numbers. The patent describes determining expected ACK sequence numbers and comparing them with received sequence numbers to calculate network latency. Cisco is the assignee with six named inventors.

Routine Rule Intellectual Property
Favicon for changeflow.com

Maintaining availability of critical information in a distributed storage network

USPTO granted patent US12596598B2 to Pure Storage, Inc. covering methods and apparatus for maintaining availability of critical information in distributed storage networks using dispersed storage error encoding. The patent protects technology for identifying, encoding, and distributing critical information across multiple storage units to ensure operational continuity.

Routine Rule Intellectual Property
Favicon for changeflow.com

Cloud controller message broker, wireless WebSocket communications

USPTO granted patent US12596597B2 to Ruckus IP Holdings LLC on April 7, 2026. The patent covers HTTP-based message broker architectures enabling communications between cloud-based controllers and network devices of wireless communications networks via WebSocket tunnel connections. The patent includes 14 claims relating to cloud controller messaging systems and gRPC proxy acknowledgments.

Routine Notice Intellectual Property
Favicon for www.ncsc.gov.uk

APT28 Exploits Routers to Enable DNS Hijacking Operations

The UK NCSC issued an advisory detailing how Russian state-sponsored actor APT28 exploits vulnerable routers by overwriting DHCP/DNS settings to redirect traffic through attacker-controlled DNS servers. These operations enable adversary-in-the-middle attacks that harvest passwords, OAuth tokens, and authentication credentials. The NCSC attributes APT28 to Russia's GRU military intelligence and provides indicators of compromise and mitigation guidance.

Urgent Guidance Cybersecurity
Favicon for www.ncsc.gov.uk

APT28 Exploits Routers for DNS Hijacking Attacks

The NCSC published an advisory exposing how Russian state cyber group APT28 compromised vulnerable internet routers to conduct DNS hijacking operations, enabling traffic interception and credential harvesting. The advisory provides mitigation guidance including protecting management interfaces, maintaining updated devices, and implementing two-step verification.

Priority review Guidance Cybersecurity
Favicon for changeflow.com

Palantir cloud resource manager cryptographic key generation

USPTO issued Patent No. US12596590B2 to Palantir Technologies Inc. covering systems and methods for managing cloud resources including cryptographic key generation for data buckets. The patent includes 20 claims and covers a method for receiving bucket creation requests, generating cryptographic keys, and provisioning data buckets in cloud platforms.

Routine Notice Intellectual Property
Favicon for www.csa.gov.sg

Secure Software Supply Chain and Development Workflows Advisory

The Cyber Security Agency of Singapore (CSA) issued an advisory on securing software supply chains and development workflows against cyber threats. The advisory highlights specific attack vectors including compromised package maintainer accounts, malicious dependency injection, and shadow IT adoption. CSA references the March 2026 Axios npm compromise and September 2025 @ctrl/tinycolor supply chain attack as examples of active threats targeting the software supply chain.

Priority review Guidance Cybersecurity
DHS Press Releases
Favicon for www.dhs.gov

ICE Arrests Criminal Illegal Aliens Including Murderers, Pedophiles, and Drug Traffickers

U.S. Immigration and Customs Enforcement announced arrests of criminal illegal aliens during Easter weekend 2026. ICE officers apprehended individuals including murderers, pedophiles, and drug traffickers in operations across multiple jurisdictions. The announcement highlights continued enforcement against non-citizens with serious criminal convictions.

Routine Enforcement Immigration
DHS Press Releases
Favicon for www.dhs.gov

ICE Requests Detention of Criminal Alien Facing Attempted Murder Charges

ICE announced it lodged an arrest detainer requesting Suffolk County, New York, not release Ruben Guanipa Ramirez, a Venezuelan national, without notifying ICE. The 26-year-old individual faces attempted murder charges for a stabbing at Gilgo Beach and was indicted on March 31, 2026.

Routine Notice Immigration