Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

CAF Bank suspends online services due to third-party software vulnerability

CAF Bank suspended its online portal due to an undisclosed vulnerability in the connection between its portal and third-party software, which was exploited to cause suspicious account activity. The article does not provide a CVE, CVSS score, or specific version information for the affected third-party software, nor does it detail a fixed version or workaround. The bank's technology partner is responsible for the remediation.
Read Full Article →

Threat Intelligence , Privacy CAF Bank suspends online services due to third-party software vulnerability July 29, 2026 Share By SC Staff (Adobe Stock) As outlined in The Register, CAF Bank, which serves approximately 14,000 charities, temporarily suspended its online banking services to address a security vulnerability. The outage, which began on July 24, caused significant disruption for some charitable organizations, impacting their ability to manage essential operations like payroll. The Charities Aid Foundation-owned bank took the precautionary measure after detecting suspicious activity on customer accounts and identifying an undisclosed vulnerability in the connection between third-party software and its online portal. While the bank assures customers that core banking services remain unaffected and funds are secure, the online portal is unavailable until the issue is resolved by its technology partner. CEO Alison Taylor apologized for the disruption and stated that phone support is still available, with a priority on time-sensitive payments. This incident follows a previous platform migration last year that also led to customer login and transaction issues. CAF Bank held £1.45 billion in customer deposits as of the end of its 2024/25 financial year. Source: The Register SC Staff Related Threat Intelligence Tanaka emerges as top data leak broker in first half of 2026 SC Staff July 29, 2026 Following insights from The Cyber Express, the cybercrime economy is increasingly valuing stolen data as a significant commodity, with one threat actor, Tanaka, leading the data leak landscape in the first half of 2026. Vulnerability Management OpenWrt releases security updates for critical DHCPv6 flaw and other vulnerabilities SC Staff July 29, 2026 As noted by The Hacker News, OpenWrt released version 24.10.8 to address a critical DHCPv6 stack overflow vulnerability (CVE-2026-53921) and a range of other remotely triggerable flaws in its network services. Vulnerability Management JetBrains patches critical TeamCity flaw enabling unauthenticated code execution SC Staff July 29, 2026 JetBrains released security updates for TeamCity On-Premises to address a critical vulnerability, CVE-2026-63077, which carries a CVSS score of 9.8. Related Events Cybercast Better Threat Intelligence Between Public and Private Sectors On-Demand Event Virtual Conference Nationwide Cybersecurity Summit 2025: Safeguarding America’s Digital Future On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Data Mining Deauthentication Attack Deepfake Dictionary Attack Distributed Scans Drive-by Download Dumpster Diving Google Hacking Identity Theft You can skip this ad in 5 seconds

Share this article