Tufin has announced the availability of Tufin Orchestration Suite (TOS) 5.3, helping enterprises further simplify security operations and maintain consistent control across increasingly complex multi-vendor, hybrid environments. As enterprise security environments continue to expand across cloud, firewalls, SASE, SD-WAN, microsegmentation, and distributed infrastructure, organizations increasingly

Tufin has announced the release of Tufin Orchestration Suite (TOS) 5.3, an update designed to enhance security operations and maintain consistent control across complex, multi-vendor hybrid environments. The new version expands Tufin's Unified Control Plane with additional integrations, AI-powered intelligence, and automation capabilities.
The company states that the update aims to address the challenges enterprises face in governing connectivity across a growing array of vendor-specific tools, including cloud, firewalls, SASE, SD-WAN, and microsegmentation. Research cited by Tufin indicates that nearly half of organizations manage more than 20 security tools, contributing to fragmented governance and slower policy changes.
A key component of the release is the new AI-powered Segmentation Intelligence solution. This tool continuously analyzes an organization's segmentation policies to understand their intent, identify policy gaps and drift, and recommend corrective actions. Tufin asserts that this solution provides continuous visibility, replacing periodic audits and manual checks to help security teams proactively address potential flaws or neglected coverage areas.
TOS 5.3 also introduces several new capabilities to expand its multi-vendor network security platform. These include enhanced AWS Firewall Support, which provides native topology, policy, and compliance visibility for AWS-native firewall environments, extending governance deeper into cloud infrastructure.
The update also offers expanded Palo Alto Strata Cloud Manager Support, enabling end-to-end automation of IP-based access requests from initiation through provisioning. For VMware environments, the release adds NSX-T Access Request Automation, which automates access requests for Distributed Firewall rules, even in environments with incomplete network topology visibility.
Furthermore, Tufin has included Cisco Meraki Provisioning Support, extending automated policy provisioning to Cisco Meraki deployments. This aims to broaden consistent policy management across branch and distributed enterprise networks.
Tufin emphasizes that these updates are intended to reduce manual effort, accelerate policy changes, and apply consistent governance across heterogeneous environments, all powered by its Dynamic Network Connectivity Graph. The company's goal is to provide an intelligent control layer for understanding connectivity, governing change, and maintaining continuous security posture control across various environments, irrespective of the vendor.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed