Finnish News

Police launch large operation in Espoo — authorities silent on details

Major police operation underway in Espoo on Saturday; officers decline to comment on incident.

Read more

Woman reports rape on Tallink Silja ferry — police investigate

Police launch investigation after a Finnish woman reports being raped aboard a Tallink Silja vessel.

Read more

Sanna Marin to leave parliament after record election loss

Finland's former PM Sanna Marin to step away from politics following her party's worst result in over a century.

Read more

Toddler dies after accident at private daycare in Vantaa

A young child has died after an accident at a private family daycare centre in Vantaa.

Read more

Student organization banned from University of Helsinki for one year

Helsinki student organization prohibited from student union premises for one year.

Read more

Child seriously injured in ATV accident in Pudasjärvi

A child has been seriously injured in an ATV accident in Pudasjärvi, northern Finland.

Read more

Turku stabbing — court to hear suspected attacker in custody hearing

Turku stabbing suspect held as police update on case; court to examine detention.

Read more

Raisio oat drink recalled — packaging damage may allow bacteria

Raisio recalls oat drink products due to damaged packaging that may allow bacterial contamination.

Read more

Science & Space

Artemis II Launches: Humans Return to the Moon After Half-Century

NASA's SLS rocket carried four astronauts on a 10-day lunar flyby, the first crewed Moon mission since Apollo 17.

Read more

Trump Administration Proposes Massive Budget Cuts to US Science

The 2027 budget plan would slash NSF and EPA by over 50% and NIH by 13%, alarming researchers.

Read more

Quantum Computers Could Break Encryption Sooner Than Expected

Google and Oratomic studies suggest quantum hacking threats may arrive within years, shocking the cybersecurity world.

Read more

China Plans Crewed Moon Landing by 2030, May Beat US to Surface

China's Mengzhou capsule and Long March 10 rocket aim to land astronauts before NASA's Artemis crewed return.

Read more

We May Have Glimpsed the Universe's First Stars

JWST observations of galaxy Hebe show hallmarks of Population III stars from just 400 million years after the big bang.

Read more

First 'Dirty Fireball' Star Explosion May Have Been Detected

The Einstein Probe telescope spotted an X-ray flash matching a stellar explosion theorised over 30 years ago.

Read more

Multipurpose Anti-viral Pill May Treat Colds, Norovirus, Flu and Covid

An AI platform identified a forgotten breast cancer drug that inhibits multiple respiratory and gastrointestinal viruses.

Read more

ASML EUV Chip Tech Breakthrough Could Meet AI's Monumental Demand

The company's new extreme ultraviolet lithography system creates 8nm features, enabling chips with nearly 3x more transistors.

Read more

Security

FBI Labels China-Linked Surveillance System Breach a 'Major Incident'

FBI classifies China hack as major US national security incident

Read more

EU Commission Cloud Hack Blamed on TeamPCP, 30 Entities Exposed

CERT-EU attributes EU Commission breach to TeamPCP threat group

Read more

Drift Protocol Loses $280M After North Korean Hackers Seize Security Council

DeFi platform drained $280M in sophisticated North Korea attack

Read more

TrueConf Zero-Day Exploited to Push Malicious Software Updates

TrueConf updater flaw exploited as zero-day, arbitrary code execution

Read more

Critical Cisco IMC Auth Bypass Gives Attackers Full Admin Access

Unauthenticated Cisco IMC flaw allows admin password change, CVSS 9.8

Read more

Over 14,000 F5 BIG-IP APM Instances Still Exposed to Active RCE Attacks

Shadowserver finds thousands of unpatched F5 hosts under exploit

Read more

Hims & Hers Warns of Data Breach After Zendesk Support Ticket Breach

Telehealth giant notifies users after third-party platform compromise

Read more

Die Linke German Political Party Confirms Data Stolen by Qilin Ransomware

German left-wing party confirms Qilin ransomware data theft

Read more

CVE Bulletin

Showing CVEs from the last 72 hours with CVSS 7.0+, Network attack vector, Low attack complexity. [KEV] indicates CVEs in CISA's Known Exploited Vulnerabilities catalog.

CVE-2026-35616 · April 4, 2026

Fortinet FortiClientEMS Improper Access Control RCE

A critical improper access control vulnerability in Fortinet FortiClientEMS versions 7.4.5 through 7.4.6 allows an unauthenticated remote attacker to execute arbitrary code via specially crafted requests. CVSS 9.8, Network attack vector, Low complexity, no authentication required.

GCVE · OpenCVE

CVE-2026-33105 · April 3, 2026

Microsoft Azure Kubernetes Service Privilege Escalation

A critical improper authorization vulnerability in Microsoft Azure Kubernetes Service (AKS) allows an unauthorized attacker to elevate privileges over the network. CVSS 10.0, Network attack vector, Low complexity, no authentication required.

GCVE · OpenCVE

CVE-2026-33107 · April 3, 2026

Azure Databricks SSRF Leading to Privilege Escalation

A critical server-side request forgery (SSRF) vulnerability in Azure Databricks allows an unauthorized attacker to elevate privileges over the network by leveraging the SSRF to access internal services and credentials. CVSS 10.0, Network attack vector, Low complexity, no authentication required.

GCVE · OpenCVE

CVE-2026-5281 · April 1, 2026 · [KEV]

Google Chrome Dawn Use-After-Free Zero-Day

A use-after-free vulnerability in Dawn (WebGPU implementation) in Google Chrome prior to 146.0.7680.178 allows a remote attacker who has compromised the renderer process to execute arbitrary code via a crafted HTML page. Actively exploited in the wild. Added to CISA KEV catalog on April 1, 2026.

GCVE · OpenCVE

CVE-2026-20093 · April 1, 2026

Cisco IMC Authentication Bypass

A critical authentication bypass vulnerability in Cisco Integrated Management Controller (IMC) allows an unauthenticated remote attacker to gain full Admin access by sending a specially crafted HTTP request targeting the password change functionality. CVSS 9.8, Network attack vector, Low complexity, no privileges required.

GCVE · OpenCVE

CVE-2026-34875 · April 1, 2026

Mbed TLS Buffer Overflow in Public Key Export

A buffer overflow vulnerability in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1.0.0 allows remote attackers to potentially execute arbitrary code via a buffer overflow in public key export for FFDH keys. CVSS 9.8, Network attack vector, Low complexity, no authentication required.

GCVE · OpenCVE

Self-Host Weekly

Self-Host Weekly

Euro-Office launches as OnlyOffice fork by European consortium (Nextcloud, IONOS, XWiki). Trivy vulnerability scanner security incident impacts self-hosted projects. April Fools' pranks include Home Assistant '95 and Googlarr. Jellyfin v10.11.7 critical security update. Dashy drops first major release in 2 years. Home Assistant 2026.4 adds native infrared support.

Read on selfh.st