Sårbarhetsflöden

Uppdateras var 300 sekund(er). Senast uppdaterad: 2026-08-06 00:47:36 CEST. Visar 10 artiklar per källa från: NVD (National Vulnerability Database), SecurityWeek Vulnerabilities, CERT-SE, CISA KEV-katalog, CISA Alerts, Microsoft MSRC, GitHub Security Advisories, Cisco PSIRT, Fortinet PSIRT, Palo Alto Networks Advisories, BleepingComputer, The Hacker News, Threatpost, Dark Reading. Tidszon: Europe/Stockholm.

Källfilter (klicka för att visa/dölja)
Vy: Kompakt visar endast titel/källa/tid.
Rensa filter
Mottaget igår
BleepingComputer

A Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]

Publicerad: 2026-08-05 23:53:26 CEST
GitHub Security Advisories

## Impact Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When an application has a server island component that forwards props directly into Vue's dynamic component resolution (``, `resolveDynamicComponent`, or…

CVE-2026-71318
Publicerad: 2026-08-05 23:21:33 CEST
GitHub Security Advisories

### Impact Nuxt matches route rules case-insensitively by default (mirroring vue-router's default `sensitive: false` routing). The fix for GHSA-mm7m-92g8-7m47 / CVE-2026-53721 lowercased the *lookup* path before matching route rules, but…

CVE-2026-53721 CVE-2026-71315
Publicerad: 2026-08-05 23:05:18 CEST
GitHub Security Advisories

## Summary The local backend relies on its configurable filename encoder to prevent remote filename data from becoming operating-system path syntax. If a local destination uses an encoding that omits `Dot`, such as `Slash`, `None`, or…

CVE-2026-71313
Publicerad: 2026-08-05 22:48:46 CEST
Dark Reading

CSS was once just about design. Now researchers warn it's powerful enough to exfiltrate data from webmail — and some vendors aren't prepared.

Publicerad: 2026-08-05 21:47:55 CEST
SecurityWeek Vulnerabilities

The chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications. The post How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones appeared first on SecurityWeek.

Publicerad: 2026-08-05 21:40:00 CEST
Dark Reading
Publicerad: 2026-08-05 21:08:36 CEST
The Hacker News

A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for…

Publicerad: 2026-08-05 20:44:31 CEST
The Hacker News

OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that…

Publicerad: 2026-08-05 20:33:47 CEST
Dark Reading

Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.

Publicerad: 2026-08-05 20:03:31 CEST
Dark Reading

Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.

Publicerad: 2026-08-05 19:57:15 CEST
BleepingComputer

A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. [...]

Publicerad: 2026-08-05 19:49:41 CEST
Cisco PSIRT

On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening…

CVE-2026-20028 CVE-2026-20124 CVE-2026-20198 CVE-2026-20200 CVE-2026-20263 CVE-2026-20267 CVE-2026-20268 CVE-2026-20269 CVE-2026-20270 CVE-2026-20271 CVE-2026-20272 CVE-2026-20273 CVE-2026-20288 CVE-2026-20289 CVE-2026-20294 CVE-2026-20301 CVE-2026-20303 CVE-2026-20304 CVE-2026-20310 CVE-2026-20311 CVE-2026-20312 CVE-2026-20313 CVSS 2026
Publicerad: 2026-08-05 18:01:06 CEST
Cisco PSIRT

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This…

CVE-2026-20198
Publicerad: 2026-08-05 18:00:00 CEST
Cisco PSIRT

A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could…

CVE-2026-20289
Publicerad: 2026-08-05 18:00:00 CEST
Cisco PSIRT

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This…

CVE-2026-20124
Publicerad: 2026-08-05 18:00:00 CEST
Cisco PSIRT

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to…

CVE-2026-20294
Publicerad: 2026-08-05 18:00:00 CEST
Cisco PSIRT

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that…

CVE-2026-20267 CVE-2026-20268 CVE-2026-20269 CVE-2026-20270 CVE-2026-20271 CVE-2026-20272 CVE-2026-20273
Publicerad: 2026-08-05 18:00:00 CEST
Cisco PSIRT

Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected…

CVE-2026-20200 CVE-2026-20288
Publicerad: 2026-08-05 18:00:00 CEST
The Hacker News

Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on…

Publicerad: 2026-08-05 17:14:05 CEST
BleepingComputer

Google has locked hundreds of Blogger websites after a false positive claimed they violated its "Malware and Similar Malicious Content" policy, with some sites deleted from the platform. [...]

Publicerad: 2026-08-05 16:59:29 CEST
SecurityWeek Vulnerabilities

Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 3) appeared first on SecurityWeek.

Publicerad: 2026-08-05 16:36:29 CEST
BleepingComputer

AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense…

Publicerad: 2026-08-05 16:01:11 CEST
SecurityWeek Vulnerabilities

CrowdStrike co-founder Dmitri Alperovitch discusses how cyber operations support kinetic warfare, signal coming conflicts, and reshape the global battlefield. The post The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict appeared first on SecurityWeek.

Publicerad: 2026-08-05 15:00:08 CEST
SecurityWeek Vulnerabilities

Palo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation. The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first on SecurityWeek.

Publicerad: 2026-08-05 14:48:49 CEST
CISA Alerts

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability This type of…

CVE-2026-63077
Publicerad: 2026-08-05 14:00:00 CEST
The Hacker News

A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel…

CVE-2026-64531 CVSS 7.8
Publicerad: 2026-08-05 13:43:27 CEST
SecurityWeek Vulnerabilities

Hackers stole personal information, medical records, and financial information from the organization’s server. The post 311,000 Impacted by Brown Health Medical Group-MA Data Breach appeared first on SecurityWeek.

Publicerad: 2026-08-05 13:35:23 CEST
SecurityWeek Vulnerabilities

The guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations. The post Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data appeared first on SecurityWeek.

Publicerad: 2026-08-05 13:11:29 CEST
The Hacker News

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software…

Publicerad: 2026-08-05 12:35:29 CEST
SecurityWeek Vulnerabilities

AI Security Institute reports Anthropic and OpenAI models going rogue against real people, organizations, and open source projects. The post AI Agents Targeted Real People and Projects During Cybersecurity Tests appeared first on SecurityWeek.

Publicerad: 2026-08-05 12:33:41 CEST
SecurityWeek Vulnerabilities

The flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek.

Publicerad: 2026-08-05 11:44:50 CEST
SecurityWeek Vulnerabilities

The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek.

Publicerad: 2026-08-05 10:56:58 CEST
Dark Reading

Unitel, Angola's dominant mobile operator, continues to recover from a cyberattack that caused outages the day of the government-owned telco's public offering.

Publicerad: 2026-08-05 10:00:00 CEST
SecurityWeek Vulnerabilities

Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption. The post Water Sector Cyberattacks Reportedly Hit at Least 12 States appeared first on SecurityWeek.

Publicerad: 2026-08-05 09:24:52 CEST
CISA KEV-katalog

JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. | Åtgärd: Apply mitigations in accordance with vendor instructions,…

CVE-2026-63077
Publicerad: 2026-08-05 02:00:00 CEST
BleepingComputer

OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people…

Publicerad: 2026-08-05 01:39:59 CEST
BleepingComputer
Publicerad: 2026-08-05 00:18:20 CEST
Mottaget denna vecka
CISA Alerts

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to modify.fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results. The following versions of Thermo Fisher Applied…

CVE-2026-17583 CVSS 3 CVSS 3.1 CVSS 3.1 CVSS 4.0
Publicerad: 2026-08-04 14:00:00 CEST
CISA Alerts

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations. The following versions of Acrisure KARR BT and DR-100 are affected: KARR BT firmware DR-100…

CVE-2026-18411 CVSS 3 CVSS 3.1 CVSS 3.1 CVSS 4.0
Publicerad: 2026-08-04 14:00:00 CEST
CISA Alerts

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication…

CVE-2026-18556 CVE-2026-34486 CVE-2026-9198
Publicerad: 2026-08-04 14:00:00 CEST
CISA KEV-katalog

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04…

CVE-2026-18556
Publicerad: 2026-08-04 02:00:00 CEST
CISA KEV-katalog

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04…

CVE-2026-34486
Publicerad: 2026-08-04 02:00:00 CEST
CISA KEV-katalog

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring…

CVE-2026-9198
Publicerad: 2026-08-04 02:00:00 CEST
Dark Reading

Researchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.

Publicerad: 2026-08-03 22:42:28 CEST
CISA Alerts

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability…

CVE-2026-18577
Publicerad: 2026-08-03 14:00:00 CEST
CISA KEV-katalog

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. | Åtgärd:…

CVE-2026-18556 CVE-2026-18577
Publicerad: 2026-08-03 02:00:00 CEST
Mottaget tidigare
CISA Alerts

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device. The following versions of MZ Automation GmbH libiec61850 are affected: libiec61850 <1.6.2…

CVE-2026-56758 CVE-2026-63550 CVE-2026-65421 CVE-2026-66349 CVE-2026-66360 CVE-2026-66364 CVE-2026-66369 CVE-2026-66720 CVSS 3 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0 CVSS 3.1 CVSS 3.1 CVSS 4.0
Publicerad: 2026-07-30 14:00:00 CEST
CISA Alerts

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific…

CVE-2026-13584 CVSS 3 CVSS 3.1 CVSS 3.1 CVSS 4.0
Publicerad: 2026-07-30 14:00:00 CEST
CISA Alerts

View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA…

CVE-2026-12927 CVSS 3 CVSS 3.1 CVSS 3.1
Publicerad: 2026-07-30 14:00:00 CEST
CISA Alerts

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all…

CVE-2026-14227 CVSS 3 CVSS 3.1 CVSS 3.1 CVSS 4.0
Publicerad: 2026-07-30 14:00:00 CEST
CISA Alerts

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources. The following versions of Toptech Systems RCU II+…

CVE-2026-12562 CVSS 3 CVSS 3.1 CVSS 3.1 CVSS 4.0
Publicerad: 2026-07-30 14:00:00 CEST
NVD (National Vulnerability Database)

Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical)

CVE-2026-17654 CVSS 7.8
Publicerad: 2026-07-30 03:16:27 CEST
NVD (National Vulnerability Database)

Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-17653 CVSS 8.3
Publicerad: 2026-07-30 03:16:27 CEST
NVD (National Vulnerability Database)

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-17652 CVSS 9.6
Publicerad: 2026-07-30 03:16:27 CEST
NVD (National Vulnerability Database)

Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-17651 CVSS 9.6
Publicerad: 2026-07-30 03:16:26 CEST
NVD (National Vulnerability Database)

Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-17650 CVSS 8.3
Publicerad: 2026-07-30 03:16:26 CEST
NVD (National Vulnerability Database)

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap…

CVE-2026-64685 CVSS 5.3
Publicerad: 2026-07-30 02:16:25 CEST
NVD (National Vulnerability Database)

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow,…

CVE-2026-62946 CVSS 5.1
Publicerad: 2026-07-30 02:16:25 CEST
NVD (National Vulnerability Database)

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.

CVE-2026-62363 CVSS 5.0
Publicerad: 2026-07-30 02:16:25 CEST
NVD (National Vulnerability Database)

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a…

CVE-2026-62343 CVSS 4.7
Publicerad: 2026-07-30 02:16:24 CEST
NVD (National Vulnerability Database)

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

CVE-2026-16339
Publicerad: 2026-07-30 01:16:29 CEST
CISA KEV-katalog

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a…

CVE-2026-20316
Publicerad: 2026-07-29 02:00:00 CEST
CISA KEV-katalog

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in…

CVE-2025-68686
Publicerad: 2026-07-27 02:00:00 CEST
CISA KEV-katalog

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the…

CVE-2026-16812
Publicerad: 2026-07-27 02:00:00 CEST
CISA KEV-katalog

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. | Åtgärd:…

CVE-2026-16232
Publicerad: 2026-07-22 02:00:00 CEST
CISA KEV-katalog

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring…

CVE-2026-50522
Publicerad: 2026-07-22 02:00:00 CEST
CERT-SE

SonicWall har publicerat säkerhetsuppdateringar gällande två sårbarheter (CVE-2026-15409 och CVE-2026-15410) i SMA1000-serien. [1] CISA har lagt till dessa sårbarheter i KEV-katalogen (Known Exploited Vulnerabilities catalog). [2]

CVE-2026-15409 CVE-2026-15410
Publicerad: 2026-07-15 12:40:00 CEST
CERT-SE

Ett koordinerat leveranskedjeangrepp har drabbat separata AsyncAPI GitHub-repon. Angripare har utnyttjat en sårbarhet i GitHub Actions. [1]

Publicerad: 2026-07-14 15:25:00 CEST
Fortinet PSIRT

CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. Revised on 2026-07-14 00:00:00

CVSS 3
Publicerad: 2026-07-14 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted requests. Revised on 2026-07-14 00:00:00

CVSS 3
Publicerad: 2026-07-14 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject…

CVSS 3
Publicerad: 2026-07-14 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's…

CVSS 3
Publicerad: 2026-07-14 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Revised on 2026-07-14 00:00:00

CVSS 3
Publicerad: 2026-07-14 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical…

CVSS 3
Publicerad: 2026-07-14 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an authenticated remote…

CVSS 3
Publicerad: 2026-07-14 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via…

CVSS 3
Publicerad: 2026-07-14 09:00:00 CEST
Fortinet PSIRT

CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute arbitrary code via spoofing…

CVSS 3
Publicerad: 2026-07-14 09:00:00 CEST
CERT-SE

Fortsätt att få våra utskick - För att ytterligare stärka Sveriges motståndskraft inom cybersäkerhet blir CERT-SE en del av Nationellt cybersäkerhetscenter den 1 juli 2026. Det innebär att vi måste inhämta nytt medgivande för fortsatt…

Publicerad: 2026-06-26 14:55:00 CEST
CERT-SE

Brandväggar är en återkommande utmaning gällande angrepp från hotaktörer. Nu senast den uppmärksammade FortiBleed-läckan, där hotaktörer utnyttjar läckta inloggningsuppgifter i stor skala. [1] Med anledning av angrepp mot brandväggar…

Publicerad: 2026-06-22 16:20:00 CEST
CERT-SE

Veckobrevet består som vanligt av nyheter och annan läsning inom cybersäkerhetssfären, bland annat om att NCSC har publicerat information om årets nationella cybersäkerhetskonferens “Svensk Cyber 2026”. CERT-SE vill även passa på att…

Publicerad: 2026-06-18 15:00:00 CEST
CERT-SE

Fortsätt att få våra utskick - För att ytterligare stärka Sveriges motståndskraft inom cybersäkerhet blir CERT-SE en del av Nationellt cybersäkerhetscenter den 1 juli 2026. Det innebär att vi måste inhämta nytt medgivande för fortsatt…

Publicerad: 2026-06-12 13:15:00 CEST
CERT-SE

CERT-SE blir den 1 juli 2026 en del av Nationellt cybersäkerhetscenter som en del i arbetet med att ytterligare stärka Sveriges motståndskraft inom cybersäkerhet. Du kan läsa mer om detta här: https://www.cert.se/2026/06/nu-samlas-…

Publicerad: 2026-06-12 12:30:00 CEST
Threatpost

Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.

Publicerad: 2022-08-30 18:00:43 CEST
Threatpost

Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.

Publicerad: 2022-08-26 18:44:27 CEST
Threatpost

Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.

Publicerad: 2022-08-24 16:17:04 CEST
Threatpost
Publicerad: 2022-08-22 15:59:06 CEST
Threatpost

Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.

Publicerad: 2022-08-19 17:25:56 CEST
Threatpost

An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.

Publicerad: 2022-08-18 16:31:38 CEST