## Summary There is a medium-severity cross-provider reference vulnerability in Traefik's Kubernetes CRD provider. The `crossProviderNamespaces` allowlist is enforced for HTTP `serversTransport` references but was not enforced for…
Publicerad: 2026-08-05 23:53:35 CESTA Canadian man pleaded guilty today to his role in accessing company accounts at cloud storage provider Snowflake and stealing data from at least 165 organizations in a scheme to extort millions of dollars from victims. [...]
Publicerad: 2026-08-05 23:53:26 CEST## Summary There is a medium-severity namespace-confusion vulnerability in Traefik's Kubernetes Gateway API provider. When resolving `HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef`, Traefik used the backend Service namespace…
Publicerad: 2026-08-05 23:49:19 CEST### Impact The internal island renderer endpoint (`/__nuxt_island/...`) decodes and hashes attacker-controlled request input before it validates the URL-resident hash. An unauthenticated `POST /__nuxt_island/_.json` with a large JSON body…
Publicerad: 2026-08-05 23:43:03 CEST## Impact Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When `vue.runtimeCompiler: true` is enabled (off by default) and the application has a server island component that forwards props into Vue's dynamic component…
Publicerad: 2026-08-05 23:29:55 CEST### Impact Nuxt DevTools (development mode only) exposes a bidirectional RPC channel over the Vite HMR WebSocket via the `nuxt:devtools:rpc` plugin. On affected versions the channel has no authentication: any client that can reach the Vite…
Publicerad: 2026-08-05 23:27:39 CEST## Impact Nuxt server islands accept props via the `/__nuxt_island/` endpoint. When an application has a server island component that forwards props directly into Vue's dynamic component resolution (``, `resolveDynamicComponent`, or…
Publicerad: 2026-08-05 23:21:33 CEST### Impact When a page is covered by `routeRules` `cache` / `swr` / `isr`, Nuxt enables runtime payload extraction and serves `//_payload.json`. On affected versions the renderer stored the SSR payload in the shared `cache:nuxt:payload`…
Publicerad: 2026-08-05 23:14:33 CEST### Impact Nuxt matches route rules case-insensitively by default (mirroring vue-router's default `sensitive: false` routing). The fix for GHSA-mm7m-92g8-7m47 / CVE-2026-53721 lowercased the *lookup* path before matching route rules, but…
Publicerad: 2026-08-05 23:05:18 CEST### Impact An unauthenticated attacker can crash a Nuxt server that renders any island / server component containing a `v-for` over a prop (for example `v-for="n in count"` or a ``). Because the island URL hash is a non-secret digest of…
Publicerad: 2026-08-05 22:59:04 CEST## Summary The local backend relies on its configurable filename encoder to prevent remote filename data from becoming operating-system path syntax. If a local destination uses an encoding that omits `Dot`, such as `Slash`, `None`, or…
Publicerad: 2026-08-05 22:48:46 CESTHackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. [...]
Publicerad: 2026-08-05 21:55:25 CESTThe chain involved the exploitation of several vulnerabilities in the Samsung Members and Samsung Account applications. The post How a $50,000 Exploit Chain Turned Bixby Against Samsung Phones appeared first on SecurityWeek.
Publicerad: 2026-08-05 21:40:00 CESTResearchers are calling attention to the risks inherent in automated network device provisioning, using a world-leading device manufacturer as a case study.
Publicerad: 2026-08-05 21:08:36 CESTA macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for…
Publicerad: 2026-08-05 20:44:31 CESTOpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that…
Publicerad: 2026-08-05 20:33:47 CESTGoogle has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.
Publicerad: 2026-08-05 20:03:31 CESTOrganized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.
Publicerad: 2026-08-05 19:57:15 CESTA phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. [...]
Publicerad: 2026-08-05 19:49:41 CESTOn August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening…
Publicerad: 2026-08-05 18:01:06 CESTA vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due…
Publicerad: 2026-08-05 18:00:00 CESTA vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This…
Publicerad: 2026-08-05 18:00:00 CESTA vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could…
Publicerad: 2026-08-05 18:00:00 CESTA vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is…
Publicerad: 2026-08-05 18:00:00 CESTA vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This…
Publicerad: 2026-08-05 18:00:00 CESTA vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of…
Publicerad: 2026-08-05 18:00:00 CESTA vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to…
Publicerad: 2026-08-05 18:00:00 CESTAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that…
Publicerad: 2026-08-05 18:00:00 CESTMultiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected…
Publicerad: 2026-08-05 18:00:00 CESTThe U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. [...]
Publicerad: 2026-08-05 17:51:33 CESTCybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude,…
Publicerad: 2026-08-05 17:36:03 CESTTwo security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on…
Publicerad: 2026-08-05 17:14:05 CESTGoogle has locked hundreds of Blogger websites after a false positive claimed they violated its "Malware and Similar Malicious Content" policy, with some sites deleted from the platform. [...]
Publicerad: 2026-08-05 16:59:29 CESTMany companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 3) appeared first on SecurityWeek.
Publicerad: 2026-08-05 16:36:29 CESTHashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam's console that hands…
Publicerad: 2026-08-05 16:27:30 CESTAI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense…
Publicerad: 2026-08-05 16:01:11 CESTCybersecurity researchers have flagged an evolution of the EtherHiding blockchain-based command-and-control (C2) technique that conceals the C2 server IP address inside a made-up destination address of a completely empty Ethereum transfer.…
Publicerad: 2026-08-05 15:41:27 CESTCrowdStrike co-founder Dmitri Alperovitch discusses how cyber operations support kinetic warfare, signal coming conflicts, and reshape the global battlefield. The post The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict appeared first on SecurityWeek.
Publicerad: 2026-08-05 15:00:08 CESTPalo Alto Networks researchers have demonstrated attacks against Google’s synced passkey implementation. The post New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts appeared first on SecurityWeek.
Publicerad: 2026-08-05 14:48:49 CESTCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability This type of…
Publicerad: 2026-08-05 14:00:00 CESTA memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel…
Publicerad: 2026-08-05 13:43:27 CESTKali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and…
Publicerad: 2026-08-05 13:43:19 CESTHackers stole personal information, medical records, and financial information from the organization’s server. The post 311,000 Impacted by Brown Health Medical Group-MA Data Breach appeared first on SecurityWeek.
Publicerad: 2026-08-05 13:35:23 CESTThe guidelines are the work of the recently launched Open Secure AI Alliance, which now includes 120 organizations. The post Cybersecurity Alliance Drafts SAFE Guidelines for Sharing AI Incident Data appeared first on SecurityWeek.
Publicerad: 2026-08-05 13:11:29 CESTAn unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup…
Publicerad: 2026-08-05 13:04:23 CESTGitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software…
Publicerad: 2026-08-05 12:35:29 CESTAI Security Institute reports Anthropic and OpenAI models going rogue against real people, organizations, and open source projects. The post AI Agents Targeted Real People and Projects During Cybersecurity Tests appeared first on SecurityWeek.
Publicerad: 2026-08-05 12:33:41 CESTThe flaws can be exploited for remote code execution, authentication bypass, and EncryptInterceptor bypass. The post CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities appeared first on SecurityWeek.
Publicerad: 2026-08-05 11:44:50 CESTEn ny självreplikerande skadlig kod, Chaindrop, har blivit uppmärksammat av bland annat StepSecurity [1]. Chaindrop påverkar över 400 paket i JavaScript ekosystemet.
Publicerad: 2026-08-05 11:00:00 CESTThe malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack appeared first on SecurityWeek.
Publicerad: 2026-08-05 10:56:58 CESTUnitel, Angola's dominant mobile operator, continues to recover from a cyberattack that caused outages the day of the government-owned telco's public offering.
Publicerad: 2026-08-05 10:00:00 CESTGeorgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption. The post Water Sector Cyberattacks Reportedly Hit at Least 12 States appeared first on SecurityWeek.
Publicerad: 2026-08-05 09:24:52 CESTJetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol. | Åtgärd: Apply mitigations in accordance with vendor instructions,…
Publicerad: 2026-08-05 02:00:00 CESTOpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people…
Publicerad: 2026-08-05 01:39:59 CESTTP-Link has patched 15 vulnerabilities in the zero-touch provisioning (ZTP) mechanism of its Omada network devices that could be chained with previously disclosed flaws to achieve remote code execution (RCE). [...]
Publicerad: 2026-08-05 00:18:20 CESTThe Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts. [...]
Publicerad: 2026-08-04 23:45:36 CESTA new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. [...]
Publicerad: 2026-08-04 21:03:09 CESTThe attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks.
Publicerad: 2026-08-04 20:37:35 CESTA Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users' meeting information and potentially join calls.
Publicerad: 2026-08-04 15:00:00 CESTView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to modify.fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results. The following versions of Thermo Fisher Applied…
Publicerad: 2026-08-04 14:00:00 CESTView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations. The following versions of Acrisure KARR BT and DR-100 are affected: KARR BT firmware DR-100…
Publicerad: 2026-08-04 14:00:00 CESTCISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication…
Publicerad: 2026-08-04 14:00:00 CESTNewer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.
Publicerad: 2026-08-04 09:00:00 CESTN-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04…
Publicerad: 2026-08-04 02:00:00 CESTApache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04…
Publicerad: 2026-08-04 02:00:00 CESTLangflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring…
Publicerad: 2026-08-04 02:00:00 CESTOver the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.
Publicerad: 2026-08-03 23:21:11 CESTResearchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.
Publicerad: 2026-08-03 22:42:28 CESTAcknowledgement Updated
Publicerad: 2026-08-03 16:00:00 CESTAcknowledgement Updated
Publicerad: 2026-08-03 16:00:00 CESTAcknowledgement Updated
Publicerad: 2026-08-03 16:00:00 CESTCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability…
Publicerad: 2026-08-03 14:00:00 CESTN-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. | Åtgärd:…
Publicerad: 2026-08-03 02:00:00 CESTUpdated an acknowledgement. This is an informational change only.
Publicerad: 2026-07-30 16:00:00 CESTAcknowledgement Updated
Publicerad: 2026-07-30 16:00:00 CESTUpdated an acknowledgement. This is an informational change only.
Publicerad: 2026-07-30 16:00:00 CESTImproper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Publicerad: 2026-07-30 16:00:00 CESTInformational Change. CVE ID stays the same.
Publicerad: 2026-07-30 16:00:00 CESTImproper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Publicerad: 2026-07-30 16:00:00 CESTView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device. The following versions of MZ Automation GmbH libiec61850 are affected: libiec61850 <1.6.2…
Publicerad: 2026-07-30 14:00:00 CESTView CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific…
Publicerad: 2026-07-30 14:00:00 CESTView CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a state-of-the-art SCADA…
Publicerad: 2026-07-30 14:00:00 CESTView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all…
Publicerad: 2026-07-30 14:00:00 CESTView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources. The following versions of Toptech Systems RCU II+…
Publicerad: 2026-07-30 14:00:00 CESTRace in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical)
Publicerad: 2026-07-30 03:16:27 CESTUse after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Publicerad: 2026-07-30 03:16:27 CESTUse after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Publicerad: 2026-07-30 03:16:27 CESTInsufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Publicerad: 2026-07-30 03:16:26 CESTUse after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Publicerad: 2026-07-30 03:16:26 CESTImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap…
Publicerad: 2026-07-30 02:16:25 CESTImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow,…
Publicerad: 2026-07-30 02:16:25 CESTImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.
Publicerad: 2026-07-30 02:16:25 CESTImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a…
Publicerad: 2026-07-30 02:16:24 CESTRejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Publicerad: 2026-07-30 01:16:29 CESTCisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a…
Publicerad: 2026-07-29 02:00:00 CESTUpdated an acknowledgement. This is an informational change only.
Publicerad: 2026-07-28 16:00:00 CESTFortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency mechanism observed in…
Publicerad: 2026-07-27 02:00:00 CESTArista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the…
Publicerad: 2026-07-27 02:00:00 CESTCheck Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. | Åtgärd:…
Publicerad: 2026-07-22 02:00:00 CESTMicrosoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring…
Publicerad: 2026-07-22 02:00:00 CESTFlera leverantörer har släppt sina månatliga säkerhetsuppdateringar för juli. Nedan finns en sammanställning av de säkerhetsuppdateringar som Cisco, Microsoft, SAP, Ivanti, Fortinet och Adobe har publicerat inför och i samband med…
Publicerad: 2026-07-15 13:30:00 CESTSonicWall har publicerat säkerhetsuppdateringar gällande två sårbarheter (CVE-2026-15409 och CVE-2026-15410) i SMA1000-serien. [1] CISA har lagt till dessa sårbarheter i KEV-katalogen (Known Exploited Vulnerabilities catalog). [2]
Publicerad: 2026-07-15 12:40:00 CESTEtt koordinerat leveranskedjeangrepp har drabbat separata AsyncAPI GitHub-repon. Angripare har utnyttjat en sårbarhet i GitHub Actions. [1]
Publicerad: 2026-07-14 15:25:00 CESTCVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via submitting a specially crafted request. Revised on 2026-07-14 00:00:00
Publicerad: 2026-07-14 09:00:00 CESTCVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted requests. Revised on 2026-07-14 00:00:00
Publicerad: 2026-07-14 09:00:00 CESTCVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject…
Publicerad: 2026-07-14 09:00:00 CESTCVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's…
Publicerad: 2026-07-14 09:00:00 CESTCVSSv3 Score: 6.7 An Improper Certificate Validation vulnerability [CWE-295] in FortiClient EMS may allow a remote unauthenticated attacker to impersonate an AD Connector via a valid API Key. Revised on 2026-07-14 00:00:00
Publicerad: 2026-07-14 09:00:00 CESTCVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Revised on 2026-07-14 00:00:00
Publicerad: 2026-07-14 09:00:00 CESTCVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated attacker with physical…
Publicerad: 2026-07-14 09:00:00 CESTCVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an authenticated remote…
Publicerad: 2026-07-14 09:00:00 CESTCVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands via…
Publicerad: 2026-07-14 09:00:00 CESTCVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute arbitrary code via spoofing…
Publicerad: 2026-07-14 09:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-07-08 22:30:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-07-08 18:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-07-08 18:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-07-08 18:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-07-08 18:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-07-08 18:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-07-08 18:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-07-08 18:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-07-08 18:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-07-08 18:00:00 CESTFortsätt att få våra utskick - För att ytterligare stärka Sveriges motståndskraft inom cybersäkerhet blir CERT-SE en del av Nationellt cybersäkerhetscenter den 1 juli 2026. Det innebär att vi måste inhämta nytt medgivande för fortsatt…
Publicerad: 2026-06-26 14:55:00 CESTBrandväggar är en återkommande utmaning gällande angrepp från hotaktörer. Nu senast den uppmärksammade FortiBleed-läckan, där hotaktörer utnyttjar läckta inloggningsuppgifter i stor skala. [1] Med anledning av angrepp mot brandväggar…
Publicerad: 2026-06-22 16:20:00 CESTVeckobrevet består som vanligt av nyheter och annan läsning inom cybersäkerhetssfären, bland annat om att NCSC har publicerat information om årets nationella cybersäkerhetskonferens “Svensk Cyber 2026”. CERT-SE vill även passa på att…
Publicerad: 2026-06-18 15:00:00 CESTFortsätt att få våra utskick - För att ytterligare stärka Sveriges motståndskraft inom cybersäkerhet blir CERT-SE en del av Nationellt cybersäkerhetscenter den 1 juli 2026. Det innebär att vi måste inhämta nytt medgivande för fortsatt…
Publicerad: 2026-06-12 13:15:00 CESTCERT-SE blir den 1 juli 2026 en del av Nationellt cybersäkerhetscenter som en del i arbetet med att ytterligare stärka Sveriges motståndskraft inom cybersäkerhet. Du kan läsa mer om detta här: https://www.cert.se/2026/06/nu-samlas-…
Publicerad: 2026-06-12 12:30:00 CESTDen 1 juli övergår cyberverksamheten från Myndigheten för civilt försvar (MCF) till Nationellt cybersäkerhetscenter (NCSC) vid Försvarets radioanstalt (FRA), enligt regeringens beslut den 20 november 2025. Syftet är att stärka Sveriges cybersäkerhet.
Publicerad: 2026-06-12 12:00:00 CEST2.5 million people were affected, in a breach that could spell more trouble down the line.
Publicerad: 2022-08-31 14:57:48 CESTResearchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
Publicerad: 2022-08-30 18:00:43 CESTOver 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
Publicerad: 2022-08-29 16:56:19 CESTLockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
Publicerad: 2022-08-26 18:44:27 CESTTens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Publicerad: 2022-08-25 20:47:15 CESTTwitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
Publicerad: 2022-08-24 16:17:04 CESTCISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.
Publicerad: 2022-08-23 15:19:58 CESTFake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.
Publicerad: 2022-08-22 15:59:06 CESTSeparate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
Publicerad: 2022-08-19 17:25:56 CESTAn insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
Publicerad: 2022-08-18 16:31:38 CEST