OpenAI has begun rolling out a new Lockdown Mode to ChatGPT for eligible personal accounts to reduce the risk of data exfiltration arising from prompt injection attacks. The feature is primarily designed for people and organizations that…
Publicerad: 2026-06-06 15:36:57 CESTRaising $59 million to date, Opal also announced five senior leadership appointments. The post Opal Security Raises $23 Million for AI-Native Identity Governance appeared first on SecurityWeek.
Publicerad: 2026-06-06 12:15:00 CESTA researcher has reverse-engineered the iOS SDK that Bright Data embeds in consumer apps and documented how it turns devices, including always-on smart TVs, into exit nodes that relay web-scraping traffic for a data business Bright Data…
Publicerad: 2026-06-06 10:29:05 CESTThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting SolarWinds Serv-U multi-protocol file server software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence…
Publicerad: 2026-06-06 10:14:31 CESTTwo things landed within days of each other this week. A security startup reported 21 previously unknown vulnerabilities in FFmpeg, the media library inside almost everything that touches video, all of them found by an autonomous AI agent.…
Publicerad: 2026-06-06 09:28:30 CESTMicrosoft's GitHub repositories have become the latest to fall victim to the ongoing Miasma self-replicating supply chain attack campaign. The incident impacted 73 Microsoft repositories across four of its GitHub organizations, including…
Publicerad: 2026-06-06 08:58:04 CESTCisco has warned that a high-severity security flaw impacting Catalyst SD-WAN Manager has come under active exploitation. The vulnerability, tracked as CVE-2026-20245, carries a CVSS score of 7.8 out of a maximum of 10.0. It affects the…
Publicerad: 2026-06-06 06:19:28 CESTA vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability…
Publicerad: 2026-06-05 23:23:51 CESTThreat actors are taking advantage of Internet-exposed tank gauges by breaching gas stations, opening the door to disruption.
Publicerad: 2026-06-05 21:04:36 CESTMultiple software supply chain attacks have hit the npm ecosystem, with threat actors using both malicious and poisoned versions of over 50 legitimate packages to distribute a Rust-based information stealer and a self-spreading worm,…
Publicerad: 2026-06-05 20:05:30 CESTCVE Lite CLI is a free, open-source command line tool that scans your projects in seconds and tells you exactly which included packages contain a vulnerability. The post OWASP Incubator Project Helps Developers Find and Fix Vulnerable…
Publicerad: 2026-06-05 18:35:02 CESTArabic-speaking users have emerged as the target of a new Android spyware codenamed Asin, according to findings from ESET. The Slovakian cybersecurity company said it first detected the malware spread via multiple campaigns in early 2025,…
Publicerad: 2026-06-05 16:53:40 CESTAI worms, or "viruses with wings and brains," adapt to new environments, seek out vulnerabilities, and will likely strike within a year, researchers say.
Publicerad: 2026-06-05 16:40:11 CESTUpdated an acknowledgement. This is an informational change only.
Publicerad: 2026-06-05 16:00:00 CESTThis CVE was updated to fix the download link for.NET Framework 3.8 & 4.81 for Windows 2025
Publicerad: 2026-06-05 16:00:00 CESTThis CVE was updated to fix the download link for.NET Framework 3.8 & 4.81 for Windows 2025
Publicerad: 2026-06-05 16:00:00 CESTOther noteworthy stories that might have slipped under the radar: Ultrahuman data leak, The Gentlemen ransomware analysis, Hola Browser bundles miner. The post In Other News: Anthropic Maps AI Threats, Unpatched Comodo Flaw, Palantir Chief…
Publicerad: 2026-06-05 15:05:06 CESTThe White House's executive order establishes voluntary framework for early government access to frontier models while investing in federal security.
Publicerad: 2026-06-05 15:00:00 CESTI veckans brev hittar du läsning om “HTTP/2 Bomb”, en metod för överbelastningsangrepp som kombinerar flera tekniker för att göra servrar otillgängliga. Du hittar även information om EU-kommissionens nya åtgärdspaket för att minska…
Publicerad: 2026-06-05 14:50:00 CESTCybersecurity researchers have discovered a previously unreported threat cluster dubbed OP-512 (where "OP" stands for "opponent") that has been observed targeting Microsoft Internet Information Services (IIS) servers to deploy a bespoke…
Publicerad: 2026-06-05 14:33:38 CESTThe ShinyHunters extortion group leaked roughly 234 GB of data allegedly stolen from the dental benefits administrator. The post Hackers Leak DentaQuest Information Impacting 2.6 Million appeared first on SecurityWeek.
Publicerad: 2026-06-05 13:33:27 CESTEighteen months ago, the AI SOC was a marketing line. Today it's a budget item. The category has crossed over from interesting to inevitable, with billions of dollars now flowing into AI-powered security operations platforms, agentic SOC…
Publicerad: 2026-06-05 13:20:00 CESTOver 100 bugs are critical or high-severity, mainly use-after-free and insufficient validation of untrusted input flaws. The post Chrome 149 Patches 429 Vulnerabilities appeared first on SecurityWeek.
Publicerad: 2026-06-05 13:13:57 CESTExperts commented on the EO’s voluntary nature, the balance between innovation and security, and potential implementation gaps. The post Industry Reactions to New Trump AI Cybersecurity Executive Order: Feedback Friday appeared first on SecurityWeek.
Publicerad: 2026-06-05 12:24:56 CESTPosing as recruiters on online platforms, Chinese intelligence officers target personnel with access to classified or privileged information. The post Five Eyes: Chinese Spies Target Government, Military Staff With Fake Job Opportunities appeared first on SecurityWeek.
Publicerad: 2026-06-05 10:46:44 CESTInformation published.
Publicerad: 2026-06-05 10:41:37 CESTInformation published.
Publicerad: 2026-06-05 10:41:29 CESTInformation published.
Publicerad: 2026-06-05 10:41:22 CESTInformation published.
Publicerad: 2026-06-05 10:41:15 CESTInformation published.
Publicerad: 2026-06-05 10:41:08 CESTInformation published.
Publicerad: 2026-06-05 10:41:01 CESTThe company detected a network intrusion in March and an investigation showed that some files were stolen during the attack. The post Nightclub Giant RCI Says Data Breach Affects 40,000 Individuals appeared first on SecurityWeek.
Publicerad: 2026-06-05 09:24:08 CESTThe vulnerability is tracked as CVE-2026-20245 and it can allow arbitrary command execution as root, but no patch yet. The post Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 appeared first on SecurityWeek.
Publicerad: 2026-06-05 07:47:09 CESTSolarWinds Serv-U contains an uncontrolled resource consumption vulnerability that allows specially crafted POST requests using the Content-Encoding: deflate header to crash the Serv-U service without authentication. | Åtgärd: Apply…
Publicerad: 2026-06-05 02:00:00 CESTLike Shai-Hulud, the campaign targets developers to steal credentials and reuses them to propagate across the software supply channel.
Publicerad: 2026-06-04 23:47:06 CESTOne of the world's most diverse, least-focused cybercrime groups is enlarging its footprint beyond East Asia.
Publicerad: 2026-06-04 23:23:59 CESTGartner analysts issued a call to action to bolster defenses against several emerging critical threats, such as deepfakes and prompt injections.
Publicerad: 2026-06-04 23:08:16 CESTAs AI agents, machine identities, and third-party applications multiply across enterprises, Offroad is betting autonomous security agents can restore control over an increasingly unmanageable identity landscape. The post Offroad Emerges…
Publicerad: 2026-06-04 17:05:45 CESTOrganizations are growing serious about what nation’s rules apply to their data. Experts point to geopolitical tensions as a main contributing factor.
Publicerad: 2026-06-04 16:22:20 CESTAuthentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.
Publicerad: 2026-06-04 16:00:00 CESTDespite broadly connected digital infrastructure, standard fare TTPs are enough to cause trouble for Afghanistan's porous cybersecurity.
Publicerad: 2026-06-04 06:01:00 CESTPython scripts were used to test malware against endpoint detection and response agents from Sophos, CrowdStrike, and Windows Defender.
Publicerad: 2026-06-03 23:34:07 CESTChina-linked espionage groups have attacked at least a dozen nations in the region, gathering information on maritime shipping, oil production, and other geopolitical interests.
Publicerad: 2026-06-03 21:52:32 CESTA vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability in the Webex Meetings…
Publicerad: 2026-06-03 18:00:00 CESTA vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request…
Publicerad: 2026-06-03 18:00:00 CESTA vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerability…
Publicerad: 2026-06-03 18:00:00 CESTCVSSv3 Score: 7.9 Linux kernel is impacted by CVE-2026-43284 and CVE-2026-43500 which chained together create the Dirty Frag vulnerability.CVE-2026-43284In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid…
Publicerad: 2026-06-03 09:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-06-03 07:45:00 CESTMirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.…
Publicerad: 2026-06-03 02:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-06-02 03:15:00 CESTLinux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance…
Publicerad: 2026-06-02 02:00:00 CESTAndroid Framework contains an integer overflow vulnerability that allows for code execution that could allow for local privilege escalation. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for…
Publicerad: 2026-06-02 02:00:00 CESTOracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized…
Publicerad: 2026-06-01 02:00:00 CESTI veckans läsning finns ett urval av nyheter, analyser och rapporter inom cybersäkerhetsområdet från veckan som har gått.
Publicerad: 2026-05-29 14:49:00 CESTPalo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection. | Åtgärd: Apply mitigations per vendor instructions, follow…
Publicerad: 2026-05-29 02:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-05-29 01:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-05-29 01:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-05-28 23:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-05-28 23:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-05-28 23:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-05-28 23:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-05-28 23:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-05-28 23:00:00 CESTMay 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability was disclosed in February 2026. This…
Publicerad: 2026-05-28 00:13:44 CESTNx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on…
Publicerad: 2026-05-27 02:00:00 CESTTanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity. | Åtgärd: Apply mitigations per vendor…
Publicerad: 2026-05-27 02:00:00 CESTDaemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability. | Åtgärd: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or…
Publicerad: 2026-05-27 02:00:00 CESTLiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges. | Åtgärd: Apply…
Publicerad: 2026-05-26 02:00:00 CESTI veckans läsning finns ett urval av nyheter, analyser och rapporter inom cybersäkerhetsområdet från veckan som har gått.
Publicerad: 2026-05-22 14:15:00 CESTA vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP…
Publicerad: 2026-05-20 18:00:00 CESTA vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to…
Publicerad: 2026-05-20 18:00:00 CESTA vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process.…
Publicerad: 2026-05-20 18:00:00 CESTOn April 23, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an update to V1: Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices related to Cisco Secure Firewall…
Publicerad: 2026-05-19 19:49:15 CESTDenna vecka vill vi tipsa om att vi har publicerat enkla och korta ”Tabletop”-övningar för hantering av utpressningsangrepp, överbelastningsangrepp och nätfiske. Du hittar övningarna här: https://www.cert.se/tema/ovningar/
Publicerad: 2026-05-15 13:15:00 CESTCisco har publicerat information om en kritisk sårbarhet som fått den högsta CVSS-klassningen på 10.0. [1] Sårbarheten, CVE-2026-20182, utnyttjas aktivt och CISA har lagt till den i KEV-katalogen (Known Exploited Vulnerabilities catalog). [2]
Publicerad: 2026-05-15 10:45:00 CESTCVSSv3 Score: 7.8 CVE-2026-31431In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated…
Publicerad: 2026-05-13 09:00:00 CESTFlera leverantörer har släppt sina månatliga säkerhetsuppdateringar för maj. Nedan finns en sammanställning av de säkerhetsuppdateringar som Microsoft, Fortinet, SAP, Ivanti och Adobe har publicerat i samband med patchtisdagen. Följ…
Publicerad: 2026-05-12 10:32:00 CESTCVSSv3 Score: 4.0 An Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability [CWE-88] in FortiDeceptor WEB UI may allow an authenticated attacker with at least read-only admin permission to read log…
Publicerad: 2026-05-12 09:00:00 CESTCVSSv3 Score: 6.1 An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] in FortiAP, FortiAP-U & FortiAP-W2 CLI may allow an authenticated privileged attacker to execute…
Publicerad: 2026-05-12 09:00:00 CESTCVSSv3 Score: 5.2 A use of potentially Dangerous Function vulnerability [CWE-676] in FortiAnalyzer and FortiManager API may allow an authenticated attacker to cause a system hang via multiple specially crafted HTTP requests causing…
Publicerad: 2026-05-12 09:00:00 CESTCVSSv3 Score: 2.1 A Missing Authorization [CWE-862] in FortiClient Windows may allow an authenticated local attacker to decrypt a currently logged in users VPN password via use of an unprotected DLL function. Revised on 2026-05-12 00:00:00
Publicerad: 2026-05-12 09:00:00 CESTCVSSv3 Score: 9.1 An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. Revised on 2026-05-12 00:00:00
Publicerad: 2026-05-12 09:00:00 CESTCVSSv3 Score: 9.1 A missing authorization vulnerability [CWE-862] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to execute unauthorized code or commands via HTTP requests. Revised on 2026-05-12 00:00:00
Publicerad: 2026-05-12 09:00:00 CESTCVSSv3 Score: 6.5 An OS command injection vulnerabtility [CWE-78] in FortiAP and FortiAP-W2 cli may allow an authenticated attacker to execute unauthorized code or commands via a specifically crafted cli command. Revised on 2026-05-12 00:00:00
Publicerad: 2026-05-12 09:00:00 CESTCVSSv3 Score: 5.0 An improper export of Android application components [CWE-926] in FortiTokenAndroid may allow other applications on the device to read the OTP code via an exported Content Provider URI. Revised on 2026-05-12 00:00:00
Publicerad: 2026-05-12 09:00:00 CESTI veckans brev kan du läsa om angreppet mot utbildningsplattformen Canvas, som tillhandahålls av det amerikanska företaget Instructure. Företaget har bekräftat att en hotaktör har stulit en mängd information, däribland personuppgifter.…
Publicerad: 2026-05-08 15:10:00 CESTIvanti har publicerat information om uppdateringar som åtgärdar fem sårbarheter.
Publicerad: 2026-05-08 09:50:00 CESTPalo Alto Networks har publicerat information om en kritisk sårbarhet i PAN-OS. Sårbarheten, CVE-2026-0300, har fått en CVSS-klassning på 9.3 och påverkar USER-ID Autentication Portal. [1]
Publicerad: 2026-05-06 15:20:00 CESTVid uppsättning av en klientorganisation (engelska: tenant) i Microsofts molnmiljö är flexibiliteten hög och nya funktioner läggs till kontinuerligt. CERT-SE uppmanar organisationer att regelbundet se över aktiverade, eller inaktiverade,…
Publicerad: 2026-03-30 11:10:00 CESTA vulnerability classified as problematic has been found in Ortus Solutions ColdBox Elixir 3.1.6. This affects an unknown part of the file src/defaultConfig.js of the component ENV Variable Handler. The manipulation leads to information…
Publicerad: 2023-11-06 09:15:21 CETA vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls.…
Publicerad: 2023-11-06 02:15:08 CET** UNSUPPPORTED WHEN ASSIGNED ** ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file…
Publicerad: 2023-11-05 22:15:09 CETA vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper…
Publicerad: 2023-11-05 22:15:09 CETA security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpected actions as well as forwarding the client's API server credentials to third parties.
Publicerad: 2023-11-03 21:15:08 CETIvanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability
Publicerad: 2023-11-03 21:15:08 CETIvanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability
Publicerad: 2023-11-03 21:15:08 CETA locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.
Publicerad: 2023-11-03 21:15:08 CETIn swtpm before 0.4.2 and 0.5.x before 0.5.1, a local attacker may be able to overwrite arbitrary files via a symlink attack against a temporary file such as TMP2-00.permall.
Publicerad: 2023-11-03 05:15:15 CETbcrypt password hashing in Botan before 2.1.0 does not correctly handle passwords with a length between 57 and 72 characters, which makes it easier for attackers to determine the cleartext password.
Publicerad: 2023-11-03 02:15:07 CET2.5 million people were affected, in a breach that could spell more trouble down the line.
Publicerad: 2022-08-31 14:57:48 CESTResearchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
Publicerad: 2022-08-30 18:00:43 CESTOver 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
Publicerad: 2022-08-29 16:56:19 CESTLockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
Publicerad: 2022-08-26 18:44:27 CESTTens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Publicerad: 2022-08-25 20:47:15 CESTTwitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
Publicerad: 2022-08-24 16:17:04 CESTCISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.
Publicerad: 2022-08-23 15:19:58 CESTFake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.
Publicerad: 2022-08-22 15:59:06 CESTSeparate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
Publicerad: 2022-08-19 17:25:56 CESTAn insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
Publicerad: 2022-08-18 16:31:38 CEST