Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]
Publicerad: 2026-10-04 23:58:01 CESTThe announcement comes after Trump hosted top executives of AI companies at the White House last week. The post Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force appeared first on SecurityWeek.
Publicerad: 2026-10-04 16:57:25 CESTCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-88779 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer…
Publicerad: 2026-10-04 14:00:00 CESTInformation published.
Publicerad: 2026-10-04 11:13:35 CESTInformation published.
Publicerad: 2026-10-04 11:13:15 CESTA suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Rey, whose real name…
Publicerad: 2026-10-04 09:22:05 CESTA new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal sector organizations.…
Publicerad: 2026-10-04 09:20:32 CESTCitrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service. |…
Publicerad: 2026-10-04 02:00:00 CESTGoogle's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. [...]
Publicerad: 2026-10-04 01:12:34 CESTA suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]
Publicerad: 2026-10-03 21:09:38 CESTThe U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert"…
Publicerad: 2026-10-03 16:38:46 CESTThe Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [...]
Publicerad: 2026-10-03 16:35:20 CESTdoxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority. The post doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures appeared first on SecurityWeek.
Publicerad: 2026-10-03 13:45:00 CESTThe bugs could lead to authentication bypass, shell command execution, and memory corruption. The post Fortra Patches Critical Vulnerabilities in BoKS appeared first on SecurityWeek.
Publicerad: 2026-10-03 13:34:00 CESTFeaturing: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing…
Publicerad: 2026-10-03 13:00:00 CESTInformation published.
Publicerad: 2026-10-03 11:05:04 CESTA vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due…
Publicerad: 2026-10-03 01:18:42 CEST### Summary act_runner appends workflow-controlled `jobs..container.options` directly to the Docker HostConfig for the job container. When runner privileged mode is disabled, only `Privileged` is forced false. Host namespace flags,…
Publicerad: 2026-10-03 01:18:12 CEST## Overview `probe-image-size` scans the SVG header with a searching regular expression, `/<[-_.:a-zA-Z0-9][^>]*>/`. On input that contains many `<` characters but no `>`, the engine restarts the `[^>]*` scan at every `<` position and runs…
Publicerad: 2026-10-03 01:18:02 CEST# Security Advisory — SiYuan Agent Tools SSRF via DNS-Rebinding TOCTOU (Bypass of `CheckHostSSRF`) | Field | Value | |---|---| | **Disclosed by** | joysinleung (`[email protected]`) | | **Report date** | 2026-08-13 | | **Product** |…
Publicerad: 2026-10-03 01:17:16 CEST# Security Advisory — SiYuan MCP `asset.upload` Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass) | Field | Value | |---|---| | **Disclosed by** | joysinleung (`[email protected]`) | | **Report date** | 2026-08-13 | |…
Publicerad: 2026-10-03 01:16:56 CEST### Impact Versions of `@fastify/busboy` from 1.0.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The multipart header parser stores part-header names on a plain JavaScript object, so a part header named `__proto__` or…
Publicerad: 2026-10-03 01:16:36 CEST### Impact Versions of `@fastify/busboy` from 3.1.0 and prior to 3.2.1 are vulnerable to a Denial of Service. The vendored streaming multipart search stores its default skip distance in a `Uint8Array(256)`. A multipart boundary of exactly…
Publicerad: 2026-10-03 01:16:17 CEST## Summary Using `Database#create_aggregate`, `#create_aggregate_handler`, or `Database#define_aggregator` to define an aggregate function that takes two or more arguments, and then evaluating it over TEXT or BLOB column values, can free…
Publicerad: 2026-10-03 01:11:51 CEST### Summary Multiple denial-of-service vulnerabilities have been discovered in HTTP/2 server implementations. All have been rated with a severity impact of [Important](https://access.redhat.com/security/updates/classification). The…
Publicerad: 2026-10-03 01:09:37 CEST### Summary The Headroom WebSocket server does not validate the `Origin` header of incoming client WebSocket requests before forwarding the request to the upstream server, allowing malicious WebSocket clients to perform arbitrary LLM…
Publicerad: 2026-10-03 01:09:15 CESTSame CWE-862 family, found via an automated bulk sweep of every `/api/block/*` handler in `kernel/api/block.go` for the presence of any access-check reference (`IsReadOnlyRoleContext`, `checkBlockPublishAccess`, `GetPublishAccess`)…
Publicerad: 2026-10-03 01:05:33 CESTThe offensive cyber operations startup looks to evolve red teaming beyond traditional methods to simulate attackers' increasingly advanced capabilities.
Publicerad: 2026-10-02 22:18:37 CESTAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that…
Publicerad: 2026-10-02 21:21:28 CESTFrontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including Social Security numbers. [...]
Publicerad: 2026-10-02 21:01:40 CESTA critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance…
Publicerad: 2026-10-02 19:33:31 CESTGovernment and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines,…
Publicerad: 2026-10-02 19:33:16 CESTDell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below -…
Publicerad: 2026-10-02 19:02:12 CESTOne company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.
Publicerad: 2026-10-02 18:56:30 CESTPatch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments.
Publicerad: 2026-10-02 18:27:54 CESTGitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]
Publicerad: 2026-10-02 18:20:05 CESTOrganizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges ahead.
Publicerad: 2026-10-02 18:01:22 CEST"Rogue AI" terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent.
Publicerad: 2026-10-02 17:51:33 CESTThe U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. [...]
Publicerad: 2026-10-02 17:20:53 CESTNoteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post In Other News: $15K iCloud Spoofing Bugs, AI…
Publicerad: 2026-10-02 16:30:00 CESTBrowser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. [...]
Publicerad: 2026-10-02 16:00:10 CESTWeak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network.
Publicerad: 2026-10-02 16:00:00 CESTOrganizations don't need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them.
Publicerad: 2026-10-02 16:00:00 CESTThe dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor appeared first on SecurityWeek.
Publicerad: 2026-10-02 15:15:00 CESTA trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it's hard to tell they're not.
Publicerad: 2026-10-02 15:00:00 CESTOpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies…
Publicerad: 2026-10-02 14:23:15 CESTCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-102489 Zammad GmbH Zammad Session Fixation Vulnerability CVE-2026-102490 Zammad GmbH Zammad…
Publicerad: 2026-10-02 14:00:00 CESTHackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account. The post Crypto Scammers Hijack Microsoft’s Official X Account appeared first on SecurityWeek.
Publicerad: 2026-10-02 13:46:10 CESTFortinet har publicerat information om en kritisk sårbarhet i FortiMail. Sårbarheten, CVE-2026-104286, har fått en CVSS-klassning på 9.8 och påverkar FortiMail managements gränssnitt. Ett framgångsrikt utnyttjande kan innebära att en…
Publicerad: 2026-10-02 13:30:00 CESTThe quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile…
Publicerad: 2026-10-02 13:30:00 CESTAmir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad. The post In Rare Move, Alleged Iranian State Hacker Extradited to US appeared first on SecurityWeek.
Publicerad: 2026-10-02 13:14:34 CESTCERT-SE presenterar vår årliga utmaning (CTF) som sker under cybersäkerhetsmånaden [1, 2]. Utmaningen vänder sig till alla med it-säkerhetsintresse oavsett kunskapsnivå.
Publicerad: 2026-10-02 12:45:00 CESTThe attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI. The post AI Agents Aimed SQL Injection at US and Canadian Government Sites appeared first on SecurityWeek.
Publicerad: 2026-10-02 10:38:46 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-10-02 10:15:00 CESTCVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system. The post Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action appeared first on SecurityWeek.
Publicerad: 2026-10-02 10:07:33 CESTOktober är cybersäkerhetsmånaden och vi vill passa att slå ett slag för de kunskapshöjande aktiviteter som erbjuds genom NCSC:s och polisens cybersäkerhetskampanj “Tänk Säkert”.
Publicerad: 2026-10-02 09:30:00 CESTZammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. | Åtgärd: Apply mitigations in…
Publicerad: 2026-10-02 02:00:00 CESTZammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. | Åtgärd: Apply mitigations in accordance with vendor…
Publicerad: 2026-10-02 02:00:00 CESTLaw enforcement from multiple countries collaborated to disrupt a cybercrime operation that has claimed some 500 victims worldwide in the past two years.
Publicerad: 2026-10-01 23:37:50 CESTA year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.
Publicerad: 2026-10-01 15:00:00 CESTView CSAF Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data. The following versions of Johnson Controls EasyIO Neo Series EC and…
Publicerad: 2026-10-01 14:00:00 CESTView CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and…
Publicerad: 2026-10-01 14:00:00 CESTView CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. The…
Publicerad: 2026-10-01 14:00:00 CESTView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical…
Publicerad: 2026-10-01 14:00:00 CESTView CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are affected: Protection and…
Publicerad: 2026-10-01 14:00:00 CESTView CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The following versions of Johnson Controls…
Publicerad: 2026-10-01 14:00:00 CESTCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability This type of vulnerability is a frequent…
Publicerad: 2026-10-01 14:00:00 CESTView CSAF Summary The following versions of CISA Malcolm are affected: Malcolm CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper…
Publicerad: 2026-10-01 14:00:00 CESTCVSSv3 Score: 9.8 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write…
Publicerad: 2026-10-01 09:00:00 CESTFortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS…
Publicerad: 2026-10-01 02:00:00 CESTIn yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.
Publicerad: 2026-09-30 23:25:47 CESTOn October 7, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Application Policy…
Publicerad: 2026-09-30 18:00:00 CESTUpdated an acknowledgement. This is an informational change only.
Publicerad: 2026-09-30 16:00:00 CESTUpdated an acknowledgement. This is an informational change only.
Publicerad: 2026-09-30 16:00:00 CESTUpdated an acknowledgement. This is an informational change only.
Publicerad: 2026-09-30 16:00:00 CESTUpdated an acknowledgement. This is an informational change only.
Publicerad: 2026-09-30 16:00:00 CESTUpdated an acknowledgement. This is an informational change only.
Publicerad: 2026-09-30 16:00:00 CESTCWE added. Informational change only.
Publicerad: 2026-09-30 16:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-09-30 08:15:00 CESTCisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP…
Publicerad: 2026-09-30 02:00:00 CESTApple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD…
Publicerad: 2026-09-29 02:00:00 CESTA vulnerability has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this issue is the function opendmarc_policy_query_dmarc in the library libopendmarc/opendmarc_policy.c of the component Internationalized Domain…
Publicerad: 2026-09-28 03:16:28 CESTA flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function opendmarc_spf_ipv6_explode in the library libopendmarc/opendmarc_spf.c of the component SPF Parser. This manipulation of…
Publicerad: 2026-09-28 03:16:28 CESTA vulnerability was detected in Trusted Domain Project OpenDKIM up to 2.11.0. Affected is the function dkim_qp_decode of the file util.c of the component Decoder. The manipulation results in off-by-one. The attack may be performed from…
Publicerad: 2026-09-28 02:16:32 CESTA weakness has been identified in Trusted Domain Project OpenDKIM up to 2.11.0. This affects the function dkim_canon_selecthdrs of the file libopendkim/dkim-canon.c of the component DKIM Signature Header Selection. Executing a manipulation…
Publicerad: 2026-09-28 02:16:32 CESTA security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System up to 81bf0b55f5933f3b0dbb1583204a612e06605b95. The impacted element is the function order_by of the file DB_query_builder.php of the component…
Publicerad: 2026-09-28 02:16:32 CESTA malicious user can get read-access to files in the flatpak-system-helper context if a system OCI repository is configured, because the OCI code paths in the system helper follow symlinks when importing OCI images that are under the user's control.
Publicerad: 2026-09-28 01:17:01 CESTA vulnerability was identified in Seetong T8108, T8108P, T8116 and T8232 4.6.1.4-build202604241011. The affected element is an unknown function of the component Debug Service. Such manipulation leads to improper authentication. The attack…
Publicerad: 2026-09-28 01:16:59 CESTA vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation…
Publicerad: 2026-09-28 01:16:58 CESTA vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation…
Publicerad: 2026-09-28 01:16:58 CESTA flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to improper access controls. The attack can be…
Publicerad: 2026-09-28 01:16:58 CESTCitrix har publicerat information om allvarliga och kritiska sårbarheter i Citrix NetScaler ADC (tidigare Citrix ADC) and Citrix NetScaler Gateway (tidigare Citrix Gateway). Två av sårbarheterna, CVE-2026-88771 och CVE-2026-88772, har fått…
Publicerad: 2026-09-27 18:09:00 CESTCitrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service | Åtgärd: Apply mitigations in…
Publicerad: 2026-09-27 02:00:00 CESTCitrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. | Åtgärd: Apply mitigations in accordance with vendor instructions,…
Publicerad: 2026-09-27 02:00:00 CESTFör tionde året genomförs Beredskapsveckan i Sverige vecka 39. I år är det fokus på Sveriges totalförsvar, där samhällets motståndskraft mot cyberhot är en viktig del. Tänk på att ha en radio inställd på Sveriges Radio P4 och viktiga telefonnummer nedskrivna på papper.
Publicerad: 2026-09-25 10:45:00 CESTMikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve…
Publicerad: 2026-09-25 02:00:00 CESTMicrosoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. | Åtgärd: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD…
Publicerad: 2026-09-25 02:00:00 CESTMultiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate…
Publicerad: 2026-09-24 19:16:37 CESTUpdate for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that…
Publicerad: 2026-09-23 15:26:33 CESTF5 har publicerat information om en kritisk sårbarhet, CVE-2026-94127, i BIG-IP APM. Sårbarheten kan resultera i att en oautentiserad angripare kan fjärrexekvera godtycklig kod.
Publicerad: 2026-09-23 11:20:00 CESTA vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated,…
Publicerad: 2026-09-18 17:50:56 CESTAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management…
Publicerad: 2026-09-18 17:50:33 CESTA vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series…
Publicerad: 2026-09-18 17:50:31 CESTA vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow…
Publicerad: 2026-09-18 17:50:30 CESTMultiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an…
Publicerad: 2026-09-18 17:50:30 CESTDen här veckan innehåller CERT-SE:s veckobrev bland annat information om att NCSC och AI Sweden med flera bjuder in till seminarium den 22 oktober på temat “Modern sårbarhetshantering i en AI-driven hotmiljö”. Läs mer om detta nedan.
Publicerad: 2026-09-18 13:15:00 CESTDen 16 september publicerade Cisco säkerhetsuppdateringar för flera sårbarheter, där några av dessa utnyttjas aktivt enligt Cisco. [1, 2] Ett exempel är CVE-2026-76460, en sårbarhet i ett API för Cisco Identity Services Engine (ISE).…
Publicerad: 2026-09-17 15:20:00 CESTCisco har publicerat information om en kritisk SQL injection-sårbarhet i Cisco Secure Email Gateway som utnyttjas aktivt. Sårbarheten (CVE-2026-76461) har fått CVSS-klassificering 9.8 (CVSS v.3.1). [1] CISA har lagt till sårbarheten i KEV-…
Publicerad: 2026-09-15 15:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-09-12 02:30:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-09-12 02:30:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-09-12 02:30:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-09-12 02:30:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-09-12 02:30:00 CESTGitLab har publicerat säkerhetsuppdateringar för flera sårbarheter i GitLab Community Edition (CE) och Enterprise Edition (EE). [1] Två av dessa sårbarheter, CVE-2026-85706 och CVE-2026-87719, klassas som kritiska.
Publicerad: 2026-09-11 23:30:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-09-09 18:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-09-09 18:00:00 CESTIngen sammanfattning tillgänglig.
Publicerad: 2026-09-09 18:00:00 CESTCVSSv3 Score: 4.7 An Unverified Ownership Vulnerability [CWE-283] in FortiClient Windows fortimon3 driver may allow an authenticated attacker to terminate arbitrary processes via an exposed minifilter communication port. Revised on 2026-09-08 00:00:00
Publicerad: 2026-09-08 09:00:00 CESTCVSSv3 Score: 4.9 An Improper Access control vulnerability [CWE-284] in FortiSOAR may allow an authenticated attacker with zero permissions to subscribe to websocket streams and topics and to inject broadcast messages to the stream via…
Publicerad: 2026-09-08 09:00:00 CESTCVSSv3 Score: 6.7 An Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability [CWE-77] in FortiSandbox may allow a privileged attacker to execute unauthorized code or commands via crafted HTTP requests. Revised on 2026-09-08 00:00:00
Publicerad: 2026-09-08 09:00:00 CESTCVSSv3 Score: 9.1 An improper authentication vulnerability [CWE-287] in the Fortinet Privileged Access Agent Chrome Extension may allow a remote unauthenticated attacker to proxy a user's browser traffic through attacker controlled servers…
Publicerad: 2026-09-08 09:00:00 CESTCVSSv3 Score: 9.6 An Inclusion of Sensitive Information in Source Code vulnerability [CWE-540] in FortiMonitorOnSight web portal may allow a remote unauthenticated attacker to bypass authentication via forged or reused JWT Revised on 2026-09-08 00:00:00
Publicerad: 2026-09-08 09:00:00 CESTCVSSv3 Score: 2.5 A NULL Pointer Dereference vulnerability [CWE-476] in FortiOS, FortiProxy and FortiPAM may allow an authenticated attacker to crash the httpsd daemon via crafted HTTP requests. Revised on 2026-09-08 00:00:00
Publicerad: 2026-09-08 09:00:00 CESTCVSSv3 Score: 2.8 An URL redirection to untrusted site ('open redirect') [CWE-601] vulnerability in FortiSIEM may allow an authenticated attacker to cause a redirection to any website via specially crafted HTTP requests Revised on 2026-09-08 00:00:00
Publicerad: 2026-09-08 09:00:00 CESTCVSSv3 Score: 8.9 An improper access control vulnerability [CWE-284] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to access sensitive information via crafted HTTP requests. Revised on 2026-09-08 00:00:00
Publicerad: 2026-09-08 09:00:00 CESTCVSSv3 Score: 5.9 A Use of Uninitialized Variable [CWE-457] vulnerability in Fortinet FortiAnalyzer SNMP daemon may allow a remote authenticated attacker with user permission to cause a denial of service via SNMP GETBULK requests. Revised on 2026-09-08 00:00:00
Publicerad: 2026-09-08 09:00:00 CEST2.5 million people were affected, in a breach that could spell more trouble down the line.
Publicerad: 2022-08-31 14:57:48 CESTResearchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
Publicerad: 2022-08-30 18:00:43 CESTOver 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
Publicerad: 2022-08-29 16:56:19 CESTLockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
Publicerad: 2022-08-26 18:44:27 CESTTens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Publicerad: 2022-08-25 20:47:15 CESTTwitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
Publicerad: 2022-08-24 16:17:04 CESTCISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.
Publicerad: 2022-08-23 15:19:58 CESTFake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.
Publicerad: 2022-08-22 15:59:06 CESTSeparate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
Publicerad: 2022-08-19 17:25:56 CESTAn insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
Publicerad: 2022-08-18 16:31:38 CEST