Cybersecurity
1,759 publications classified by Officially as Cybersecurity, judged from each publication's own title and summary.
Our reading, not the publisher's. An organization that has claimed its profile can say what its own publications are about, and that will take precedence here. See everything published by organizations filed under Cybersecurity instead.
-
Upozorenje: WhatsApp prijevara “Glasajte za moje dijete”
Nacionalni CERT zaprimio je prijave o phishing (smishing) prijevari putem preuzetog WhatsApp računa te je prijavio prijevare izvorima incidenta i nadležnim CERT timovima. Primjer WhatsApp por...
Announcement Cybersecurity -
Kwetsbaarheid in N-central van N-able: update nu
Er is een ernstige kwetsbaarheid, CVE-2026-86218, gevonden in N-central van N-able met een CVSS-score van 10. Deze kwetsbaarheid maakt het voor onbevoegden mogelijk om op afstand, zonder inloggegev...
-
PAPILDINĀTS Uzbrucēji pastiprināti cenšas kompromitēt MikroTik maršrutētājus
Novērota pastiprināta uzbrucēju aktivitāte, kas vērsta pret MikroTik maršrutētājiem (rūteriem), mēģinot tos kompromitēt. Nekavējoties jāuzstāda atjauninājumi izmantotajām MikroTik iekārtām.
Announcement Cybersecurity -
Europol celebrates the International Day of Police Cooperation
On 7 September, Europol is marking the International Day of Police Cooperation together with its partners to recognise the central role our network plays in tackling the most serious threats agains...
Announcement Cybersecurity -
SI-CERT 2026-05 / Kritična ranljivost v MikroTik RouterOS – MikroTrick
Veriga kritičnih ranljivosti v RouterOS omogoča popolno kompromitacijo MikroTik naprav, ki imajo dostopno SSH storitev. Ranljivosti se že izkorišča v napadih, zato priporočamo takojšnjo namestitev ...
Announcement Cybersecurity -
MikroTik: rilevato sfruttamento in rete di nuove vulnerabilità
MikroTik ha rilasciato aggiornamenti di sicurezza al fine di correggere 6 nuove vulnerabilità, di cui 2 con gravità “critica” e 2 con gravità “alta”. …
Advisory Cybersecurity -
Active Exploitation of Vulnerability in NetScaler ADC and NetScaler Gateway
Attackers are exploiting a critical vulnerability in NetScaler ADC and NetScaler Gateway. Patch immediately.
Announcement Cybersecurity -
Critical N-able N-central Vulnerability and Active Exploitation
UPDATE: Critical vulnerability in N-able N-central gives attackers unauthenticated, "god-mode" access to the RMM console.
Cybersecurity 3 versions -
Podatności w oprogramowaniu Mikrotik RouterOS
Zespół CERT Polska znalazł 6 podatności (od CVE-2026-67276 do CVE-2026-67279, CVE-2026-67281 oraz CVE-2026-86060) w oprogramowaniu Mikrotik RouterOS.
Announcement Cybersecurity -
Krytyczne podatności w MikroTik RouterOS są aktywnie wykorzystywane. Zalecana pilna aktualizacja
Zespół CERT Polska zidentyfikował i skoordynował ujawnienie sześciu podatności w MikroTik RouterOS, w tym dwóch krytycznych. Podatności te są już aktywnie wykorzystywane do przejmowania urządzeń, k...
Announcement Cybersecurity -
OpenSSF at Hacker Summer Camp 2026: Black Hat & DEF CON Highlights and Recap
Las Vegas was once again the center of the cybersecurity universe from August 1–9 for Black Hat and DEF CON 2026. The Open Source Security Foundation (OpenSSF) had a major presence throughout the w...
-
Uzbrukumos izmantota ievainojamība Google Chrome
Google Chrome pārlūkprogrammā ir atklāta ievainojamība CVE-2026-85046, kas jau pirms drošības "ielāpa" publicēšanas tika aktīvi izmantota uzbrukumos. Ievainojamība var ļaut izpildīt uzb...
Announcement Cybersecurity -
Kwetsbaarheden in Google Chrome – voer updates uit
Er zijn meerdere kwetsbaarheden gevonden in Google Chrome, specifiek in versie 152.0.7977.82. Deze kwetsbaarheden, waaronder CVE-2026-85042 en CVE-2026-85047, betreffen verschillende onderdelen van...
-
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy inst...
Cybersecurity 2 versions -
Ruští aktéři cílí na uživatele Signalu. NÚKIB vydává analýzu a doporučení, jak si aplikaci zabezpečit
Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB) upozorňuje na cílené phishingové kampaně zaměřené na uživatele komunikační aplikace Signal. …
Announcement Cybersecurity -
CERT-SE:s veckobrev v.36
Den 13 september är det val i Sverige och Nationellt cybersäkerhetscenter (NCSC) bevakar hotläget från ett cybersäkerhetsperspektiv. NCSC:s chef John Billow berättar om uppdraget i Sveriges Radios ...
Announcement Cybersecurity -
Angry Birds: Toy Ghouls’ new toys
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matr...
-
Interinfo|DreamMaker - 2 Vulnerabilities
Announcement Cybersecurity -
Managed EDR: What It Is & How to Choose a Provider
Huntress breaks down what managed EDR is, how it differs from unmanaged, and what to look for when choosing a provider for your business.
Cybersecurity 3 versions -
Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models
Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Di...
-
The story behind the intelligence
From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to...
-
VU#889462: Casdoor authentication server is vulnerable to authorization bypass
Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions up to v4.2.0. …
-
Active Exploitation of Vulnerabilities in SonicWall SMA1000 Series
Attackers are exploiting vulnerabilities in SonicWall SMA1000 Series appliances to gain unauthorised access to sensitive functionalities and execute arbitrary operating system (OS) commands.
Announcement Cybersecurity -
How Microsoft’s Physical Security Engineering Team scaled hybrid operations with Azure Arc and Azure Virtual Desktop
Learn how Microsoft used Azure Arc and Azure Virtual Desktop to simplify hybrid security operations, improve visibility, and scale globally. The post How Microsoft’s Physical Security Engineering T...
-
NSA Highlights Cyber Hygiene Best Practices Effective Against AI-Enhanced Targeting
FORT MEADE, Md. — Today, the National Security Agency (NSA) is releasing the Cybersecurity Information Sheet (CSI), “Best Practices for Cyber Hygiene.”
Announcement Cybersecurity -
Podatność w oprogramowaniu OptimiDoc Server (On-Premise)
W oprogramowaniu OptimiDoc Server (On-Premise) wykryto podatność polegającą na przechowywaniu poświadczeń w jawnej formie (CVE-2026-15933).
Announcement Cybersecurity -
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use ...
-
August in cyberspace: service disruptions, ransomware attacks, and phishing messages
In August, the Information System Authority registered 899 cyber incidents with an impact. Over the course of the month, there were disruptions to several key services, a school in Harju County was...
Announcement Cybersecurity -
La AEMPS informa de un riesgo de acceso no autorizado en el sistema Albert e-motion M25 de accionamiento adicional para sillas de ruedas
Generar PDF Fecha de publicación: 03 de septiembre de 2026 Categoría: productos sanitarios, seguridad Referencia: PS, 38/2026 El fabricante ha recibido dos informes de intentos de piratería informá...
Announcement Cybersecurity -
Lärdomar från Polen: frontlinjen för hybridhot
Erfarenheter från Polen visar hur civila samhällsfunktioner hamnar i frontlinjen för hybridhot. Angrepp mot energi, transporter, sjukvård och digital infrastruktur har kombinerats med otillbörlig i...
Announcement Cybersecurity -
CRPC Informs of a Potential Security Incident in a CRPC Information System
With particular attention to data security, the Consumer Rights Protection Centre (CRPC) informs the public of a recently identified data security incident…
Announcement Cybersecurity -
Critical Authentication Bypass in Proxmox Virtual Environment 7.x and 8.0 (CVE-2023-54391) – 20260902007
Severity CRITICAL Threat Category Vulnerability – Authentication Bypass (CWE-304) Affected Platforms Proxmox Virtual Environment 7.0 – 7.4 and 8.0 with […] The post Critical Authentication Bypass i...
Announcement Cybersecurity -
Temporary Easing of Network Separation Rule Available for More Financial Companies for AI Cybersecurity Purpose
The Financial Services Commission held a meeting on frontier AI and cybersecurity strategy with officials from the Financial Supervisory Service and the Financial Security Institute on September 3....
-
Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-835...
Cybersecurity 2 versions -
CMMC Hit Pause, the FAR Council Hit Play
CMMC Phase 2 is paused, but the FAR CUI proposed rule pushes NIST 800-171 obligations past the defense industrial base. Here's what changed, what didn't, and the 32 requirements you can't defer.
Cybersecurity 3 versions -
Anatomy of a Silent Domain Takeover
Key Takeaways Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the ...
-
'Subsidie voor cybermaatregelen kwam op het juiste moment'
Ondernemers kunnen vanaf 7 september 2026 gebruikmaken van de subsidieregeling ‘Mijn Cyberweerbare Zaak’. Hiermee kun je als mkb’er of zzp’er 50% vergoed krijgen voor belangrijke basismaatregelen t...
-
Sveriges cybersäkerhet ska stärkas med AI
(Ny version) Regeringen avser att ge Försvarets radioanstalt (FRA) och Försvarsmakten i uppdrag att utveckla en AI-stödd förmåga att skydda samhällsviktig verksamhet mot cyberhot.
Announcement Cybersecurity -
‘We hebben de subsidie gebruikt voor een cyberbewustwordingstraining’
Kleine ondernemers kunnen vanaf 7 september gebruikmaken van de subsidieregeling ‘Mijn Cyberweerbare Zaak’. Hiermee kunnen mkb’ers en zzp’ers 50% van de kosten van een cybermaatregel, tot een maxim...
-
Inside Knight Office, a New M365 AiTM Phishing Kit
An inside look at Knight Office, a newly discovered AiTM phishing kit featuring custom control panels, Cloudflare Turnstile, and M365 Token theft.
Cybersecurity 3 versions -
Subsidie voor cyberweerbaarheid kleine bedrijven binnenkort van start
De subsidieregeling ‘Mijn Cyberweerbare Zaak’ opent op 7 september opnieuw voor kleine bedrijven, zo heeft staatssecretaris Aerdts van Economische Zaken en Klimaat aangekondigd.
-
Actief misbruikte kwetsbaarheden in SonicWall SMA 1000-apparaten - voer updates uit
SonicWall heeft twee kwetsbaarheden verholpen in de SMA 1000-serie waarvan actief misbruik werd gemaakt. Via de eerste kwetsbaarheid kan een aanvaller zonder inloggegevens ongeautoriseerde handelin...
-
Kwetsbaarheid in JFrog Artifactory Self-Hosted – update direct
Er is een kwetsbaarheid gevonden in JFrog Artifactory Self-Hosted, een product voor het opslaan en beheren van softwarepakketten. De kwetsbaarheid kan aanwezig zijn bij een standaardconfiguratie. E...
-
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking ...
-
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Insi...
-
Nowości od CERT Polska - premiera wiedza.cert.pl i nowa funkcja w moje.cert.pl
W CERT Polska stale rozwijamy dostępne narzędzia i tworzymy nowe rozwiązania, które pomagają zapobiegać incydentom, a kiedy już do nich dojdzie - skutecznie reagować. Dziś swoją premierę ma serwis ...
Announcement Cybersecurity