Cybersecurity 1,878 records

Cybersecurity

1,878 publications from 84 organizations filed under Cybersecurity.

Filed by publisher, not by subject — these are everything those organizations published, not everything published about Cybersecurity. See the 1,758 publications Officially classified as Cybersecurity instead.

  1. High-Severity Vulnerability in PostgreSQL

    Attackers can exploit a high-severity vulnerability in PostgreSQL to execute arbitrary code on the affected system. Patch promptly.

    Announcement Cybersecurity
  2. 4 Questions to Ask When Evaluating an Exposure Management Platform

    Executive Summary Exposure management platforms are increasingly evaluated based on post-detection actions rather than detection itself. …

  3. VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot

    The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot pro...

    Advisory Cybersecurity 3 versions
  4. Microsoft 製品の脆弱性対策について(2026年9月)

    情報処理推進機構(IPA)の「Microsoft 製品の脆弱性対策について(2026年9月)」に関する情報です。

    Announcement Cybersecurity
  5. VU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability

    Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed int...

    Advisory Cybersecurity 3 versions
  6. VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

    A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate ...

    Advisory Cybersecurity 3 versions
  7. StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

    A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed ...

    Cybersecurity 2 versions
  8. What’s in the SOSS? Podcast #72 – S3E24 Balancing AI’s Double-Edged Sword: Software Engineering, Unlearning, and Ecosystem Sustainability with Mark Russinovich

    Join Azure CTO and OpenSSF Chair Mark Russinovich as he discusses AI's impact on software engineering, supply chain security, and vulnerability management.

  9. Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)

    Automatic Key Exchange probes TLS 1.3-capable customer origins to learn which key agreement algorithms they support. We then lead with the most secure algorithm when connecting to the origin, prefe...

  10. The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

    Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional depend...

  11. Kwetsbaarheden in MikroTik RouterOS actief misbruikt: update nu

    Er zijn meerdere ernstige kwetsbaarheden gevonden in MikroTik RouterOS. Deze kwetsbaarheden worden actief misbruikt en is vooral gericht op routers met publiek toegankelijke SSH-diensten. Het NCSC ...

  12. CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

    While conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-centr...

    Cybersecurity 2 versions
  13. ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

    We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as...

  14. ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

    Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google S...

  15. Drug trafficking investigation leads to some of the world’s biggest underground bankers

    The investigation, led by the Spanish National Police (Policía Nacional) and supported by Europol, has resulted in the arrest of 21 suspects for offences including participation in a criminal organ...

    Announcement Sanctions
  16. Adobe: rilevato sfruttamento in rete della CVE-2026-75650

    Aggiornamenti di sicurezza Adobe sanano una vulnerabilità con gravità “critica” in Adobe Commerce, Adobe Commerce B2B e Magento Open Source, piattaforme per il commercio elettronico utilizzate per ...

    Advisory Cybersecurity
  17. Kritiska ievainojamība Adobe Commerce un Magento e-komercijas platformās

    E-komercijas platformās Adobe Commerce un Magento Open Source ir atklāta kritiska ievainojamība CVE-2026-75650, kas jau tiek aktīvi izmantota uzbrukumos. Tā ļauj neautorizētam uzbrucējam ...

    Announcement Cybersecurity
  18. Ernstige kwetsbaarheid in Adobe Commerce en Magento actief misbruikt: update onmiddellijk

    Er is een zeer ernstige kwetsbaarheid, CVE-2026-75650, gevonden in Adobe Commerce en Magento met een maximale CVSS-score van 10.0. Met deze kwetsbaarheid is het mogelijk voor een aanvaller om op af...

  19. Kiberlaikapstākļi 2026 | Augusts

    Pieejami kiberlaikapstākļi par 2026. gada augustu. Kiberlaikapstākļi ir CERT.LV speciālistu apkopots pārskats īsā un pārskatāmā formā par Latvijas kibertelpā svarīgākajiem notikumiem pagājušajā mēn...

    Announcement Cybersecurity
  20. September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs

    Microsoft has released security updates for 972 vulnerabilities, including two exploited zero-days and 113 critical, in its September 2026 Patch Tuesday rollout.

  21. AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance

    Active Directory Rights Management Services still ships in Windows Server 2025, years after Microsoft began steering customers to the cloud, and it remains fully supported on-premises. …

    Cybersecurity 3 versions
  22. 7th September – Threat Intelligence Report

    For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Thomson Reuters, a global information and tech...

  23. AI SIEM Search

    The new Huntress AI SIEM search feature lets you find answers in plain English, with no query language fluency required. Ask questions, get results, and skip the syntax.

    Cybersecurity AI 3 versions
  24. Microsoft 365 un Azure ierīces koda (Device Code) ļaunprātīga izmantošana

    Ierīces koda (Device Code) autentifikācija ir leģitīma funkcionalitāte, kas risina praktisku problēmu - tā ļauj ērti pieteikties ierīcē, kurai nav pārlūkprogrammas vai pilnvērtīgas tastatūras, izma...

    Announcement Cybersecurity
  25. Upozorenj: kritična ranjivosti u MikroTik RouterOS-u. Preporučuje se hitna nadogradnja.

    Poljski CERT (CERT Polska) identificirao je i koordinirao objavu šest ranjivosti u sustavu MikroTik RouterOS. Kombinacijom dviju od njih (CVE-2026-67276 i CVE-2026-86060), nazvanom “MikroTrick”, na...

    Announcement Cybersecurity
  26. Upozorenje: WhatsApp prijevara “Glasajte za moje dijete”

    Nacionalni CERT zaprimio je prijave o phishing (smishing) prijevari putem preuzetog WhatsApp računa te je prijavio prijevare izvorima incidenta i nadležnim CERT timovima.  Primjer WhatsApp por...

    Announcement Cybersecurity
  27. Kwetsbaarheid in N-central van N-able: update nu

    Er is een ernstige kwetsbaarheid, CVE-2026-86218, gevonden in N-central van N-able met een CVSS-score van 10. Deze kwetsbaarheid maakt het voor onbevoegden mogelijk om op afstand, zonder inloggegev...

  28. PAPILDINĀTS Uzbrucēji pastiprināti cenšas kompromitēt MikroTik maršrutētājus

    Novērota pastiprināta uzbrucēju aktivitāte, kas vērsta pret MikroTik maršrutētājiem (rūteriem), mēģinot tos kompromitēt. Nekavējoties jāuzstāda atjauninājumi izmantotajām MikroTik iekārtām.

    Announcement Cybersecurity
  29. Europol celebrates the International Day of Police Cooperation

    On 7 September, Europol is marking the International Day of Police Cooperation together with its partners to recognise the central role our network plays in tackling the most serious threats agains...

    Announcement Cybersecurity
  30. SI-CERT 2026-05 / Kritična ranljivost v MikroTik RouterOS – MikroTrick

    Veriga kritičnih ranljivosti v RouterOS omogoča popolno kompromitacijo MikroTik naprav, ki imajo dostopno SSH storitev. Ranljivosti se že izkorišča v napadih, zato priporočamo takojšnjo namestitev ...

    Announcement Cybersecurity
  31. MikroTik: rilevato sfruttamento in rete di nuove vulnerabilità

    MikroTik ha rilasciato aggiornamenti di sicurezza al fine di correggere 6 nuove vulnerabilità, di cui 2 con gravità “critica” e 2 con gravità “alta”. …

    Advisory Cybersecurity
  32. Active Exploitation of Vulnerability in NetScaler ADC and NetScaler Gateway

    Attackers are exploiting a critical vulnerability in NetScaler ADC and NetScaler Gateway. Patch immediately.

    Announcement Cybersecurity
  33. Critical N-able N-central Vulnerability and Active Exploitation

    UPDATE: Critical vulnerability in N-able N-central gives attackers unauthenticated, "god-mode" access to the RMM console.

    Cybersecurity 3 versions
  34. Podatności w oprogramowaniu Mikrotik RouterOS

    Zespół CERT Polska znalazł 6 podatności (od CVE-2026-67276 do CVE-2026-67279, CVE-2026-67281 oraz CVE-2026-86060) w oprogramowaniu Mikrotik RouterOS.

    Announcement Cybersecurity
  35. Krytyczne podatności w MikroTik RouterOS są aktywnie wykorzystywane. Zalecana pilna aktualizacja

    Zespół CERT Polska zidentyfikował i skoordynował ujawnienie sześciu podatności w MikroTik RouterOS, w tym dwóch krytycznych. Podatności te są już aktywnie wykorzystywane do przejmowania urządzeń, k...

    Announcement Cybersecurity
  36. OpenSSF at Hacker Summer Camp 2026: Black Hat & DEF CON Highlights and Recap

    Las Vegas was once again the center of the cybersecurity universe from August 1–9 for Black Hat and DEF CON 2026. The Open Source Security Foundation (OpenSSF) had a major presence throughout the w...

  37. Asset Recovery IT (ARIT)

    HO's Asset Recovery IT (ARIT) alpha assessment report

  38. Uzbrukumos izmantota ievainojamība Google Chrome

    Google Chrome pārlūkprogrammā ir atklāta ievainojamība CVE-2026-85046, kas  jau pirms drošības "ielāpa" publicēšanas tika aktīvi izmantota uzbrukumos.  Ievainojamība var ļaut izpildīt uzb...

    Announcement Cybersecurity
  39. Kwetsbaarheden in Google Chrome – voer updates uit

    Er zijn meerdere kwetsbaarheden gevonden in Google Chrome, specifiek in versie 152.0.7977.82. Deze kwetsbaarheden, waaronder CVE-2026-85042 en CVE-2026-85047, betreffen verschillende onderdelen van...

  40. DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

    A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy inst...

    Cybersecurity 2 versions
  41. Ruští aktéři cílí na uživatele Signalu. NÚKIB vydává analýzu a doporučení, jak si aplikaci zabezpečit

    Národní úřad pro kybernetickou a informační bezpečnost (NÚKIB) upozorňuje na cílené phishingové kampaně zaměřené na uživatele komunikační aplikace Signal. …

    Announcement Cybersecurity
  42. CERT-SE:s veckobrev v.36

    Den 13 september är det val i Sverige och Nationellt cybersäkerhetscenter (NCSC) bevakar hotläget från ett cybersäkerhetsperspektiv. NCSC:s chef John Billow berättar om uppdraget i Sveriges Radios ...

    Announcement Cybersecurity
  43. Angry Birds: Toy Ghouls’ new toys

    Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matr...

  44. Interinfo|DreamMaker - 2 Vulnerabilities

    Announcement Cybersecurity
  45. Managed EDR: What It Is & How to Choose a Provider

    Huntress breaks down what managed EDR is, how it differs from unmanaged, and what to look for when choosing a provider for your business.

    Cybersecurity 3 versions

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.