Meldingen
420 meldingen uit primaire bronnen. Filter op ernst, type of vendor, of zoek op een CVE-nummer of productnaam. Bulkpublicaties (BSI-updates, Patch Tuesday) staan als één regel.
Koppelen
Zet de feed in je RSS-lezer, of in Slack (/feed subscribe) of Teams (RSS-connector), dan komen nieuwe meldingen vanzelf in je teamkanaal.
Liever zelf bouwen? Dezelfde selectie als JSON, of de volledige API-specificatie (OpenAPI).
Kwetsbaarheden verholpen in Oracle Database Producten
Oracle heeft 16 kwetsbaarheden verholpen in diverse Database producten, waaronder Database Server, Autonomous Health Framework en Application Testing Suite. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle-producten, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwa
30middelValse telefoontjes met eigen telefoonnummer
We ontvangen meldingen van mensen die aangeven gebeld te zijn door hun eigen telefoonnummer. Wie opneemt hoort of niets of... Het bericht Valse telefoontjes met eigen telefoonnummer verscheen eerst…
5laagSecuring the unpatchable in an age of AI-driven vulnerabilities
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous…
0laagAtomic macOS (AMOS) Stealer Activity
Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared…
0laagZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this…
11 meldingen van Zero Day Initiative op één dag. Toon alle 11
15laagCVE-2026-58704: Google Pixel Improper Authorization Vulnerability
Google Pixel devices contain an improper authorization vulnerability in the cellular modem. A logic error may allow an attacker to bypass permission checks and escalate privileges. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security
48hoogCVE-2026-76460: Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Vereiste actie: Appl
75kritiekCVE-2026-87886: Acronis Backup Incorrect Default Permissions Vulnerability
Acronis Backup plugin for cPanel & WHM and extension for Plesk contains an incorrect default permissions vulnerability that could allow for privilege escalation. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Ri
48hoogCisco Integrated Management Controller Argument Injection Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the…
8laagCisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials…
8laagIranian cyber targeting of dissidents, activists and journalists
Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.
0laagUK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists
UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.
0laagCisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive…
15laagUnmasking Cloud Identities: From Behavioral Clustering to Automated Detection
We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From…
0laagZDI-26-702: Linux Kernel usbnet Driver Race Condition Privilege Escalation Vulnerability
This vulnerability allows physically present attackers to escalate privileges on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. The ZDI has…
0laagZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on…
15laagCVE-2026-76461: Cisco Secure Email Gateway SQL Injection Vulnerability
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuri
65hoogKritieke kwetsbaarheid in GitLab wordt actief misbruikt: update nu
Er is een kritieke kwetsbaarheid in GitLab Community Edition en Enterprise Edition gevonden met het kenmerk CVE-2026-85706. De kwetsbaarheid heeft een CVSS-score van 10.0 en wordt actief misbruikt. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en adviseert om zo snel mogelijk beveiligingsupdat
80kritiek- 0laag
- 0laag
- 0laag
- 0laag
- 0laag
- 0laag
- 5laag
CVE-2026-42018: JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance
48hoogCVE-2026-84869: ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to transfer and execute files through an active remote session without authorization or host confirmation. Vereiste actie: Apply mitigations in accordance with vendor instructions
55hoogCVE-2026-42016: JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory contains an incorrect authorization vulnerability that leads to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Vereiste actie: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioriti
48hoogCVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API. Vereiste actie: Apply mitigations in accordance with vendor instr
75kritiekWe've got one word for it, and it's usually the wrong one
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address…
52hoog