Aggregator
CVE-2026-33186 | grpc grpc-go up to 1.79.2 improper authorization (EUVD-2026-13830 / Nessus ID 303458)
CVE-2026-4800 | Lodash up to 4.17.x Parameter Function options.imports code injection (GHSA-35jh-r3h4-6jhm / Nessus ID 304625)
CVE-2025-54574 | Squid Web Proxy up to 6.3 URN heap-based overflow (GHSA-w4gv-vw3f-29g3 / Nessus ID 253521)
CVE-2026-34986 | go-jose up to 3.0.4/4.1.3 on JSON cipher.KeyUnwrap uncaught exception (Nessus ID 306612 / WID-SEC-2026-1268)
Используете Kaspersky или другой антивирус? Поздравляем — Vidar v1.5 знает их по именам и подстраивается под вашу защиту
G.O.S.S.I.P 阅读推荐 2026-05-20 OffensiveCon 2026 小结
正版软件 5 月折扣:Fences / Groupy / Start11 / GoodSync / Office 等…
Carding site B1ack’s Stash dumps 4.6 Million stolen cards for free
Carding site B1ack’s Stash dumps 4.6 Million stolen cards for free
威胁情报|Shai-Hulud 供应链投毒:云凭据窃取与自我扩散分析
威胁情报|Shai-Hulud 供应链投毒:云凭据窃取与自我扩散分析
Yahoo, Apple и китайские хакеры. Twill Typhoon прячет вирусы за вывесками IT-гигантов, чтобы оставаться невидимой
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2008-4250 Microsoft Windows Buffer Overflow Vulnerability
- CVE-2009-1537 Microsoft DirectX NULL Byte Overwrite Vulnerability
- CVE-2009-3459 Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
- CVE-2010-0249 Microsoft Internet Explorer Use-After-Free Vulnerability
- CVE-2010-0806 Microsoft Internet Explorer Use-After-Free Vulnerability
- CVE-2026-41091 Microsoft Defender Elevation of Privilege Vulnerability
- CVE-2026-45498 Microsoft Defender Denial of Service Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.