Aggregator
«Вас вызывают на ковер». Гениальный способ красть аккаунты придумали хакеры — и жертвы сами отдают пароли
Webinar: Why modern attacks require both security and recovery
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-6973 Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Google Chrome Accused of Silently Installing 4GB AI Model on User Devices
白签藏锋|银狐团伙近白利用与非 PE 载荷藏匿分析报告
CVE-2026-42459 | Free5GC Error Message api_subscriberdatamanagement.go information disclosure
CVE-2026-42596 | gotenberg 8.1.0/8.31.0 downloadFrom/webhook server-side request forgery
CVE-2026-44001 | vm2 up to 3.10.5 denial of service
CVE-2026-42586 | Redis Codec Encoder crlf injection
CVE-2026-3953 | Gosoft Proticaret E-Commerce 6.0 cross site scripting
CVE-2026-27415 | PluginUs BEAR Plugin up to 1.1.5 on WordPress cross-site request forgery (EUVD-2026-28343)
CVE-2026-33588 | Open Notebook up to 1.8.3 Docker Container path traversal (GHSA-x4q2-89g5-594v / EUVD-2026-28347)
CVE-2026-33589 | Open Notebook up to 1.8.3 Docker Container input validation (GHSA-842v-h4cj-r646 / EUVD-2026-28348)
CVE-2026-28201 | Open Notebook up to 1.8.2 cross-domain policy (GHSA-5wj9-f8q5-8f9c / EUVD-2026-28345)
WatchGuard Agent Vulnerabilities Let Attackers Grant Full SYSTEM Privileges on Windows
WatchGuard has released urgent security updates to address multiple high-severity vulnerabilities affecting the WatchGuard Agent on Windows. The most critical of these flaws allows authenticated local attackers to escalate their privileges to the highest system level, granting them complete control over the compromised machine. Additional vulnerabilities discovered in the software include network-based buffer overflows that […]
The post WatchGuard Agent Vulnerabilities Let Attackers Grant Full SYSTEM Privileges on Windows appeared first on Cyber Security News.
CVE-2026-6805 | Ercom Cryptobox up to 4.37.x/4.40.182 insufficient permissions or privileges (EUVD-2026-28342)
CVE-2026-33587 | NotebookOpen Notebook up to 1.8.3 Docker Container special elements used in a template engine (GHSA-f35w-wx37-26q7 / EUVD-2026-28346)
Critical Redis Vulnerabilities Enables Remote Code Execution Attacks
Five dangerous vulnerabilities in Redis expose Redis Cloud, Redis Software, and all open-source community editions to potential remote code execution, giving authenticated attackers a direct path to compromise affected systems. All require authenticated access to exploit, but successful exploitation can lead to arbitrary code execution, full system compromise, data exfiltration, or service disruption. The advisory, […]
The post Critical Redis Vulnerabilities Enables Remote Code Execution Attacks appeared first on Cyber Security News.