Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology ... Read more
Published Date: Aug 24, 2026 (3 days, 1 hour ago)Vulnerabilities has been mentioned in this article.
CVE-2026-58231 CVE-2022-27925 CVE-2022-0995 CVE-2022-0847 CVE-2021-23758 CVE-2021-21551 CVE-2021-29442 CVE-2021-29441 CVE-2021-3156 CVE-2019-18935 CVE-2019-16098 CVE-2015-5287 CVE-2015-3246 CVE-2010-3904Microsoft disclosed and fixed a maximum-severity remote code execution vulnerability in Entra ID, its cloud identity platform, on August 20, then quietly reversed the advisory’s exploitation status a ... Read more
Published Date: Aug 24, 2026 (2 days, 21 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-69836 CVE-2026-19478Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Win ... Read more
Published Date: Aug 21, 2026 (5 days, 1 hour ago)Vulnerabilities has been mentioned in this article.
CVE-2021-24092Microsoft disclosed on Thursday that a maximum-severity remote code execution vulnerability in Entra ID, the identity service underpinning Microsoft 365, Azure and Dynamics 365, was exploited in the w ... Read more
Published Date: Aug 21, 2026 (5 days ago)Vulnerabilities has been mentioned in this article.
CVE-2026-69836 CVE-2026-19478 CVE-2025-55241This weekly roundup highlights a broad range of cybersecurity threats affecting government agencies, businesses, enterprise AI systems, and software platforms. From a major French tax authority breach ... Read more
Published Date: Aug 21, 2026 (5 days, 1 hour ago)Vulnerabilities has been mentioned in this article.
CVE-2026-19650 CVE-2026-19478The Good | U.S. Charges Iranian Cyberattackers Over Mass Intellectual Property Theft The U.S. Justice Department has indicted 17 Iranian nationals associated with the Mabna Institute, a state-sponsore ... Read more
Published Date: Aug 21, 2026 (4 days, 22 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-33824Microsoft waarschuwt organisaties voor misbruik van een kritieke kwetsbaarheid in Entra ID waar aanvallers actief misbruik van maken. Er is een beveiligingsupdate uitgebracht om het probleem te verhel ... Read more
Published Date: Aug 21, 2026 (4 days, 22 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-69836Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabi ... Read more
Published Date: Aug 21, 2026 (4 days, 7 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-20359 CVE-2026-20358 CVE-2026-20357 CVE-2026-20319 CVE-2026-20318 CVE-2026-20317 CVE-2026-20315 CVE-2026-20231 CVE-2026-20030 CVE-2026-20349A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4) ... Read more
Published Date: Aug 21, 2026 (4 days, 8 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-19478Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as C ... Read more
Published Date: Aug 21, 2026 (4 days, 9 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-69836 CVE-2026-68820Cloud Software Group has released security updates for NetScaler ADC and NetScaler Gateway addressing two vulnerabilities, including a critical authentication-bypass flaw rated CVSS 9.3.The more serio ... Read more
Published Date: Aug 21, 2026 (4 days, 11 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-19490 CVE-2026-19489A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do.Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header chec ... Read more
Published Date: Aug 20, 2026 (4 days, 17 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-43774 CVE-2026-52813 CVE-2026-52810 CVE-2026-33696A Five-Vulnerability Warning: From AI Infrastructure to Virtualization and Enterprise CollaborationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five vulnerabilities to i ... Read more
Published Date: Aug 20, 2026 (4 days, 19 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-65400 CVE-2026-59310 CVE-2026-55040 CVE-2026-33824 CVE-2025-62593Een kritieke kwetsbaarheid in de populaire WordPress-plug-in Elementor Pro maakt het mogelijk voor ongeauthenticeerde aanvallers om WordPress-sites volledig over te nemen. Via het beveiligingslek kan ... Read more
Published Date: Aug 20, 2026 (4 days, 20 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-32475Een kritieke kwetsbaarheid in Citrix NetScaler ADC en Citrix NetScaler Gateway kan ongeauthenticeerde aanvallers toegang tot het systeem geven. Er zijn beveiligingsupdates uitgebracht om het probleem ... Read more
Published Date: Aug 20, 2026 (4 days, 19 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-19490Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the ... Read more
Published Date: Aug 20, 2026 (4 days, 19 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-19490 CVE-2026-19489 CVE-2026-8451A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerabili ... Read more
Published Date: Aug 20, 2026 (4 days, 19 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-73570 CVE-2025-66376Een kritieke kwetsbaarheid in AI-platform MLflow wordt misbruikt bij aanvallen, zo meldt het Amerikaanse cyberagentschap CISA. MLflow is een open source 'AI engineering platform' voor het ontwikkelen, ... Read more
Published Date: Aug 20, 2026 (4 days, 5 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-64849Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the ... Read more
Published Date: Aug 20, 2026 (4 days, 3 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-14456Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacke ... Read more
Published Date: Aug 20, 2026 (4 days ago)Vulnerabilities has been mentioned in this article.
CVE-2026-71289 CVE-2026-71214 CVE-2026-60112 CVE-2026-47731 CVE-2024-35058Vulnerabilities in ATutor software CVE ID CVE-2026-64960 Publication date 20 August 2026 Vendor ATutor Product ATutor Vulnerable versions 2.2.4 Vulnerability type (CWE) Unrestricted upload of file wit ... Read more
Published Date: Aug 20, 2026 (4 days ago)Vulnerabilities has been mentioned in this article.
De Poolse overheid waarschuwt voor misbruik van een beveiligingslek in Zimbra waardoor ongeauthenticeerde aanvallers commando's en code op mailservers kunnen uitvoeren. Er is daarbij geen enkele inter ... Read more
Published Date: Aug 20, 2026 (4 days, 1 hour ago)Vulnerabilities has been mentioned in this article.
CVE-2026-73570Een kritieke kwetsbaarheid in GitLab, de populaire online DevOps-tool voor het ontwikkelen van software, wordt twee dagen na het uitkomen van de beveiligingsupdate al misbruikt bij aanvallen. Dat laat ... Read more
Published Date: Aug 20, 2026 (4 days ago)Vulnerabilities has been mentioned in this article.
CVE-2026-19478Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, track ... Read more
Published Date: Aug 20, 2026 (4 days, 3 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-32475 CVE-2026-65640Een kritieke kwetsbaarheid in de Windows Internet Key Exchange (IKE)-extensie, die remote code execution op Windowssystemen mogelijk (RCE) maakt, wordt misbruikt bij aanvallen. Dat meldt het Amerikaan ... Read more
Published Date: Aug 19, 2026 (4 days, 21 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-33824Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two auth ... Read more
Published Date: Aug 19, 2026 (2 days, 7 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2025-31702 CVE-2024-39943 CVE-2021-33045 CVE-2021-33044The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited i ... Read more
Published Date: Aug 19, 2026 (2 days, 5 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-65400 CVE-2026-59310 CVE-2026-55040 CVE-2026-33824Vulnerabilities in nnn software CVE ID CVE-2026-65609 Publication date 19 August 2026 Vendor nnn Product nnn Vulnerable versions 5.2 Vulnerability type (CWE) Out-of-bounds write (CWE-787) Report sourc ... Read more
Published Date: Aug 19, 2026 (2 days, 4 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-65612 CVE-2026-65611 CVE-2026-65610 CVE-2026-65609De Australische overheid waarschuwt bedrijven voor aanvallen op N-central RMM-servers, waarbij misbruik wordt gemaakt van twee kwetsbaarheden waarvoor beveiligingsupdates beschikbaar zijn. N-central i ... Read more
Published Date: Aug 19, 2026 (2 days, 4 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-18577 CVE-2026-18556GitLab has patched two security flaws, including CVE-2026-19478, a critical code injection vulnerability that could allow unauthenticated attackers to remotely modify or delete public projects and use ... Read more
Published Date: Aug 19, 2026 (2 days, 5 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-19650 CVE-2026-19478 CVE-2026-21858A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Ma ... Read more
Published Date: Aug 19, 2026 (2 days, 7 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-12569 CVE-2023-34362 CVE-2021-27101GitLab has released an ad-hoc critical security patch for its Community Edition (CE) and Enterprise Edition (EE), addressing a critical GraphQL-related vulnerability that could allow an unauthenticat ... Read more
Published Date: Aug 19, 2026 (2 days, 8 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-19650 CVE-2026-19478Varonis Threat Labs has disclosed three vulnerabilities in Microsoft Copilot Personal that it said could allow a single click on a crafted link to silently pull data from connected apps and other info ... Read more
Published Date: Aug 18, 2026 (2 days, 15 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-24301 CVE-2026-24299Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and ... Read more
Published Date: Aug 18, 2026 (2 days, 11 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-64849 CVE-2026-25939 CVE-2026-25895 CVE-2023-33831Microsoft heeft een kritieke kwetsbaarheid in AI-assistent Copilot verholpen waardoor informatie kon lekken. Het beveiligingslek werd gevonden door cybersecuritybedrijf Varonis, dat het probleem 'CoSn ... Read more
Published Date: Aug 18, 2026 (2 days, 14 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-24301Vulnerability in Carbone software CVE ID CVE-2026-18929 Publication date 18 August 2026 Vendor Carbone Product Carbone Vulnerable versions All before 3.8.2 Vulnerability type (CWE) Improper handling o ... Read more
Published Date: Aoû 18, 2026 (2 jours, 10 heures ago)Vulnerabilities has been mentioned in this article.
CVE-2026-18929dinsdag 18 augustus 2026, 10:20 door Redactie, 1 reactiesLaatst bijgewerkt: Vandaag, 12:02 Een kritieke kwetsbaarheid in Citrix NetScaler ADC en Citrix NetScaler Gateway die remote code execution (RCE ... Read more
Published Date: Aug 18, 2026 (2 days, 8 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-8452Apple heeft beveiligingsupdates voor iOS, iPadOS en macOS uitgebracht die meerdere kwetsbaarheden verhelpen, waaronder een beveiligingslek dat het uitvoeren van willekeurige code maakt bij het verwerk ... Read more
Published Date: Aug 18, 2026 (2 days, 7 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-65346The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitat ... Read more
Published Date: Aug 18, 2026 (2 days, 8 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2025-62593GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauth ... Read more
Published Date: Aug 17, 2026 (2 days, 17 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-19650 CVE-2026-19478A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on suscepti ... Read more
Published Date: Aug 17, 2026 (2 days, 20 hours ago)Vulnerabilities has been mentioned in this article.
This year has seen a real boom in ClickFix attacks. It’s such a hit with criminals that we barely finish writing about one variation before it’s time to cover the next. This time, attackers are target ... Read more
Published Date: Aoû 17, 2026 (2 jours, 20 heures ago)Vulnerabilities has been mentioned in this article.
CVE-2025-59489The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems ... Read more
Published Date: Aoû 17, 2026 (2 jours, 23 heures ago)Vulnerabilities has been mentioned in this article.
MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is running. As more org ... Read more
Published Date: Aoû 17, 2026 (3 jours ago)Vulnerabilities has been mentioned in this article.
CVE-2025-6514Vulnerability in OutSystems Service Center software CVE ID CVE-2026-40126 Publication date 17 August 2026 Vendor OutSystems Product Service Center Vulnerable versions All before 11.41.2 Vulnerability ... Read more
Published Date: Aug 17, 2026 (2 days, 23 hours ago)Vulnerabilities has been mentioned in this article.
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, wit ... Read more
Published Date: Aug 17, 2026 (2 days, 23 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2025-31718 CVE-2022-20210Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn inte ... Read more
Published Date: Aug 17, 2026 (2 days, 23 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2025-10123 CVE-2025-55583 CVE-2025-1974 CVE-2024-10914 CVE-2024-4577 CVE-2024-29269 CVE-2023-1389 CVE-2022-37055 CVE-2022-26134 CVE-2022-30525 CVE-2021-46422 CVE-2022-29464 CVE-2021-36260 CVE-2020-10987 CVE-2019-14931 CVE-2018-14558 CVE-2016-6277 CVE-2007-3010Ruim tweeduizend installaties van Metabase, waaronder zo'n vijftig in Nederland, missen een beveiligingsupdate voor een actief aangevallen kwetsbaarheid. Dat meldt The Shadowserver Foundation op basis ... Read more
Published Date: Aug 17, 2026 (3 days, 1 hour ago)Vulnerabilities has been mentioned in this article.
CVE-2026-72898Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve ... Read more
Published Date: Aug 17, 2026 (2 days, 5 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-59310 CVE-2026-59309Microsoft werkt aan een beveiligingsupdate voor een kwetsbaarheid in Microsoft Defender, de in Windows ingebouwde antivirussoftware. Via het beveiligingslek, genaamd 'ShieldBreak', kan een aanvaller d ... Read more
Published Date: Aug 17, 2026 (2 days, 5 hours ago)Vulnerabilities has been mentioned in this article.
CVE-2026-69414