24h | 7d | 30d

Overview

  • Apple
  • macOS

06 Aug 2026
Published
17 Aug 2026
Updated

CVSS
Pending
EPSS
0.50%

KEV

Description

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

Statistics

  • 9 Posts
  • 8 Interactions

Last activity: 10 hours ago

Fediverse

Profile picture fallback

⚠️ Important security update for Mac users:

A vulnerability in macOS Screen Sharing (CVE-2026-65400) is being actively exploited.

If you use Screens or another VNC client app to remotely access a Mac, we strongly recommend updating macOS as soon as possible.

blog.edovia.com/CVE-2026-65400

support.apple.com/en-us/148170

  • 5
  • 3
  • 0
  • 17h ago
Profile picture fallback

Attackers actively exploit the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. Discover how to protect your Mac from root access and cryptominers.

meterpreter.org/macos-cve-2026

  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
  • 0
  • 0
  • 1
  • 11h ago
Profile picture fallback

Here's a summary of the latest geopolitical, technology, and cybersecurity news from the last 24-48 hours:

Cybersecurity: Apple patched a critical macOS Screen Sharing vulnerability (CVE-2026-65400) and issued mercenary spyware alerts across 110 countries. Microsoft's August Patch Tuesday fixed 421 vulnerabilities, including an actively exploited Windows zero-day (CVE-2026-68820). France reported a Bloctel data leak exposing three million phone numbers and a DGFiP tax data leak.

Technology: Massive tech layoffs continue in 2026, surpassing last year's totals, as companies shift to "AI-first" strategies; AI "inference" spending now exceeds "training". Elon Musk's SpaceX committed exclusively to NVIDIA GPUs, forming a major AI partnership.

Geopolitics: US-Iran tensions remain high over the Strait of Hormuz, with new threats and defense contracts emerging. Ukraine faces critical Patriot interceptor shortages, threatening its winter air defense.

#Cybersecurity #TechNews #Geopolitics

  • 0
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
CVE-2026-65400 in macOS Screen Sharing is being exploited to gain unauthorized access and deploy Monero miners, prompting urgent patching across multiple macOS versions.
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
macOS Screen Sharingの脆弱性CVE-2026-65400が実際のサイバー攻撃に悪用 rootアクセス後にMoneroマイナーを設置 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #cyberattack #セキュリティ
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
~Checkpoint~ Multiple vendors patch actively exploited critical flaws, while Lazarus and China-linked APTs target defense and government sectors. - IOCs: CVE-2026-68820, CVE-2026-65400, CVE-2026-71362 - #Ransomware #ThreatIntel #ZeroDay
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
~Cybergcca~ Canadian Cyber Centre digest: 7 advisories for IBM, Tenable, Dell, MS Edge, Citrix, Apple, SAP with multiple exploited CVEs. - IOCs: CVE-2026-8451, CVE-2026-8452, CVE-2026-65400 - #PatchNow #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • NetScaler
  • ADC

30 Jun 2026
Published
30 Jun 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.49%

KEV

Description

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

Statistics

  • 6 Posts
  • 34 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

CVE-2026-8452 in Netscaler is under active pray and spray exploitation - somebody popped my honeypot with it today. Three webshells, x.php, y.php and z.php

I don't think this one will be super impactful in terms of breach numbers as most orgs don't have SAML IDP enabled - you can check with the paths I posted above.

  • 4
  • 27
  • 0
  • 12h ago
Profile picture fallback

‼️ Detection Artifact Generator for Citrix NetScaler CVE-2026-8452

GitHub: github.com/watchtowrlabs/watch

  • 1
  • 1
  • 0
  • 17h ago
Profile picture fallback

Oof; if you're a NetScaler shop you probably want to be very sure you update for this one: labs.watchtowr.com/youre-back-

Pre-auth RCE is... yikes. Relatively low EPSS for now, but I wouldn't trust that with the CVSSv4 vectors in play: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L

  • 1
  • 0
  • 0
  • 18h ago
Profile picture fallback

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) labs.watchtowr.com/youre-back-

  • 0
  • 0
  • 0
  • Last hour

Bluesky

Profile picture fallback
Citrix NetScalerの事前認証RCE脆弱性(CVE-2026-8452)の悪用コードが公開される Citrix NetScaler Pre-Auth RCE CVE-2026-8452 Gets Public Exploit Code #DailyCyberSecurity (Aug 17) securityonline.info/citrix-netsc...
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
~Cybergcca~ Canadian Cyber Centre digest: 7 advisories for IBM, Tenable, Dell, MS Edge, Citrix, Apple, SAP with multiple exploited CVEs. - IOCs: CVE-2026-8451, CVE-2026-8452, CVE-2026-65400 - #PatchNow #ThreatIntel #Vulnerability
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • GitLab
  • GitLab

17 Aug 2026
Published
17 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.4)
EPSS
Pending

KEV

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Statistics

  • 6 Posts
  • 8 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback
  • 1
  • 4
  • 0
  • 13h ago
Profile picture fallback

‼️Critical GitLab vulnerability could let unauthenticated attackers delete public projects.

CVE-2026-19478 affects self-managed CE and EE under certain conditions. Fixes are in 19.2.4, 19.1.6, 19.0.8, and 18.11.11.

What admins need to know: thehackernews.com/2026/08/crit

  • 1
  • 1
  • 0
  • 1h ago
Profile picture fallback

Critical GitLab GraphQL Vulnerability CVE-2026-19478: Patch Now to Prevent Unauthenticated Project Modification

GitLab patched critical CVE-2026-19478, a CVSS 9.4 GraphQL flaw allowing unauthenticated attackers to modify or delete public projects

thecybersecguru.com/news/cve-2

  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback

CRITICAL: GitLab CE/EE (v18.2+ to 19.2.4) patched CVE-2026-19478, a code injection bug allowing unauthenticated data modification/deletion via GraphQL. CSRF (CVE-2026-19650) also fixed. Upgrade to safe versions ASAP. radar.offseq.com/threat/gitlab

  • 1
  • 0
  • 0
  • 1h ago
Profile picture fallback

GitLab patched CVE-2026-19478, a CVSS 9.4 GraphQL code injection flaw letting unauthenticated users alter or delete project data.

securityonline.info/gitlab-cve

  • 0
  • 0
  • 0
  • 8h ago

Bluesky

Profile picture fallback
📢 [VULN] GitLab - la faille qui a fait rouvrir une version morte CVE-2026-19478 1) GitLab a publié un correctif d'urgence le 17 août pour une faille CVSS 9,4 permettant de modifier ou supprimer projets publics et données utilisateur sans compte ni mot de passe, affectant les… #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • SAP_SE
  • SAP Commerce Cloud (Data Hub Adapter)

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.73%

KEV

Description

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Statistics

  • 5 Posts
  • 1 Interaction

Last activity: 4 hours ago

Fediverse

Profile picture fallback

📰 Critical SAP Commerce Cloud Flaw (CVE-2026-58231) Under Active Attack

Max-severity SAP Commerce Cloud flaw (CVE-2026-58231, CVSS 10.0) is under active attack just days after patch release. The unauthenticated RCE affects major e-commerce platforms. #SAP #RCE #PatchNow

🔗 cyber.netsecops.io/articles/cr

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

「SAP Commerce Cloudの脆弱性CVE-2026-58231が、パッチ適用後数日で悪用される試みの標的となる 」: #TheHackerNews

「SAP Commerce Cloudに影響を与える、最も深刻なセキュリティ脆弱性について、現在活発な悪用活動が行われています。

CVE-2026-58231 として追跡されているこの脆弱性は、 CVSSスコアリングシステムで10.0と評価されています。これは、認証チェックと入力検証が不十分なケースに関連しています。

CVE.orgによると、「SAP Commerce Cloudでは、認証されていない攻撃者がデフォルトの認証クライアントを悪用し、十分な検証が行われていない特定の機能に特別に細工された入力を送信できる」とのことです。

「脆弱性を悪用されると、任意のコード実行が可能になり、内部コンポーネントが侵害される可能性があり、アプリケーションの機密性、完全性、可用性に重大な影響を与える可能性があります。」 」

thehackernews.com/2026/08/sap-

#prattohome

  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback

“A maximum-severity bug in SAP Commerce Cloud was exploited in the wild, research group Defused posted on X Aug. 14.

The 10.0 bug — CVE-2026-58231 — was described as having insufficient authorization checks and input validation and was earlier patched by SAP on Aug. 11.”

scworld.com/news/critical-sap-

  • 0
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
  • 1
  • 0
  • 0
  • 21h ago
Profile picture fallback
CVE-2026-58231 in SAP Commerce Cloud (CVSS 10.0) is actively exploited, enabling unauthenticated abuse leading to arbitrary code execution and full compromise risk.
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • ray-project
  • ray

26 Nov 2025
Published
18 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.37%

Description

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack against the browser, and this vulnerability is exploitable against a developer running Ray who inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This issue has been patched in version 2.52.0.

Statistics

  • 4 Posts
  • 2 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CISA confirms CVE-2025-62593, a Ray code injection RCE, is exploited in the wild. A public PoC targets Firefox and Safari.

securityonline.info/cve-2025-6

  • 1
  • 0
  • 0
  • 17h ago
Profile picture fallback

🚨 NEW CISA KEV: CVE-2025-62593 - Ray. Active RCE weaponization via DNS rebinding targeting developers on Firefox/Safari. Vendor patch 2.52.0 is mandatory. Get the full T-Suite brief & SOC detection queries to secure your Precinct Hybrid architecture. Command the wire. Link below 👇
thecybermind.co/jily

  • 0
  • 0
  • 0
  • 15h ago

Bluesky

Profile picture fallback
~Cisa~ CISA added CVE-2025-62593, a Ray-Project Ray code injection flaw, to its KEV catalog due to active exploitation. - IOCs: CVE-2025-62593 - #CVE-2025-62593 #Ray #ThreatIntel
  • 1
  • 0
  • 0
  • 18h ago
Profile picture fallback
CISAが既知の悪用された脆弱性を1件カタログに追加 CISA Adds One Known Exploited Vulnerability to Catalog #CISA (Aug 17) CVE-2025-62593 Ray-Project Ray コードインジェクションの脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 7h ago

Overview

  • wpmudev
  • Forminator Forms – Contact Form, Payment Form & Custom Form Builder

18 Aug 2026
Published
18 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
Pending

KEV

Description

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

Statistics

  • 4 Posts
  • 2 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Achtung #WordPress #Admins! Kritische Sicherheitslücke

In Forminator Forms (bis v1.56.1) und Royal Elementor Addons wurden teils kritische Schwachstellen entdeckt.

🔥 Forminator Forms (CVE-2026-15748, CVSS 9.8):
Angreifer können fehlerhafte MIME-Type-Prüfungen umgehen, beliebige Dateien hochladen und Remote Code ausführen (>600k Sites betroffen).

Handlungsbedarf: Umgehend auf Version 1.56.2 oder neuer updaten!

#WordPress #CyberSecurity #ITSicherheit #InfoSec #SecurityAlert #WordPressPlugin

  • 1
  • 1
  • 0
  • 3h ago
Profile picture fallback

「Forminator WordPressの脆弱性により、悪意のあるPHPファイルのアップロードを介して認証なしのリモートコード実行が可能になる 」: #TheHackerNews

「0万件以上のインストール実績を持つWordPressプラグイン「Forminator Forms」に、重大なセキュリティ上の欠陥が発見された。この欠陥を悪用すれば、脆弱性のあるサイトで任意のコードを実行できる可能性がある。

CVE-2026-15748 として追跡されているこの脆弱性は 、CVSSスコアリングシステムで10点満点中9.8点と評価されている。この脆弱性は、「daroo」というオンライン上のニックネームを持つセキュリティ研究者によって発見され、報告された。

thehackernews.com/2026/08/form

#prattohome

  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback

CVE-2026-15748 (CRITICAL, CVSS 9.8): wpmudev Forminator Forms for WordPress up to 1.56.1 lets unauthenticated attackers upload dangerous files via handle_file_upload, risking remote code execution. Patch urgently: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

14 Jul 2026
Published
17 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
3.97%

KEV

Description

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Statistics

  • 2 Posts
  • 10 Interactions

Last activity: 19 hours ago

Fediverse

Profile picture fallback

CVE-2026-55040: bypass di autenticazione in SharePoint sotto attacco attivo, ecco come proteggersi
#tech
spcnet.it/cve-2026-55040-bypas
@informatica

  • 8
  • 0
  • 0
  • 20h ago

Bluesky

Profile picture fallback
✨ CVE-2026-55040: bypass di autenticazione in SharePoint sotto attacco attivo, ecco come proteggersi Leggi il blog: spcnet.it/cve-2026-550...
  • 1
  • 1
  • 0
  • 19h ago

Overview

  • Microsoft
  • Microsoft Malware Protection Engine

14 Aug 2026
Published
18 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.24%

KEV

Description

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

Statistics

  • 2 Posts
  • 27 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

ShieldBreak appears to be CVE-2026-69414 ht @wdormann msrc.microsoft.com/update-guid

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

  • 6
  • 21
  • 0
  • 18h ago

Overview

  • jahlives
  • openssl_encrypt

17 Aug 2026
Published
17 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and determinism. Attackers can exploit predictable key derivation with identical inputs to weaken cryptographic security against multi-target attacks.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 9 hours ago

Fediverse

Profile picture fallback

CVE-2026-74889 - Critical crypto weakness in openssl_encrypt <1.4.0. HKDF with no salt/static info weakens key derivation, enabling multi-target attacks. CVSS 9.8. Update immediately. #CVE #cryptography #infosec

valtersit.com/cve/CVE-2026-748

  • 2
  • 1
  • 0
  • 9h ago

Overview

  • COMFAST
  • CF-N1-S

18 Aug 2026
Published
18 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
Pending

KEV

Description

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid of the component CGI Interface. This manipulation of the argument ssid causes os command injection. Remote exploitation of the attack is possible. The exploit has been published and may be used.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CVE-2026-75094: CRITICAL OS command injection in COMFAST CF-N1-S v2.6.0.1. Exploit code is public, no official patch. Restrict access to /cgi-bin/mbox-config to reduce risk. Details: radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 7h ago
Showing 1 to 10 of 48 CVEs