24h | 7d | 30d

Overview

  • Apple
  • macOS

06 Aug 2026
Published
15 Aug 2026
Updated

CVSS
Pending
EPSS
0.50%

KEV

Description

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

Statistics

  • 4 Posts
  • 2 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public explo…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
Nizozemské centrum NCSC varuje před aktivním zneužíváním kritické chyby v systému sdílení obrazovky macOS (CVE-2026-65400). Útočníci využívají port 5900 k získání root přístupu
  • 0
  • 1
  • 0
  • 16h ago
Profile picture fallback
macOS Screen Sharing vulnerability (CVE-2026-65400) exploited. Attackers gained root access via exposed port 5900, deploying Monero miners. Apple released an update Aug 6. If you can't update, disable Screen Sharing ASAP. Stay safe! #crypto #blockchain #news
  • 0
  • 1
  • 0
  • 12h ago
Profile picture fallback
Critical macOS screen sharing bug CVE-2026-65400 gives root password. CISA 9.8! Disable sharing restrict access patch now! #MacSecurity #CyberAttack #CVE2026 #RootAccess #PatchNow
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Metabase
  • Metabase

10 Aug 2026
Published
12 Aug 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
10.40%

Description

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 2 hours ago

Bluesky

Profile picture fallback
We are also scanning & reporting Metabase IPs likely unpatched to CVE-2026-72898 SQLi, which is exploited in the wild & on @CISACyber KEV. 2171 unpatched (version check) instances seen 2026-08-15. Top: US (603), Germany (278) Dashboard World Map stats: dashboard.shadowserver.org/statistics/c...
  • 0
  • 1
  • 0
  • 4h ago
Profile picture fallback
IP Data in our Vulnerable HTTP reporting tagged 'cve-2026-72898' : www.shadowserver.org/what-we-do/n... (since 2026-08-11) NVD entry: nvd.nist.gov/vuln/detail/... Metabase advisory & patch info: github.com/metabase/met...
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
MetabaseのSQLインジェクションの脆弱性(CVE-2026-72898)に関する注意喚起 #JPCERTCC (Aug 14) www.jpcert.or.jp/at/2026/at26...
  • 0
  • 0
  • 0
  • 3h ago
Profile picture fallback
JPCERT/CC、MetabaseのSQLインジェクション 脆弱性 CVE-2026-72898に注意喚起 ゼロデイ悪用とPoC公開を確認 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #脆弱性
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
14 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.14%

KEV

Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Statistics

  • 3 Posts

Last activity: 1 hour ago

Fediverse

Profile picture fallback

2026-W33 — Weekly Threat Roundup

🔥 VMware vCenter RCE (CVE-2026-59310) under active APT exploitation across 47 countries, patch and hunt for persistence now.
🤖 Near-autonomous AI cyberattack observed against Taiwan's government, adapting mid-operation without human direction.
💀 Lazarus Group's Operation Dream Job exploits Windo…

threatnoir.com/weekly/2026-w33

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback

vCenter Flaw Exploited Just Five Days After Disclosure infosecurity-magazine.com/news

  • 0
  • 0
  • 0
  • 12h ago

Bluesky

Profile picture fallback
VMware vCenterのCVE-2026-59310が実際のサイバー攻撃に悪用 47カ国361 IPで侵害確認、reverse_sshで永続化 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #cyberattack #セキュリティ
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • SAP_SE
  • SAP Commerce Cloud (Data Hub Adapter)

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.73%

KEV

Description

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Statistics

  • 2 Posts

Last activity: 10 hours ago

Fediverse

Profile picture fallback

En las últimas 24 horas, se desmanteló una red que usaba deepfakes para fraudes digitales, mientras Shell investiga una filtración vinculada a ransomware Cl0p y Francia sufre el robo de datos de 678,000 ciudadanos; por si fuera poco, una grave vulnerabilidad en SAP Commerce Cloud y fallas en e-commerce aumentan riesgos, destacando la urgencia de fortalecer redes con tecnologías innovadoras y defensa proactiva. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 16/08/26 📆 |====

🔍 CIBERCRIMINAL DETENIDO POR USAR DEEPFAKES PARA OBTENER CERTIFICADOS DIGITALES

La Policía Nacional logra detener a un delincuente que explotaba imágenes manipuladas con inteligencia artificial para engañar sistemas y obtener certificados digitales mediante una vulnerabilidad (glitch). Este caso subraya la creciente amenaza que representa el uso de tecnologías deepfake en delitos informáticos, y la urgencia de fortalecer mecanismos de verificación digital para proteger la identidad y la información sensible.

Descubre cómo se detectó y desarticuló esta sofisticada técnica aquí 👉 djar.co/msVFp

🛢️ SHELL INVESTIGA FILTRACIÓN DE DATOS A TRAVÉS DEL RANSOMWARE CLOP

La multinacional energética Shell confirma una investigación en marcha tras una filtración de datos vinculada al ransomware Cl0p. Este incidente evidencia la persistencia y evolución de los ataques mediante ransomware, que no solo cifran información sino que también exponen datos sensibles para presionar a las víctimas.

Conoce los detalles y recomendaciones para mitigar este tipo de ataques aquí 👉 djar.co/WE55v

🇫🇷 CIBERATAQUE A LA DGFiP: ROBO DE DATOS DE 678,000 PERSONAS EN FRANCIA

La Dirección General de Finanzas Públicas de Francia sufrió un ataque que comprometió datos personales de más de seiscientos setenta y ocho mil particulares y profesionales. Este caso enfatiza la necesidad crítica de actualizar y reforzar la protección en entidades públicas para evitar brechas que pongan en riesgo información fiscal y personal.

Infórmate de las consecuencias y medidas adoptadas aquí 👉 djar.co/k58ON5

🛒 VULNERABILIDADES EN PLATAFORMAS DE COMERCIO ELECTRÓNICO Y CÓMO PROTEGERTE

Análisis profundo sobre recientes fallas de seguridad detectadas en plataformas de venta online, un objetivo frecuente de ciberataques. El boletín ofrece las mejores prácticas para proteger datos de usuarios, evitar fraudes y garantizar transacciones seguras, crucial para consumidores y administradores de tiendas digitales.

Aprende a blindar tu tienda online y proteger tu información aquí 👉 djar.co/H4Qf7s

⚠️ EXPLOIT CRÍTICO EN SAP COMMERCE CLOUD: CVE-2026-58231

Se detectó una vulnerabilidad de máxima gravedad en SAP Commerce Cloud solo días después de que se publicara el parche correspondiente. Este fallo permite la ejecución de código malicioso, poniendo en peligro la integridad y confidencialidad de las plataformas empresariales basadas en SAP.

Consulta cómo proteger tu sistema y aplicar la actualización aquí 👉 djar.co/uejO

🌐 SEGURIDAD EN REDES: TÉCNICAS AVANZADAS CONTRA AMENAZAS SOFISTICADAS

Una guía especializada que aborda métodos modernos para el análisis de tráfico y la defensa proactiva frente a ataques complejos en redes corporativas. Se destacan herramientas y estrategias para anticipar movimientos del atacante y fortalecer la infraestructura ante amenazas persistentes y avanzadas.

Descubre cómo mejorar la seguridad de tu red con estas prácticas clave aquí 👉 djar.co/MJaRSN

🚀 TECNOLOGÍAS QUE REVOLUCIONAN LA CIBERSEGURIDAD EN 2023

Explora las innovaciones más relevantes que están transformando la protección digital, como la inteligencia artificial aplicada a detección de intrusiones, el aprendizaje automático para análisis predictivo y la implementación de arquitecturas zero trust. Esta evolución tecnológica redefine las defensas frente a los ataques cada vez más sofisticados.

Conoce las tendencias que marcan el futuro de la ciberseguridad aquí 👉 djar.co/lksjg

  • 0
  • 0
  • 0
  • 14h ago
Profile picture fallback

📰 Critical SAP Commerce Cloud Flaw (CVE-2026-58231) Under Active Attack

Max-severity SAP Commerce Cloud flaw (CVE-2026-58231, CVSS 10.0) is under active attack just days after patch release. The unauthenticated RCE affects major e-commerce platforms. #SAP #RCE #PatchNow

🔗 cyber.netsecops.io/articles/cr

  • 0
  • 0
  • 0
  • 10h ago

Overview

  • siyuan-note
  • siyuan

16 Aug 2026
Published
16 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
Pending

KEV

Description

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware. The middleware accepts the API token (Conf.Api.Token) via an Authorization header (Token/Bearer) or a ?token= query parameter, and neither path is protected by the application's CAPTCHA/lockout mechanism (NeedCaptcha/WrongAuthCount). As a result, an unauthenticated remote attacker can perform unlimited automated guesses of the API token, particularly when a short or weak custom token has been configured, and upon success gains full RoleAdministrator access enabling arbitrary file operations and SQL queries.

Statistics

  • 2 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

siyuan-note siyuan (kernel <3.7.4) hit by CRITICAL vuln: CVE-2026-73056 allows unlimited API token brute-forcing via CheckAuth(). Weak tokens = full admin takeover. Update & review tokens! 🔑 radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

CVE-2026-73056 - Critical auth bypass in SiYuan kernel <3.7.4. Unauthenticated attackers can brute-force API tokens via CheckAuth() middleware, no lockout. CVSS 9.8. Update immediately. #CVE #SiYuan #infosec

valtersit.com/cve/CVE-2026-730

  • 0
  • 0
  • 0
  • Last hour

Overview

  • PTC
  • Windchill PDMLink

18 Jun 2026
Published
01 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
30.20%

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

Statistics

  • 2 Posts

Last activity: 10 hours ago

Fediverse

Profile picture fallback

📰 Clop Group Claims Massive Data Heist from Shell, Philips, GE via PTC Flaw

Clop ransomware group claims massive data theft from Shell, Philips, GE, and 40+ others by exploiting a critical PTC Windchill vulnerability (CVE-2026-12569). #Clop #Ransomware #SupplyChainAttack

🔗 cyber.netsecops.io/articles/cl

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
Cl0p Ransomware Hits PTC Windchill: CVE-2026-12569 tech-insider.org/clop-ransomw...
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • n8n-io
  • n8n

25 Mar 2026
Published
25 Mar 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.76%

KEV

Description

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin nodes. By supplying a crafted parameters as part of node configuration, an attacker could write attacker-controlled values onto `Object.prototype`. An attacker could use this prototype pollution to achieve remote code execution on the n8n instance. The issue has been fixed in n8n versions 2.14.1, 2.13.3, and 1.123.27. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only, and/or disable the XML node by adding `n8n-nodes-base.xml` to the `NODES_EXCLUDE` environment variable. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 11 hours ago

Bluesky

Profile picture fallback
CVE-2026-33696: From a Schema Name to RCE in n8n
  • 0
  • 2
  • 1
  • 11h ago

Overview

  • Zyxel
  • WAX650S firmware

04 Aug 2026
Published
05 Aug 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
0.95%

KEV

Description

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an authenticated attacker with administrator privileges to execute OS commands on an affected device.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 6 hours ago

Bluesky

Profile picture fallback
CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling
  • 0
  • 1
  • 1
  • 6h ago

Overview

  • Linux
  • Linux

15 Aug 2026
Published
15 Aug 2026
Updated

CVSS
Pending
EPSS
0.20%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() The page-table walk framework may pass a NULL *child pointer for unpopulated entries. xe_pt_zap_ptes_entry() called container_of(*child) before checking for NULL, then dereferenced the result, causing a crash. Move the container_of() call after a NULL guard, so the function returns early instead of proceeding with an invalid pointer. XE_WARN_ON is kept to help root cause the issue, but we now bail instead of crashing the driver. v2: Comment that triggering XE_WARN_ON is unexpected behavior (Matt Brost) (cherry picked from commit b9297d19d9df5d4b6c994648570c5dcd1cac68ff)

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 13 hours ago

Fediverse

Profile picture fallback

CVE-2026-72362 - Linux kernel NULL pointer deref in drm/xe/pt. Unpatched, crash risk. No CVSS. Update when patch lands. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-723

  • 0
  • 1
  • 0
  • 13h ago

Overview

  • Linux
  • Linux

15 Aug 2026
Published
15 Aug 2026
Updated

CVSS
Pending
EPSS
0.16%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix writes_pending leak on write request failures raid10_make_request() acquires a writes_pending reference with md_write_start() before dispatching write requests. Several failure paths in raid10_write_request() complete the bio and return without reaching the normal write completion path, causing the corresponding md_write_end() to be skipped. Make raid10_write_request() return a status indicating whether the write request was successfully queued. This allows raid10_make_request() to release the writes_pending reference with md_write_end() when a write request fails.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 13 hours ago

Fediverse

Profile picture fallback

CVE-2026-72439 - Linux kernel md/raid10 write failure leak. Unpatched, can cause data integrity issues. CVSS N/A. Monitor for patches and update when available. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-724

  • 0
  • 1
  • 0
  • 13h ago
Showing 1 to 10 of 30 CVEs