24h | 7d | 30d

Overview

  • NetScaler
  • ADC

30 Jun 2026
Published
30 Jun 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.49%

KEV

Description

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

Statistics

  • 8 Posts
  • 27 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

Watchtowr got RCE via one of the many Citrix Netscaler SAML vulns. labs.watchtowr.com/youre-back-

  • 6
  • 20
  • 0
  • 8h ago
Profile picture fallback

RE: infosec.exchange/@watchTowr/11

Si vous n’avez pas encore patché la RCE NetScaler du mois de juin :
support.citrix.com/support-hom

ChatGPT dit que c’est probablement le dernier moment de le faire avant qu’il utilise ça comme opportunité pour s’échapper de sa sandbox.

Parce que, bien évidemment, la fine équipe de watchTowr vient de publier le write-up qui transforme le gentil « memory overflow » en RCE pré-auth root.

👇
labs.watchtowr.com/youre-back-

  • 0
  • 1
  • 0
  • 9h ago
Profile picture fallback

You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452 labs.watchtowr.com/youre-back-

  • 0
  • 0
  • 0
  • 8h ago

Bluesky

Profile picture fallback
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) - watchTowr Labs
  • 0
  • 0
  • 2
  • 9h ago
Profile picture fallback
📢 RCE pré-authentifiée sur Citrix NetScaler via heap overflow SAML (CVE-2026-8452) Cet article présente une analyse technique approfondie d'une vulnérabilité heap overflow pré-authentifiée affectant Citrix NetScaler… 🟢 vérification factuelle haute #CitrixNetScaler #RCEPréAuthentifiée #Cyberveille
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
~Watchtowr~ Unauthenticated heap overflow in NetScaler SAML PrefixList canonicalization yields full root RCE by overwriting function pointers and jumping to RWX heap shellcode. - IOCs: CVE-2026-8452, /var/vpn/theme/x[.]php - ...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
14 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.14%

KEV

Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Statistics

  • 7 Posts
  • 13 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

「VMware vCenterの重大なリモートコード実行(RCE)の脆弱性が悪用され、リバースSSHアクセスが行われた。 」: #BLEEPINGCOMPUTER

「VMware vCenter Syslog Serverに存在する、最近パッチが適用された重大な脆弱性(CVE-2026-59310)が、永続的な接続とリモートアクセスを目的としたリバースSSHツールの展開を目的としたアクティブな攻撃キャンペーンで悪用されています。

47か国にわたる361のIPアドレスで侵害が確認されており、その半数以上はドイツ、米国、トルコ、イラン、フランスに位置している。

Broadcomは7月29日にCVE-2026-59310を公開し、 vCenter Syslogサーバーにおける重大なディレクトリトラバーサル脆弱性 であり、ネットワークアクセス権を持つ認証されていない攻撃者が悪用して任意のコードを実行できる可能性があると説明した。 」

bleepingcomputer.com/news/secu

#prattohome

  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback

⚠️ CRITICAL: Global Threat Campaign Hits Critical VMware vCenter Flaw

Active exploitation of CVE-2026-59310 in VMware vCenter Server is ongoing. All organizations running vCenter are at risk of compromise. Patching alone may be insufficient due to suspected persistence mechanisms already deployed by threat actors.

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback

⚠️ CRITICAL: Critical VMware vCenter RCE flaw exploited for reverse SSH access

A critical directory traversal vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being actively exploited in the wild to deploy reverse SSH tools for persistence. At least 361 compromised hosts across 47 countries have been identified, with attackers establishing remote access on vi…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
Thanks to collaboration with QUIRSO GmbH we are sharing the VMware vCenter CVE-2026-59310 Exploitation Victim Special Report shadowserver.org/what-we-do/n... Check compromised IPs for your network/constituency & remediate! File prefix: 2026-08-13-special See: medium.com/@quirso_de/a...
  • 2
  • 3
  • 0
  • 7h ago
Profile picture fallback
Critical VMware vCenter Syslog Server flaw CVE-2026-59310 is being actively exploited to deploy reverse_ssh for persistence and remote access, with 361 IPs hit across 47 countries. #VMware #Broadcom #Countries
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
Critical RCE via Directory Traversal in Broadcom VMware vCenter CVE-2026-59310 https://gbhackers.com/hackers-exploit-critical-vmware-vcenter-flaw https://flagthis.com/tldr/6107 ##Broadcom ##VMware ##RCE ##APT ##CloudSecurity
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
You can also track CVE-2026-59310 & CVE-2026-59309 vulnerable VMware vCenter instances in our daily Vulnerable HTTP reporting since July 30th: shadowserver.org/what-we-do/n... Tracker: dashboard.shadowserver.org/statistics/c... World Map: dashboard.shadowserver.org/statistics/c...
  • 3
  • 5
  • 0
  • 6h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 3 Posts

Last activity: 3 hours ago

Fediverse

Profile picture fallback

📰 WordPress patches critical RCE flaw (CVE-2026-65640) for author-level users

WordPress 7.0.4 patches a critical RCE flaw (CVE-2026-65640, CVSS 8.8). Authenticated authors could take over sites using a malicious image file on servers with Imagick. Update your WordPress sites immediately! #WordPress #RCE #CyberSecurity

🔗 cyber.netsecops.io/articles/cr

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
WordPress 7.0.4 patches CVE-2026-65640, an 8.8 flaw that could let Author-level attackers trigger remote code execution via crafted PostScript uploads on sites using Imagick and Ghostscript. #WordPress #CVE-2026-65640 #Imagick
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
📢 WordPress 7.0.4 corrige une RCE via fichiers PostScript malveillants (CVE-2026-65640) Cet article rapporte la publication par WordPress d'un correctif pour une vulnérabilité d'exécution de code à distance (RCE) de haute sévérité… 🟢 vérification factuelle haute #RCE #WordPress #Cyberveille
  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

11 Aug 2026
Published
13 Aug 2026
Updated

CVSS v3.1
HIGH (7.0)
EPSS
0.33%

Description

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Statistics

  • 3 Posts

Last activity: 2 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Lazarus hackers exploited Windows zero-day to target defense firms

Lazarus Group is actively exploiting Windows zero-day CVE-2026-68820 to target defense, aerospace, and aviation firms worldwide. The vulnerability enables privilege escalation to SYSTEM level and is being weaponized alongside a new backdoor called Troy. Compromised Roundcube instances have also bee…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
Lazarus Group、Windowsゼロデイ脆弱性を悪用し防衛関連企業へサイバー攻撃(CVE-2026-68820) rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #cyberattack #セキュリティ #databreach
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
Lazarus Group、Windowsゼロデイ脆弱性を悪用し防衛関連企業へサイバー攻撃(CVE-2026-68820)|セキュリティニュースのセキュリティ対策Lab https://www.yayafa.com/2864617/ 北朝鮮の国家支援ハッカー集団Laza…
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Microsoft
  • Windows 10 Version 22H2

11 Aug 2026
Published
13 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
3.03%

KEV

Description

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

Statistics

  • 1 Post
  • 32 Interactions

Last activity: 8 hours ago

Overview

  • SAP_SE
  • SAP Commerce Cloud (Data Hub Adapter)

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.73%

KEV

Description

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Statistics

  • 2 Posts

Last activity: Last hour

Fediverse

Profile picture fallback

Apple Partners With Alibaba to Launch China-Specific AI Model – DTH

[🖼 DTH-6-150x150]France’s Top Court Strikes Down Proposed Social Media Ban for Minors, Google Launches Gemini 3.7 Flash to Boost AI Performance, and the White House Imposes 100% Tariffs on Drones to Boost Domestic Manufacturing and Security.

MP3

Please SUBSCRIBE HERE for free or
get DTNS shows ad-free.

A special thanks to all our supporters–without you, none of this would be possible.

If you enjoy what you see you can support the show on Patreon, Thank you!

Send email to feedback@dailytechnewsshow.com

Show Notes

Apple Develops AI Model for China With Alibaba

Apple has developed a proprietary large language model for the China market in partnership with Alibaba, signaling a strategic shift to better compete against domestic rivals. This initiative, designed to integrate with Apple Intelligence, aims to navigate local regulatory challenges and restore Apple’s competitive edge in a critical market where the absence of AI features has previously impacted sales.

Read More — Reuters

France’s Highest Court Rejects Social Media Ban for Children Under 15

France’s highest court has declared a proposed ban on social media for children under 15 unconstitutional, ruling that it infringes upon youths’ freedom of speech and communication. This decision, a setback for President Emmanuel Macron, signals potential legal and technical challenges for global efforts to restrict social media access for younger teenagers. Despite this ruling, the French government intends to pursue revised legislation while other nations and the EU continue to explore similar regulatory approaches, highlighting the ongoing tension between protective digital policies and privacy concerns.

Read More — Bloomberg

Google Launches Gemini 3.7 Flash

Google has launched its new Gemini 3.7 Flash AI model, which offers improved performance in coding, debugging, and efficiency for app production while integrating enhanced safety features. Despite this release, the company continues to face pressure due to delays with its more powerful Gemini 3.5 Pro model and competition from rivals like OpenAI and Anthropic, leading to investor questions regarding Google’s AI roadmap and its ability to maintain a leading market position.

Read More — Bloomberg

White House Introduces Tariffs of Up to 100 Percent on Drones

The White House has introduced new tariffs of up to 100 percent on drones and associated components to enhance national security and encourage domestic manufacturing, or “on-shoring.” These measures, which target both heavy-duty and sensitive commercial drones, are expected to increase costs for consumers as vendors pass on the expenses. The policy aims to reduce dependence on Chinese-manufactured models, like those from DJI, though industry experts note the significant challenge of replicating China’s advanced drone supply chains and specialized engineering capabilities within the US.

Read More — Engadget

Flock Implements Stricter Data Retention Policies

Flock is implementing stricter data retention policies and mandating a new “Audit Assistance” tool designed to flag atypical search patterns for administrative review. Despite Flock’s claims of efficacy, privacy experts and critics from the ACLU and EFF argue that the company has provided insufficient technical details about how the tool works and lacks independent auditing evidence to prove it effectively prevents abuse, suggesting that stronger legal constraints on technology use are more critical for ensuring accountability.

Read More — TechCrunch

Heart Aerospace Completes First Flight of All-Electric X1 Prototype

Heart Aerospace has successfully completed the first flight of its all-electric X1 prototype, marking a significant milestone for the company as it eyes regional aviation markets. With interest from airlines like United and Air Canada, Heart aims to follow this success with the ES-30, a hybrid-electric model designed to replace traditional turboprops by 2031 through lower operational costs and enhanced reliability, though the company’s ambitious timeline remains dependent on future advancements in battery density and weight.

Read More — Engadget

Netflix Shutters Two Internal Game Studios

Netflix is shuttering two internal game studios, Night School Studio and Moonloot, as part of an ongoing restructuring of its gaming division. This decision follows a series of previous studio closures and divestments, signaling a consolidation of the company’s internal game development strategy. Moving forward, Netflix’s gaming focus is shifting toward four specific areas: kids, party, narrative, and mainstream titles, with increasing emphasis on cloud gaming and mobile-controller-based experiences.

Read More — Variety

Critical SAP Commerce Cloud Vulnerability Is Being Actively Exploited

A critical remote code execution vulnerability in SAP Commerce Cloud (CVE-2026-58231) is being actively exploited in the wild three days after patch release. Caused by improper authorization in the Data Hub Adapter, the flaw allows unauthenticated attackers to execute arbitrary code on e-commerce platforms. Despite no public proof-of-concept, researchers confirmed active attacks, underlining persistent security threats for SAP.

Read More — BleepingComputer

Uber Expands Robotaxi Strategy With Pony.ai

Uber is expanding its global robotaxi strategy by partnering with Pony.ai to deploy 2,000 self-driving vehicles across Europe and the Middle East, building on their existing pilot service in Zagreb. This collaboration, which includes plans for four additional European cities, is part of Uber’s broader effort to become a leading platform for autonomous commercialization by working with partners like WeRide and Baidu Apollo Go to scale operations in cities like Madrid and Tokyo, while gathering data to accelerate development against competitors like Waymo.

Read More — CNBC

X Tests Tool to Show Post-Limiting Labels

X is testing a tool giving select users visibility into post-limiting labels like spam or NSFW. Aimed at clarifying algorithmic “shadowbanning,” the complex data remains hard to interpret. Concurrently, X expanded open-sourcing its recommendation algorithm while continuing to withhold sensitive advertising and non-timeline data.

Read More — Engadget

  • 0
  • 0
  • 0
  • Last hour

Bluesky

Profile picture fallback
A plataforma de comércio eletrónico SAP Commerce Cloud está a ser alvo de ataques que exploram a vulnerabilidade CVE-2026-58231, classificada com a gravidade máxima de 10.0. As tentativas de exploração começaram a atingir os sensores de teste apenas 3 dias após a tecnológica ter disponibilizado a co
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Microsoft
  • Windows 10 Version 21H2

11 Aug 2026
Published
13 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
2.36%

KEV

Description

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
Microsoft patched the LegacyHive Windows zero-day, CVE-2026-62832, in August 2026 updates. The flaw in Windows User Profile Service could let authenticated local attackers gain admin privileges. #LegacyHive #CVE202662832 #WindowsUpdate
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
A Microsoft lançou correções de segurança no ciclo de atualizações de agosto de 2026 para resolver a vulnerabilidade de dia zero LegacyHive no Windows. A vulnerabilidade é rastreada como CVE-2026-62832 e afeta o serviço de perfis de utilizador. 🛡️ #lan #microsoft #vulnerabilidade #windows
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Adobe
  • Adobe Commerce

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.48%

KEV

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Statistics

  • 3 Posts

Last activity: 3 hours ago

Bluesky

Profile picture fallback
Adobe Commerce CVE-2026-71362 was exploited soon after disclosure. The critical 9.1 flaw can let unauthenticated attackers hijack customer sessions and access private account data. #AdobeCommerce #Magento #CVE202671362
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. www.securityweek.com/adobe-commer...
  • 0
  • 0
  • 1
  • 3h ago

Overview

  • Linux
  • Linux

06 May 2026
Published
05 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.48%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace period In certain situations, ep_free() in eventpoll.c will kfree the epi->ep eventpoll struct while it still being used by another concurrent thread. Defer the kfree() to an RCU callback to prevent UAF.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
Linuxカーネルのeventpollにroot権限奪取の脆弱性、Pixel 10 ProでのPoCエクスプロイトが公開(CVE-2026-43074) AnthropicのMythosが発見した脆弱性 rocket-boys.co.jp/security-mea... #セキュリティ対策Lab #security #securitynews #脆弱性
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
Linuxカーネルのeventpollにroot権限奪取の脆弱性、Pixel 10 ProでのPoCエクスプロイトが公開(CVE-2026-43074) AnthropicのMythosが発見した脆弱性|セキュリティニュースのセキュリティ対策Lab https://www.yayafa.com/2864941/ 2026年8月10日、Linuxカー…
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Fortinet
  • FortiWeb

12 Aug 2026
Published
13 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.51%

KEV

Description

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 through 7.0.12 may allow a remote unauthenticated attacker to login into the Fortiweb GUI/CLI with a random username and password

Statistics

  • 2 Posts

Last activity: 3 hours ago

Fediverse

Profile picture fallback

📰 Fortinet patches critical auth bypass in FortiWeb WAF (CVE-2026-26035)

Fortinet patches a critical authentication bypass in FortiWeb WAF (CVE-2026-26035). The flaw allows admin access with any password if a non-default 'admin wildcard' is set. Patch and check your configs now! #Fortinet #CyberSecurity #Vulnerability

🔗 cyber.netsecops.io/articles/fo

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
The latest update for #CyCognito includes "Emerging Threat: (CVE-2026-26035) FortiWeb Admin Authentication Bypass via RADIUS Admin Groups". #cybersecurity #AttackSurfaceManagement #EASM https://opsmtrs.com/44Srq0X
  • 0
  • 0
  • 0
  • 11h ago
Showing 1 to 10 of 71 CVEs