24h | 7d | 30d

Overview

  • SAP_SE
  • SAP Commerce Cloud (Data Hub Adapter)

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
0.73%

KEV

Description

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Attackers are actively exploiting a maximum severity vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231, just days after SAP released a patch. The flaw is a remote code execution vulnerabi
securityaffairs.com/197244/sec
#cybersecurity #vulnerability #SAP

  • 1
  • 0
  • 0
  • 20h ago
Profile picture fallback

Συναγερμός για το SAP Commerce Cloud: μόλις τρεις ημέρες μετά τη διόρθωση, καταγράφηκαν προσπάθειες εκμετάλλευσης μιας αδυναμίας με τη μέγιστη βαθμολογία σοβαρότητας.

Το πιο ανησυχητικό; Δεν χρειάζεται λογαριασμός για να ξεκινήσει κάποιος.

Δεν έχει επιβεβαιωθεί επίθεση σε οργανισμό, αλλά οι διαχειριστές πρέπει να κινηθούν γρήγορα.

Δες τι πρέπει να κάνουν και ποιο προσωρινό μέτρ…

hacks.gr/sto-stochastro-chaker

#Cybersecurity #SAPCommerceCloud #CVE202658231 #RemoteCodeExecution #AuthenticationBypass

  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback

En las últimas 24 horas, se desmanteló una red que usaba deepfakes para fraudes digitales, mientras Shell investiga una filtración vinculada a ransomware Cl0p y Francia sufre el robo de datos de 678,000 ciudadanos; por si fuera poco, una grave vulnerabilidad en SAP Commerce Cloud y fallas en e-commerce aumentan riesgos, destacando la urgencia de fortalecer redes con tecnologías innovadoras y defensa proactiva. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 16/08/26 📆 |====

🔍 CIBERCRIMINAL DETENIDO POR USAR DEEPFAKES PARA OBTENER CERTIFICADOS DIGITALES

La Policía Nacional logra detener a un delincuente que explotaba imágenes manipuladas con inteligencia artificial para engañar sistemas y obtener certificados digitales mediante una vulnerabilidad (glitch). Este caso subraya la creciente amenaza que representa el uso de tecnologías deepfake en delitos informáticos, y la urgencia de fortalecer mecanismos de verificación digital para proteger la identidad y la información sensible.

Descubre cómo se detectó y desarticuló esta sofisticada técnica aquí 👉 djar.co/msVFp

🛢️ SHELL INVESTIGA FILTRACIÓN DE DATOS A TRAVÉS DEL RANSOMWARE CLOP

La multinacional energética Shell confirma una investigación en marcha tras una filtración de datos vinculada al ransomware Cl0p. Este incidente evidencia la persistencia y evolución de los ataques mediante ransomware, que no solo cifran información sino que también exponen datos sensibles para presionar a las víctimas.

Conoce los detalles y recomendaciones para mitigar este tipo de ataques aquí 👉 djar.co/WE55v

🇫🇷 CIBERATAQUE A LA DGFiP: ROBO DE DATOS DE 678,000 PERSONAS EN FRANCIA

La Dirección General de Finanzas Públicas de Francia sufrió un ataque que comprometió datos personales de más de seiscientos setenta y ocho mil particulares y profesionales. Este caso enfatiza la necesidad crítica de actualizar y reforzar la protección en entidades públicas para evitar brechas que pongan en riesgo información fiscal y personal.

Infórmate de las consecuencias y medidas adoptadas aquí 👉 djar.co/k58ON5

🛒 VULNERABILIDADES EN PLATAFORMAS DE COMERCIO ELECTRÓNICO Y CÓMO PROTEGERTE

Análisis profundo sobre recientes fallas de seguridad detectadas en plataformas de venta online, un objetivo frecuente de ciberataques. El boletín ofrece las mejores prácticas para proteger datos de usuarios, evitar fraudes y garantizar transacciones seguras, crucial para consumidores y administradores de tiendas digitales.

Aprende a blindar tu tienda online y proteger tu información aquí 👉 djar.co/H4Qf7s

⚠️ EXPLOIT CRÍTICO EN SAP COMMERCE CLOUD: CVE-2026-58231

Se detectó una vulnerabilidad de máxima gravedad en SAP Commerce Cloud solo días después de que se publicara el parche correspondiente. Este fallo permite la ejecución de código malicioso, poniendo en peligro la integridad y confidencialidad de las plataformas empresariales basadas en SAP.

Consulta cómo proteger tu sistema y aplicar la actualización aquí 👉 djar.co/uejO

🌐 SEGURIDAD EN REDES: TÉCNICAS AVANZADAS CONTRA AMENAZAS SOFISTICADAS

Una guía especializada que aborda métodos modernos para el análisis de tráfico y la defensa proactiva frente a ataques complejos en redes corporativas. Se destacan herramientas y estrategias para anticipar movimientos del atacante y fortalecer la infraestructura ante amenazas persistentes y avanzadas.

Descubre cómo mejorar la seguridad de tu red con estas prácticas clave aquí 👉 djar.co/MJaRSN

🚀 TECNOLOGÍAS QUE REVOLUCIONAN LA CIBERSEGURIDAD EN 2023

Explora las innovaciones más relevantes que están transformando la protección digital, como la inteligencia artificial aplicada a detección de intrusiones, el aprendizaje automático para análisis predictivo y la implementación de arquitecturas zero trust. Esta evolución tecnológica redefine las defensas frente a los ataques cada vez más sofisticados.

Conoce las tendencias que marcan el futuro de la ciberseguridad aquí 👉 djar.co/lksjg

  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback

📰 Critical SAP Commerce Cloud Flaw (CVE-2026-58231) Under Active Attack

Max-severity SAP Commerce Cloud flaw (CVE-2026-58231, CVSS 10.0) is under active attack just days after patch release. The unauthenticated RCE affects major e-commerce platforms. #SAP #RCE #PatchNow

🔗 cyber.netsecops.io/articles/cr

  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Apple
  • macOS

06 Aug 2026
Published
15 Aug 2026
Updated

CVSS
Pending
EPSS
0.50%

KEV

Description

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials.

Statistics

  • 3 Posts
  • 2 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

Attackers are actively exploiting CVE-2026-65400, an authentication bypass flaw in macOS Screen Sharing, to gain root access and deploy Monero miners on internet-exposed systems. Any macOS system with port 5900 open and unpatched is at immediate risk. This is a known active threat with public explo…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
Nizozemské centrum NCSC varuje před aktivním zneužíváním kritické chyby v systému sdílení obrazovky macOS (CVE-2026-65400). Útočníci využívají port 5900 k získání root přístupu
  • 0
  • 1
  • 0
  • 10h ago
Profile picture fallback
macOS Screen Sharing vulnerability (CVE-2026-65400) exploited. Attackers gained root access via exposed port 5900, deploying Monero miners. Apple released an update Aug 6. If you can't update, disable Screen Sharing ASAP. Stay safe! #crypto #blockchain #news
  • 0
  • 1
  • 0
  • 6h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
14 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.14%

KEV

Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Statistics

  • 2 Posts

Last activity: 6 hours ago

Fediverse

Profile picture fallback

2026-W33 — Weekly Threat Roundup

🔥 VMware vCenter RCE (CVE-2026-59310) under active APT exploitation across 47 countries, patch and hunt for persistence now.
🤖 Near-autonomous AI cyberattack observed against Taiwan's government, adapting mid-operation without human direction.
💀 Lazarus Group's Operation Dream Job exploits Windo…

threatnoir.com/weekly/2026-w33

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

vCenter Flaw Exploited Just Five Days After Disclosure infosecurity-magazine.com/news

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • PTC
  • Windchill PDMLink

18 Jun 2026
Published
01 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
30.20%

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

Statistics

  • 2 Posts

Last activity: 3 hours ago

Fediverse

Profile picture fallback

📰 Clop Group Claims Massive Data Heist from Shell, Philips, GE via PTC Flaw

Clop ransomware group claims massive data theft from Shell, Philips, GE, and 40+ others by exploiting a critical PTC Windchill vulnerability (CVE-2026-12569). #Clop #Ransomware #SupplyChainAttack

🔗 cyber.netsecops.io/articles/cl

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
Cl0p Ransomware Hits PTC Windchill: CVE-2026-12569 tech-insider.org/clop-ransomw...
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • n8n-io
  • n8n

25 Mar 2026
Published
25 Mar 2026
Updated

CVSS v4.0
CRITICAL (9.4)
EPSS
0.76%

KEV

Description

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflows could exploit a prototype pollution vulnerability in the XML and the GSuiteAdmin nodes. By supplying a crafted parameters as part of node configuration, an attacker could write attacker-controlled values onto `Object.prototype`. An attacker could use this prototype pollution to achieve remote code execution on the n8n instance. The issue has been fixed in n8n versions 2.14.1, 2.13.3, and 1.123.27. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only, and/or disable the XML node by adding `n8n-nodes-base.xml` to the `NODES_EXCLUDE` environment variable. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 5 hours ago

Bluesky

Profile picture fallback
CVE-2026-33696: From a Schema Name to RCE in n8n
  • 0
  • 2
  • 1
  • 5h ago

Overview

  • jackdewey
  • Link Library

15 Aug 2026
Published
15 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
1.21%

KEV

Description

The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields function in all versions up to, and including, 7.9.4 This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php). Exploitation requires the administrator to have enabled the 'Delete local file on link deletion' plugin option (disabled by default) and to subsequently permanently delete the attacker-submitted link, which is a routine moderation action.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 19 hours ago

Fediverse

Profile picture fallback

CVE-2026-18855 - Critical RCE in WordPress Link Library plugin. Unauthenticated arbitrary file deletion via ll_delete_link_fields. CVSS 9.1. Patch under review. Update immediately. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-188

  • 0
  • 1
  • 0
  • 19h ago

Overview

  • Linux
  • Linux

15 Aug 2026
Published
15 Aug 2026
Updated

CVSS
Pending
EPSS
0.20%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: drm/xe/pt: Fix NULL pointer dereference in xe_pt_zap_ptes_entry() The page-table walk framework may pass a NULL *child pointer for unpopulated entries. xe_pt_zap_ptes_entry() called container_of(*child) before checking for NULL, then dereferenced the result, causing a crash. Move the container_of() call after a NULL guard, so the function returns early instead of proceeding with an invalid pointer. XE_WARN_ON is kept to help root cause the issue, but we now bail instead of crashing the driver. v2: Comment that triggering XE_WARN_ON is unexpected behavior (Matt Brost) (cherry picked from commit b9297d19d9df5d4b6c994648570c5dcd1cac68ff)

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 6 hours ago

Fediverse

Profile picture fallback

CVE-2026-72362 - Linux kernel NULL pointer deref in drm/xe/pt. Unpatched, crash risk. No CVSS. Update when patch lands. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-723

  • 0
  • 1
  • 0
  • 6h ago

Overview

  • Linux
  • Linux

15 Aug 2026
Published
15 Aug 2026
Updated

CVSS
Pending
EPSS
0.16%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: md/raid10: fix writes_pending leak on write request failures raid10_make_request() acquires a writes_pending reference with md_write_start() before dispatching write requests. Several failure paths in raid10_write_request() complete the bio and return without reaching the normal write completion path, causing the corresponding md_write_end() to be skipped. Make raid10_write_request() return a status indicating whether the write request was successfully queued. This allows raid10_make_request() to release the writes_pending reference with md_write_end() when a write request fails.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CVE-2026-72439 - Linux kernel md/raid10 write failure leak. Unpatched, can cause data integrity issues. CVSS N/A. Monitor for patches and update when available. #CVE #Linux #infosec

valtersit.com/cve/CVE-2026-724

  • 0
  • 1
  • 0
  • 7h ago

Overview

  • scriban
  • scriban

16 Aug 2026
Published
16 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
Pending

KEV

Description

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded recursion, causing a StackOverflowException that fatally terminates the hosting .NET process.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 1 hour ago

Fediverse

Profile picture fallback

CVE-2026-74787 - Uncontrolled recursion in Scriban's object.to_json. Crafted templates cause stack overflow, crashing .NET apps. CVSS 7.5. No patch yet - mitigate by limiting template input. #CVE #Scriban #infosec

valtersit.com/cve/CVE-2026-747

  • 0
  • 1
  • 0
  • 1h ago

Overview

  • scriban
  • scriban

16 Aug 2026
Published
16 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
Pending

KEV

Description

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and triggering an uncatchable StackOverflowException that terminates the hosting process.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

CVE-2026-74794 – Unpatched DoS in Scriban template engine. Infinite recursion via circular refs crashes host process. CVSS 7.5. Update to 6.6.0 or limit recursion. #CVE #infosec #Scriban

valtersit.com/cve/CVE-2026-747

  • 0
  • 1
  • 0
  • 3h ago
Showing 1 to 10 of 25 CVEs