Overview
Description
Statistics
- 9 Posts
- 8 Interactions
Fediverse
⚠️ Important security update for Mac users:
A vulnerability in macOS Screen Sharing (CVE-2026-65400) is being actively exploited.
If you use Screens or another VNC client app to remotely access a Mac, we strongly recommend updating macOS as soon as possible.
Attackers actively exploit the critical CVE-2026-65400 vulnerability in macOS Screen Sharing. Discover how to protect your Mac from root access and cryptominers.
#macOS #CVE202665400 #ScreenSharing #Vulnerability #Cybersecurity
An AI agent built a working exploit for this macOS flaw in four hours
https://thenextweb.com/news/macos-screen-sharing-flaw-cve-2026-65400-monero-miner?utm_source=flipboard&utm_medium=activitypub
Posted into TNW - All Stories @tnw-all-stories-thenextweb
Here's a summary of the latest geopolitical, technology, and cybersecurity news from the last 24-48 hours:
Cybersecurity: Apple patched a critical macOS Screen Sharing vulnerability (CVE-2026-65400) and issued mercenary spyware alerts across 110 countries. Microsoft's August Patch Tuesday fixed 421 vulnerabilities, including an actively exploited Windows zero-day (CVE-2026-68820). France reported a Bloctel data leak exposing three million phone numbers and a DGFiP tax data leak.
Technology: Massive tech layoffs continue in 2026, surpassing last year's totals, as companies shift to "AI-first" strategies; AI "inference" spending now exceeds "training". Elon Musk's SpaceX committed exclusively to NVIDIA GPUs, forming a major AI partnership.
Geopolitics: US-Iran tensions remain high over the Strait of Hormuz, with new threats and defense contracts emerging. Ukraine faces critical Patriot interceptor shortages, threatening its winter air defense.
Bluesky
Overview
Description
Statistics
- 6 Posts
- 34 Interactions
Fediverse
CVE-2026-8452 in Netscaler is under active pray and spray exploitation - somebody popped my honeypot with it today. Three webshells, x.php, y.php and z.php
I don't think this one will be super impactful in terms of breach numbers as most orgs don't have SAML IDP enabled - you can check with the paths I posted above.
‼️ Detection Artifact Generator for Citrix NetScaler CVE-2026-8452
GitHub: https://github.com/watchtowrlabs/watchTowr-vs-Citrix-Netscaler-PreAuth-RCE-CVE-2026-8452
Oof; if you're a NetScaler shop you probably want to be very sure you update for this one: https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/
Pre-auth RCE is... yikes. Relatively low EPSS for now, but I wouldn't trust that with the CVSSv4 vectors in play: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:H/SC:L/SI:L/SA:L
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/
Bluesky
Overview
- GitLab
- GitLab
Description
Statistics
- 6 Posts
- 8 Interactions
Fediverse
‼️Critical GitLab vulnerability could let unauthenticated attackers delete public projects.
CVE-2026-19478 affects self-managed CE and EE under certain conditions. Fixes are in 19.2.4, 19.1.6, 19.0.8, and 18.11.11.
What admins need to know: https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html
Critical GitLab GraphQL Vulnerability CVE-2026-19478: Patch Now to Prevent Unauthenticated Project Modification
GitLab patched critical CVE-2026-19478, a CVSS 9.4 GraphQL flaw allowing unauthenticated attackers to modify or delete public projectshttps://thecybersecguru.com/news/cve-2026-19478-gitlab-graphql-vulnerability/
CRITICAL: GitLab CE/EE (v18.2+ to 19.2.4) patched CVE-2026-19478, a code injection bug allowing unauthenticated data modification/deletion via GraphQL. CSRF (CVE-2026-19650) also fixed. Upgrade to safe versions ASAP. https://radar.offseq.com/threat/gitlab-patches-critical-code-injection-vulnerability-ce00fcde61cd1cd5 #OffSeq #GitLab #Infosec #CVE
GitLab patched CVE-2026-19478, a CVSS 9.4 GraphQL code injection flaw letting unauthenticated users alter or delete project data.
#CVE202619478 #GitLab #CodeInjection #GraphQL #CVE202619650 #PatchNow
Bluesky
Overview
- SAP_SE
- SAP Commerce Cloud (Data Hub Adapter)
Description
Statistics
- 5 Posts
- 1 Interaction
Fediverse
「SAP Commerce Cloudの脆弱性CVE-2026-58231が、パッチ適用後数日で悪用される試みの標的となる 」: #TheHackerNews
「SAP Commerce Cloudに影響を与える、最も深刻なセキュリティ脆弱性について、現在活発な悪用活動が行われています。
CVE-2026-58231 として追跡されているこの脆弱性は、 CVSSスコアリングシステムで10.0と評価されています。これは、認証チェックと入力検証が不十分なケースに関連しています。
CVE.orgによると、「SAP Commerce Cloudでは、認証されていない攻撃者がデフォルトの認証クライアントを悪用し、十分な検証が行われていない特定の機能に特別に細工された入力を送信できる」とのことです。
「脆弱性を悪用されると、任意のコード実行が可能になり、内部コンポーネントが侵害される可能性があり、アプリケーションの機密性、完全性、可用性に重大な影響を与える可能性があります。」 」
https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html
“A maximum-severity bug in SAP Commerce Cloud was exploited in the wild, research group Defused posted on X Aug. 14.
The 10.0 bug — CVE-2026-58231 — was described as having insufficient authorization checks and input validation and was earlier patched by SAP on Aug. 11.”
https://www.scworld.com/news/critical-sap-commerce-cloud-flaw-exploited-days-after-patch
Bluesky
Overview
Description
Statistics
- 4 Posts
- 2 Interactions
Fediverse
CISA confirms CVE-2025-62593, a Ray code injection RCE, is exploited in the wild. A public PoC targets Firefox and Safari.
#CVE202562593 #Ray #RemoteCodeExecution #DNSRebinding #KEV #ExploitedInTheWild
https://securityonline.info/cve-2025-62593-ray-rce/?utm_source=mastodon&utm_medium=jetpack_social
🚨 NEW CISA KEV: CVE-2025-62593 - Ray. Active RCE weaponization via DNS rebinding targeting developers on Firefox/Safari. Vendor patch 2.52.0 is mandatory. Get the full T-Suite brief & SOC detection queries to secure your Precinct Hybrid architecture. Command the wire. Link below 👇
https://thecybermind.co/jily
#CyberSecurity
Bluesky
Overview
- wpmudev
- Forminator Forms – Contact Form, Payment Form & Custom Form Builder
Description
Statistics
- 4 Posts
- 2 Interactions
Fediverse
Achtung #WordPress #Admins! Kritische Sicherheitslücke
In Forminator Forms (bis v1.56.1) und Royal Elementor Addons wurden teils kritische Schwachstellen entdeckt.
🔥 Forminator Forms (CVE-2026-15748, CVSS 9.8):
Angreifer können fehlerhafte MIME-Type-Prüfungen umgehen, beliebige Dateien hochladen und Remote Code ausführen (>600k Sites betroffen).
Handlungsbedarf: Umgehend auf Version 1.56.2 oder neuer updaten!
#WordPress #CyberSecurity #ITSicherheit #InfoSec #SecurityAlert #WordPressPlugin
「Forminator WordPressの脆弱性により、悪意のあるPHPファイルのアップロードを介して認証なしのリモートコード実行が可能になる 」: #TheHackerNews
「0万件以上のインストール実績を持つWordPressプラグイン「Forminator Forms」に、重大なセキュリティ上の欠陥が発見された。この欠陥を悪用すれば、脆弱性のあるサイトで任意のコードを実行できる可能性がある。
CVE-2026-15748 として追跡されているこの脆弱性は 、CVSSスコアリングシステムで10点満点中9.8点と評価されている。この脆弱性は、「daroo」というオンライン上のニックネームを持つセキュリティ研究者によって発見され、報告された。
https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html
CVE-2026-15748 (CRITICAL, CVSS 9.8): wpmudev Forminator Forms for WordPress up to 1.56.1 lets unauthenticated attackers upload dangerous files via handle_file_upload, risking remote code execution. Patch urgently: https://radar.offseq.com/threat/cve-2026-15748-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-wpmudev-forminator-forms-087a3235e4aa61cd #OffSeq #WordPress #Vuln
Overview
- Microsoft
- Microsoft SharePoint Enterprise Server 2016
Description
Statistics
- 2 Posts
- 10 Interactions
Fediverse
CVE-2026-55040: bypass di autenticazione in SharePoint sotto attacco attivo, ecco come proteggersi
#tech
https://spcnet.it/cve-2026-55040-bypass-di-autenticazione-in-sharepoint-sotto-attacco-attivo-ecco-come-proteggersi/
@informatica
Overview
- Microsoft
- Microsoft Malware Protection Engine
Description
Statistics
- 2 Posts
- 27 Interactions
Fediverse
ShieldBreak appears to be CVE-2026-69414 ht @wdormann https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69414
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.
ShieldBreak : cette faille zero-day menace Windows, Microsoft prépare un patch https://www.it-connect.fr/shieldbreak-zero-day-defender-cve-2026-69414/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft #Windows
Overview
- jahlives
- openssl_encrypt
Description
Statistics
- 1 Post
- 3 Interactions
Fediverse
CVE-2026-74889 - Critical crypto weakness in openssl_encrypt <1.4.0. HKDF with no salt/static info weakens key derivation, enabling multi-target attacks. CVSS 9.8. Update immediately. #CVE #cryptography #infosec
Overview
- COMFAST
- CF-N1-S
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-75094: CRITICAL OS command injection in COMFAST CF-N1-S v2.6.0.1. Exploit code is public, no official patch. Restrict access to /cgi-bin/mbox-config to reduce risk. Details: https://radar.offseq.com/threat/cve-2026-75094-os-command-injection-in-comfast-cf-n1-s-07737fa4c8cac0ee #OffSeq #CVE #IoT #Security