24h | 7d | 30d

Overview

  • Microsoft
  • Windows 10 Version 1607

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (7.0)
EPSS
0.36%

Description

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Statistics

  • 23 Posts
  • 18 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

「Microsoft 製品の脆弱性対策について(2026年8月)」: #IPA

「 2026年8月12日(日本時間)に Microsoft 製品に関するセキュリティ更新プログラム(月例)が公表されています。
これらの脆弱性を悪用された場合、アプリケーションプログラムが異常終了する、攻撃者によってパソコンを制御される、といった様々な被害が発生するおそれがあります。

この内 CVE-2026-68820 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。 」

ipa.go.jp/security/security-al

#prattohome

  • 2
  • 1
  • 0
  • 16h ago
Profile picture fallback

「マイクロソフトは、現在攻撃を受けているWindowsドライバーのゼロデイ脆弱性を含む398件の脆弱性を修正した。 」: #TheHackerNews

「マイクロソフトは火曜日に月例のセキュリティアップデートを公開したが、修正された脆弱性の1つが既に攻撃に悪用されている。

このバグは、ネットワークソケット操作を処理するWindowsカーネルの中核ドライバに存在します。既にマシン上でコードを実行している攻撃者は、このバグを利用してSYSTEM権限に昇格できます。このパッチが最初にリリースされます。

この脆弱性は CVE-2026-68820 (CVSSスコア:7.0)として追跡されており、今月のリリースでマイクロソフトが現在悪用されていると警告している唯一の脆弱性です。悪用は、ドライバーの競合状態をトリガーすることによって行われます。マイクロソフトは、この悪用を行った組織を公表していません。」

thehackernews.com/2026/08/micr

#prattohome

  • 1
  • 0
  • 0
  • 18h ago
Profile picture fallback

🚨 THREAT ALERT: CISA adds CVE-2026-68820 (Windows WinSock AFD Use-After-Free) to the KEV catalog due to active exploitation. Local attackers can elevate privileges to system level. Access our TSUITE brief with CrowdStrike CQL telemetry queries: thecybermind.co/jily

  • 0
  • 1
  • 0
  • 14h ago
Profile picture fallback

📰 Lazarus Group Exploits Windows Zero-Day in Espionage Campaign

Microsoft patches actively exploited Windows zero-day (CVE-2026-68820) used by Lazarus Group. The bug allows SYSTEM-level access and was used in the 'Operation Dream Job' campaign to deploy rootkits against the defense sector. #CVE202668820 #Lazarus ...

🔗 cyber.netsecops.io/articles/la

  • 0
  • 0
  • 1
  • 23h ago
Profile picture fallback

Microsoft August 2026 Patch Tuesday fixes 421 flaws, including CVE-2026-68820, a WinSock zero-day exploited in the wild, plus two disclosed bugs.

securityonline.info/microsoft-

  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback

Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor.

securityonline.info/lazarus-ze

  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback

CVE-2026-68820: CRITICAL Windows afd.sys zero-day exploited by Lazarus Group for SYSTEM access in defense/aerospace. Patch released 2026-08-11. Prioritize updates & check for ForestTiger/Troy backdoors. radar.offseq.com/threat/fresh-

  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback

⚠️ CRITICAL: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

Microsoft patched CVE-2026-68820, a zero-day use-after-free in afd.sys kernel driver actively exploited for SYSTEM privilege escalation. This is the fourth afd.sys zero-day since 2022, with historical links to nation-state actors. All Windows systems running unpatched afd.sys are at immediate risk…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign.
  • 2
  • 4
  • 0
  • 7h ago
Profile picture fallback
Check Point researchers look into the latest variant of the Operation Dream Job campaign where the threat actor exploited CVE-2026-68820, a 0-day vulnerability in the Microsoft AFD.sys driver, to deploy a new version of Lazarus’s kernel-mode rootkit FudModule. research.checkpoint.com/2026/shatter...
  • 1
  • 1
  • 0
  • 14h ago
Profile picture fallback
Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820) 🔗 Read more: www.helpnetsecurity.com/2026/08/12/a... #patchtuesday #patching #windows #0day #sharepointserver #cybersecurity #cybersecuritynews #ITsec @microsoft.com @dustinchilds.bsky.social @thezdi.bsky.social
  • 1
  • 1
  • 0
  • 13h ago
Profile picture fallback
Microsoft patches 398 flaws, including exploited CVE-2026-68820 that lets local attackers reach SYSTEM, plus four unauthenticated 9.8 RCEs.
  • 0
  • 1
  • 0
  • 23h ago
Profile picture fallback
Lazarus-linked Operation Dream Job hit defense firms in Europe and India with trojanized PDF viewers, spear-phishing, and new FudModule exploits, including CVE-2026-68820 and Roundcube abuse. #Lazarus #India #Europe
  • 0
  • 1
  • 0
  • 20h ago
Profile picture fallback
이번 Microsoft 8월 Patch Tuesday 업데이트는 미루지 않는 것이 좋겠습니다. 특히 Windows 11의 CVE-2026-68820은 CVSS가 7.0이라 숫자만 보면 덜 심각해 보이지만, Microsoft Defender는 공개된 익스플로잇이 존재하는 취약점으로 별도 경고하고 있습니다. 취약점은 CVSS 점수만 보고 우선순위를 정하면 안 됩니다. Windows Update를 확인하고 이번 보안 업데이트는 가급적 신속하게 적용하시길 권합니다.
  • 0
  • 1
  • 0
  • 5h ago
Profile picture fallback
Microsoft’s August 2026 Patch Tuesday fixes an actively exploited zero-day (CVE-2026-68820) in the Windows kernel driver, used by Lazarus Group […]
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
"Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack" published by Checkpoint. #DreamJob, #Troy, #FudModule, #Lazarus, #MISTPEN, #CVE202668820, #ForestTiger https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
「この内 CVE-2026-68820 の脆弱性について、Microsoft 社では悪用の事実を確認済みと公表しており、今後被害が拡大するおそれがあるため、至急、セキュリティ更新プログラムを適用してください。」
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
微软八月例行更新修复 421 个 bug,包括正被朝鲜黑客利用的 0day 微软本周二释出了八月例行安全更新,共修复 421 个 bug,比上个月少约 200 个,在 AI 辅助漏洞披露和修复时代,bug 修复数动辄数百已成为新常态。其中一个 bug CVE-2026-68820 正被朝鲜黑客组织 Lazarus Group 利用。它是 Windows Ancillary Function Driver for WinSock 的一个释放后使用 bug,攻击者能利用该 bug 以 SYSTEM 权限执行代码且无需用户交互。
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
Lazarus Group is exploiting Windows zero-day CVE-2026-68820 in fake job lures to hit defense, aerospace, and aviation targets with SYSTEM-level malware and data theft. #LazarusGroup #India #WindowsZeroDay
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
Microsoft lança atualização de emergência para corrigir a CVE-2026-68820, uma falha de gravidade elevada no controlador Ancillary Function para WinSock. A vulnerabilidade, que afeta diversas versões do Windows, já está a ser explorada em ataques reais. 🚨 #falha #lan #microsoft #windows
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
Lazarus-linked hackers are exploiting Windows zero-day CVE-2026-68820 in Operation Dream Job to gain SYSTEM access, targeting defense, aerospace, and aviation firms with FudModule, Troy, and RelayShell. #Lazarus #NorthKorea #Windows0day
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
@talosintelligence.com Microsoft's August 2026 update patches 421 vulnerabilities, including 62 critical and one actively exploited EoP flaw (CVE-2026-68820). - IOCs: CVE-2026-68820, CVE-2026-62893, CVE-2026-62878 - #CVE #PatchTuesday #ThreatIntel
  • 0
  • 0
  • 0
  • 18h ago

Overview

  • Cisco
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (8.6)
EPSS
0.97%

Description

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Statistics

  • 9 Posts

Last activity: 7 hours ago

Fediverse

Profile picture fallback

Cisco confirms CVE-2026-20349, a Cisco ASA and FTD VPN vulnerability (CVSS 8.6), is exploited in the wild to crash firewalls. Patch now.

securityonline.info/cisco-asa-

  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback

「Ciscoは、ASAおよびFTD VPNの脆弱性が悪用され、デバイスがクラッシュする可能性があると警告している。 」: #BLEEPINGCOMPUTER

「シスコは、Secure Firewall ASAおよびThreat Defense(FTD)ソフトウェアに存在する深刻なサービス拒否攻撃の脆弱性が、影響を受けるデバイスをリモートからクラッシュさせる攻撃で積極的に悪用されていると警告している。

CVE-2026-20349として追跡されているこの脆弱性は、深刻度スコアが8.6であり、特定のリモートアクセスサービスが有効になっているCisco Secure Firewall Adaptive Security Appliance(ASA)またはSecure Firewall Threat Defense(FTD)ソフトウェアを実行しているデバイスに影響を与えます。

シスコは本日公開したセキュリティ勧告の中で、この脆弱性はHTTPリクエスト処理時のエラーチェックが不十分なことに起因すると述べた。 」

bleepingcomputer.com/news/secu

#prattohome

  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback

🚨 THREAT ALERT: CISA adds CVE-2026-20349 (Cisco ASA/FTD Heap Inspection DoS) to the KEV catalog due to active exploitation. Unauthenticated remote actors can crash perimeter firewalls. Read our full TSUITE brief with SPL, KQL, AQL & Chronicle queries: thecybermind.co/jily

  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback

CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. securityweek.com/cisco-patches

  • 0
  • 0
  • 1
  • 9h ago
Profile picture fallback

📰 Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Cisco patches an actively exploited zero-day (CVE-2026-20349) in ASA and FTD firewalls. The flaw allows a remote, unauthenticated attacker to cause a denial-of-service (DoS). Patch immediately to prevent network disruption. #Cisco #ZeroDay #CyberSecu...

🔗 cyber.netsecops.io/articles/ci

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
CVE-2026-20349 enables unauthenticated attackers to trigger reloads and denial-of-service on Cisco ASA/FTD firewalls via crafted HTTP requests to SSL VPN.
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
Cisco patched CVE-2026-20349 in Secure Firewall ASA and FTD, a zero-day that could let remote attackers trigger DoS via crafted HTTP requests to the Remote Access SSL VPN service. #Cisco #CVE202620349 #CISA
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
Cisco has confirmed active exploitation of a high-severity vulnerability (CVE-2026-20349) in its Secure Firewall ASA and FTD Software. The flaw […]
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

14 Jul 2026
Published
10 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
1.63%

KEV

Description

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Statistics

  • 11 Posts
  • 5 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Rapid7 published full details and a PoC for CVE-2026-55040, a critical SharePoint authentication bypass that forges JWT tokens. Patch now.

securityonline.info/sharepoint

  • 3
  • 1
  • 0
  • 16h ago
Profile picture fallback
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)

https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-jwt-token-authentication-bypass-cve-2026-55040/
  • 0
  • 1
  • 0
  • 16h ago
Profile picture fallback

「研究者らが、認証不要のリモートコード実行(RCE)を実現するAI支援型SharePointエクスプロイトチェーンを公開 」: #TheHackerNews

「セキュリティ研究者らは、有効なアカウントを持たずに、管理者を含むあらゆるユーザーとしてMicrosoft SharePointサーバーに侵入する方法を発見した。この発見に大きく貢献したのが、AIエージェントを用いた作業だった。

CVE-2026-55040 (CVSS 9.1)として追跡されているこの脆弱性は 、SharePoint Server Subscription Edition、SharePoint Server 2019、およびSharePoint Server 2016に影響します。マイクロソフトの影響を受ける製品リストには、これら3つのオンプレミス版のみが含まれており、SharePoint Onlineは含まれていません。

この攻撃手法は、認証されていないリモート攻撃者が、選択したユーザーの身元を偽装することを可能にします。 」

thehackernews.com/2026/08/rese

#prattohome

  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback

Tracked as CVE-2026-55040, this authentication bypass security flaw in the JWT token validation pipeline can be exploited by attackers without privileges to perform operations as a SharePoint site user or administrator. bleepingcomputer.com/news/micr

  • 0
  • 0
  • 1
  • 10h ago
Profile picture fallback

New SharePoint auth bypass already being exploited hours after PoC went public

Rapid7 published a proof-of-concept exploit today for CVE-2026-55040, an authentication bypass in SharePoint's JWT token validation that lets an attacker impersonate any user or admin without credentials....

itnerd.blog/2026/08/12/new-sha

  • 0
  • 0
  • 1
  • 6h ago
Profile picture fallback

En las últimas 24 horas, se detectaron vulnerabilidades críticas en Microsoft SharePoint que permiten ejecución remota de código sin autenticación, potenciada por IA, y fallas en autenticación con manipulación de tokens. Cisco alerta sobre exploits activos que afectan sus VPN ASA y FTD, mientras México enfrenta pérdidas millonarias por rezago en ciberseguridad. Además, DEF CON ofrece acceso libre a su valioso contenido formativo. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 12/08/26 📆 |====

🔓 VULNERABILIDAD CRÍTICA EN MICROSOFT SHAREPOINT: EJECUCIÓN REMOTA DE CÓDIGO

Rapid7 y Microsoft han revelado una grave vulnerabilidad en SharePoint, identificada como CVE-2026-63520, que permite la ejecución remota de código sin autenticación cuando se combina con otra falla. Esta amenaza pone en riesgo servidores corporativos, facilitando ataques sofisticados que pueden comprometer datos sensibles y el control del sistema. Mantener SharePoint actualizado es vital para proteger su entorno. Descubre los detalles completos sobre esta vulnerabilidad y cómo proteger tu infraestructura aquí 👉 djar.co/3cd5Vh

🛡️ ANÁLISIS DETALLADO DE FALLAS EN LA AUTENTICACIÓN DE MICROSOFT SHAREPOINT (CVE-2026-55040)

Un análisis técnico profundo revela cómo CVE-2026-55040 permite eludir el sistema de autenticación mediante la manipulación del token JWT en SharePoint. Esta brecha puede ser explotada por atacantes para suplantar identidades y obtener acceso indebido, facilitando ataques posteriores. Comprender la naturaleza de esta vulnerabilidad es esencial para implementar medidas de defensa eficaces. Consulta el informe técnico completo y fortalece tu seguridad aquí 👉 djar.co/SrXg

🤖 CADENA DE EXPLOTACIÓN CON ASISTENCIA DE IA EN SHAREPOINT: RIESGO DE EJECUCIÓN REMOTA SIN AUTENTICAR

Investigadores han demostrado cómo la vulnerabilidad CVE-2026-55040, combinada con CVE-2026-63520, permite a los atacantes no autenticados ejecutar código remotamente en SharePoint. El uso de inteligencia artificial en esta cadena de explotación agiliza y potencia la sofisticación del ataque, elevando los riesgos para organizaciones que no actualizan a tiempo sus sistemas. Infórmate sobre esta amenaza avanzada y cómo mitigarla inmediatamente 👉 djar.co/h7SaRv

🔥 ALERTA DE CISCO: VULNERABILIDAD EN VPN ASA Y FTD CON EXPLOIT ACTIVAMENTE USADO

Cisco ha emitido una advertencia crítica sobre una vulnerabilidad de alta gravedad en sus productos Secure Firewall ASA y Threat Defense (FTD). Ha sido detectado un exploit activo que provoca ataques de denegación de servicio remoto, llevando a la caída de dispositivos, comprometiendo la continuidad operativa de las redes corporativas. Es imprescindible aplicar los parches y seguir las recomendaciones oficiales para evitar interrupciones. Conoce la advertencia oficial y pasos para proteger tus dispositivos aquí 👉 djar.co/qy7j

💸 IMPACTO DEL REZAGO EN CIBERSEGURIDAD EN MÉXICO: PÉRDIDAS MILLONARIAS

El rezago en ciberseguridad que enfrenta México está generando un impacto económico de miles de millones de pesos, afectando tanto al sector privado como al público. La falta de inversiones adecuadas y estrategias de protección digital robustas pone en riesgo la estabilidad tecnológica y financiera del país. Conocer esta realidad invita a reflexionar sobre la urgencia de implementar políticas y prácticas eficaces en seguridad informática. Lee el análisis completo sobre esta problemática y su impacto económico aquí 👉 djar.co/QWHu9

📼 ACCESO LIBRE A TODO EL CONTENIDO DE DEF CON: PRESENTACIONES, DOCUMENTALES Y MÁS

Para quienes buscan formación continua en seguridad informática, media.defcon.org ofrece un archivo completo con videos, presentaciones, documentales y más del reconocido congreso DEF CON. Este extenso repositorio es una fuente invaluable de conocimiento actual, técnicas, y tendencias en hacking ético y defensa digital. No pierdas la oportunidad de aprender de los mejores expertos del mundo. Explora todo el material disponible para potenciar tu expertise aquí 👉 djar.co/XzsPs

  • 0
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) www.rapid7.com -> Original->
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
Rapid7's PoC for CVE-2026-55040, a critical SharePoint auth bypass, is already being used in attacks on honeypots. Microsoft patched it in July 2026. #SharePoint #Rapid7 #CVE202655040
  • 0
  • 0
  • 0
  • 9h ago
Profile picture fallback
SharePoint CVE-2026-55040 is being exploited in the wild soon after Rapid7 published a PoC. Microsoft also patched CVE-2026-63520, which may chain to enable unauthenticated RCE on SharePoint servers. #SharePoint #Microsoft #Rapid7
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Microsoft
  • Microsoft Malware Protection Engine

16 Jun 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
10.75%

KEV

Description

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".

Statistics

  • 5 Posts
  • 1 Interaction

Last activity: 6 hours ago

Fediverse

Profile picture fallback

A public PoC named ShieldBreak bypasses Microsoft's CVE-2026-50656 patch, enabling Windows Defender privilege escalation to SYSTEM.

securityonline.info/shieldbrea

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

„Microsoft hat mit dem August 2026-Patchday zwar einige Sicherheitskorrekturen ausgeliefert. Aber die RoguePlanet genannte Schwachstelle (CVE-2026-50656) soll nicht ausreichend abgeschwächt worden sein. Der als Nightmare Eclipse agierende Sicherheitsforscher hat einen ShieldBreak genannten Proof of Concept (PoC) veröffentlicht.“

borncity.com/blog/2026/08/12/s

  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback

August 2026 Patchday: Updates gerade freigegeben, da veröffentlicht Nightmare Eclipse #Shieldbreak als Proof of Concept (PoC). Der PoC umgeht die ungenügend gepatchte #Defender Schwachstelle CVE-2026-50656 (#RoguePlanet).
borncity.com/blog/2026/08/12/s

  • 0
  • 0
  • 1
  • 15h ago

Bluesky

Profile picture fallback
ShieldBreak is a claimed patch bypass for Defender flaw CVE-2026-50656, with a PoC tested on Windows 11 25H2 and Server 2025.
  • 0
  • 1
  • 0
  • 6h ago

Overview

  • Adobe
  • Adobe Commerce

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
0.48%

KEV

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: Last hour

Bluesky

Profile picture fallback
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.
  • 1
  • 1
  • 0
  • 1h ago
Profile picture fallback
Adobe Commerce and Magento are facing CVE-2026-71362, a critical auth flaw that can hijack customer sessions and expose account data. Sansec says its Shield WAF is already blocking exploit attempts. #AdobeCommerce #Magento #CVE2026-71362
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Metabase
  • Metabase

10 Aug 2026
Published
12 Aug 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
1.07%

Description

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.

Statistics

  • 2 Posts

Last activity: 9 hours ago

Fediverse

Profile picture fallback

🚨 CRITICAL THREAT: CISA adds CVE-2026-72898 (Metabase SQL Injection) to the KEV catalog due to active exploitation. Unauthenticated attackers can hijack admin rights and steal database credentials. Full TSUITE brief with SPL, KQL, AQL & YARA-L: thecybermind.co/jily

  • 0
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
🚨 Critical Metabase SQL injection (CVE-2026-72898) CVSS 10.0. No authentication required. Actively exploited in the wild.
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Ivanti
  • Endpoint Manager

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.87%

KEV

Description

Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections.

Statistics

  • 3 Posts

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Tracked as CVE-2026-18129, the first is described as a cleartext transmission of sensitive information issue that can be exploited by an attacker in a man-in-the-middle (MitM) position to leak credentials for external SQL connections. securityweek.com/ivanti-epm-up

  • 0
  • 0
  • 1
  • 10h ago

Bluesky

Profile picture fallback
Ivanti patched 4 flaws in Endpoint Manager and Neurons for MDM, including a credential leak in SQL connections and a crash bug. No in-the-wild exploitation seen. #Ivanti #EndpointManager #CVE202618129
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Trusted Computing Group
  • TPM2.0

11 Aug 2026
Published
12 Aug 2026
Updated

CVSS
Pending
EPSS
0.22%

KEV

Description

An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.

Statistics

  • 2 Posts

Last activity: 18 hours ago

Bluesky

Profile picture fallback
Compute Engine update on August 11, 2026 https://docs.cloud.google.com/compute/docs/release-notes#August_11_2026 #googlecloud A vulnerability (CVE-2026-6726) in the Trusted Computing Group's TPM 2.0 reference implementation code was discovered and is being addressed
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
JVNVU#96623328: TCG TPM2.0のリファレンス実装における複数の脆弱性(CVE-2026-6726、CVE-2026-6727) https://jvn.jp/vu/JVNVU96623328/
  • 0
  • 0
  • 0
  • 20h ago

Overview

  • Phoenix Contact
  • AXC F 1152

12 Aug 2026
Published
12 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.59%

KEV

Description

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote attacker could exploit this vulnerability to reboot the device or execute arbitrary code.

Statistics

  • 2 Posts
  • 5 Interactions

Last activity: 8 hours ago

Fediverse

Profile picture fallback

BoF in a PROFINET service?! I'm shocked. Shocked! Well, not that shocked.

nvd.nist.gov/vuln/detail/CVE-2

  • 0
  • 4
  • 0
  • 8h ago
Profile picture fallback

VDE-2025-056
Phoenix Contact: Improper Input Validation Vulnerabilities in PLCnext Firmware

This advisory addresses multiple security vulnerabilities in PLCnext firmware versions prior to 2026.0.3. The vulnerabilities may allow unauthenticated attackers to cause denial of service, trigger unexpected system behavior, or execute unauthorized SQL queries. Successful exploitation could impact the availability, integrity, and confidentiality of affected PLCnext Control devices. All issues are resolved in PLCnext firmware version 2026.0.3.
CVE-2025-41769, CVE-2025-41770, CVE-2025-41771

certvde.com/en/advisories/vde-

phoenixcontact.csaf-tp.certvde

  • 0
  • 1
  • 0
  • 14h ago

Overview

  • VMware
  • Cloud Foundation

30 Jul 2026
Published
30 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.14%

KEV

Description

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.

Statistics

  • 3 Posts

Last activity: 7 hours ago

Fediverse

Profile picture fallback

The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. thehackernews.com/2026/08/atta

  • 0
  • 0
  • 1
  • 10h ago
Profile picture fallback

📰 VMware Patches Critical VM Escape Flaw (CVE-2026-47876) in ESXi

Broadcom patches critical VMware flaws, including a VM escape in ESXi (CVE-2026-47876) and unauthenticated RCE in vCenter (CVE-2026-59309, CVE-2026-59310). CVSS scores up to 9.8. Immediate patching is crucial. #VMware #CyberSecurity #PatchTuesday

🔗 cyber.netsecops.io/articles/vm

  • 0
  • 0
  • 0
  • 7h ago
Showing 1 to 10 of 87 CVEs