24h | 7d | 30d

Overview

  • Cisco
  • Cisco Secure Endpoint

07 Aug 2026
Published
07 Aug 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.36%

KEV

Description

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
Cisco alerta para duas falhas graves no ClamAV que ameaçam sistemas Windows, permitindo ataques remotos de negação de serviço (DoS) sem autenticação prévia. As vulnerabilidades, CVE-2026-20337 e CVE-2026-20338, afetam o analisador de ficheiros ZIP do sistema de código aberto. 🚨 #alerta #graves #win
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Cisco
  • Cisco Secure Endpoint

07 Aug 2026
Published
07 Aug 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
Pending

KEV

Description

A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software.

Statistics

  • 1 Post

Last activity: Last hour

Bluesky

Profile picture fallback
Cisco alerta para duas falhas graves no ClamAV que ameaçam sistemas Windows, permitindo ataques remotos de negação de serviço (DoS) sem autenticação prévia. As vulnerabilidades, CVE-2026-20337 e CVE-2026-20338, afetam o analisador de ficheiros ZIP do sistema de código aberto. 🚨 #alerta #graves #win
  • 0
  • 0
  • 0
  • Last hour

Overview

  • Red Hat
  • Red Hat Enterprise Linux 10
  • libvirt

07 Aug 2026
Published
07 Aug 2026
Updated

CVSS
Pending
EPSS
0.24%

KEV

Description

An injection vulnerability was found in libvirt's virtual network driver. The network XML parser does not strip newline characters from DNS TXT record value attributes and SRV record domain/target attributes. These values are written verbatim into the dnsmasq configuration file generated by the network driver, allowing a user with permission to define virtual networks to inject arbitrary dnsmasq configuration directives such as dhcp-script, leading to arbitrary command execution as root.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
[release-26.05] libvirt: fix CVE-2026-61478 and CVE-2026-61477 https://github.com/NixOS/nixpkgs/pull/551428 #security
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • SolarWinds
  • Web Help Desk

30 Jul 2026
Published
31 Jul 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.64%

KEV

Description

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to be enabled.

Statistics

  • 1 Post

Last activity: 9 hours ago

Bluesky

Profile picture fallback
The latest update for #ArcticWolf includes "Active #SupplyChain Attack on npm Packages (keyv, cacheable): Immediate Mitigation Required" and "SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299". #cybersecurity #infosec #networks https://opsmtrs.com/2ZFbaTl
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Linux
  • Linux

04 Aug 2026
Published
09 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.12%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root. On its own, populating an invalid root is "fine", but because child shadow pages inherit their parent's role, any children created during the map/fetch will be created as invalid pages, thus violating KVM's invariant that invalid pages are never on the list of active MMU pages. Note, the underlying flaw has existed since KVM first started tracking invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root pagetables"), but the true badness only came along in 2020 (Linux 5.9) with the invariant that invalid shadow pages can't be on the list of active pages. Note #2, inheriting role.invalid when creating child shadow pages is also far from ideal; that flaw will be addressed separately.

Statistics

  • 1 Post

Last activity: 1 hour ago

Fediverse

Profile picture fallback

La innovadora botnet Aeternum usa blockchain para evadir detección, mientras cámaras IP ucranianas y drones militares sufren infiltraciones que exponen datos sensibles; una vulnerabilidad crítica en KVM permite escalada de privilegios y ataques a plugins de WordPress generan accesos administrativos falsos; además, ransomware de origen chino amenaza sistemas empresariales. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 11/08/26 📆 |====

🔐 ANÁLISIS DE LA AMENAZA PERMANENTE: BOTNET AETERNUM USANDO BLOCKCHAIN

La botnet Aeternum representa un riesgo avanzado al utilizar contratos inteligentes en la blockchain Polygon para establecer una infraestructura descentralizada de comando y control (C2). Esta arquitectura evita la detección tradicional y facilita la ejecución de cargas maliciosas. Conocer esta técnica innovadora es esencial para reforzar las defensas contra amenazas persistentes modernas. Descubre el análisis completo y cómo proteger tus sistemas aquí 👉 djar.co/tLv9vV

🎥 EXPLOITACIÓN DE CÁMARAS IP UCRANIANAS POR OPERADOR DE HABLA RUSA

Se ha revelado un directorio abierto que expone las herramientas usadas para comprometer cámaras IP en Ucrania, además de intentos de acceso a sitios gubernamentales y militares. Este caso destaca los riesgos reales en dispositivos IoT y la importancia crítica de proteger infraestructuras sensibles ante actores sofisticados. Infórmate sobre las tácticas y medidas preventivas recomendadas aquí 👉 djar.co/Qd0A

⚠️ CVE-2026-64561: ESCAPE DE INVITADOS KVM CON PRIVILEGIOS ROOT EN LINUX

Una vulnerabilidad crítica permite a usuarios invitados de máquinas virtuales KVM escapar al host Linux con privilegios root, comprometiendo la seguridad del sistema completo. Este fallo subraya la urgencia de aplicar parches y fortalecer configuraciones en entornos virtualizados para evitar accesos no autorizados de alto nivel. Lee el análisis técnico y recomendaciones aquí 👉 djar.co/v9txO

🛠️ ATAQUE A LA CADENA DE SUMINISTRO EN PLUGINS DE WORDPRESS BdThemes

Se ha detectado la explotación de paquetes JSON maliciosos en plugins de WordPress, permitiendo a atacantes crear usuarios administradores falsos y desplegar shells web PHP sin necesidad de actualizar los plugins. Esta vulnerabilidad de tipo XSS evidencia el peligro que representa no validar adecuadamente componentes de terceros y la necesidad de mantener actualizaciones constantes. Entiende cómo mitigar este riesgo hoy mismo aquí 👉 djar.co/3ib0TB

🚁 VULNERABILIDADES EN DRONES MILITARES DE LA MARINA REAL: FILTRACIÓN DE DATOS HACIA CHINA

Un informe revela que drones de la Marina Real presentan fallas de seguridad que permiten la transmisión no autorizada de información sensible hacia China. Este incidente resalta la importancia de implementar controles robustos en sistemas militares y tecnológicos para proteger datos estratégicos. Accede al reporte completo y medidas recomendadas aquí 👉 djar.co/DLBej8

🦠 RANSOMWARE STORMENCRYPTOR DESPLEGADO POR HACKERS VINCULADOS A CHINA

Microsoft alerta que el grupo Storm-1175 utiliza el ransomware StormEncryptor, aprovechando la vulnerabilidad CVE-2026-18577 en N-able N-central para comprometer sistemas empresariales. Se recomienda la aplicación inmediata de parches y monitoreo activo para evitar daños severos por este ataque sofisticado. Profundiza en la investigación y pautas de defensa aquí 👉 djar.co/tV8x

  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post

Last activity: 1 hour ago

Bluesky

Profile picture fallback
[release-26.05] libvirt: fix CVE-2026-61478 and CVE-2026-61477 https://github.com/NixOS/nixpkgs/pull/551428 #security
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • SolarWinds
  • Web Help Desk

02 Jun 2026
Published
03 Jun 2026
Updated

CVSS v3.1
HIGH (8.2)
EPSS
0.49%

KEV

Description

SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash due to insufficient memory.

Statistics

  • 1 Post

Last activity: 9 hours ago

Bluesky

Profile picture fallback
The latest update for #ArcticWolf includes "Active #SupplyChain Attack on npm Packages (keyv, cacheable): Immediate Mitigation Required" and "SolarWinds Web Help Desk Vulnerabilities: CVE-2026-28323 and CVE-2026-28299". #cybersecurity #infosec #networks https://opsmtrs.com/2ZFbaTl
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Microsoft
  • Microsoft Defender Antimalware Platform

14 Apr 2026
Published
19 Jun 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
6.75%

Description

Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
~Kaspersky~ Q2 2026: ~400M attacks blocked; Qilin led ransomware (15% DLS victims); CVE-2026-33825 & CVE-2026-50751 actively exploited. - IOCs: CVE-2026-33825, CVE-2026-50751, CVE-2026-50752 - #CVE2026 #Ransomware #ThreatIntel
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • checkpoint
  • Quantum Security Gateway

08 Jun 2026
Published
10 Jun 2026
Updated

CVSS v3.1
HIGH (7.4)
EPSS
4.55%

KEV

Description

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
~Kaspersky~ Q2 2026: ~400M attacks blocked; Qilin led ransomware (15% DLS victims); CVE-2026-33825 & CVE-2026-50751 actively exploited. - IOCs: CVE-2026-33825, CVE-2026-50751, CVE-2026-50752 - #CVE2026 #Ransomware #ThreatIntel
  • 0
  • 0
  • 0
  • 23h ago

Overview

  • checkpoint
  • Quantum Security Gateway

08 Jun 2026
Published
04 Aug 2026
Updated

CVSS
Pending
EPSS
82.55%

Description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Statistics

  • 1 Post

Last activity: 23 hours ago

Bluesky

Profile picture fallback
~Kaspersky~ Q2 2026: ~400M attacks blocked; Qilin led ransomware (15% DLS victims); CVE-2026-33825 & CVE-2026-50751 actively exploited. - IOCs: CVE-2026-33825, CVE-2026-50751, CVE-2026-50752 - #CVE2026 #Ransomware #ThreatIntel
  • 0
  • 0
  • 0
  • 23h ago
Showing 41 to 50 of 50 CVEs