Aggregator
Завершить сессии, сменить пароли, включить 2FA. Что Fortinet советует сделать владельцам FortiGate прямо сейчас
5 days 20 hours ago
Хакеры атаковали сетевые шлюзы Fortinet с помощью старых утечек и подбора паролей.
CVE-2017-6679 | Cisco Umbrella Virtual Appliance up to 2.0.3 SSH 7pk security (BID-101567)
5 days 20 hours ago
A vulnerability, which was classified as critical, was found in Cisco Umbrella Virtual Appliance up to 2.0.3. Affected by this vulnerability is an unknown functionality of the component SSH. The manipulation results in 7pk security features.
This vulnerability is cataloged as CVE-2017-6679. The attack must be initiated from a local position. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2022-20773 | Cisco Umbrella Virtual Appliance Key-based SSH Authentication hard-coded key (cisco-sa-uva-static-key-6RQTRs4c)
5 days 20 hours ago
A vulnerability classified as critical was found in Cisco Umbrella Virtual Appliance. This affects an unknown part of the component Key-based SSH Authentication Handler. Executing a manipulation can lead to use of hard-coded cryptographic key
.
This vulnerability is registered as CVE-2022-20773. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2022-20969 | Cisco Umbrella Dashboard cross site scripting (cisco-sa-umbrella-xss-LfeYQV3)
5 days 20 hours ago
A vulnerability categorized as problematic has been discovered in Cisco Umbrella. Affected by this vulnerability is an unknown functionality of the component Dashboard. The manipulation results in cross site scripting.
This vulnerability is known as CVE-2022-20969. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-30794 | rustdesk-client RustDesk Client up to 1.4.5 http_client.Rs certificate validation
5 days 20 hours ago
This appears to be a false positive. Please validate the mentioned sources and consider excluding this entry altogether.
vuldb.com
CVE-2026-30789 | rustdesk-client RustDesk Client up to 1.4.5 src/client.Rs hash_password authentication replay
5 days 20 hours ago
A vulnerability, which was classified as critical, was found in rustdesk-client RustDesk Client up to 1.4.5. This impacts the function hash_password of the file src/client.Rs. Executing a manipulation can lead to authentication bypass by capture-replay.
The identification of this vulnerability is CVE-2026-30789. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-30790 | RustDesk Server Pro/RustDesk Server up to 1.7.5 src/server/connection.Rs excessive authentication
5 days 20 hours ago
This issue was flagged as a false-positive. Please consult the sources mentioned and consider not using this entry at all.
vuldb.com
CVE-2026-0419 | Netgear JR6150 up to 1.0.1.26 input validation
5 days 20 hours ago
A vulnerability was found in Netgear JR6150 up to 1.0.1.26. It has been classified as critical. Affected by this vulnerability is an unknown functionality. This manipulation causes improper input validation.
This vulnerability is tracked as CVE-2026-0419. The attack is restricted to local execution. No exploit exists.
vuldb.com
CVE-2026-0420 | Netgear RAX120v1/RAX120v2/RAX35/RAX38/RAX40 prior 1.2.9.52 TLS Certificate Validation missing cryptographic step
5 days 20 hours ago
A vulnerability was found in Netgear RAX120v1, RAX120v2, RAX35, RAX38 and RAX40. It has been declared as problematic. Affected by this issue is some unknown functionality of the component TLS Certificate Validation Handler. Such manipulation leads to missing cryptographic step.
This vulnerability is listed as CVE-2026-0420. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-3088 | Netgear RBSE960 prior 7.2.7.15 out-of-bounds write
5 days 20 hours ago
A vulnerability classified as critical was found in Netgear RBR860, RBRE950, RBRE960, RBRE970, RBRE971, RBS860, RBSE950 and RBSE960. Affected by this issue is some unknown functionality. Executing a manipulation can lead to out-of-bounds write.
The identification of this vulnerability is CVE-2026-3088. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-8450 | OALDERS HTTP::Daemon up to 6.16 on Perl send_file os command injection (EUVD-2026-32050 / Nessus ID 321644)
5 days 20 hours ago
A vulnerability has been found in OALDERS HTTP::Daemon up to 6.16 on Perl and classified as critical. This affects the function send_file. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2026-8450. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
Red Hat security advisory (AV26-621)
5 days 20 hours ago
Canadian Centre for Cyber Security
Threat Hunting Beyond Alerts: Finding the Activity Detection Misses
5 days 20 hours ago
Disclosure: This article was provided by ANY.RUN. The information and analysis presented are based on their research and findings.
Owais Sultan
He Thought He Was Secure; His Phone Number Was Stolen Anyway
5 days 20 hours ago
Threat actors can easily steal one-time passwords sent by text when they conduct a SIM swap attack. This can lead to account takeovers, so users must layer up their security measures.
Arielle Waldman
Suspected cyberattack triggers false emergency alerts across parts of Brazil
5 days 20 hours ago
The incident occurred early Saturday when at least a dozen unauthorized alerts were sent through Brazil's Civil Defense Alert system, a platform designed to warn residents about imminent threats such as floods, landslides and other natural disasters.
[Control systems] CISA ICS security advisories (AV26–620)
5 days 20 hours ago
Canadian Centre for Cyber Security
A Glimpse into the “Search Your Target” Market for Stolen Credentials
5 days 20 hours ago
Attackers no longer need to sift through massive credential dumps. They can pay others to do it for them. Flare explores how an emerging underground market searches stolen credential databases for specific companies, domains, and accounts. [...]
Sponsored by Flare
76% кибератак в России направлены на остановку бизнеса
5 days 20 hours ago
Согласно исследованию более чем 100 крупных киберинцидентов за 2023–2025 годы от «Инфосистемы Джет»
Unpatchable BootROM Flaw Impacts Apple A12, A13 Chips
5 days 20 hours ago
Apple BootROM exploit exposes unpatchable USB flaw on A12 and A13 devices