Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-07-28 16:55 Nästa om --:-- Försenad
14 av 14 källor 10 per källa

IT-säkerhet och cybersäkerhet i realtid — CVE-varningar, sårbarhetsrapporter, incidenter och hotinformation från NVD, CISA, BleepingComputer och fler SOC-källor.

Snabbfilter
Toppnyheter Säkerhet
SecurityWeek Vulnerabilities 6 min
SecurityWeek Vulnerabilities

Cyera Acquiring Oasis Security in $1 Billion Deal

Oasis Security recently raised $120 million in Series B funding for its agentic access management platform. The post Cyera Acquiring Oasis Security in $1 Billion Deal appeared first on SecurityWeek.

2026-07-28 16:55 6 min
Full coverage Flera perspektiv på samma ämne.
2 källor · 2026-07-28 08:40
BleepingComputer SecurityWeek Vulnerabilities
Fler källor:
Säkerhet 120 artiklar
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Cyera Acquiring Oasis Security in $1 Billion Deal

Oasis Security recently raised $120 million in Series B funding for its agentic access management platform. The post Cyera Acquiring Oasis Security in $1 Billion Deal appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-54545: @wakaru/cli arbitrary file write during bundle unpack

### Impact `@wakaru/cli` is vulnerable to arbitrary file write when unpacking a crafted JavaScript bundle with `--unpack`. Bundle-controlled module filenames were sanitized before writing extracted modules to the...

GitHub Security Advisories ikon GitHub Security Advisories
GitHub Security Advisories ikon
GitHub Security Advisories
GHSA-hp74-gm6m-2qm5: Pocket ID has a reauthentication bypass via one-time access token login — passkey step-up requirement defeated by JWT freshness check that accepts any login method

# Reauthentication Bypass via One-Time Access Token Login ## Summary A weaker authentication method (OTA token or signup token) is accepted as passkey step-up proof, yielding unauthorized renewable 30-day OIDC refresh...

GitHub Security Advisories ikon GitHub Security Advisories
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe

Apple announced that dozens of vulnerabilities have been patched in each of its operating systems. The post Apple Patches 87 Vulnerabilities in iOS, 155 in macOS Tahoe appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
BleepingComputer ikon
BleepingComputer
Is Your SSO Protected Against Modern Credential Attacks?

A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure...

BleepingComputer ikon BleepingComputer
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
OT Security Startup Frenos Raises $1.52 Million

The company will use the fresh investment to grow its customer success and AI R&D teams. The post OT Security Startup Frenos Raises $1.52 Million appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
CISA Alerts ikon
CISA Alerts
CI Fortify – Advice for isolating vital systems

CI Fortify – Advice for isolating vital systems CISA and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), in collaboration with the Federal Bureau of Investigation and international...

CISA Alerts ikon CISA Alerts
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model

The company claims MAI-Cyber-1-Flash tops Anthropic’s Mythos and OpenAI’s GPT-5.6 Sol in CyberGym testing. The post Microsoft Unveils MAI-Cyber-1-Flash, Its First Cybersecurity AI Model appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Act Security Emerges from Stealth to Fight the Patch Problem

Act Security tackles the spiraling patch problem caused by AI’s ability to find new vulnerabilities in existing cloud environments. The post Act Security Emerges from Stealth to Fight the Patch Problem appeared first...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Hush Security Raises $30 Million for AI Agent Governance

The startup will invest in expanding engineering and sales teams, accelerating ecosystem support, and expanding corporate partnerships. The post Hush Security Raises $30 Million for AI Agent Governance appeared first...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Google Adopts New Threat Actor Naming System

The new two-word naming convention uses a memorable term utilized in public reporting and a cluster-categorization word. The post Google Adopts New Threat Actor Naming System appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Unpatched Fastjson Vulnerability Exploited in Attacks

The critical remote code execution bug can be exploited without authentication, under the library’s stock default configurations. The post Unpatched Fastjson Vulnerability Exploited in Attacks appeared first on...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

Impacting on-premises deployments, the OS command injection allows attackers to access privileged internal functionality. The post Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day appeared...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
1 fler källor
BleepingComputer Arista patches VeloCloud Orchestrator zero-day exploited in attacks 2026-07-28 00:49
BleepingComputer ikon
BleepingComputer
Hackers target US firms in FastJson RCE zero-day attacks

Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. [...]

BleepingComputer ikon BleepingComputer
BleepingComputer ikon
BleepingComputer
New Dysphoria DDoS botnet spreads to 200k devices worldwide

A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]

BleepingComputer ikon BleepingComputer
BleepingComputer ikon
BleepingComputer
New Certighost PoC exploit lets attackers hijack Windows domains

A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]

BleepingComputer ikon BleepingComputer
Dark Reading ikon
Dark Reading
Why Resetting Passwords No Longer Stops Attackers

As attackers shift from password theft to session and token theft to bypass multifactor authentication controls, organizations must move beyond login security and protect authenticated sessions.

Dark Reading ikon Dark Reading
BleepingComputer ikon
BleepingComputer
Ernst & Young data breach claimed by ShinyHunters extortion gang

The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. [...]

BleepingComputer ikon BleepingComputer
CISA Alerts ikon
CISA Alerts
CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an...

CISA Alerts ikon CISA Alerts
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2025-68686 – Fortinet FortiOS

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-16812 – Arista VeloCloud Orchestrator

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may...

CISA KEV-katalog ikon CISA KEV-katalog
Microsoft MSRC ikon
Microsoft MSRC
Chromium: CVE-2026-16804 Use after free in Input

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Microsoft MSRC ikon Microsoft MSRC
Dark Reading ikon
Dark Reading
CISOs vs. Boards: Myth or Misunderstanding?

Escalating threats are forcing boards to prioritize security, but communication gaps persist. Boards and security teams each say they need more support to bridge the divide.

Dark Reading ikon Dark Reading
CISA Alerts ikon
CISA Alerts
MZ Automation libIEC61850

View CSAF Summary Successful exploitation of these vulnerabilities could allow an unauthenticated network-adjacent attacker to crash critical IEC 61850 services or execute arbitrary code, disrupting or compromising...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Panduit IntraVUE

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with access to the IT network to manipulate industrial control devices without requiring physical access, specialized insider...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Johnson Controls C-CURE 9000 and Victor application server

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
MZ Automation lib60870

View CSAF Summary Successful exploitation of this vulnerability could cause the parsing process to crash, which will cause a denial of service. The following versions of MZ Automation lib60870 are affected: lib60870...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Johnson Controls XAAP Android

View CSAF Summary Successful exploitation of this vulnerability could result in an attacker obtaining confidential information from the device. The following versions of Johnson Controls XAAP Android are affected:...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Rockwell Automation ThinManager

View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended directory. The...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Weintek cMT3092X

View CSAF Summary Successful exploitation of these vulnerabilities could allow a non-privileged user to escalate privileges or view the credentials of other users. The following versions of Weintek cMT3092X are...

CISA Alerts ikon CISA Alerts
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-16232 – Check Point SmartConsole

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-50522 – Microsoft SharePoint

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. | Åtgärd: Apply mitigations in accordance with vendor...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-58644 – Microsoft SharePoint 2026-07-16 02:00
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-59850 — MEDIUM — CVSS 4.3

A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invoked after the associated data has already been freed, leading to crashes or possible use-after-...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-47122 — MEDIUM — CVSS 4.2 2026-07-21 17:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-59849 — LOW — CVSS 3.1

A flaw was found in libssh. Logic errors in automatic certificate-based public key authentication can cause libssh clients to loop indefinitely when configured certificates are missing or repeatedly rejected by a...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-56587 — LOW — CVSS 3.7 2026-07-21 17:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-56584 — LOW — CVSS 3.7

HCL IEM was affected with the Information disclosure nginx server. It may enable attackers to identify outdated software versions and target known vulnerabilities or publicly available exploits.

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-46681

@nevware21/ts-utils is a comprehensive TypeScript/JavaScript utility library. Prior to version 0.14.0, the _copyProps function in lib/src/object/copy.ts uses for...in to iterate over source object properties without...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-16448 — MEDIUM — CVSS 6.3

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4,...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-11876 — MEDIUM — CVSS 5.0 2026-07-21 17:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-15226 — HIGH — CVSS 8.4

A sandbox confinement bypass vulnerability exists in Canonical snapd within its internal execution environment compiler (snap-confine). The default seccomp security templates generated by the engine to restrict system...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2024-5300 — MEDIUM — CVSS 5.6

An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules located in /etc/apparmor.d/abstractions/nss-...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-60137 – WordPress Core

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-63030 – WordPress Core 2026-07-21 02:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-0770 – Langflow Langflow

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. | Åtgärd: Apply mitigations in accordance...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2021-27137 – DD-WRT DD-WRT

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. | Åtgärd: Apply...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-25089 – Fortinet FortiSandbox

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP...

CISA KEV-katalog ikon CISA KEV-katalog
Cisco PSIRT ikon
Cisco PSIRT
Cisco RoomOS Security Hardening Release: July 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...

Cisco PSIRT ikon Cisco PSIRT
Cisco PSIRT ikon
Cisco PSIRT
Cisco Identity Services Engine Path Traversal Vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating...

Cisco PSIRT ikon Cisco PSIRT
CERT-SE ikon
CERT-SE
Kritiska sårbarheter i SonicWall SMA1000

SonicWall har publicerat säkerhetsuppdateringar gällande två sårbarheter (CVE-2026-15409 och CVE-2026-15410) i SMA1000-serien. [1] CISA har lagt till dessa sårbarheter i KEV-katalogen (Known Exploited Vulnerabilities...

CERT-SE ikon CERT-SE
CERT-SE ikon
CERT-SE
Skadliga npm-paket

Ett koordinerat leveranskedjeangrepp har drabbat separata AsyncAPI GitHub-repon. Angripare har utnyttjat en sårbarhet i GitHub Actions. [1]

CERT-SE ikon CERT-SE
Fortinet PSIRT ikon
Fortinet PSIRT
Buffer overread in authd and wad daemon

CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Cross-Site Scripting in Domain parameter

CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Header injection in Web Filter warning page

CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Header injection in captive portal authentication form

CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Out of bounds read in GUI

CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Revised on...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Path traversal in CLI command allows deletion of root file system

CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
SSL-VPN Reflected XSS

CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Stack Buffer Overflow in Log Report

CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Supers override fails to properly override supervisor address

CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute...

Fortinet PSIRT ikon Fortinet PSIRT
1 fler källor
Palo Alto Networks Advisories CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface (Severity: LOW) 2026-07-08 18:00
Cisco PSIRT ikon
Cisco PSIRT
Cisco Catalyst Center Arbitrary File Read Vulnerability

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied...

Cisco PSIRT ikon Cisco PSIRT
Ladda fler
Visar 120 av 140 artiklar