Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-07-23 12:10 Nästa om --:-- Försenad
14 av 14 källor 20 per källa

IT-säkerhet och cybersäkerhet i realtid — CVE-varningar, sårbarhetsrapporter, incidenter och hotinformation från NVD, CISA, BleepingComputer och fler SOC-källor.

Snabbfilter
Toppnyheter Säkerhet
Full coverage Flera perspektiv på samma ämne.
2 källor · 2026-07-23 11:06
BleepingComputer SecurityWeek Vulnerabilities
Fler källor:
2 källor · 2026-07-22 17:01
SecurityWeek Vulnerabilities The Hacker News
Säkerhet 120 artiklar
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Assaf Keren Appointed New CISO of Meta

He replaces Guy Rosen, who announced his retirement from the company after 13 years. The post Assaf Keren Appointed New CISO of Meta appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
New Check Point Zero-Day Vulnerability Exploited in the Wild

The vulnerability tracked as CVE-2026-16232 has been exploited against customers with certain configurations. The post New Check Point Zero-Day Vulnerability Exploited in the Wild appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
1 fler källor
Microsoft MSRC CVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service 2026-07-23 10:02
GitHub Security Advisories ikon
GitHub Security Advisories
GHSA-h5v5-8746-g7mm: JupyterLab PluginManager lock-rule enforcement bypass

JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with...

GitHub Security Advisories ikon GitHub Security Advisories
Dark Reading ikon
Dark Reading
Attackers Are Learning to Live Off the AI Toolchain

Sandworm_Mode is an early example of malware that exploits trusted AI tools and workflows to make malicious activity virtually indistinguishable from normal activity.

Dark Reading ikon Dark Reading
BleepingComputer ikon
BleepingComputer
South Korea discloses data breach impacting diplomats worldwide

South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign...

BleepingComputer ikon BleepingComputer
The Hacker News ikon
The Hacker News
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP...

The Hacker News ikon The Hacker News
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts

Hackers leaked names, email addresses, phone numbers, passwords, and financial information stolen from the two platforms. The post Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts appeared first on...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Palo Alto Networks to Acquire Observability Platform Provider Embrace

Acquisition follows January's Chronosphere deal, deepening Palo Alto Networks' push beyond core security into observability. The post Palo Alto Networks to Acquire Observability Platform Provider Embrace appeared...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

An attacker only needed to convince the targeted user to visit a malicious website to exfiltrate WhatsApp messages and contacts. The post Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft appeared...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
StrongestLayer Raises $4.1 Million in Seed Funding Extension

The startup will use the fresh investment to accelerate its go-to-market strategy and to expand its platform. The post StrongestLayer Raises $4.1 Million in Seed Funding Extension appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Vibe-Coded Apps Riddled With Exploitable Security Flaws

Analysis found 434 exploitable flaws in AI-generated apps, with denial-of-service, authorization and secrets exposure risks among the most common issues. The post Vibe-Coded Apps Riddled With Exploitable Security...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
CISA Alerts ikon
CISA Alerts
CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability...

CISA Alerts ikon CISA Alerts
1 fler källor
CISA Alerts CISA Adds Four Known Exploited Vulnerabilities to Catalog 2026-07-21 14:00
The Hacker News ikon
The Hacker News
The Fastest Path to AI Adoption Runs Through Security

Security leaders who build fast, visible paths to AI adoption are becoming the most valued partners in their organizations. AI governance done right gives security teams the visibility they need, employees the tools...

The Hacker News ikon The Hacker News
BleepingComputer ikon
BleepingComputer
CISA orders urgent action on actively exploited Langflow RCE flaw

The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI...

BleepingComputer ikon BleepingComputer
The Hacker News ikon
The Hacker News
Why Modern SOCs Need Multi-Layered Detections

The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most...

The Hacker News ikon The Hacker News
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-16232 – Check Point SmartConsole

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-50522 – Microsoft SharePoint

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. | Åtgärd: Apply mitigations in accordance with vendor...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-58644 – Microsoft SharePoint 2026-07-16 02:00
CISA Alerts ikon
CISA Alerts
Tycon Systems TPDIN-Monitor-WEB2

View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Siemens SIDIS Secured SmartPlug

View CSAF Summary SIDIS Secured SmartPlug before V7.26.0310 is affected by multiple vulnerabilities in the components OpenSSL, OpenSSH, and several other packages as described below. Siemens has released a new version...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Siemens IAM Client

View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Siemens RUGGEDCOM APE1808 with Palo Alto Networks Virtual NGFW

View CSAF Summary Palo Alto Networks has published [1] information on vulnerabilities in PAN-OS. This advisory lists the related Siemens Industrial products affected by these vulnerabilities. Customers are advised to...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Rockwell Automation 1734 POINT I/O

View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1734 POINT I/O are...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Rockwell Automation 1718-AENTR/1719-AENTR

View CSAF Summary Successful exploitation of this vulnerability could allow for an attacker to cause a denial-of-service condition on the product. The following versions of Rockwell Automation 1718-AENTR/1719-AENTR...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Rockwell Automation Studio 5000 Logix Designer

View CSAF Summary Successful exploitation of these vulnerabilities could allow for a local attacker to execute arbitrary files, alter configurations, or execute arbitrary code. The following versions of Rockwell...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Siemens CADRA

View CSAF Summary CADRA is affected by multiple zlib and Foxit vulnerabilities. Siemens has released a new version for CADRA and recommends to update to the latest version. Siemens is preparing further fix versions...

CISA Alerts ikon CISA Alerts
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-60137 – WordPress Core

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-63030 – WordPress Core 2026-07-21 02:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-0770 – Langflow Langflow

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. | Åtgärd: Apply mitigations in accordance...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2021-27137 – DD-WRT DD-WRT

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. | Åtgärd: Apply...

CISA KEV-katalog ikon CISA KEV-katalog
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2025-71377

stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2024-58360 — MEDIUM — CVSS 6.5

stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with unverified...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-59249

Inconsistent interpretation of HTTP requests (HTTP response smuggling) vulnerability in elixir-mint mint allows a malicious HTTP/1 server to desynchronize a strict intermediary and the Mint client on the same pooled...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-35149 — HIGH — CVSS 8.2

HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation. An unauthorized user without valid credentials can exploit this flaw by intercepting and altering the server's...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-35147 — HIGH — CVSS 8.2 2026-07-16 14:17
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-35148 — MEDIUM — CVSS 6.3

HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-35146 — MEDIUM — CVSS 6.3 2026-07-16 14:17
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2023-49900 — CRITICAL — CVSS 9.8

An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2023-49899 — CRITICAL — CVSS 9.8 2026-07-16 13:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-22752 — CRITICAL — CVSS 9.6

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Server: from 7.0.0 through 7.0.4, from 1.5.0 through 1.5.6, from 1.4.0...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-25089 – Fortinet FortiSandbox

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-39808 – Fortinet FortiSandbox 2026-07-16 02:00
Cisco PSIRT ikon
Cisco PSIRT
Cisco RoomOS Security Hardening Release: July 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening...

Cisco PSIRT ikon Cisco PSIRT
Cisco PSIRT ikon
Cisco PSIRT
Cisco Identity Services Engine Path Traversal Vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating...

Cisco PSIRT ikon Cisco PSIRT
CERT-SE ikon
CERT-SE
Kritiska sårbarheter i SonicWall SMA1000

SonicWall har publicerat säkerhetsuppdateringar gällande två sårbarheter (CVE-2026-15409 och CVE-2026-15410) i SMA1000-serien. [1] CISA har lagt till dessa sårbarheter i KEV-katalogen (Known Exploited Vulnerabilities...

CERT-SE ikon CERT-SE
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-46817 – Oracle E-Business Suite

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this...

CISA KEV-katalog ikon CISA KEV-katalog
CERT-SE ikon
CERT-SE
Skadliga npm-paket

Ett koordinerat leveranskedjeangrepp har drabbat separata AsyncAPI GitHub-repon. Angripare har utnyttjat en sårbarhet i GitHub Actions. [1]

CERT-SE ikon CERT-SE
Fortinet PSIRT ikon
Fortinet PSIRT
Buffer overread in authd and wad daemon

CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Cross-Site Scripting in Domain parameter

CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Header injection in Web Filter warning page

CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Header injection in captive portal authentication form

CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Out of bounds read in GUI

CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Revised on...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Path traversal in CLI command allows deletion of root file system

CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
SSL-VPN Reflected XSS

CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Stack Buffer Overflow in Log Report

CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Supers override fails to properly override supervisor address

CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute...

Fortinet PSIRT ikon Fortinet PSIRT
Cisco PSIRT ikon
Cisco PSIRT
Cisco Catalyst Center Arbitrary File Read Vulnerability

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied...

Cisco PSIRT ikon Cisco PSIRT
Ladda fler
Visar 120 av 140 artiklar