Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-08-02 16:04 Nästa om --:-- Försenad
14 av 14 källor 20 per källa

IT-säkerhet och cybersäkerhet i realtid — CVE-varningar, sårbarhetsrapporter, incidenter och hotinformation från NVD, CISA, BleepingComputer och fler SOC-källor.

Snabbfilter
Toppnyheter Säkerhet
CERT-SE 51 d
CERT-SE

Fortsätt att få våra utskick

CERT-SE blir den 1 juli 2026 en del av Nationellt cybersäkerhetscenter som en del i arbetet med att ytterligare stärka Sveriges motståndskraft inom cybersäkerhet. Du kan läsa mer om detta här:...

2026-06-12 12:30 51 d
Security-widgeten är dold. Visa widget
Säkerhet 120 artiklar
BleepingComputer ikon
BleepingComputer
Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

BleepingComputer ikon BleepingComputer
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2016-1000305: guard-livereload has a directory traversal vulnerability

The vulnerability allows remote attackers to read arbitrary files on the server by exploiting improper path validation in the livereload server functionality. This vulnerability is related to the handling of file...

GitHub Security Advisories ikon GitHub Security Advisories
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-53573: core-geonetwork has an Open Redirect Bypass

### Summary GeoNetwork's post-login redirect handling can be bypassed to redirect users to an attacker-controlled external site, even though the code attempts to restrict redirect targets to relative, in-application...

GitHub Security Advisories ikon GitHub Security Advisories
BleepingComputer ikon
BleepingComputer
Online ad firm Adform’s script compromised to steal cryptocurrency

Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones...

BleepingComputer ikon BleepingComputer
1 fler källor
Cisco PSIRT Cisco Secure Firewall Management Center Software Static Credential Vulnerability 2026-07-31 21:49
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-53510: Savon::Model evaluates WSDL operation names as Ruby source

### Impact `Savon::Model` generated SOAP operation methods by interpolating operation names into Ruby source passed to `module_eval`. An attacker who can control the operation names of a WSDL, can inject Ruby code...

GitHub Security Advisories ikon GitHub Security Advisories
BleepingComputer ikon
BleepingComputer
CISA warns of cyberattacks disrupting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a significant increase in attacks targeting internet-exposed programmable logic controllers (PLCs) in the water and wastewater systems...

BleepingComputer ikon BleepingComputer
BleepingComputer ikon
BleepingComputer
ESET tracks rise in malicious AI skills and adaptable malware

Attackers are adapting established techniques to AI platforms, emerging technologies, and changing user behavior. ESET's new threat report examines the rise of malicious AI skills, AI-assisted malware, ClickFix...

BleepingComputer ikon BleepingComputer
BleepingComputer ikon
BleepingComputer
VMware fixes three critical flaws allowing auth bypass, VM escapes

Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code,...

BleepingComputer ikon BleepingComputer
1 fler källor
Microsoft MSRC CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability 2026-07-30 16:00
CISA Alerts ikon
CISA Alerts
NASA Core Flight System (cFS) Health & Safety (HS) Application

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Mitsubishi Electric CC-Link IE TSN Communication Protocol

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
MikroTik RouterOS

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Toptech Systems RCU II+ and Multiload II+

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources. The following versions of...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Watchfire Controller Software

View CSAF Summary Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller. The following versions of...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Johnson Controls OpenBlue Employee

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
MZ Automation GmbH libiec61850

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device. The following versions of MZ Automation GmbH libiec61850 are affected:...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
o6 Automation open62541

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code. The following versions of...

CISA Alerts ikon CISA Alerts
Dark Reading ikon
Dark Reading
Hugging Face Hack: Lessons for Cyber Defenders

Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face.

Dark Reading ikon Dark Reading
CISA Alerts ikon
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password...

CISA Alerts ikon CISA Alerts
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC)

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an...

CISA KEV-katalog ikon CISA KEV-katalog
CISA Alerts ikon
CISA Alerts
ABB KNX Update Tool

View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Siemens Desigo CC

View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
igloohome Smart Lock Mobile Application

View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Application are...

CISA Alerts ikon CISA Alerts
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-13714 — CRITICAL — CVSS 9.8

The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.3.0 does not validate the type of uploaded files, and its file upload functionality is gated only by an API that is enabled by default and...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-13597 — CRITICAL — CVSS 9.1 2026-07-27 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-13390 — MEDIUM — CVSS 5.3

The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-17501 — MEDIUM — CVSS 5.3 2026-07-27 03:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-13332 — CRITICAL — CVSS 9.1

The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-12255 — HIGH — CVSS 8.1

The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-57990 — HIGH — CVSS 7.4 2026-07-26 20:18
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2025-15662 — HIGH — CVSS 8.6

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-17500 — MEDIUM — CVSS 5.3

A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. This affects the function _visit_pattern of the file common/json-schema-to-grammar.cpp. The manipulation results in null pointer dereference. The...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-57978 — MEDIUM — CVSS 5.4 2026-07-26 20:18
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2025-68686 – Fortinet FortiOS

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-16812 – Arista VeloCloud Orchestrator

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may...

CISA KEV-katalog ikon CISA KEV-katalog
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-57989 — HIGH — CVSS 7.4

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-17497 — HIGH — CVSS 8.3 2026-07-26 17:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-17496 — HIGH — CVSS 8.1

NoteGen before 0.32.0 renders AI chat responses with markdown-it configured with html:true and injects the result into the DOM via dangerouslySetInnerHTML in chat-preview, without HTML sanitization and with CSP set to...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-16232 – Check Point SmartConsole

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-50522 – Microsoft SharePoint

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. | Åtgärd: Apply mitigations in accordance with vendor...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-58644 – Microsoft SharePoint 2026-07-16 02:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-60137 – WordPress Core

WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-63030 – WordPress Core 2026-07-21 02:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-0770 – Langflow Langflow

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. | Åtgärd: Apply mitigations in accordance...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2021-27137 – DD-WRT DD-WRT

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. | Åtgärd: Apply...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-25089 – Fortinet FortiSandbox

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-39808 – Fortinet FortiSandbox 2026-07-16 02:00
Cisco PSIRT ikon
Cisco PSIRT
Cisco Identity Services Engine Path Traversal Vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating...

Cisco PSIRT ikon Cisco PSIRT
1 fler källor
CERT-SE Patchtisdag juni 2026 – samlad information om månadens säkerhetsuppdateringar 2026-06-10 14:00
CERT-SE Patchtisdag maj 2026 – samlad information om månadens säkerhetsuppdateringar 2026-05-12 10:32
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-46817 – Oracle E-Business Suite

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this...

CISA KEV-katalog ikon CISA KEV-katalog
Fortinet PSIRT ikon
Fortinet PSIRT
Buffer overread in authd and wad daemon

CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Header injection in Web Filter warning page

CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Header injection in captive portal authentication form

CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Out of bounds read in GUI

CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Revised on...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Path traversal in CLI command allows deletion of root file system

CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Stack Buffer Overflow in Log Report

CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Supers override fails to properly override supervisor address

CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Unauthenticated VNC access exposed on all interfaces

CVSSv3 Score: 7.7 An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSandbox may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests. Revised...

Fortinet PSIRT ikon Fortinet PSIRT
CERT-SE ikon
CERT-SE
CERT-SE:s veckobrev v.26

Fortsätt att få våra utskick - För att ytterligare stärka Sveriges motståndskraft inom cybersäkerhet blir CERT-SE en del av Nationellt cybersäkerhetscenter den 1 juli 2026. Det innebär att vi måste inhämta nytt...

CERT-SE ikon CERT-SE
1 fler källor
CERT-SE CERT-SE:s veckobrev v.25 2026-06-18 15:00
CERT-SE CERT-SE:s veckobrev v.24 2026-06-12 13:15
CERT-SE CERT-SE:s veckobrev v.23 2026-06-05 14:50
CERT-SE CERT-SE:s veckobrev v.20 2026-05-15 13:15
CERT-SE CERT-SE:s veckobrev v.19 2026-05-08 15:10
CERT-SE ikon
CERT-SE
Fortsätt att få våra utskick

CERT-SE blir den 1 juli 2026 en del av Nationellt cybersäkerhetscenter som en del i arbetet med att ytterligare stärka Sveriges motståndskraft inom cybersäkerhet. Du kan läsa mer om detta här:...

CERT-SE ikon CERT-SE
CERT-SE ikon
CERT-SE
Åtgärder för att säkra upp Microsoft 365-miljöer

Vid uppsättning av en klientorganisation (engelska: tenant) i Microsofts molnmiljö är flexibiliteten hög och nya funktioner läggs till kontinuerligt. CERT-SE uppmanar organisationer att regelbundet se över aktiverade,...

CERT-SE ikon CERT-SE
Threatpost ikon
Threatpost
Watering Hole Attacks Push ScanBox Keylogger

Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.

Threatpost ikon Threatpost
Threatpost ikon
Threatpost
Ransomware Attacks are on the Rise

Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.

Threatpost ikon Threatpost
Ladda fler
Visar 120 av 143 artiklar