Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-10-05 13:15 Nästa om --:-- Försenad
14 av 14 källor 10 per källa

IT-säkerhet och cybersäkerhet i realtid — CVE-varningar, sårbarhetsrapporter, incidenter och hotinformation från NVD, CISA, BleepingComputer och fler SOC-källor.

Snabbfilter
Toppnyheter Säkerhet
CERT-SE 3 d
CERT-SE

Antar du vår utmaning? / Do you accept our challenge?

CERT-SE presenterar vår årliga utmaning (CTF) som sker under cybersäkerhetsmånaden [1, 2]. Utmaningen vänder sig till alla med it-säkerhetsintresse oavsett kunskapsnivå.

2026-10-02 12:45 3 d
Säkerhet 28 artiklar
GitHub Security Advisories ikon
GitHub Security Advisories
GHSA-cjcg-cxmh-9wcr: Praxis affected by HTTP/2 Bomb

### Summary Multiple denial-of-service vulnerabilities have been discovered in HTTP/2 server implementations. All have been rated with a severity impact of...

GitHub Security Advisories ikon GitHub Security Advisories
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
CERT-SE ikon
CERT-SE
Kritisk sårbarhet i FortiMail

Fortinet har publicerat information om en kritisk sårbarhet i FortiMail. Sårbarheten, CVE-2026-104286, har fått en CVSS-klassning på 9.8 och påverkar FortiMail managements gränssnitt. Ett framgångsrikt utnyttjande kan...

CERT-SE ikon CERT-SE
CISA Alerts ikon
CISA Alerts
Johnson Controls EasyIO Neo Series EC and CW Controllers

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data. The following versions of Johnson Controls...

CISA Alerts ikon CISA Alerts
1 fler källor
CISA Alerts Johnson Controls EasyIO Neo Series EC and CW Controllers 2026-10-01 14:00
CISA Alerts ikon
CISA Alerts
Meari IoT Cloud Platform OpenAPI Service

View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Monta monta.app

View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Armatura LLC Armatura One

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
ABB Protection and Control IED Manager PCM600

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
CISA Malcolm

View CSAF Summary The following versions of CISA Malcolm are affected: Malcolm CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation ('Cross-site...

CISA Alerts ikon CISA Alerts
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-91006 — HIGH — CVSS 8.8

Apache Karaf's instance-management service (InstanceServiceImpl) builds the command line used to launch a child Karaf JVM by string concatenation, then executes it through /bin/sh (Unix) or cscript (Windows). The...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
CERT-SE ikon
CERT-SE
CERT-SE:s veckobrev v.38

Den här veckan innehåller CERT-SE:s veckobrev bland annat information om att NCSC och AI Sweden med flera bjuder in till seminarium den 22 oktober på temat “Modern sårbarhetshantering i en AI-driven hotmiljö”. Läs mer...

CERT-SE ikon CERT-SE
CERT-SE ikon
CERT-SE
Kritisk sårbarhet i Cisco Secure Email Gateway utnyttjas aktivt

Cisco har publicerat information om en kritisk SQL injection-sårbarhet i Cisco Secure Email Gateway som utnyttjas aktivt. Sårbarheten (CVE-2026-76461) har fått CVSS-klassificering 9.8 (CVSS v.3.1). [1] CISA har lagt...

CERT-SE ikon CERT-SE
CERT-SE ikon
CERT-SE
GitLab rättar kritiska sårbarheter

GitLab har publicerat säkerhetsuppdateringar för flera sårbarheter i GitLab Community Edition (CE) och Enterprise Edition (EE). [1] Två av dessa sårbarheter, CVE-2026-85706 och CVE-2026-87719, klassas som kritiska.

CERT-SE ikon CERT-SE