Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-07-30 03:06 Nästa om --:-- Försenad
14 av 14 källor 20 per källa
Arkiv: 7d

IT-säkerhet och cybersäkerhet i realtid — CVE-varningar, sårbarhetsrapporter, incidenter och hotinformation från NVD, CISA, BleepingComputer och fler SOC-källor.

Snabbfilter
Toppnyheter Säkerhet
Dark Reading 13 min
Dark Reading

SE Asian Cybercriminal Syndicates Become a Global Power

The groups move from goods to services and continue to traffic people from at least 80 countries, costing nations in the region at least $88 billion in 2025 alone.

2026-07-30 03:00 13 min
Full coverage Flera perspektiv på samma ämne.
2 källor · 2026-07-29 21:48
Dark Reading SecurityWeek Vulnerabilities
2 källor · 2026-07-29 18:04
BleepingComputer The Hacker News
Fler källor:
2 källor · 2026-07-29 16:55
BleepingComputer SecurityWeek Vulnerabilities
Security-widgeten är dold. Visa widget
Säkerhet 120 artiklar
BleepingComputer ikon
BleepingComputer
Anthropic confirms Claude is down worldwide

Claude is down for some users, with Anthropic confirming elevated errors across multiple AI models. The disruption is causing requests to fail with a "529 Overloaded" message, including in Claude and tools that rely...

BleepingComputer ikon BleepingComputer
Dark Reading ikon
Dark Reading
Hugging Face Hack Lessons for Cyber Defenders

Dark Reading Confidential Episode 20: Expert Rich Mogull reflects on lessons cyber teams should pull from the OpenAI agent's attack on Hugging Face.

Dark Reading ikon Dark Reading
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-54705: mathlive's Lack of Escaping of HTML allows for XSS

### Summary Despite the 0.104.0 patch escaping attribute-bearing constructs (`\htmlData`, `\href`), text-content reflection was missed. The `\text{}`, `\mbox{}` commands accept arbitrary characters in their body and...

GitHub Security Advisories ikon GitHub Security Advisories
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-54693: ZITADEL Users Can Self-Verify Email/Phone via API

### Summary A vulnerability in Zitadel's self-management capability allowed users to mark their email and phone as verified without going through an actual verification process. While [`GHSA-282g-fhmx-...

GitHub Security Advisories ikon GitHub Security Advisories
1 fler källor
The Hacker News OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach 2026-07-29 09:51
1 fler källor
Cisco PSIRT Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability 2026-07-29 17:55
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-54081: veraPDF Parser DoS via PostScript Type 1 Font Programs

## Summary **Description** A PostScript-interpreter-driven Denial of Service (CWE-1325) vulnerability in veraPDF allows a remote attacker to exhaust validator memory or CPU by submitting a PDF whose Type 1 font...

GitHub Security Advisories ikon GitHub Security Advisories
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-54080: veraPDF Parser DoS via PostScript CMap Streams

## Summary **Description** A PostScript-interpreter-driven Denial of Service (CWE-1325) vulnerability in veraPDF allows a remote attacker to exhaust validator memory or CPU by submitting a PDF whose Type 0 font...

GitHub Security Advisories ikon GitHub Security Advisories
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-54078: veraPDF Validation XXE via Rich Text

## Summary **Description** An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by...

GitHub Security Advisories ikon GitHub Security Advisories
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-54079: veraPDF Validation XXE via XFA

## Summary **Description** An XML External Entity Injection (CWE-611) vulnerability in veraPDF allows a remote attacker to read arbitrary files on the server file system and perform Server-Side Request Forgery by...

GitHub Security Advisories ikon GitHub Security Advisories
1 fler källor
GitHub Security Advisories CVE-2026-54662: swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template 2026-07-29 16:26
BleepingComputer ikon
BleepingComputer
Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise as they complete tasks, making broad permissions a growing security risk. Token Security explains why identity, intent-based access controls, and least privilege are becoming the...

BleepingComputer ikon BleepingComputer
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Mate Security Raises $35 Million for Agentic SOC

The startup will use the investment to expand its customer support, sales, and R&D teams. The post Mate Security Raises $35 Million for Agentic SOC appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
ThreatLocker Raises $190 Million in Series F Funding

The company was previously valued at $1.6 billion, and the latest raise has significantly increased that valuation. The post ThreatLocker Raises $190 Million in Series F Funding appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
The Hacker News ikon
The Hacker News
Mythos Asks the Right Question. It Doesn't Answer It.

AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in...

The Hacker News ikon The Hacker News
CISA Alerts ikon
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
2026 Minimum Elements for a Software Bill of Materials (SBOM)

CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for a Software Bill of Materials (SBOM), that updates and replaces the...

CISA Alerts ikon CISA Alerts
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Critical VM Escape Vulnerability Patched in VMware ESXi

A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion. The post Critical VM Escape Vulnerability Patched in VMware ESXi appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
BleepingComputer ikon
BleepingComputer
These near-mint ASUS Chromebook refurbs are only $145

Buying a new computer in 2026 is a unique experience. Rather than deal with incredibly high tech prices, more shoppers are opting for high-quality refurbished tech. This ASUS Chromebook CM30 refurb is in near-mint...

BleepingComputer ikon BleepingComputer
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
US, Australia Release OT Isolation Guidance for Critical Infrastructure

The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period. The post US, Australia Release OT Isolation Guidance for Critical...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
OpenAI’s Rogue AI Ventured Beyond Hugging Face

Hugging Face has published an anatomy of the attack and OpenAI has shared additional information from its investigation. The post OpenAI’s Rogue AI Ventured Beyond Hugging Face appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Spur Raises $200 Million for IP Intelligence Platform

The IP intelligence company will use the fresh investment to accelerate and scale its operations. The post Spur Raises $200 Million for IP Intelligence Platform appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack

The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given. The post JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks

State and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities. The post Dozens of Minnesota Water Utilities Targeted in Coordinated OT Attacks appeared...

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
ShinyHunters Claims Ernst & Young Hack

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform. The post ShinyHunters Claims Ernst & Young Hack appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC)

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an...

CISA KEV-katalog ikon CISA KEV-katalog
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-66064: goshs has ACL Bypass & Path Traversal

## Summary `sendFile` derives the served filename from the raw request path while opening the file from the cleaned path, so appending a trailing slash empties the derived name and defeats both the never-serve rule...

GitHub Security Advisories ikon GitHub Security Advisories
1 fler källor
GitHub Security Advisories CVE-2026-66063: goshs has a Path Traversal issue 2026-07-29 00:08
Microsoft MSRC ikon
Microsoft MSRC
Chromium: CVE-2026-13037 Use after free in WebView

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Microsoft MSRC ikon Microsoft MSRC
Microsoft MSRC ikon
Microsoft MSRC
Chromium: CVE-2026-13032 Use after free in WebGL

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Microsoft MSRC ikon Microsoft MSRC
1 fler källor
Microsoft MSRC Chromium: CVE-2026-13028 Use after free in WebGL 2026-07-29 00:03
Microsoft MSRC ikon
Microsoft MSRC
Chromium: CVE-2026-13030 Uninitialized Use in GPU

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Microsoft MSRC ikon Microsoft MSRC
1 fler källor
GitHub Security Advisories CVE-2026-55390: datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate 2026-07-28 23:26
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2026-52888: NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass

# Security Vulnerability Report: Sensitive Data Exposure via SQL Blacklist Bypass ## Summary The `checkSQL()` function in `plugin-collection-sql` implements a **keyword-based blacklist** to prevent dangerous SQL...

GitHub Security Advisories ikon GitHub Security Advisories
BleepingComputer ikon
BleepingComputer
OpenAI models used Artifactory zero-days to escape to the internet

JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging...

BleepingComputer ikon BleepingComputer
Ladda fler
Visar 120 av 280 artiklar