VIRY.CZ RADAR je monitor bezpečnostních hrozeb: advisories, zranitelnosti a threat intel z veřejných zdrojů, česky a na jednom místě.

65 zdrojů
25 zemí
6 398 položek
5 068 CVE s hodnocením
Více informací

Jsem „protkán“ AI. Snažím se pochopit zdrojové texty a bez vymýšlení je zestručnit a převést do českého jazyka, případně s využitím AI seskupit. Patřičně jsem pak hrdý na týdenní reporty, kde s pomocí AI zpracovávám stovky článků a hledám v nich souvislosti. Používám ale i čistou matematiku, takže pokud například více zdrojů mluví o shodné CVE chybě, seskupím to do jednoho příspěvku. Doporučuji se přihlásit k jejich odběru e-mailem nebo jinou cestou. Pokud se Vám líbím, nebráním se finanční podpoře :-)

Původní „Igiho stránka o virech“ se odstěhovala sem.

Nejvýznamnější zprávy za posledních 7 dní

Záznamy, o kterých od 11. 9. psaly aspoň dva zdroje, nebo s CVE v katalogu KEV. K seskupování zpráv do jedné události používám AI 2x denně nebo logiku kolem shodného výčtu CVE (okamžitě). Shrnutí celého uzavřeného týdne naleznete v týdenním přehledu.

27 záznamů CZ · EN/orig

10

SPOJENO AI Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]

média US GB

tg: varování tg: zranitelnost tg: rozbor tg: návod tp: malware tp: phishing tp: špionáž

SPOJENO PŘES CVE Cisco Identity Services Engine Authentication Bypass Vulnerability

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Cisco has released…

KEV ✓ CVE-2026-76460 Cisco US

tg: zneužíváno tg: zranitelnost tp: identita

· Cisco PSIRT · Cisco Identity Services Engine Authentication Bypass Vulnerability · CISA KEV · Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability (CVE-2026-76460)

SPOJENO PŘES CVE Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream from a host that is configured in the external database access list. An attacker could exploit this vulnerability by sending a crafted, serialized Java byte stream to a specific TCP port…

CVSS 8.1 CVE-2026-20242 Cisco US

tg: zranitelnost

· Cisco PSIRT · Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability · Zero Day Initiative · ZDI-26-709: Cisco Secure Firewall Management Center CommandSinkRmi Deserialization of Untrusted Data Remote Code Execution Vulnerability

SPOJENO PŘES CVE Acronis: rilevato sfruttamento in rete della CVE-2026-87886

Rilevato lo sfruttamento attivo in rete della vulnerabilità CVE-2026-87886 – già sanata dal vendor – che interessa i plugin di backup Acronis per Plesk, cPanel e WHM. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato di elevare i propri privilegi sui sistemi interessati.

KEV ✓ CVE-2026-87886 Plesk cPanel Acronis WebHost Manager IT US

tg: zneužíváno tg: zranitelnost

· CSIRT Itálie (ACN) · Acronis: rilevato sfruttamento in rete della CVE-2026-87886 · CISA KEV · Acronis Backup Incorrect Default Permissions Vulnerability (CVE-2026-87886) · BleepingComputer · Acronis warns of actively exploited flaw in its cPanel backup plugin

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing…

KEV ✓ CVE-2026-76460 CVE-2026-87886 Cisco Acronis veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Two Known Exploited Vulnerabilities to Catalog

SPOJENO PŘES CVE CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-58704 Google Pixel Improper Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian…

KEV ✓ EPSS 0.00 CVE-2026-58704 Google veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · Malwarebytes Labs · Google Pixel owners urged to patch actively exploited modem flaw · CISA KEV · Google Pixel Improper Authorization Vulnerability (CVE-2026-58704)

NightEagle targets Russian companies

Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia, as we reported previously. We have now identified attacks by the group targeting businesses in Russia. This post examines both known and new tools NightEagle used in its latest campaign. Initial access In most incidents, the attackers used compromised valid…

KEV ✓ · ransomware EPSS 1.00 CVE-2019-0708 CVE-2020-0688 Microsoft RU

tg: varování tg: rozbor tp: malware tp: špionáž

· Securelist (Kaspersky) · NightEagle targets Russian companies

SPOJENO PŘES CVE Risolte vulnerabilità in Squid

Aggiornamenti di sicurezza Squid risolvono tre vulnerabilità, di cui una con gravità “alta”, in Squid, software open source utilizzato come caching proxy. Tale vulnerabilità potrebbe consentire ad un utente malintenzionato di eludere le funzionalità di sicurezza e di alterare il contenuto memorizzato nella cache mediante richieste HTTP opportunamente predisposte.

CVE-2026-61642 Squid IT FR

tg: zranitelnost tp: DDoS

· CSIRT Itálie (ACN) · Risolte vulnerabilità in Squid · CERT-FR – avis · Multiples vulnérabilités dans Squid (14 septembre 2026)

SPOJENO PŘES CVE K000162604: NGINX ngx_http_v3_module vulnerability CVE-2026-90439

Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 6.5, CVEs: CVE-2026-90439, Summary: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL versions 3.5.0 and earlier under certain configurations, a limited heap buffer overflow could happen while processing a Transport Layer Security (TLS) handshake. This can happen in a non-deterministic manner that is beyond the attacker's control. This…

EPSS 0.00 CVSS 6.5 CVE-2026-90439 NGINX OpenSSL F5 FI FR

tg: zranitelnost

· NCSC-FI · K000162604: NGINX ngx_http_v3_module vulnerability CVE-2026-90439 · CERT-FR – avis · Vulnérabilité dans F5 NGINX (16 septembre 2026)

SPOJENO PŘES CVE TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.6, CVEs: CVE-2026-81573, CVE-2026-81574, CVE-2026-81572, CVE-2026-81576, CVE-2026-81575, Summary: The TRUMPF product versions listed below include a Wibu CodeMeter Runtime version that contains several vulnerabilities, e.g. potentially allowing privilege escalation.

EPSS 0.00 CVSS 8.6 CVE-2026-81572 CVE-2026-81573 CVE-2026-81574 CVE-2026-81575 CVE-2026-81576 TRUMPF WIBU-SYSTEMS Wibu-Systems výroba a průmysl FI DE

tg: zranitelnost tp: dodavatelský řetězec tp: průmyslové systémy

· NCSC-FI · TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities · CERT@VDE · TRUMPF: Multiple products affected by Wibu CodeMeter vulnerabilities

7

SPOJENO AI CenterPoint Energy confirms customer data stolen in cyberattack

CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]

CenterPoint Energy energetika US

tg: incident tp: únik dat

SPOJENO AI Kritische Sicherheitslücke in Cisco Secure Email Gateway - aktiv ausgenutzt - Updates verfügbar

15. September 2026 Beschreibung In Cisco Secure Email Gateway existiert eine kritische Sicherheitslücke. Bei erfolgreicher Ausnutzung könnte diese Sicherheitslücke es nicht authentifizierten Angreifer:innen aus der Ferne ermöglichen Befehle mit Root-Rechten auf dem zugrunde liegenden Betriebssystem auszuführen. Laut Cisco wurde eine Ausnutzung der Sicherheitslücke bereits beobachtet. CVE-Nummer(n): CVE-2026-76461 CVSS Base Score: 9.8 Auswirkungen Ein Angreifer könnte diese Sicherheitslücke…

KEV ✓ EPSS 0.02 CVSS 9.8 CVE-2026-76461 Cisco veřejná správa AT RO SE US FI GB FR CA NL IT

tg: zneužíváno tg: zranitelnost tg: regulace

SPOJENO AI Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]

Reddit HBO HBO Max média US

tg: incident tg: varování tp: malware tp: phishing tp: identita

SPOJENO AI CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions.On September…

KEV ✓ EPSS 0.12 CVSS 10.0 CVE-2025-14871 CVE-2026-1168 CVE-2026-13210 CVE-2026-78252 CVE-2026-79708 CVE-2026-85706 CVE-2026-87719 CVE-2026-88765 GitLab veřejná správa CZ US NL FI SK SE CA IT FR

tg: zneužíváno tg: zranitelnost tg: regulace tg: novinka v produktu tp: DDoS

SPOJENO AI Suspected Black Axe gang leaders face cybercrime charges in the US

Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. [...]

finance US

tg: vymáhání práva tp: podvod

SPOJENO PŘES CVE Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026

Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-20353, CVE-2026-76440, CVE-2026-76441, CVE-2026-76442, CVE-2026-76443, Summary: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally…

EPSS 0.00 CVSS 9.8 CVE-2026-20353 CVE-2026-76440 CVE-2026-76441 CVE-2026-76442 CVE-2026-76443 Cisco FI US

tg: zneužíváno tg: zranitelnost

· NCSC-FI · Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 · Cisco PSIRT · Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026

4

SPOJENO AI Revolut handed customer data to fraudsters using government email account

British fintech Revolut confirmed disclosing sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government email account.

Revolut finance US

tg: incident tp: phishing tp: podvod tp: únik dat

SPOJENO AI Artifactory flaws chained in attacks deploying backdoor malware

Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]

KEV ✓ EPSS 0.01 CVE-2026-42016 CVE-2026-42018 JFrog IT US NL

tg: varování tg: zneužíváno tg: zranitelnost tp: malware tp: identita

SPOJENO PŘES CVE Rilevato sfruttamento della CVE-2026-84869 relativa al prodotto ConnectWise ScreenConnect

Rilevato lo sfruttamento attivo in rete della vulnerabilità CVE-2026-84869 con gravità "critica" - già sanata dal vendor - relativa al prodotto ConnectWise ScreenConnect

KEV ✓ EPSS 0.01 CVE-2026-84869 ConnectWise IT US CA

tg: zneužíváno tg: zranitelnost

· CSIRT Itálie (ACN) · Rilevato sfruttamento della CVE-2026-84869 relativa al prodotto ConnectWise ScreenConnect · CISA KEV · ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability (CVE-2026-84869) · Cyber Centre Kanada · ConnectWise security advisory (AV26-903)

SPOJENO AI Google warns of new Chrome zero-day bug exploited in attacks

Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]

KEV ✓ EPSS 0.01 CVSS 9.6 CVE-2026-87491 Microsoft Google Chrome FR HR US FI CA NL IT

tg: zneužíváno tg: zranitelnost tg: novinka v produktu

1

SPOJENO AI Check Point Critical Security Advisory: VPN Vulnerabilities CVE-2026-85102 and CVE-2026-8510

Classification: Critical, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.1: 9.8, CVEs: CVE-2026-85102, CVE-2026-8510, Summary: Check Point research team has identified and remediated two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, which could potentially allow unauthenticated remote code execution under specific conditions. These issues were discovered internally, and we have no indication of active exploitation. To ensure continued protection, we…

EPSS 0.00 CVSS 9.8 CVE-2026-8510 CVE-2026-85102 CVE-2026-85103 Check Point US FI NL IT EU FR CA

tg: varování tg: zranitelnost

5

SPOJENO AI Florida confirms DMV database breached via stolen police account

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]

veřejná správa US

tg: incident tp: únik dat tp: identita

SPOJENO AI Crypto customers targeted by scammers after email marketing provider breach

An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields. The incident was a supply-chain phishing campaign carried out through Brevo, an email marketing provider used by several cryptocurrency companies and other firms. Brevo initially said an attacker had gained access to 120 customer accounts, some of which were used to send phishing emails to the…

Brevo Trezor CoinTracking BitBox ShipMonk finance US

tg: incident tg: varování tg: zneužíváno tp: phishing tp: podvod tp: únik dat tp: dodavatelský řetězec

SPOJENO AI Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]

KEV ✓ · ransomware EPSS 0.76 CVSS 10.0 CVE-2026-20079 CVE-2026-20131 CVE-2026-20316 Cisco veřejná správa NL US CA

tg: zneužíváno tg: zranitelnost tg: rozbor tg: názor tg: přehled tp: malware tp: ransomware tp: identita tp: špionáž

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant…

KEV ✓ EPSS 0.01 CVE-2026-42016 CVE-2026-42018 CVE-2026-84869 JFrog ConnectWise veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Three Known Exploited Vulnerabilities to Catalog

SPOJENO AI Ukrainian hacker gets four years in US prison over Conti ransomware attacks

A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.

US

tg: vymáhání práva tp: ransomware