VIRY.CZ RADAR je monitor bezpečnostních hrozeb: advisories, zranitelnosti a threat intel z veřejných zdrojů, česky a na jednom místě.

64 zdrojů
24 zemí
4 643 položek
3 582 CVE s hodnocením
Více informací

Jsem „protkán“ AI. Snažím se pochopit zdrojové texty a bez vymýšlení je zestručnit a převést do českého jazyka. Patřičně jsem pak hrdý na týdenní reporty, kde s pomocí AI zpracovávám stovky článků a hledám v nich souvislosti. Používám ale i čistou matematiku, takže pokud například více zdrojů mluví o shodné CVE chybě, seskupím to do jednoho příspěvku. Doporučuji se přihlásit k jejich odběru e-mailem nebo jinou cestou. Pokud se Vám líbím, nebráním se finanční podpoře :-)

Původní „Igiho stránka o virech“ se odstěhovala sem.

Bezpečnostní přehled — posledních 7 dnů

Různé zkratky a hodnoty pod každou zprávou mají svoji legendu — pokud na údaji postojíte myší. Některé jsou klikatelné. Typicky CVE.
Vyzkoušejte rozsáhlé možnosti filtrace přes ikonu lupy vpravo nahoře!

232 karet z 254 položek · strana 1 z 4 CZ · EN/orig

19

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan,…

Google zdravotnictví veřejná správa média US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: AI tp: identita

Mandiant / Google TI ·

Risolte vulnerabilità in prodotti Qualcomm Technologies Inc.

Aggiornamenti di sicurezza Qualcomm Technologies Inc. sanano 14 vulnerabilità con gravità “alta” che interessano componenti software impiegati nelle piattaforme e nei chipset del produttore, utilizzati in dispositivi mobili, sistemi di connettività wireless, piattaforme automotive e soluzioni di calcolo. Tali vulnerabilità, qualora sfruttate, potrebbero consentire di accedere a informazioni riservate, compromettere la disponibilità del servizio sui sistemi interessati.

CVE-2025-59607 CVE-2026-24073 CVE-2026-24074 CVE-2026-24075 CVE-2026-24081 CVE-2026-25275 CVE-2026-25278 CVE-2026-25280 CVE-2026-25281 CVE-2026-25282 CVE-2026-25283 CVE-2026-25284 CVE-2026-25290 CVE-2026-25294 Qualcomm Technologies IT

tg: zranitelnost

CSIRT Itálie (ACN) ·

CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

OverviewWhile conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.CVE IDDescriptionCWECVSSv4CVE-2026-86206Semicolon/Forwarded access-control bypassCWE…

KEV ✓ EPSS 0.54 CVE-2026-18577 CVE-2026-86206 CVE-2026-86207 N-able US

tg: zneužíváno tg: zranitelnost

Rapid7 ·

ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

Cisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. Pivoting around the similar WebDAV behavior led to a second loader named "pf.ch" and allowed us to reconstruct its earlier delivery…

Cisco Cloudflare Google Microsoft veřejná správa US

tg: varování tg: zneužíváno tg: rozbor tp: malware tp: phishing tp: identita tp: špionáž

Cisco Talos ·

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. The actors use a variation on ClickFix social engineering. Instead of convincing targets to run commands against the operating system, they convince targets to paste JavaScript into the Chrome address bar or install it into the…

Google Google Chrome Tampermonkey US

tg: varování tg: zneužíváno tp: malware tp: podvod

Cisco Talos ·

Risolte vulnerabilità in prodotti JetBrains

Aggiornamenti di sicurezza JetBrains sanano alcune vulnerabilità, di cui 2 con gravità “critica” e 7 con gravità “alta”, che interessano vari prodotti. Tali vulnerabilità potrebbero consentire a un utente malintenzionato di accedere a informazioni riservate, alterare dati, eludere i meccanismi di sicurezza ed eseguire codice arbitrario sui sistemi interessati.

CVE-2026-86478 CVE-2026-86479 CVE-2026-86480 CVE-2026-86482 CVE-2026-86492 CVE-2026-86494 CVE-2026-86498 CVE-2026-86502 CVE-2026-86504 JetBrains IT

tg: zranitelnost

CSIRT Itálie (ACN) ·

MikroTik router flaws allow takeover without a password

CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet. Although the warning comes from Poland’s national cybersecurity response team, MikroTik routers are sold worldwide, including in the US. The vulnerabilities can affect users anywhere if their router is running a vulnerable version of RouterOS and its SSH remote-management service is accessible from the internet. Attackers are exploiting two…

CVSS 9.2 CVE-2026-67276 CVE-2026-86060 MikroTik US HR IT 3 zdrojů

tg: zneužíváno tg: zranitelnost tp: průmyslové systémy

Malwarebytes Labs · CERT.hr · CSIRT Itálie (ACN)

NCSC-2026-0345 [1.00] [M/H] Kwetsbaarheden verholpen in MikroTik RouterOS

MikroTik heeft meerdere kwetsbaarheden verholpen in RouterOS. De eerste kwetsbaarheid betreft een fout in de SSH-authenticatiemechanisme waarbij de exponent van RSA-sleutels niet werd geverifieerd. Hierdoor kunnen aanvallers RSA-handtekeningen vervalsen en ongeautoriseerde SSH-toegang verkrijgen. De tweede kwetsbaarheid betreft een probleem met gebruikersnamen die beginnen met een verboden teken, waardoor de trusted policy mask kan worden gemanipuleerd en privilege escalation mogelijk is binnen…

MikroTik NL

tg: zneužíváno tg: zranitelnost tp: identita

NCSC-NL ·

Adobe: rilevato sfruttamento in rete della CVE-2026-75650

Aggiornamenti di sicurezza Adobe sanano una vulnerabilità con gravità “critica” in Adobe Commerce, Adobe Commerce B2B e Magento Open Source, piattaforme per il commercio elettronico utilizzate per la realizzazione e la gestione di siti e servizi di vendita online. Tale vulnerabilità, della quale si evidenzia lo sfruttamento attivo in rete, potrebbe consentire a un attaccante non autenticato di eseguire codice arbitrario sui sistemi interessati.

CVE-2026-75650 Adobe obchod IT

tg: zneužíváno tg: zranitelnost tp: malware

CSIRT Itálie (ACN) ·

NCSC-2026-0344 [1.00] [H/H] Kwetsbaarheid verholpen in Adobe Commerce en Magento

Adobe heeft een kwetsbaarheid verholpen in Adobe Commerce en Magento. De kwetsbaarheid bevindt zich in de template engine van Adobe Commerce, waarbij speciale elementen niet correct worden geneutraliseerd. Een aanvaller kan hierdoor op afstand willekeurige code uitvoeren zonder dat er gebruikersinteractie nodig is. Dit gebeurt door misbruik te maken van een gewijzigde scope om privileges te escaleren of de uitvoeringcontext aan te passen. Adobe geeft aan dat deze kwetsbaarheid reeds actief…

Adobe NL

tg: zneužíváno tg: zranitelnost tp: malware

NCSC-NL ·

30

Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

This week on the Lock and Code podcast… Crooks are taking a holiday. They’re counting on you to fund it. For decades, cybercriminals have stolen roughly the same types of data. Biographical and personal details—like Social Security numbers, birthdates, addresses, and phone numbers—can be stolen to commit identity fraud. Credit card numbers, expiration dates, and CVC codes can be stolen to make fraudulent purchases. Usernames and passwords can, in the wrong hands, let a cybercriminal impersonate…

Malwarebytes US

tg: rozbor tg: návod tp: podvod tp: identita

Malwarebytes Labs ·

7th September – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platform affecting courts across 11 US states and Canada. An unauthorized party obtained C-Track files containing court records, including names and other personal information. Hit, a major Slovenian gambling and tourism…

KEV ✓ EPSS 0.00 CVSS 10.0 CVE-2026-82329 CVE-2026-83548 CVE-2026-83549 Thomson Reuters Dropbox SonicWall JFrog veřejná správa finance zdravotnictví IL

tg: incident tg: varování tg: zneužíváno tg: zranitelnost tg: rozbor tp: malware tp: ransomware tp: únik dat tp: AI tp: identita tp: špionáž tp: průmyslové systémy

Check Point Research ·

LG TV flaws could let attackers listen in, even in standby mode

Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices. In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR). ACR technology samples what appears on or is heard through a TV, creates a digital fingerprint, and compares…

LG US

tg: zranitelnost tg: rozbor tp: identita tp: soukromí

Malwarebytes Labs ·

Upozorenje: WhatsApp prijevara “Glasajte za moje dijete”

Nacionalni CERT zaprimio je prijave o phishing (smishing) prijevari putem preuzetog WhatsApp računa te je prijavio prijevare izvorima incidenta i nadležnim CERT timovima. Primjer WhatsApp poruke: Sadržaj lažnih WhatsApp poruka je: “Glasajte za … dijete na natjecanju”Možete primiti poruku od poznate osobe s poveznicom za glasovanje na natjecanju. Nakon klika traži se unos broja mobitela te kôda – time prevarantu nesvjesno dajete pristup svom WhatsApp računu i omogućavate širenje lažnih poruka…

HR

tg: varování tp: phishing tp: podvod

CERT.hr ·

NCSC-2026-0343 [1.00] [M/H] Kwetsbaarheden verholpen in GeoNetwork door OpenGeo

OpenGeo heeft meerdere kwetsbaarheden verholpen in GeoNetwork, een open-source catalogusapplicatie, specifiek in versies 4.4.5 tot en met 4.4.11 en versies voorafgaand aan 4.4.12 en 4.2.17. De eerste kwetsbaarheid betreft een reflected cross-site scripting (XSS) in de publieke, niet-geauthenticeerde cataloguszoekfunctie. Dit wordt veroorzaakt door onvoldoende sanering van de uiconfig queryparameter, waardoor een aanvaller JavaScript kan injecteren en uitvoeren in de browsercontext van…

OpenGeo NL

tg: zranitelnost

NCSC-NL ·

NCSC-2026-0342 [1.00] [H/H] Kwetsbaarheid verholpen in N-central van N-able

N-able heeft een kwetsbaarheid verholpen in N-central versies eerder dan 2026.3.1.14. De kwetsbaarheid betreft een pre-authenticatie remote code execution flaw. Een aanvaller kan hierdoor op afstand willekeurige code uitvoeren op het getroffen systeem zonder enige vorm van authenticatie. Alle installaties die draaien op de kwetsbare versies van N-central zijn getroffen. Klanten met een on-premises N-central-omgeving wordt geadviseerd zo snel mogelijk te upgraden naar N-central 2026.3 HF4. Voor…

N-able NL

tg: zneužíváno tg: zranitelnost

NCSC-NL ·

Flirty OnlyFans promoters on X may be using AI to appear human

In a recent post, we looked at reports of League of Legends players receiving suspicious friend requests shortly after matches. The accounts quickly steered the conversation toward Discord, where they promoted paid adult-content pages. At the time, one unanswered question was how much of those conversations was automated. Were people working from scripts behind the accounts? Were they conventional, rules-based chatbots following a limited decision tree? Or were they using generative AI to…

US

tg: rozbor tp: podvod tp: AI

Malwarebytes Labs ·

VAROVANIE: Útočníci aktívne zneužívajú zraniteľnosti MIKROTIK smerovačov

Národné centrum kybernetickej bezpečnosti (NCKB) NBÚ varuje pred útokmi na smerovače značky MikroTik. Útočníci zreťazením bezpečnostných zraniteľností operačného systému MikroTik RouterOS dokážu získať úplnú kontrolu nad zariadením bez potreby autentifikácie. MikroTik routre sú sieťové zariadenia vyrábané spoločnosťou MikroTik a využívajú vlastný operačný systém RouterOS. Využívané sú poskytovateľmi internetových služieb, v komerčnej sfére a rovnako aj v domácnostiach.... The post VAROVANIE:…

MikroTik SK

tg: varování tg: zneužíváno

SK-CERT (NBÚ SR) ·

Risolte vulnerabilità nei chipset MediaTek

Aggiornamenti di sicurezza MediaTek sanano alcune vulnerabilità, di cui 5 con gravità “alta”, nei chipset MediaTek, componenti hardware impiegati in numerosi dispositivi mobili e sistemi embedded. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato di eseguire codice arbitrario o compromettere la disponibilità del servizio sui sistemi interessati.

CVE-2026-20500 CVE-2026-20501 CVE-2026-20502 CVE-2026-20503 CVE-2026-20504 MediaTek IT

tg: zranitelnost

CSIRT Itálie (ACN) ·

Control de acceso incorrecto en PrestaShop

Incorrect access control in PrestaShop Mon, 09/07/2026 - 13:19 Aviso Affected Resources PrestaShop, versions prior to 9.1.5 and 8.2.8, depending on the branch. Description INCIBE has coordinated the publication of a medium-severity vulnerability affecting PrestaShop, a free and open-source content management system designed to build e-commerce online shops from scratch. The vulnerability was discovered by Pedro Gabaldón Juliá.This vulnerability has been assigned the following code, CVSS v4.0…

CVSS 6.9 CVE-2026-84186 PrestaShop obchod ES

tg: zranitelnost tp: identita

INCIBE-CERT ·

Upozornění na zranitelnost ve firmware RouterOS v zařízeních MikroTik

Upozorňujeme na zranitelnost ve firmware RouterOS v zařízeních MikroTik, kterou lze před autentizací zneužít k vzdálenému spuštění kódu s administrátorskými oprávněními. Aktuálně dochází k masovému zneužití této zranitelnosti. Dne 4. září 2026 byla vydána aktualizace RouterOS, v současnosti jsou však na internetu v ČR stále vystaveny tisíce zranitelných zařízení. Útočníci navíc u napadených zařízení upravují konfiguraci, aby si zajistili trvalý přístup k zařízení, který přežije jakoukoli…

MikroTik CZ

tg: zneužíváno tg: zranitelnost tp: malware

NÚKIB ·

Multiples vulnérabilités dans les produits Juniper Networks (07 septembre 2026)

De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.

EPSS 0.98 CVE-2013-5211 CVE-2016-9042 CVE-2016-9310 CVE-2017-6451 CVE-2017-6452 CVE-2017-6455 CVE-2017-6458 CVE-2017-6459 CVE-2017-6460 CVE-2017-6462 CVE-2017-6463 CVE-2017-6464 Juniper Networks FR

tg: zranitelnost

CERT-FR – avis ·

Multiples vulnérabilités dans MongoDB (07 septembre 2026)

De multiples vulnérabilités ont été découvertes dans MongoDB. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et une injection de requêtes illégitimes par rebond (CSRF).

EPSS 0.00 CVE-2026-84962 CVE-2026-84963 CVE-2026-84964 CVE-2026-84965 CVE-2026-84966 CVE-2026-84967 CVE-2026-84968 CVE-2026-84969 CVE-2026-84970 CVE-2026-84971 MongoDB FR

tg: zranitelnost

CERT-FR – avis ·

2

Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed. The patch will attempt to detect compromise and set the "Flagged" status. Details: https://mikrotik.com/supportsec/september-2026-vulnerability -- Johannes B. Ullrich, Ph.D. , Dean of…

MikroTik US

tg: zneužíváno tg: zranitelnost tp: identita

SANS Internet Storm Ctr. ·

6

Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended

The CERT Polska team has identified and coordinated the disclosure of six vulnerabilities in MikroTik RouterOS, including two critical ones. The vulnerabilities are already being actively exploited to take over devices whose SSH service is accessible from the internet. We recommend immediately updating devices to the patched versions and verifying the configuration for signs of compromise.

MikroTik PL

tg: zneužíváno tg: zranitelnost tp: identita

CERT Polska ·

Google Chrome Stable Channel Update

Classification: Severe, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: None, CVEs: CVE-2026-85046, CVE-2026-85052, CVE-2026-85043, CVE-2026-85048, CVE-2026-85045, CVE-2026-85050, CVE-2026-85053, CVE-2026-85042, CVE-2026-85049, CVE-2026-85051, CVE-2026-85047, CVE-2026-85044, Summary: The Stable channel has been updated to 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available…

KEV ✓ EPSS 0.00 CVE-2026-85042 CVE-2026-85043 CVE-2026-85044 CVE-2026-85045 CVE-2026-85046 CVE-2026-85047 CVE-2026-85048 CVE-2026-85049 CVE-2026-85050 CVE-2026-85051 CVE-2026-85052 CVE-2026-85053 Google FI

tg: zneužíváno tg: zranitelnost tg: novinka v produktu tp: malware

NCSC-FI ·

numbat - AI agent observability, (Fri, Sep 4th)

​​​​​​​ Enterprises face an unmanaged crisis of AI agent and MCP server sprawl, characterized by rapid, decentralized proliferation of autonomous agents, protocol connections operating with excessive privilege, opaque execution paths, and identity blind spots. Absent agent-aware governance, modern enterprises struggle to prevent, detect, or contain multi-hop autonomous exploits, leaving environments vulnerable to lateral movement, shadow collaboration, and unauthorized data exfiltration. More…

Perplexity AI US

tg: rozbor tg: návod tp: AI

SANS Internet Storm Ctr. ·

3

How to secure edge AI in customer-owned environments

In this article Edge AI changes the trust model for AI systemsConstrain model actions through deterministic mediationEstablish trust before releasing sensitive assetsVerify runtime before releasing sensitive assetsVerify artifacts that shape model behaviorNext steps Edge AI moves model execution, model IP, customer data, and system authority into infrastructure the customer owns and operates. That changes who must verify the stack before sensitive assets are released. Edge AI includes AI…

US

tg: rozbor tg: návod tp: AI

Microsoft Security Blog ·

AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489

Number: AL26-019Date: September 4, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre…

EPSS 0.03 CVSS 9.3 CVE-2026-19489 CVE-2026-19490 Citrix CA IT NL FI FR 5 zdrojů

tg: zneužíváno tg: zranitelnost tp: identita

Cyber Centre Kanada · CSIRT Itálie (ACN) · NCSC-NL · NCSC-FI · CERT-FR – avis

The hidden work of modernizing Malwarebytes

Most of the work that keeps a security product trustworthy is invisible. Users see a scan complete, a threat blocked, an update applied overnight. They don’t see the platform underneath. Runtimes, managed libraries, native drivers, and Windows requirements must all stay current and work together across millions of endpoints. Our migration to .NET 10 is one example of how we keep that platform moving and our focus in this article. It would be easy to call these upgrades maintenance tasks and…

Malwarebytes US

tg: rozbor tg: novinka v produktu

Malwarebytes Labs ·