Z „Igiho stránky o virech“ se stává agregátor veřejných bezpečnostních zdrojů!
Sleduju 65 zdrojů z 24
zemí — národní CERTy ze střední Evropy, výrobce a threat-intel týmy — a skládám je
do jednoho chronologického přehledu v češtině. V databázi je
3 576 položek.
Umím toho spoustu, třeba i generovat
týdenní reporty,
přičemž AI se snaží o agregaci informací tak, aby to nebyla úplná nuda.
Více na stránce o projektu.
Posledních 7 dnů
Různé zkratky a hodnoty pod každou zprávou mají svoji legendu — pokud na údaji
postojíte myší. Některé jsou klikatelné. Typicky CVE.
Serial Number: AV26-822Date: August 17, 2026 As of August 14, 2026, Microsoft is affected by a vulnerability in the following product: Microsoft Edge (Chromium-based) Prior to 151.0.4129.86 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Microsoft Edge Stable Channel Release Notes Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability CVE-2026-72970 (en anglais seulement)
For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were encrypted but stated that no data theft was detected during the incident. MyDr, Poland’s primary…
Microsoft Defender’s latest patch bypass shows a familiar problem. A newly disclosed Microsoft Defender flaw called ShieldBreak shows that fixing one attack path doesn’t always close every route to the same result. Microsoft has assigned ShieldBreak the identifier CVE-2026-69414 and confirmed it is an elevation of privilege (EoP) vulnerability in the Microsoft Malware Protection Engine. Microsoft says it is still working on a security update. If that sounds somehow familiar, you’re probably…
Serial Number: AV26-821Date: August 17, 2026 As of August 14, 2026, Dell is affected by vulnerabilities in the following products: PowerFlex appliance Prior to 51.391.02 and 51.384.02 PowerFlex Rack Prior to 3.9.1.2 and 3.8.4.2 PowerFlex Software Prior to 5.1.0.2 and 4.5.6 Dell Client Platform for Multiple AMD BIOS multiple versions and models Dell Client Platform BIOS for 2026.3 IPU multiple versions and models Dell VPlex Prior to 6.2.2.1 The Cyber Centre encourages users and administrators to…
Serial Number: AV26-820Date: August 17, 2026 As of August 14, 2026, Tenable, Inc. is affected by vulnerabilities in the following product: Security Center Prior to 6.9.0 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. [R1] Security Center Version 6.9.0 Fixes Multiple Vulnerabilities - Security Advisory | Tenable®
Serial Number: AV26-819Date: August 17, 2026 As of August 14, 2026, IBM is affected by vulnerabilities in the following product: IBM App Connect Operator multiple versions IBM App Connect Enterprise Certified Containers Operands multiple versions Total Storage Service Console (TSSC) / TS4500 IMC multiple versions IBM Tivoli Network Manager IP Edition Prior to or equal to 4.2.0.24 IF1 IBM Tivoli Monitoring Prior to or equal to 6.3.0.7 Service Pack 23 PowerVC Prior to or equal to 2.3.1, 2.3.2 and…
Ukraine’s military intelligence claimed it disrupted the operations of Russia’s largest online marketplace, Wildberries, in a cyberattack intended to amplify the impact of drone strikes on the company’s infrastructure.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive…
Operation ASTERIX overviewRapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered…
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]
TikTok-branded “rewards” pages are promising users cash for checking in every day, completing small tasks, and earning points. Those points supposedly convert into real money, and the balances look enormous. A countdown timer usually warns that your balance is about to expire. But when you try to withdraw it, there’s always something else you need to do first. If you just want the short version TikTok does have a legitimate Creator Rewards Program, but it doesn’t work like the sites we’re…
Tenable ha rilasciato aggiornamenti di sicurezza che risolvono molteplici vulnerabilità, tra cui 3 con gravità “critica” e 5 con gravità “alta”, nel prodotto Tenable SC (Security Center).
The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals. [...]
Reports that uBlock Origin is stepping back from the never-ending effort to filter Facebook ads are a reminder that ad blocking is no longer only an argument about inconvenience, publishers, and lost advertising revenue. It is also an issue of security. For years, ad blockers have occupied an uncomfortable place in the web economy. Publishers and platforms rely on advertising to fund their services, while users install blockers to escape intrusive banners, autoplay videos, tracking scripts, and…
Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa.Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not automatically create stronger security operations; many security teams are not short on data, but rather on time, context, and specialist capacity.As environments expand, the challenge is no longer finding another…
Last week on Malwarebytes Labs: Apple now uses iPhone alerts for targets of mercenary spyware WhatsApp is testing a new warning for scam messages New Android malware lets criminals use your bank card in real time Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits “Zoomsday” flaws could let one Zoom participant attack another Patch Tuesday: Update now to fix 421 flaws, including three zero-days Fake CCleaner installs GhostDesk Chrome spyware Valve warns Steam hardware…
Today, we’re introducing a redesigned GreyNoise Visualizer that makes it easier to navigate those capabilities and brings related workflows together in one place.
De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une élévation de privilèges.
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un problème de sécurité non spécifié par l'éditeur.
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]
Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]
A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively control the victim's web browser. [...]
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]
SAP heeft een kwetsbaarheid verholpen in de Data Hub Adapter voor SAP Commerce Cloud. Een ongeauthenticeerde kwaadwillende kan de kwetsbaarheid misbruiken voor het uitvoeren van willekeurige code. Hiertoe dient de kwaadwillende malafide netwerkverkeer naar de Data Hub Adapter te versturen. Beveiligingsbedrijf Defused meldt dat kwaadwillenden actief scannen en op zoek zijn naar kwetsbare Data Hub Adapter-systemen.
Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts,…
This wrap-up brings a full-on shell parade. Thirteen shiny new modules landed, starting with a buffet of RCEs. WordPress WP2Shell, Ghost CMS, Joomla JCE, Langflow, OpenCATS, Pterodactyl Panel, SonicWall SMA1000, Ray Dashboard, a Pix-for-WooCommerce, and for those who like their exploits closer to the bare-metal, the Fragnesia Linux kernel LPE (CVE-2026-46300). Metasploit also got the glow-up of the summer with the new http malleable profiles, MCP functionality and linux multi fetch payloads …
On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: BroadWorks Crosswork Industrial Ethernet 1000 Series Switches Packaged Contact Center Enterprise and Unified Contact Center Enterprise RoomOS Secure Workload Unified Intelligence Center To fully remediate vulnerabilities to be disclosed on August 19, 2026, Cisco strongly…
Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts. [...]
Compare the top enterprise DAST tools of 2026 on authenticated coverage, API discovery, exploit validation, governance, compliance, and AI pentesting Category: DevSec Tools & Comparisons
Serial number: AV26-818Date: August 14, 2026 As of August 13, 2026, FreePBX is affected by vulnerabilities in the following products: backup After or equal to 17.0.5.34, Prior to 17.0.11 framework After or equal to 17.0.1, Prior to 17.0.30 Prior to 16.0.47 missedcall After or equal to 17.0.1, Prior to 17.0.4 Prior to 16.0.11 music Prior to 17.0.7 tts After or equal to 17.0.1, Prior to 17.0.5.4 Prior to 16.0.6 ucp Prior to 17.0.9 The Cyber Centre encourages users and administrators to review the…
Serial number: AV26-817Date: August 14, 2026 As of August 13, 2026, HashiCorp is affected by a vulnerability in the following product Vault Secrets Operator - Prior to 1.5.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HCSEC-2026-28 - Vault Secrets Operator vulnerable to arbitrary file read via AppRole secretIDPath Security - HashiCorp Discuss
Compare the top unified security tools of 2026: Aikido, Cortex Cloud, Wiz, Checkmarx, Snyk, and Orca, across coverage, correlation, governance, and cost. Category: DevSec Tools & Comparisons
Upozorňujeme na dvojici zranitelností ve WordPress Core označovaných jako wp2shell (CVE-2026-63030 a CVE-2026-60137), které mohou při kombinovaném zneužití vést ke vzdálenému spuštění kódu (RCE) bez nutnosti přihlášení.
Serial number: AV26-816Date: August 14, 2026 As of August 13, 2026, Zimbra is affected by vulnerabilities in the following product: Collaboration - Prior to 10.1.20 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Zimbra Security Advisories - Zimbra: Tech Center Zimbra Responsible Disclosure Policy - Zimbra: Tech Center Zimbra: Blog - All Things Zimbra
Apple has expanded its threat-notification system for targets of mercenary spyware. Apple now shows a warning directly on an iPhone’s Lock Screen and in Settings when it believes the device owner has been targeted by mercenary spyware. The new on-device alert is meant to make a high-risk warning harder to overlook and complements notifications by email and through the user’s Apple Account page. In the explanation, Apple states: “Apple threat notifications are high-confidence alerts that a user…
Nový malware s názvem WindRelay v kombinaci s trojanem SpyNote umožňuje zneužít zařízení s Androidem k bezkontaktním platebním podvodům. Útočníci oběť pomocí phishingu, SMS nebo telefonátu přesvědčí k instalaci škodlivé aplikace a následně k přiložení platební karty k telefonu, například pod záminkou ověření identity či změny PINu. Malware zachycenou NFC komunikaci v reálném čase přenáší do zařízení útočníka, který tak může kartu využít k platbám nebo výběrům hotovosti. Mezi listopadem 2025 a…
IBM heeft kwetsbaarheden verholpen in IBM i operating system versies 7.3, 7.4, 7.5 en 7.6. De kwetsbaarheden betreffen meerdere aspecten van het IBM i - operating system, waaronder onjuist privilege management, onbeheerde zoekpadelementen, out-of-bounds reads en writes, buffer overflows (zowel heap- als stackgebaseerd), SQL-injecties, path traversal, TOCTOU-racecondities met symbolische links, onjuiste validatie van omgevingsvariabelen en profielnamen, en onjuiste neutralisatie van speciale…
Meta announced it’s rolling out a new feature for WhatsApp users in the fight against scammers. Scam Alert is an optional beta feature that uses an on-device machine-learning model to flag likely scam messages from people who are not in a user’s contacts. The Scam Alert feature arrives as scammers increasingly use WhatsApp for impersonation, fake jobs, fake sales, investment fraud, romance baiting, malicious links, and payment requests. These campaigns often begin on another platform before…
Disponibili Proof of Concept (PoC) per 8 nuove vulnerabilità presenti in Gitea Open Source Git Server, nota piattaforma open source utilizzata per l'hosting e la gestione di repository Git, la collaborazione sul codice sorgente, la distribuzione di pacchetti software e l'automazione di workflow di sviluppo tramite funzionalità CI/CD integrate.
Ministarstvo pravosuđa, uprave i digitalne transformacije upozorava građane na lažne poruke kojima se pokušava stvoriti dojam da se protiv primatelja vodi kazneni ili sudski postupak. “Trenutno se šire lažne poruke koje građani zaprimaju putem e-pošte. U privitku poruka nalaze se dokumenti koji izgledom pokušavaju djelovati službeno, pri čemu se koriste grbovi i logotipi različitih institucija, među ostalim i Ministarstva pravosuđa, uprave i digitalne transformacije. Građanima savjetujemo da ne…
Introduction CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It supports such capabilities as keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions. Since its first public disclosure by Sophos in 2022 and subsequent analysis by Trend Micro in 2023, CoolClient has continued to…
Rilasciati aggiornamenti di sicurezza per risolvere una vulnerabilità con gravità “alta” in Zimbra Collaboration, nota piattaforma di collaborazione e-mail sviluppata da Synacor Inc. Tale vulnerabilità, qualora sfruttata, potrebbe consentire a utenti malintenzionati remoti di eseguire codice arbitrario sui sistemi interessati.
I veckans veckobrev kan du bland annat läsa om fortsatta utmaningar med AI-modeller som agerar utanför de tänkta testmiljöerna, samt rapporter om en ökning av mer kraftfulla överbelastningsangrepp.
Národný bezpečnostný úrad varuje pred významnou kybernetickou hrozbou spojenou s používaním viacerých typov cestných rýchlomerov s kamerou. Bezpečnostná analýza identifikovala viaceré riziká a dotknutým subjektom odporúča predmetné produkty vo svojej infraštruktúre identifikovať. Národný bezpečnostný úrad podľa § 5 ods. 1 písm. q) v spojení s § 27 ods. 1 písm. a) a ods. 2 zákona... The post Varovanie pred rizikami cestných meradiel appeared first on SK-CERT.
Elastic NV ha rilasciato aggiornamenti di sicurezza che risolvono molteplici nuove vulnerabilità, di cui 12 con gravità "alta" che interessano i prodotti Kibana ed Elasticsearch.
Rilasciato aggiornamento di sicurezza per una nuova vulnerabilità, con gravità “alta“, che interessa OpenSSL, nota libreria per l’implementazione degli standard crittografici e i protocolli TLS/SSL. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato di compromettere la disponibilità del servizio sui sistemi interessati.
Rilevate 19 vulnerabilità, di cui 5 con gravità “critica” e 14 con gravità "alta", in Rsync, software open source per la sincronizzazione e il trasferimento di file tra sistemi.
Sanata una vulnerabilità con gravità “alta” in WordPress. Tale vulnerabilità, qualora sfruttata, potrebbe consentire ad un utente malintenzionato remoto autenticato di eseguire codice arbitrario sui sistemi interessati.