CISA: Medusa ransomware hit over 500 critical infrastructure orgs
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]
Různé zkratky a hodnoty pod každou zprávou mají svoji legendu — pokud na údaji postojíte myší. Některé jsou klikatelné. Typicky CVE.
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]
Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing the patch alone does not complete remediation, as the fix replaces a kernel driver and requires…
KEV ✓ EPSS 0.00 CVSS 7.0 CVE-2026-68820 Microsoft Qualys veřejná správa US FR 5 zdrojů
The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.
The affected ministries — one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment — have been isolated from government networks since Friday as a precaution.
You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use automation and AI-assisted tooling to compress the time between disclosure and exploitation. The gap that patch cycles were built to fill is closing. Speed and volume are overwhelming security teams that have relied on traditional patch cycles and reactive…
CVSS 7.0 Rapid7 Microsoft veřejná správa zdravotnictví finance výroba a průmysl US
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability CVE-2026-65400 Apple macOS Improper Authentication Vulnerability These types of vulnerabilities are a frequent attack vector…
KEV ✓ EPSS 0.56 CVE-2026-33824 CVE-2026-55040 CVE-2026-59310 CVE-2026-65400 Microsoft Broadcom Apple veřejná správa US
CISA added CVE-2026-33824 to the Known Exploited Vulnerabilities catalog. Affected product: Microsoft Internet Key Exchange (IKE) Service Extensions. Remediation due date: 2026-08-21.
KEV ✓ EPSS 0.56 CVE-2026-33824 Microsoft veřejná správa US 2 zdrojů
CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and treating PKI as the Tier 0 identity infrastructure it has always been. [...]
EPSS 0.01 CVE-2026-54121 veřejná správa US 2 zdrojů
For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were encrypted but stated that no data theft was detected during the incident. MyDr, Poland’s primary…
KEV ✓ EPSS 0.00 CVSS 9.8 CVE-2026-53413 CVE-2026-65400 CVE-2026-68820 CVE-2026-71362 Microsoft Apple Adobe Zoom veřejná správa zdravotnictví obrana energetika IL
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive…
KEV ✓ EPSS 0.00 CVE-2025-62593 Ray-Project veřejná správa US 2 zdrojů
Prin proiectul PNRR 184 „Crearea de noi competențe de securitate cibernetică pentru societat...
The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data belonging to 678,000 individuals. [...]
Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa.Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not automatically create stronger security operations; many security teams are not short on data, but rather on time, context, and specialist capacity.As environments expand, the challenge is no longer finding another…
Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts,…
KEV ✓ EPSS 1.00 CVE-2025-3248 Tenable Palo Alto Networks veřejná správa energetika US
București, 14 august 2026 În urma aprobării de către Consiliul Suprem de Apărare a Țări...
Ministarstvo pravosuđa, uprave i digitalne transformacije upozorava građane na lažne poruke kojima se pokušava stvoriti dojam da se protiv primatelja vodi kazneni ili sudski postupak. “Trenutno se šire lažne poruke koje građani zaprimaju putem e-pošte. U privitku poruka nalaze se dokumenti koji izgledom pokušavaju djelovati službeno, pri čemu se koriste grbovi i logotipi različitih institucija, među ostalim i Ministarstva pravosuđa, uprave i digitalne transformacije. Građanima savjetujemo da ne…
Introduction CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It supports such capabilities as keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions. Since its first public disclosure by Sophos in 2022 and subsequent analysis by Trend Micro in 2023, CoolClient has continued to…
Národný bezpečnostný úrad varuje pred významnou kybernetickou hrozbou spojenou s používaním viacerých typov cestných rýchlomerov s kamerou. Bezpečnostná analýza identifikovala viaceré riziká a dotknutým subjektom odporúča predmetné produkty vo svojej infraštruktúre identifikovať. Národný bezpečnostný úrad podľa § 5 ods. 1 písm. q) v spojení s § 27 ods. 1 písm. a) a ods. 2 zákona... The post Varovanie pred rizikami cestných meradiel appeared first on SK-CERT.
Number: AL26-018Date: August 13, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian…
KEV ✓ EPSS 0.01 CVE-2026-20349 Cisco veřejná správa CA RO IT FR US 6 zdrojů
View CSAF Summary Successful exploitation of this vulnerability could allow a low-privilege user or attacker to inject a persistent malicious payload via a crafted URL that executes in the context of other users' sessions, including administrators, potentially leading to session hijacking and unauthorized access. The following versions of Johnson Controls Metasys are affected: Metasys 12 vers:all/* (CVE-2026-34491) Metasys 13 vers:all/* (CVE-2026-34491) Metasys 14 Metasys 15 CVSS Vendor…
CVSS 8.0 CVE-2026-34491 Johnson Controls energetika výroba a průmysl veřejná správa doprava US
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to decrypt sensitive data, bypass authentication controls, gaining unauthorized access to read arbitrary files on the system, or gain unauthorized access to protected system resources. The following versions of Johnson Controls Inc. Airwall are affected: Airwall <=4.0.4 (CVE-2026-64887, CVE-2026-34492) CVSS Vendor Equipment Vulnerabilities v3 6.8 Johnson Controls Inc. Johnson Controls Inc. Airwall Use of…
EPSS 0.00 CVSS 6.8 CVE-2026-34492 CVE-2026-64887 Johnson Controls výroba a průmysl veřejná správa energetika doprava US
In May 2026, we discovered a new cyber-espionage campaign by the Armored Likho group, also known as Eagle Werewolf, that targets private individuals and organizations across various industries in Russia, including major corporations, the public sector, IT, and education. The attackers used a fake app as bait that mimics a service for donations. However, the most interesting part of this campaign isn’t the initial infection method – it’s the malicious implants the attackers use for cyber…
Microsoft’s August 2026 Patch Tuesday addresses 421 Microsoft vulnerabilities, including 62 rated Critical. One Windows vulnerability has been exploited in the wild by the Lazarus group to gain SYSTEM privileges. The August update is smaller than July’s record-breaking release, but it’s still among Microsoft’s largest Patch Tuesday batches. More importantly, it includes several flaws likely to attract attacker interest: a publicly disclosed Windows privilege escalation flaw with a proof-of…
EPSS 0.02 CVSS 9.8 CVE-2026-62832 CVE-2026-62893 Microsoft školství veřejná správa US
De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-65780 veřejná správa US
Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVSS 8.8 CVE-2026-62911 Microsoft finance veřejná správa US 2 zdrojů
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
EPSS 0.01 CVE-2026-62814 veřejná správa US
Improper link resolution before file access ('link following') in Windows DHCP Server allows an authorized attacker to elevate privileges locally.
EPSS 0.00 CVE-2026-62761 veřejná správa US
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an authorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-61920 veřejná správa US
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
EPSS 0.02 CVSS 7.5 CVE-2026-62893 Microsoft veřejná správa US 2 zdrojů
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.
EPSS 0.00 CVE-2026-62820 veřejná správa US
Out-of-bounds write in Windows DNS allows an unauthorized attacker to execute code over an adjacent network.
EPSS 0.01 CVE-2026-62817 veřejná správa telekomunikace US
Use after free in Windows LDAP - Lightweight Directory Access Protocol allows an unauthorized attacker to execute code over a network.
EPSS 0.01 CVE-2026-62795 veřejná správa US
Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information over an adjacent network.
EPSS 0.00 CVE-2026-62716 veřejná správa US
OverviewRapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month.Our…
KEV ✓ EPSS 0.04 CVSS 8.1 CVE-2026-55040 CVE-2026-63520 Microsoft veřejná správa finance US
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability CVE-2026-72898 Metabase SQL Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious…
KEV ✓ EPSS 0.10 CVE-2026-20349 CVE-2026-68820 CVE-2026-72898 Cisco Microsoft Metabase veřejná správa US
Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom…
KEV ✓ EPSS 0.98 CVE-2024-55591 CVE-2025-24472 veřejná správa zdravotnictví finance energetika US
Naše letní Postřehy z bezpečnosti, které dnes vyšly na serveru Root.cz, informují mimo jiné také o tom, že i v létě myslí v APT skupinách spadajících pod ruskou rozvědku SVR na blaho celého světa. Proto si třeba z dovolené v USA můžete přivést suvenýr až z daleké Tróji.
OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unsafe deserialization vulnerability affecting JetBrains TeamCity. An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling protocol without credentials and execute operating system commands with the privileges of the TeamCity server process.JetBrains reported no known active exploitation when it disclosed the vulnerability. However, on August 5, 2026, CISA added…
KEV ✓ EPSS 0.11 CVSS 9.8 CVE-2026-63077 JetBrains CISA Rapid7 veřejná správa US 3 zdrojů
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-8037 Progress LoadMaster Command Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian…
KEV ✓ EPSS 0.99 CVE-2026-8037 Progress veřejná správa US 2 zdrojů
Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-50481 veřejná správa US
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-50516 Microsoft veřejná správa telekomunikace finance výroba a průmysl US
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device. The following versions of Johnson Controls Inc. TL280 are affected: TL280 <5.63 (CVE-2026-27871) CVSS Vendor Equipment Vulnerabilities v3 4.1 Johnson Controls Inc. Johnson Controls Inc. TL280 Use of a Broken or Risky Cryptographic Algorithm Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and…
EPSS 0.00 CVSS 4.1 CVE-2026-27871 Johnson Controls energetika výroba a průmysl veřejná správa doprava US
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the…
EPSS 0.38 CVE-2026-20079 Cisco veřejná správa US
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the…
KEV ✓ EPSS 0.83 CVE-2026-18556 CVE-2026-34486 CVE-2026-9198 IBM N-able Apache veřejná správa US
Welcome to this week’s edition of the Threat Source newsletter. For my fianceé’s 30th birthday, I took her on a weekend trip to Shenandoah National Park – a favorite of ours since we went to a wedding there several years back. We’ve done several incredible hikes over the years, but one in particular had always loomed over my head: Old Rag, a 9.3 mile circuit hike that’s largely considered the most difficult in Virginia. I've always been warned that at the beginning and end, you hate Old Rag.…
Cisco Microsoft Check Point Zoho zdravotnictví veřejná správa vodárenství US
Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance.Key takeaways:Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active…
Introduction We have been tracking two new backdoors, OctLurk and SilkLurk, observed in attacks against government organizations primarily in Central Asia since January 2025. Identified victims are located in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These organizations operate across several sectors, including healthcare, research, government offices, ministries of foreign affairs, logistics, law‑enforcement agencies, urban planning and…
For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft, while the RansomHouse group claimed responsibility and published a subset of the stolen…
KEV ✓ EPSS 0.77 CVE-2025-66376 CVE-2026-16232 CVE-2026-50522 Check Point Oracle Microsoft OpenAI energetika vodárenství veřejná správa doprava IL
TrendAI™ Research breaks down what changed in CISA’s updated advisory on an ongoing PLC exploitation, why this activity might be more dangerous than a similar campaign in 2023, and how organizations can take action now to protect themselves.
We ran a noisy wget detection rule on Elastic's own cloud fleet for seven days. Three destinations survived deterministic filtering, Elasticsearch Query Language (ES|QL) COMPLETION triaged all three, and none of them created an alert that an analyst had to open. Each rule parses the destination from curl and wget executions, filters known-good hosts, redacts secrets, and then hands whatever’s left to a large language model (LLM) for a triage verdict. File transfer detections stay on in cloud…
CISA added CVE-2026-50522 to the Known Exploited Vulnerabilities catalog. Affected product: Microsoft SharePoint. Remediation due date: 2026-07-25.
KEV ✓ EPSS 0.77 CVSS 8.1 CVE-2026-50522 Microsoft veřejná správa US 3 zdrojů
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50311.
EPSS 0.00 CVSS 7.8 CVE-2026-50311 Microsoft veřejná správa US 2 zdrojů
Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50682 veřejná správa US
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
EPSS 0.00 CVE-2026-50684 veřejná správa US
Untrusted pointer dereference in Windows Domain Controller allows an unauthorized attacker to deny service over a network.
EPSS 0.01 CVE-2026-50424 veřejná správa US
Missing authentication for critical function in Windows Server Update Service allows an authorized attacker to elevate privileges over a network.
EPSS 0.01 CVE-2026-50444 veřejná správa US
Null pointer dereference in Active Directory Domain Services allows an authorized attacker to deny service over a network.
EPSS 0.01 CVSS 6.5 CVE-2026-50366 veřejná správa US