Výsledky hledání

sektor: telekomunikace v celém archivu

Různé zkratky a hodnoty pod každou zprávou mají svoji legendu — pokud na údaji postojíte myší. Některé jsou klikatelné. Typicky CVE.

zrušit filtry CZ · EN/orig

22 karet z 23 položek

1

More than 200 victims of Medusa ransomware identified over the last year, CISA says

The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.

veřejná správa energetika vodárenství telekomunikace US

The Record ·

2

Siemens Siveillance Video

View CSAF Summary Siveillance Video Management Servers contains a vulnerability that could allow a Remote Code Execution attack. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Siveillance Video are affected: Siveillance Video V2023 R3 vers:intdot/<23.3.27 (CVE-2026-3014) Siveillance Video V2024 R1 vers:intdot/<24.1.16 (CVE-2026-3014) Siveillance Video V2025 vers:intdot/<25.1.15 (CVE-2026-3014) CVSS…

EPSS 0.01 CVSS 9.1 CVE-2026-3014 Siemens výroba a průmysl telekomunikace US

CISA Advisories ·

ZDI-26-580: Cisco Identity Services Engine Missing Authentication for Critical Function Information Disclosure Vulnerability

The vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-20190.

EPSS 0.01 CVSS 7.5 CVE-2026-20190 Cisco telekomunikace US

Zero Day Initiative ·

2

Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants

Overview of the attack In July 2026, Kaspersky experts detected a new attack by the Head Mare group. Previously, we classified them as hacktivists, but now we define them as an APT group due to the sophistication of their TTPs and the absence of destructive activity (encryption, wiping) in the targeted infrastructures. In this latest campaign, the attackers exploited a chain of vulnerabilities in the TrueConf video conferencing server and replaced the original TrueConf client installers with…

TrueConf Kaspersky Microsoft energetika výroba a průmysl doprava telekomunikace RU

Securelist (Kaspersky) ·

2

1

3rd August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federal…

KEV ✓ EPSS 0.70 CVSS 9.8 CVE-2026-20316 CVE-2026-42897 CVE-2026-59309 CVE-2026-59310 CVE-2026-59726 CVE-2026-63077 CVE-2026-66066 Check Point Cisco Broadcom Microsoft vodárenství finance zdravotnictví telekomunikace IL

Check Point Research ·

2

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

In this article The CaptiveCrunch campaignStorm-2945 and Midnight BlizzardCaptiveCrunch tradecraft and toolingHow to protect against CaptiveCrunch activityMicrosoft Defender detections and hunting guidanceIndicators of compromise Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some…

Microsoft telekomunikace obchod doprava US

Microsoft Security Blog ·

1

Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance.Key takeaways:Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active…

Tenable veřejná správa energetika telekomunikace doprava US

Tenable Research ·

1

Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the…

KEV ✓ EPSS 0.92 CVE-2026-20127 CVE-2026-20182 CVE-2026-20245 Cisco telekomunikace energetika doprava finance obchod zdravotnictví US 2 zdrojů

Cisco PSIRT · Mandiant / Google TI

1

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

Note: SysAid was not compromised, and no SysAid vulnerability was involved. The attacker had already gained access to the victim environment and abused a legitimate software-deployment feature to deploy malware onto another machine within it. Key Points Check Point Research (CPR) tracks ‘Cavern Manticore’ as an Iran-nexus threat actor operating against Israeli targets, with a focus on the government and IT sectors. Cavern Manticore shares technical overlaps with other Iranian MOIS (Ministry of…

Check Point veřejná správa telekomunikace IL

Check Point Research ·

1

Update #1: Angriffswelle gegen FortiGate Devices - "FortiBleed"

22. Juni 2026 Beschreibung Fortinet hat letzten Freitag, am 19.5.2026, nun auch ein offizielles Statement zu "FortiBleed" veröffentlicht. Wir hatten zuvor in einem Blog-Artikel unseren aktuellen Wissensstand beschrieben. Bei dieser Angriffswelle handelt es sich nicht um die Ausnutzung einer neuen Schwachstelle. Die Angreifer:innen verwenden stattdessen Zugangsdaten, die bei früheren Sicherheitsvorfällen (u. a. im Zusammenhang mit CVE-2025-59718, CVE-2025-59719 und CVE-2026-24858) erlangt wurden…

KEV ✓ EPSS 0.86 CVE-2025-59718 CVE-2025-59719 CVE-2026-24858 Fortinet telekomunikace AT

CERT.at ·

1

Útočníci získali přístup k desítkám tisíc firewallů Fortinet

Bezpečnostní výzkumníci upozornili na rozsáhlou kampaň zaměřenou na firewally a VPN brány Fortinet, při níž mělo být kompromitováno téměř 74 000 zařízení ve 194 zemích. Útočníci podle zveřejněných informací automatizovaně vyhledávali veřejně dostupná administrační rozhraní, získávali konfigurace zařízení a následně offline prolamovali přístupové údaje. Mezi údajně zasaženými organizacemi jsou nadnárodní společnosti, státní instituce i provozovatelé kritické infrastruktury. Případ zároveň…

Fortinet veřejná správa energetika vodárenství telekomunikace CZ

CSIRT.CZ (CZ.NIC) ·

1

1

1

Cisco Nexus 3000 and 9000 Series Switches Border Gateway Protocol Denial of Service Vulnerability

A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect parsing of a transitive BGP attribute. An attacker could exploit this vulnerability by sending a crafted BGP update through an established BGP peer session. If…

EPSS 0.00 CVE-2026-20171 Cisco telekomunikace US

Cisco PSIRT ·

1

SMS Pumping útoky

Varovanie pred zvýšeným rizikom SMS Pumping útokov Národné centrum kybernetickej bezpečnosti (NCKB) NBÚ varuje pred zvýšenou frekvenciou takzvaných SMS Pumping útokov, ktoré sú zamerané aj na slovenské subjekty. SMS Pumping, označovaný aj ako AIT (Artificially Inflated Traffic), je pokročilá forma telekomunikačného podvodu, pri ktorej útočníci umelo vytvárajú vysoký objem neautentickej SMS komunikácie s cieľom neoprávnene... The post SMS Pumping útoky appeared first on SK-CERT.

telekomunikace SK

SK-CERT (NBÚ SR) ·

1

1

1

Kritische Sicherheitslücken in Cisco Catalyst SD-WAN - aktiv ausgenutzt - Updates verfügbar

26. Februar 2026 Beschreibung In Cisco Catalyst SD-WAN existieren mehrere kritische Sicherheitslücken. Die schwerwiegendste Schwachstelle (CVE-2026-20127) ermöglicht es einem nicht authentifizierten Angreifer aus der Ferne, die Authentifizierung zu umgehen und administrative Berechtigungen auf einem betroffenen System zu erlangen. Weitere Schwachstellen betreffen den Cisco Catalyst SD-WAN Manager und ermöglichen unter anderem Authentication Bypass, Privilege Escalation, Information Disclosure…

KEV ✓ EPSS 0.88 CVSS 10.0 CVE-2026-20122 CVE-2026-20126 CVE-2026-20127 CVE-2026-20128 CVE-2026-20129 CVE-2026-20133 Cisco telekomunikace finance AT

CERT.at ·