VIRY.CZ RADAR je monitor bezpečnostních hrozeb: advisories, zranitelnosti
a threat intel z veřejných zdrojů, česky a na jednom místě.
65zdrojů
25zemí
6 553položek
5 290CVE s hodnocením
Více informací
Jsem „protkán“ AI. Snažím se pochopit zdrojové texty a bez vymýšlení je
zestručnit a převést do českého jazyka, případně s využitím AI seskupit.
Patřičně jsem pak hrdý na
týdenní reporty, kde s pomocí AI zpracovávám
stovky článků a hledám v nich souvislosti. Používám ale i čistou matematiku,
takže pokud například více zdrojů mluví o shodné CVE chybě, seskupím to do
jednoho příspěvku.
Doporučuji se přihlásit k jejich
odběru e-mailem nebo
jinou cestou.
Pokud se Vám líbím, nebráním se
finanční podpoře :-)
Původní „Igiho stránka o virech“ se odstěhovala sem.
Všechny zprávy za posledních 7 dní
K seskupování zpráv do jedné události používám AI 2x denně nebo logiku kolem shodného výčtu CVE (okamžitě).
355 záznamů z 421 položek
· strana 1 z 6
CZ ·
EN/orig
Serial number: AV26-942Date: September 18, 2026 As of September 18, 2026, ABB published a security advisory to address vulnerabilities in the following product: Freelance Controller Multiple versions and models The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Freelance SECURITY - Missing Length Check CVE ID: CVE-2023-5778 ABB Cyber security alerts and notifications
Serial number: AV26-941Date: September 18, 2026 As of September 17, 2026, SolarWinds is affected by a vulnerability in the following product: SolarWinds Access Rights Manager Prior to 2026.2 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SolarWinds Access Rights Manager Unauthenticated Remote Code Execution Vulnerability (CVE-2026-28326)
Serial number: AV26-940Date: September 18, 2026 As of September 9, 2026, Arista Networks is affected by vulnerabilities in the following product: EOS Multiple versions and platforms The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Advisory 0174 Arista Networks Advisories & Notices
Executive Summary Following disclosure of the TraderTraitor attack against LayerZero in April 2026, SentinelOne identified an additional victim with the same macOS backdoors. Our analysis explores the mechanics of these backdoors and the expanded targeting against a victim in the IT services sector with no relationship to cryptocurrency trading. We also identified more weaponized GitHub repositories from the social engineering schemes used to target job seekers in these campaigns. This report…
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. [...]
Serial number: AV26-939Date: September 18, 2026 As of September 17, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.53 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Stable Channel Update for Desktop
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]
Serial number: AV26-938Date: September 18, 2026 As of September 18, 2026, Moxa is affected by a vulnerability in the following product: TN-4500B Series Prior to or equal to v2.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-15579: Out-of-bounds Write Vulnerability in Ethernet Switch Moxa Security Advisory
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...]
A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study.
Amid discussions about slowing down AI development, the Telegraph ran the headline: “OpenAI sounds alarm after bot tries to break free from human control.” That headline is slightly misleading, in my opinion. The Telegraph headline overstates what happened, although the underlying behavior is still genuinely concerning. The article reports that OpenAI has disclosed rare but troubling cases in which an unreleased model generated its own instructions that appeared to reject developer control.…
Serial number: AV26-937Date: September 18, 2026 As of September 4, 2026, Advantech is affected by vulnerabilities in the following products: EKI-1242EIMS Prior to or equal to V2.00.01 EKI-1242IEIMS Prior to or equal to V2.00.01 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Vulnerabilities Identified in EKI-1242EIMS/EKI-1242IEIMS (PDF) Advantech Security Advisories
Rilevato PoC pubblico per la la vulnerabilità identificata tramite la CVE-2026-81934 in Redis, sistema per l'archiviazione e la gestione di dati in memoria.
Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. [...]
Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements. [...]
Serial number: AV26-936Date: September 18, 2026 As of September 17, 2026, Grafana is affected by vulnerabilities in the following product: Grafana OSS Version 12.3.0 to 12.4.10 Version 13.0.0 to 13.08 Version 13.1.0 to 13.1.5 Version 13.2.0 to 13.2.1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Geomap MapLibre XSS Grafana Security Advisories
Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams should focus their resources. [...]
Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. [...]
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management…
Den här veckan innehåller CERT-SE:s veckobrev bland annat information om att NCSC och AI Sweden med flera bjuder in till seminarium den 22 oktober på temat “Modern sårbarhetshantering i en AI-driven hotmiljö”. Läs mer om detta nedan.
Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42.
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. [...]
Risolte molteplici vulnerabilità di cui 3 con gravità ”alta” in Grafana, nota applicazione web per la visualizzazione e l’analisi interattiva di dati. Tali vulnerabilità, qualora sfruttate, potrebbero consentire ad un utente malintenzionato di elevare i propri privilegi e/o di eseguire codice arbitrario remoto sui sistemi interessati
Rilasciato aggiornamento che risolve 2 vulnerabilità di sicurezza, con gravità “critica”, in pgAdmin, nota piattaforma di amministrazione e sviluppo open source per PostgreSQL. Tali vulnerabilità, qualora sfruttate, potrebbero consentire a un utente malintenzionato di eludere i meccanismi di autenticazione e di scrivere file arbitrari sul filesystem dei sistemi interessati
Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be delivered. Similar messages impersonate Colissimo and Chronopost in France, Correos in Spain, Poste Italiane in Italy, and PostNL in the Netherlands. The details vary, but the aim is usually the same: to persuade you to visit a fake courier website and provide personal and financial…
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 16 nuove vulnerabilità di sicurezza, di cui 2 con gravità “critica” e 7 con gravità “alta”.
Stored Cross-Site Scripting (XSS) in T-Systems’ TAO 2.0 Fri, 09/18/2026 - 11:30 Aviso Affected Resources TAO 2.0 Description INCIBE has coordinated the publication of a medium-severity vulnerability affecting T-Systems’ TAO 2.0 suite, a management platform for the public sector. The vulnerability was discovered by Cayetano de Juan Úbeda.This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:CVE-2026-92976: CVSS v4.0: 5.1 | CVSS:4.0…
In June 2026 the IETF published RFC 10008[1], defining a new HTTP method: "QUERY". The HTTP protocol faced already by changes (HTTP/2, HTTP/2) but it’s the first new standard HTTP verb since "PATCH" in 2010! This new method sits between “GET” and “POST” and can be resumed like this: “QUERY is a GET with a body”. It's safe and idempotent: the request is processed without state change and can be automatically repeated or restarted without concern for partial state changes. The query itself lives…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19772.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20176.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20211.
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20235.
This TSUBAME Report Overflow series discusses observation trends from TSUBAME sensors both in Japan and overseas, as well as other topics not covered in the JPCERT/CC Quarterly Report. This article covers monitoring results from April to June 2026. Note: Starting in FY2026, the JPCERT/CC Internet Threat Monitoring Report has been integrated into the JPCERT/CC Quarterly Report. Sharp Increase in Mirai-like Packets Targeting 23/TCP Observed in Early May 2026 In early May 2026, TSUBAME observed a…
The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies.
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 9.9, CVEs: CVE-2026-13348, CVE-2026-31431, CVE-2026-13336, CVE-2026-13337, CVE-2025-6625, CVE-2024-4872, CVE-2024-3980, CVE-2024-3982, CVE-2024-7940, CVE-2024-7941, CVE-2026-15688, CVE-2026-86520, CVE-2026-86689, CVE-2026-77960, CVE-2026-13584, Summary: CISA released eight Industrial Control Systems (ICS) Advisories. These advisories provide timely information about current security issues,…
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.1, CVEs: CVE-2026-81642, CVE-2026-81634, CVE-2026-82717, CVE-2026-77955, CVE-2026-78227, CVE-2026-80225, CVE-2026-82720, CVE-2026-85501, CVE-2026-77860, Summary: Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report. Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC…
Run security operations for more than one team, region, or customer, and you inherit a familiar tradeoff. One giant deployment gives you a single view but costs you tenant isolation, while separate environments preserve isolation and scatter your analysts across contexts, with detection rules drifting into 12 slightly different copies along the way. Cross-project search (CPS) on Elastic Cloud Serverless is built to end that tradeoff. One Elastic Security project runs detection and triage, along…
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Une vulnérabilité a été découverte dans Kaspersky Secure Mail Gateway. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.
De multiples vulnérabilités ont été découvertes dans WordPress. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
Key Takeaways Periodic audits provide a point-in-time assessment, but they cannot demonstrate whether controls remain effective between audit cycles. Qualys platform data shows 10.5 billion configuration findings across customer environments but only 1.6% represent meaningful exposure and under 1% are prioritized, business-critical findings. Verizon’s 2026 DBIR found the median time to resolve weak passwords and misconfigured permissions is about 8 months. Across 1 billion misconfiguration…
The best on-prem AI pentesting tools of 2026 for regulated teams, compared on air-gap support, whitebox depth, and application coverage Category: DevSec Tools & Comparisons
Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending the Cross-Environment Pivot appeared first on Unit 42.
Serial Number: AV26-935Date: September 17, 2026 As of September 16, 2026, Tanium is affected by a vulnerability in the following product: Threat Response Prior to Update 15 (v4.12.317) Prior to Update 8 (v4.17.289) Prior to Update 25 (v4.9.447) The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. TAN-2026-047 - Tanium Security Advisories All Advisories - Tanium Security Advisories
Serial number: AV26-934Date: September 17, 2026 As of September 17, 2026, Dell is affected by vulnerabilities in the following products: Dell Networking OS10 Prior to 10.6.1.3 Dell OpenManage Server Administrator (OMSA) Multiple versions and models Elastic Cloud Storage (ECS) Prior to 4.4.0.0 ObjectScale Prior to 4.4.0.0 Dell Update Package (DUP) Framework Prior to 26.07.03 Dell Wyse Management Suite Prior to 2605.0.3.683 Dell Repository Manager (DRM) Prior to 3.5.2 The Cyber Centre encourages…
Executive Summary Vulnerability exploitation now happens at a speed that manual, ticket-based remediation can’t match. Qualys’s Enterprise TruRisk Management Platform closes that gap with autonomous remediation: exposures are prioritized by threat, business, and environmental context, then validated by TruConfirm and Agent Val before any resource is committed, eliminating over 90% of remediation noise across 1,600+ CVEs. Confirmed risks move to TruRisk Eliminate, which scores patch reliability…
OpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. [...]
Flock Safety’s cameras are automated license plate readers (ALPRs) designed to help police find stolen cars or wanted suspects. A joint investigation by 404 Media and WIRED, based on data recovered from a physically removed Flock camera, found that its on-device software explicitly detects people as well as vehicles, bicycles, and license plates. Separately, Washington DC’s police union says the Metropolitan Police Department used Flock data to track officers under Internal Affairs…
Welcome to this week’s edition of the Threat Source newsletter. There’s been a lot of talk recently about slowing down the pace of AI development. And yes, there are legitimate moral, ethical, geopolitical, and safety concerns with the use of AI. It’s not clear yet whether an AI slowdown could happen, let alone whether it should (hat tip to Dr. Ian Malcolm). I admit, I’m not really qualified to opine on the impacts unrestricted AI might have on bioterrorism, the balance of international power,…