Výsledky hledání

výrobce: Microsoft× v celém archivu zrušit filtry

1035 karet z 1072 položek · strana 15 z 18 CZ · EN/orig

28

4

1

2

1

1

1

SPOJENO PŘES CVE ZDI-26-387: Oracle PeopleSoft HttpListeningConnector Server-Side Request Forgery Vulnerability

This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Oracle PeopleSoft. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.3. The following CVEs are assigned: CVE-2026-35273.

KEV ✓ · ransomware EPSS 0.95 CVSS 9.8 CVE-2026-35273 Oracle Google Microsoft školství US

· Zero Day Initiative · ZDI-26-387: Oracle PeopleSoft HttpListeningConnector Server-Side Request Forgery Vulnerability · Mandiant / Google TI · ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

2

Lost in relocation: analysis of a new loader distributing CASTLESTEALER

A previously undocumented Windows loader tracked as OXLOADER is delivering the CASTLESTEALER infostealer via malicious Google Ads, with low detection rates across static engines and sandbox detonations. The loader uses several obfuscation layers (control-flow flattening, opaque predicates, mixed Boolean-Arithmetic), self-modifying decryption stubs, and abuses the Windows .reloc section to stage shellcode. Elastic Security Labs identified OXLOADER in an active campaign targeting one of our…

Microsoft Google US

tg: varování tg: rozbor tp: malware

· Elastic Security · Lost in relocation: analysis of a new loader distributing CASTLESTEALER

Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

AAD Graph Activity Logs are now ingestible into Elastic and usable for threat detection within the SIEM/XDR solution. That sentence shouldn't be exciting, but it is. For most of the past decade, this slice of telemetry simply didn't exist as a customer-accessible log stream. Microsoft Graph Activity Logs (the modern graph.microsoft.com surface) went GA in April 2024. The legacy graph.windows.net surface, the one adversary tooling actually hits, stayed dark until early 2026. This post walks the…

Microsoft Elastic US

tg: rozbor tg: novinka v produktu tg: návod tp: identita

· Elastic Security · Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gap

7

1

1

CVE-2026-50656 Microsoft Defender Elevation of Privilege Vulnerability

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

EPSS 0.11 CVE-2026-50656 Microsoft US

· Microsoft Security · CVE-2026-50656 Microsoft Defender Elevation of Privilege Vulnerability

1

1

Riasztás Microsoft és Adobe szoftverek 2026 júniusában javított sérülékenységeiről

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Microsoft és az Adobe szoftvereket érintő kritikus kockázati besorolású sérülékenységek kapcsán azok súlyossága, a szoftverek széleskörű elterjedtsége, valamint az egyes biztonsági hibákat érintő aktív kihasználások miatt. A Microsoft tárgyhavi biztonsági csomagjában összesen 206 különböző biztonsági hibát javított, köztük 3 db nulladik napi (zero-day) sebezhetőséget is, […]

Microsoft Adobe HU

· NKI Maďarsko · Riasztás Microsoft és Adobe szoftverek 2026 júniusában javított sérülékenységeiről

2

2

2026-007: Critical Vulnerability in Windows Netlogon

On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors. It is strongly recommended updating affected Windows servers as soon as possible.

Microsoft veřejná správa EU

· CERT-EU · 2026-007: Critical Vulnerability in Windows Netlogon

5

The June 2026 Security Update Review

I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for June 2026For June,…

KEV ✓ EPSS 0.54 CVSS 10.0 CVE-2025-10263 CVE-2026-32193 CVE-2026-41091 CVE-2026-44815 CVE-2026-45585 CVE-2026-45586 CVE-2026-45657 CVE-2026-47291 CVE-2026-47644 CVE-2026-48567 CVE-2026-49160 CVE-2026-50507 Adobe Microsoft US

· ZDI Blog · The June 2026 Security Update Review