VIRY.CZ RADAR je monitor bezpečnostních hrozeb: advisories, zranitelnosti
a threat intel z veřejných zdrojů, česky a na jednom místě.
65zdrojů
25zemí
6 560položek
5 318CVE s hodnocením
Více informací
Jsem „protkán“ AI. Snažím se pochopit zdrojové texty a bez vymýšlení je
zestručnit a převést do českého jazyka, případně s využitím AI seskupit.
Patřičně jsem pak hrdý na
týdenní reporty, kde s pomocí AI zpracovávám
stovky článků a hledám v nich souvislosti. Používám ale i čistou matematiku,
takže pokud například více zdrojů mluví o shodné CVE chybě, seskupím to do
jednoho příspěvku.
Doporučuji se přihlásit k jejich
odběru e-mailem nebo
jinou cestou.
Pokud se Vám líbím, nebráním se
finanční podpoře :-)
Původní „Igiho stránka o virech“ se odstěhovala sem.
Všechny zprávy za posledních 7 dní
K seskupování zpráv do jedné události používám AI 2x denně nebo logiku kolem shodného výčtu CVE (okamžitě).
360 záznamů z 428 položek
· strana 2 z 6
CZ ·
EN/orig
Serial number: AV26-934Date: September 17, 2026 As of September 17, 2026, Dell is affected by vulnerabilities in the following products: Dell Networking OS10 Prior to 10.6.1.3 Dell OpenManage Server Administrator (OMSA) Multiple versions and models Elastic Cloud Storage (ECS) Prior to 4.4.0.0 ObjectScale Prior to 4.4.0.0 Dell Update Package (DUP) Framework Prior to 26.07.03 Dell Wyse Management Suite Prior to 2605.0.3.683 Dell Repository Manager (DRM) Prior to 3.5.2 The Cyber Centre encourages…
Executive Summary Vulnerability exploitation now happens at a speed that manual, ticket-based remediation can’t match. Qualys’s Enterprise TruRisk Management Platform closes that gap with autonomous remediation: exposures are prioritized by threat, business, and environmental context, then validated by TruConfirm and Agent Val before any resource is committed, eliminating over 90% of remediation noise across 1,600+ CVEs. Confirmed risks move to TruRisk Eliminate, which scores patch reliability…
OpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. [...]
Flock Safety’s cameras are automated license plate readers (ALPRs) designed to help police find stolen cars or wanted suspects. A joint investigation by 404 Media and WIRED, based on data recovered from a physically removed Flock camera, found that its on-device software explicitly detects people as well as vehicles, bicycles, and license plates. Separately, Washington DC’s police union says the Metropolitan Police Department used Flock data to track officers under Internal Affairs…
Welcome to this week’s edition of the Threat Source newsletter. There’s been a lot of talk recently about slowing down the pace of AI development. And yes, there are legitimate moral, ethical, geopolitical, and safety concerns with the use of AI. It’s not clear yet whether an AI slowdown could happen, let alone whether it should (hat tip to Dr. Ian Malcolm). I admit, I’m not really qualified to opine on the impacts unrestricted AI might have on bioterrorism, the balance of international power,…
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
AI has already made fundamental changes to the operating environment for cybersecurity. Cyberattackers are testing more paths, adapting their techniques, and moving across digital environments with greater speed and persistence. The weaknesses they exploit remain familiar: excessive permissions, unprotected authentication flows, unpatched systems, exposed execution paths, and gaps between controls. What has changed is how quickly these weaknesses can combine into attack paths that cross…
Every benchmark tells a story. The most valuable ones tell us where to improve next. For five consecutive quarters Microsoft has published email security benchmarking reports to provide greater transparency into real-world protection outcomes. The results have shown strong Microsoft Defender performance across pre-delivery and post-delivery scenarios, while revealing where threats and defenses continue to evolve. This quarter’s benchmark examines how continuous measurement informs protection…
Questo CSIRT ha recentemente registrato, nel contesto nazionale, un aumento significativo di sfruttamenti attivi della CVE-2026-48907 – già sanata dal vendor e trattata nell’ambito dell’AL02/260615/CSIRT-ITA – ai danni di server web esposti. Tale vulnerabilità interessa il plugin Joomla Content Editor (JCE), estensione per il noto Content Management System (CMS) Joomla!.
At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company. The receiving gateway quarantined the message because it detected malicious content in the attachment, though even if it didn’t, the e-mail would not have…
Rilevato lo sfruttamento in rete di una vulnerabilità, identificata tramite la CVE-2026-59822, in LiteLLM di BerriAI, server proxy impiegato come gateway per l'accesso a modelli linguistici di grandi dimensioni (LLM). La vulnerabilità consente a un attaccante remoto non autenticato di eludere i meccanismi di autenticazione e accedere agli strumenti MCP senza disporre di credenziali valide.
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature along the lines tracked in earlier editions: models now act as attack operators, an underground market supplies the access, and AI systems have themselves become a target. The substantial distance between what the strongest models demonstrated under evaluation…
Aggiornamenti di sicurezza Dell Technologies sanano molteplici vulnerabilità, di cui una con gravità "critica" e 11 con gravità "alta", in vari prodotti.
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. [...]
AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted. [...]
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthorized attacker to perform spoofing over a network.
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
Apache Software Foundation ha rilasciato aggiornamenti di sicurezza per Apache NiFi e Apache NiFi Registry, piattaforme open source per la gestione, l'elaborazione e il versionamento dei flussi di dati, che sanano alcune vulnerabilità, di cui 2 con gravità "alta". Tali vulnerabilità potrebbero consentire a un attaccante di effettuare operazioni sui file al di fuori della directory prevista, manipolare dati, eludere misure di sicurezza e, tramite richieste HTTP opportunamente predisposte, comprom
An anonymous hacking group claimed to have broken into computer systems connected to Russia’s election infrastructure just days before the country begins voting for a new parliament.
Introduction Torrent trackers have long been abused for distributing malicious software, disguised as popular films, games, and other content. Our previous research has shown that cybercriminals repeatedly turn torrents as an initial infection vector, using trojanized cracks and installers to reach a large number of users. Installation guides for pirated software routinely instruct users to disable their antivirus, conditioning them to ignore potential threats they are inviting onto their…
HP ha rilasciato aggiornamenti di sicurezza per risolvere diverse vulnerabilità, di cui 4 con gravità "critica" e 5 con gravità "alta", che interessano HP AC Print & Scan, HP Output Central e HP Linux Imaging and Printing Software (HPLIP), soluzioni software destinate alla gestione delle funzionalità di stampa e scansione.
Weak password recovery mechanism for forgotten password in MobiAPParc Thu, 09/17/2026 - 14:21 Aviso Affected Resources IOS MobiAPParc v0 – v2.28;Android MobiAPParc v0 – v2.42. Description INCIBE has coordinated the disclosure of a high-severity vulnerability affecting SMAP’s MobiAPParc, an app that enables users to pay for parking in regulated parking zones and in municipal car parks managed by Palma City Council. The vulnerability was discovered by Llorenç Romá.This vulnerability has been…
View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete…
View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data. The following versions of Schneider Electric…
View CSAF Summary Schneider Electric is aware of a vulnerability in its Modicon M340 https://www.se.com/ww/en/product-range/1468-modicon-m340-pac/, BMXNOR0200H https://www.se.com/us/en/product/BMXNOR0200H/communication-module-modicon-m340-iec-608705101-104-dnp3-for-severe-environments/: Modicon M340 X80 Ethernet Communication Modules, BMXNGD0100 https://www.se.com/us/en/product/BMXNGD0100/communication-module-modicon-m580-global-data-service/: M580 Global Data module, BMXNOC0401 https://www.se…
View CSAF Summary Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access. The following versions…
View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) iOS <1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) CVSS Vendor Equipment Vulnerabilities v3 7.5 Bransys Bransys ELD Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors:…
View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. • SVC Light (STATCOM) • Fixed Series…
View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs. The following versions of Mitsubishi Electric GX Works3 and Motion Control Settings are affected: Mitsubishi Electric GX Works3 vers:all/* (CVE-2026-15688)…
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly. The following versions of Mitsubishi Electric CC-Link IE TSN…
AWS has recognized Aikido with its Security Competency for Application Security, validating how Aikido secures applications from code to cloud to runtime. Category: Product & Company Updates
The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms. [...]
The Manhattan District Attorney’s Office has seized the domains of 12 deepfake websites in what it called the largest known seizure of celebrity deepfake sites in history. The sites, which marketed themselves as deepfake pornography platforms, hosted AI-generated videos of over 1,200 people, including those in the public eye, ranging from politicians to actors, musicians, and social justice advocates. At least one allowed users to create their own deepfakes by grafting real faces and bodies…
Oracle heeft 19 kwetsbaarheden verholpen in Oracle VM VirtualBox. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle VM VirtualBox, waaronder mogelijkheden voor lokale en geauthenticeerde kwaadwillenden om ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van laag tot hoog. Van de in totaal 19 kwetsbaarheden kan volgens Oracle één kwetsbaarheid zonder authenticatie op afstand worden misbruikt. Succesvol misbruik kan onder meer leiden…
Since early May 2026, we’ve been monitoring a large phishing campaign based on T-Mobile rewards points. The messages falsely warn that a customer’s rewards points are about to expire. They aren’t legitimate account notices: They use urgency, invented point balances, and phishing links to push recipients into acting before they can verify the claim. A typical message says that a T-Mobile Rewards account holds 18,400 points, gives an imminent expiry date, and states that unused points will be…
Compared with the same period last year, ransomware incidents in Japan increased slightly by approximately 4.7%, indicating that ransomware continues to pose a significant threat.In Japan, The Gentlemen was the most active ransomware group in the first half of 2026.Attackers continue to primarily target small- and medium-sized enterprises, with organizations capitalized at less than JPY 1 billion accounting for approximately 80% of the total — an increase of around 13% from the previous year…
Rilasciati aggiornamenti di sicurezza per Craft CMS, sistema di gestione dei contenuti per la realizzazione e gestione di siti e applicazioni web, che sanano alcune vulnerabilità, di cui 4 con gravità "alta". Tali vulnerabilità potrebbero consentire a un attaccante di accedere a informazioni sensibili, eludere restrizioni di sicurezza, elevare i privilegi utente ed eseguire codice arbitrario sui sistemi interessati.
Siemens ha rilasciato aggiornamenti di sicurezza per sanare una vulnerabilità presente in alcuni dispositivi di telelettura e contabilizzazione energetica della serie WTV.
ISC ha rilasciato aggiornamenti di sicurezza per BIND 9 e BIND Supported Preview Edition, software per la gestione e la risoluzione delle richieste DNS, che sanano alcune vulnerabilità, di cui 7 con gravità "alta". Tali vulnerabilità possono causare la terminazione anomala di alcuni processi o un consumo eccessivo delle risorse, fino a compromettere la disponibilità del servizio sui sistemi interessati.
Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been used to surveil Iranian dissidents, journalists and government opponents, enabling remote command execution, data exfiltration, and persistence over Telegram command-and-control.
Most fraud platforms only see a threat once it becomes a transaction. This guide compares the top 5 fraud prevention platforms for banks and fintechs in 2026, including Group-IB, Feedzai, Sift, DataVisor, and Kount, and what actually separates them.