Výsledky hledání

sektor: veřejná správa× v celém archivu zrušit filtry

214 karet z 216 položek · strana 3 z 4 CZ · EN/orig

3

CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

OverviewRapid7 Labs conducted a zero-day research project against Microsoft SharePoint, resulting in the discovery of two new vulnerabilities that, when chained together, achieve unauthenticated remote code execution (RCE) against a vulnerable SharePoint server. Today, both Rapid7 and Microsoft are disclosing the second vulnerability in this chain, the RCE vulnerability CVE-2026-63520. The first vulnerability in the chain, CVE-2026-55040, was disclosed by Rapid7 and Microsoft last month.Our…

KEV ✓ EPSS 0.51 CVSS 8.1 CVE-2026-55040 CVE-2026-63520 Microsoft veřejná správa finance US

· Rapid7 · CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability CVE-2026-72898 Metabase SQL Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious…

KEV ✓ EPSS 0.94 CVE-2026-20349 CVE-2026-68820 CVE-2026-72898 Cisco Microsoft Metabase veřejná správa US

· CISA Advisories · CISA Adds Three Known Exploited Vulnerabilities to Catalog

2

#StopRansomware: Gunra Ransomware

Advisory at a Glance Title #StopRansomware: Gunra Ransomware Original Publication August 10, 2026 Executive Summary Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom…

KEV ✓ · ransomware EPSS 0.98 CVE-2024-55591 CVE-2025-24472 veřejná správa zdravotnictví finance energetika US

· CISA Advisories · #StopRansomware: Gunra Ransomware

3

Johnson Controls Inc. TL280

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to access sensitive information on the device. The following versions of Johnson Controls Inc. TL280 are affected: TL280 <5.63 (CVE-2026-27871) CVSS Vendor Equipment Vulnerabilities v3 4.1 Johnson Controls Inc. Johnson Controls Inc. TL280 Use of a Broken or Risky Cryptographic Algorithm Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and…

EPSS 0.00 CVSS 4.1 CVE-2026-27871 Johnson Controls energetika výroba a průmysl veřejná správa doprava US

· CISA Advisories · Johnson Controls Inc. TL280

1

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the…

KEV ✓ EPSS 0.99 CVE-2026-18556 CVE-2026-34486 CVE-2026-9198 IBM N-able Apache veřejná správa US

· CISA Advisories · CISA Adds Three Known Exploited Vulnerabilities to Catalog

1

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

In this article The CaptiveCrunch campaignStorm-2945 and Midnight BlizzardCaptiveCrunch tradecraft and toolingHow to protect against CaptiveCrunch activityMicrosoft Defender detections and hunting guidanceIndicators of compromise Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some…

Microsoft veřejná správa US

tg: varování tg: rozbor tp: malware tp: phishing tp: identita tp: špionáž

· Microsoft Security Blog · CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

3

You were onto something with “It’s the Climb,” Miley

Welcome to this week’s edition of the Threat Source newsletter. For my fianceé’s 30th birthday, I took her on a weekend trip to Shenandoah National Park – a favorite of ours since we went to a wedding there several years back. We’ve done several incredible hikes over the years, but one in particular had always loomed over my head: Old Rag, a 9.3 mile circuit hike that’s largely considered the most difficult in Virginia. I've always been warned that at the beginning and end, you hate Old Rag.…

zdravotnictví veřejná správa US

tg: rozbor tg: přehled tp: phishing tp: ransomware tp: identita

· Cisco Talos · You were onto something with “It’s the Climb,” Miley

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

Introduction We have been tracking two new backdoors, OctLurk and SilkLurk, observed in attacks against government organizations primarily in Central Asia since January 2025. Identified victims are located in Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and the Syrian Arab Republic. These organizations operate across several sectors, including healthcare, research, government offices, ministries of foreign affairs, logistics, law‑enforcement agencies, urban planning and…

veřejná správa zdravotnictví školství RU

· Securelist (Kaspersky) · OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

1

27th July – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Nichirei, a Japan-based frozen-food supplier and logistics company, has experienced a ransomware attack that disrupted shipping operations and affected approximately 5,000 customers. KFC Japan warned of possible shortages. Nichirei confirmed personal data theft, while the RansomHouse group claimed responsibility and published a subset of the stolen…

KEV ✓ EPSS 0.85 CVE-2025-66376 CVE-2026-16232 CVE-2026-50522 Check Point Oracle Microsoft Zimbra energetika vodárenství doprava veřejná správa IL

tg: incident tg: zneužíváno tg: přehled tp: ransomware tp: únik dat tp: AI tp: průmyslové systémy

· Check Point Research · 27th July – Threat Intelligence Report

2

Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure

TrendAI™ Research breaks down what changed in CISA’s updated advisory on an ongoing PLC exploitation, why this activity might be more dangerous than a similar campaign in 2023, and how organizations can take action now to protect themselves.

veřejná správa energetika vodárenství výroba a průmysl JP

· Trend Micro · Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure

1

SPOJENO PŘES CVE Microsoft SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2026-50522)

CISA added CVE-2026-50522 to the Known Exploited Vulnerabilities catalog. Affected product: Microsoft SharePoint. Remediation due date: 2026-07-25.

KEV ✓ EPSS 0.85 CVSS 8.1 CVE-2026-50522 Microsoft veřejná správa US

· CISA KEV · Microsoft SharePoint Deserialization of Untrusted Data Vulnerability (CVE-2026-50522) · Zero Day Initiative · ZDI-26-412: (Pwn2Own) Microsoft SharePoint Deserialization of Untrusted Data Remote Code Execution Vulnerability · Microsoft Security · CVE-2026-50522 Microsoft SharePoint Remote Code Execution Vulnerability

1

2

SPOJENO PŘES CVE ZDI-26-417: Microsoft Windows ServerManager Exposed Dangerous Method Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-50311.

EPSS 0.00 CVSS 7.8 CVE-2026-50311 Microsoft veřejná správa US

· Zero Day Initiative · ZDI-26-417: Microsoft Windows ServerManager Exposed Dangerous Method Local Privilege Escalation Vulnerability · Microsoft Security · CVE-2026-50311 Windows Server Elevation of Privilege Vulnerability

25

AI Security Report 2026

For years, the cyber security industry tracked AI as a force multiplier: something that made existing attack techniques faster, cheaper, and more accessible. That framing was accurate. But the Annual AI Security Report 2026 from Check Point Research documents a transition that goes further. AI has crossed from assistant to operator. Where it once helped attackers prepare, it now runs the operation. Key observed findings AI has crossed from development aid to live attack operator. It now does…

veřejná správa IL

tg: rozbor tp: malware tp: phishing tp: AI tp: špionáž

· Check Point Research · AI Security Report 2026

1

1

One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement

Executive Summary SentinelLABS has been tracking sustained cyberespionage activity against several Pakistani law enforcement organizations, taking place from February 2024 to April 2026. All these actors converged on Balochistan Police over this period, bringing both a partner and an adversary of Pakistan to the same police force in a province shaped by a separatist insurgency and the regional tensions it has drawn in. At Balochistan Police, the compromised assets included servers hosting web…

veřejná správa US

· SentinelLabs · One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement

1

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to any SAML-federated application, bypassing multifactor authentication (MFA), conditional access, and…

Microsoft veřejná správa US

· Mandiant / Google TI · The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

1

Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

Note: SysAid was not compromised, and no SysAid vulnerability was involved. The attacker had already gained access to the victim environment and abused a legitimate software-deployment feature to deploy malware onto another machine within it. Key Points Check Point Research (CPR) tracks ‘Cavern Manticore’ as an Iran-nexus threat actor operating against Israeli targets, with a focus on the government and IT sectors. Cavern Manticore shares technical overlaps with other Iranian MOIS (Ministry of…

veřejná správa IL

tg: rozbor tp: malware tp: špionáž

· Check Point Research · Cavern Manticore: Exposing Iran-Linked Modular C2 Framework

2

22nd June – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 22nd June, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Texas Parks and Wildlife Department has been affected by a third-party data breach involving its license system vendor. The incident exposed driver’s license information, passport numbers, emails, phone numbers, and residential addresses for 3,087,721 hunting and fishing license customers. Social Security numbers and payment data were not affected.…

KEV ✓ EPSS 0.96 CVE-2026-20245 CVE-2026-33017 CVE-2026-34908 CVE-2026-34909 CVE-2026-34910 CVE-2026-41947 CVE-2026-41948 CVE-2026-55255 Cisco Ubiquiti Dify Langflow veřejná správa zdravotnictví finance IL

· Check Point Research · 22nd June – Threat Intelligence Report

1

The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem

Written by: James Sadowski, Alden Wahlstrom Introduction Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert information operations (IO) campaigns and a revitalization of pro-Russia hacktivism at an unprecedented…

veřejná správa US

· Mandiant / Google TI · The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem

1

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing…

Google veřejná správa obrana US

· Mandiant / Google TI · STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

1

Útočníci získali přístup k desítkám tisíc firewallů Fortinet

Bezpečnostní výzkumníci upozornili na rozsáhlou kampaň zaměřenou na firewally a VPN brány Fortinet, při níž mělo být kompromitováno téměř 74 000 zařízení ve 194 zemích. Útočníci podle zveřejněných informací automatizovaně vyhledávali veřejně dostupná administrační rozhraní, získávali konfigurace zařízení a následně offline prolamovali přístupové údaje. Mezi údajně zasaženými organizacemi jsou nadnárodní společnosti, státní instituce i provozovatelé kritické infrastruktury. Případ zároveň…

Fortinet veřejná správa energetika vodárenství telekomunikace CZ

· CSIRT.CZ (CZ.NIC) · Útočníci získali přístup k desítkám tisíc firewallů Fortinet

1

2

WEBINÁR: Praktické rady k používaniu JISKB (Jednotný informačný systém kybernetickej bezpečnosti)

V súvislosti so zavádzaním požiadaviek projektu NIS2 sme pre vás pripravili dva bezplatné webináre zamerané na praktické používanie JISKB – Jednotného informačného systému kybernetickej bezpečnosti. Počas 90-minútového online stretnutia získate prehľad o práci so systémom a priestor bude aj na vaše otázky. Obsah oboch termínov je rovnaký – vyberte si ten, ktorý vám viac vyhovuje.... The post WEBINÁR: Praktické rady k používaniu JISKB (Jednotný informačný systém kybernetickej bezpečnosti)…

veřejná správa SK

· SK-CERT (NBÚ SR) · WEBINÁR: Praktické rady k používaniu JISKB (Jednotný informačný systém kybernetickej bezpečnosti)

1

UNC1151/Ghostwriter phishing campaign targeting Gmail accounts

Recently, we have been observing attacks by the UNC1151/Ghostwriter group targeting Gmail accounts. This group has been regularly attacking the mailboxes of Polish citizens for several years, although in the past these attacks focused on other email providers. The techniques used evolve over time, but the core theme of the messages and their objective remain unchanged.

veřejná správa PL

· CERT Polska · UNC1151/Ghostwriter phishing campaign targeting Gmail accounts

1

2026-007: Critical Vulnerability in Windows Netlogon

On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors. It is strongly recommended updating affected Windows servers as soon as possible.

Microsoft veřejná správa EU

· CERT-EU · 2026-007: Critical Vulnerability in Windows Netlogon

1