Výsledky hledání

sektor: veřejná správa× v celém archivu zrušit filtry

214 karet z 216 položek · strana 1 z 4 CZ · EN/orig

2

SPOJENO PŘES CVE CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management…

KEV ✓ EPSS 0.01 CVE-2025-39682 Linux veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2025-39682)

Cross-Site Scripting (XSS) almacenado en TAO 2.0 de T-Systems

Stored Cross-Site Scripting (XSS) in T-Systems’ TAO 2.0 Fri, 09/18/2026 - 11:30 Aviso Affected Resources TAO 2.0 Description INCIBE has coordinated the publication of a medium-severity vulnerability affecting T-Systems’ TAO 2.0 suite, a management platform for the public sector. The vulnerability was discovered by Cayetano de Juan Úbeda.This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:CVE-2026-92976: CVSS v4.0: 5.1 | CVSS:4.0…

EPSS 0.00 CVSS 5.1 CVE-2026-92976 T-Systems veřejná správa ES

tg: zranitelnost

· INCIBE-CERT · Cross-Site Scripting (XSS) almacenado en TAO 2.0 de T-Systems

4

Flock cameras are tracking people as well as cars

Flock Safety’s cameras are automated license plate readers (ALPRs) designed to help police find stolen cars or wanted suspects. A joint investigation by 404 Media and WIRED, based on data recovered from a physically removed Flock camera, found that its on-device software explicitly detects people as well as vehicles, bicycles, and license plates. Separately, Washington DC’s police union says the Metropolitan Police Department used Flock data to track officers under Internal Affairs…

Flock Safety veřejná správa US

tg: rozbor tg: propagace tp: soukromí

· Malwarebytes Labs · Flock cameras are tracking people as well as cars

12 celebrity deepfake websites seized by Manhattan DA

The Manhattan District Attorney’s Office has seized the domains of 12 deepfake websites in what it called the largest known seizure of celebrity deepfake sites in history. The sites, which marketed themselves as deepfake pornography platforms, hosted AI-generated videos of over 1,200 people, including those in the public eye, ranging from politicians to actors, musicians, and social justice advocates. At least one allowed users to create their own deepfakes by grafting real faces and bodies…

média veřejná správa US

tg: vymáhání práva tp: AI tp: soukromí

· Malwarebytes Labs · 12 celebrity deepfake websites seized by Manhattan DA

4

House passes bill to equip local law enforcement with scam-fighting tools

The Guarding Unprotected Aging Retirees from Deception Act (GUARD) attempts to address a common complaint from the victims of online scams like pig butchering — that such cases typically do not rise to the level of a federal investigation but local law enforcement is unequipped to properly investigate them.

veřejná správa US

tg: vymáhání práva tg: regulace tp: podvod

· The Record · House passes bill to equip local law enforcement with scam-fighting tools

Ukraine moves to crack down on scam call centers after corruption scandal

Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations.

veřejná správa US

tg: vymáhání práva tg: regulace tp: podvod tp: soukromí

· The Record · Ukraine moves to crack down on scam call centers after corruption scandal

SPOJENO PŘES CVE CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-58704 Google Pixel Improper Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian…

KEV ✓ EPSS 0.00 CVE-2026-58704 Google veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · Malwarebytes Labs · Google Pixel owners urged to patch actively exploited modem flaw · CISA KEV · Google Pixel Improper Authorization Vulnerability (CVE-2026-58704)

5

SPOJENO PŘES CVE Kritische Sicherheitslücke in Cisco Secure Email Gateway - aktiv ausgenutzt - Updates verfügbar

15. September 2026 Beschreibung In Cisco Secure Email Gateway existiert eine kritische Sicherheitslücke. Bei erfolgreicher Ausnutzung könnte diese Sicherheitslücke es nicht authentifizierten Angreifer:innen aus der Ferne ermöglichen Befehle mit Root-Rechten auf dem zugrunde liegenden Betriebssystem auszuführen. Laut Cisco wurde eine Ausnutzung der Sicherheitslücke bereits beobachtet. CVE-Nummer(n): CVE-2026-76461 CVSS Base Score: 9.8 Auswirkungen Ein Angreifer könnte diese Sicherheitslücke…

KEV ✓ EPSS 0.02 CVSS 9.8 CVE-2026-76461 Cisco veřejná správa AT SE US FI GB FR CA IT

tg: zneužíváno tg: zranitelnost tg: regulace

· CERT.at · Kritische Sicherheitslücke in Cisco Secure Email Gateway - aktiv ausgenutzt - Updates verfügbar · CERT-SE · Kritisk sårbarhet i Cisco Secure Email Gateway utnyttjas aktivt · Rapid7 · CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild · NCSC-FI · Cisco Secure Email Gateway SQL Injection Vulnerability · Sophos Threat Research · Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation · CERT-FR – avis · Multiples vulnérabilités dans les produits Cisco (15 septembre 2026) · Cyber Centre Kanada · Cisco security advisory (AV26-921) · CSIRT Itálie (ACN) · Cisco: sfuttamento in rete della CVE-2026-76461 relativa a Secure Email Gateway · Cisco PSIRT · Cisco Secure Email Gateway SQL Injection Vulnerability · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · Cisco Secure Email Gateway SQL Injection Vulnerability (CVE-2026-76461)

Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture.Key takeawaysThe Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI.The Essential…

veřejná správa US

tg: regulace tg: návod tp: AI tp: identita tp: průmyslové systémy

· Tenable Research · Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Digital Watchdog VMAX DVR and NVR Product Lineups

View CSAF Summary Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point. The following versions of Digital Watchdog VMAX DVR and NVR Product Lineups are affected: VMAX A1 G4 DVRs vers:all/* (CVE-2026-68953, CVE-2026-66890, CVE-2026-68070, CVE-2026-68950, CVE-2026-66887, CVE-2026-66372) VMAX IP G4 NVRs vers:all/* …

EPSS 0.00 CVSS 9.6 CVE-2026-66372 CVE-2026-66887 CVE-2026-66890 CVE-2026-68070 CVE-2026-68950 CVE-2026-68953 Digital Watchdog veřejná správa zdravotnictví doprava US

tg: zranitelnost tp: identita

· CISA Advisories · Digital Watchdog VMAX DVR and NVR Product Lineups

Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers

Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and authorization. As agencies adopt hybrid and multi-cloud environments, single sign-on, federation, and application programming interface (API)-based access increasingly depend on signed tokens and…

veřejná správa US

tg: návod tp: identita

· CISA Advisories · Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers

SPOJENO PŘES CVE GitLab opravil kritickou zranitelnost umožňující čtení citlivých dat

GitLab vyzval uživatele k okamžité aktualizaci serverů kvůli kritické zranitelnosti CVE-2026-85706 typu path traversal. Chyba v rozhraní API pro revize kódu v repozitářích umožňuje za určitých podmínek neověřenému útočníkovi číst libovolná data ze zranitelného serveru, včetně přihlašovacích údajů a dalších citlivých informací. Společnost watchTowr již zaznamenala pokusy o vyhledávání neaktualizovaných serverů dostupných z internetu. GitLab zranitelnost opravil ve verzích 19.3.2, 19.2.6 a 19.1 a…

KEV ✓ EPSS 0.15 CVE-2026-85706 GitLab veřejná správa CZ NL CA US

tg: zneužíváno tg: zranitelnost tg: regulace tg: novinka v produktu

· CSIRT.CZ (CZ.NIC) · GitLab opravil kritickou zranitelnost umožňující čtení citlivých dat · NCSC-NL · NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions · Cyber Centre Kanada · GitLab security advisory (AV26-917) · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability (CVE-2026-85706)

2

4

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant…

KEV ✓ EPSS 0.01 CVE-2026-42016 CVE-2026-42018 CVE-2026-84869 JFrog ConnectWise veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Three Known Exploited Vulnerabilities to Catalog

5

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational…

KEV ✓ EPSS 0.01 CVE-2026-67277 CVE-2026-86060 MikroTik veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Two Known Exploited Vulnerabilities to Catalog

ST Engineering iDirect iQ-Series Terminals (Update A)

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected: Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058) 3315‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058) 9‑Series terminals <=4…

EPSS 0.01 CVSS 8.8 CVE-2026-38056 CVE-2026-38057 CVE-2026-38058 CVE-2026-38059 ST Engineering iDirect telekomunikace obrana energetika veřejná správa US

tg: zranitelnost tp: identita

· CISA Advisories · ST Engineering iDirect iQ-Series Terminals (Update A)

SPOJENO PŘES CVE Vulnérabilité dans Microsoft Edge (10 septembre 2026)

Une vulnérabilité a été découverte dans Microsoft Edge. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Microsoft indique que la vulnérabilité CVE-2026-85046 est activement exploitée.

KEV ✓ EPSS 0.01 CVE-2026-85046 Microsoft Google veřejná správa FR CA NL US IT

tg: zneužíváno tg: zranitelnost tg: regulace

· CERT-FR – avis · Vulnérabilité dans Microsoft Edge (10 septembre 2026) · Cyber Centre Kanada · Google security advisory (AV26-883) · NCSC-NL · NCSC-2026-0341 [1.00] [M/H] Kwetsbaarheden verholpen in Google Chrome · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CSIRT Itálie (ACN) · Google: rilevato sfruttamento di vulnerabilità zero-day in Chrome · CISA KEV · Google Chromium V8 Type Confusion Vulnerability (CVE-2026-85046)

5

SPOJENO PŘES CVE Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]

KEV ✓ EPSS 0.76 CVE-2026-20079 Cisco veřejná správa US

tg: zneužíváno tg: zranitelnost tp: identita

· BleepingComputer · Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks · CISA KEV · Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability (CVE-2026-20079) · Cisco PSIRT · Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel…

KEV ✓ EPSS 0.76 CVE-2025-25249 CVE-2026-19490 CVE-2026-20079 CVE-2026-87491 Fortinet Citrix Google Cisco veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Four Known Exploited Vulnerabilities to Catalog

SPOJENO PŘES CVE ZDI-26-646: Progress Software Kemp LoadMaster escape_quotes Uninitialized Memory Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-8037.

KEV ✓ EPSS 1.00 CVSS 7.2 CVE-2026-8037 Progress Software Progress veřejná správa US

tg: zranitelnost

· Zero Day Initiative · ZDI-26-646: Progress Software Kemp LoadMaster escape_quotes Uninitialized Memory Remote Code Execution Vulnerability · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · Progress LoadMaster Command Injection Vulnerability (CVE-2026-8037)

7

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan,…

PyPI npm Docker GitHub zdravotnictví veřejná správa média US

tg: varování tg: rozbor tp: malware tp: dodavatelský řetězec tp: AI tp: identita

· Mandiant / Google TI · GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability CVE-2026-86218 N-able N-central Static Code Injection Vulnerability These types of vulnerabilities…

KEV ✓ EPSS 0.02 CVE-2026-75650 CVE-2026-81963 CVE-2026-85880 CVE-2026-86218 Adobe Magento Microsoft N-able veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Four Known Exploited Vulnerabilities to Catalog

ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

Cisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. Pivoting around the similar WebDAV behavior led to a second loader named "pf.ch" and allowed us to reconstruct its earlier delivery…

Google Cloudflare NetSupport veřejná správa US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Cisco Talos · ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

1

2

4

Preparing for the Post-Quantum Era: A Call to Action

CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats. The G7 Cyber Security Working Group’s call to action outlines five priorities for a successful transition to PQC: Raising awareness of quantum…

veřejná správa US

tg: návod

· CISA Advisories · Preparing for the Post-Quantum Era: A Call to Action

RIASZTÁS Magyarország Ügyészségének nevével visszaélő ransomware támadásokkal kapcsolatban

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet (NBSZ NKI) riasztást ad ki Magyarország Ügyészségének nevével és arculati elemeivel visszaélő, zsarolóvírus fertőzéshez vezető adathalász üzenetekről. A bejelentések alapján a támadók hamis, hivatalos megkeresés látszatát keltő leveleket küldenek, amelyekben ügyészségi alkalmazottak nevével élnek vissza. A kampány célja az, hogy a felhasználó a levélben szereplő hivatkozásra kattintson, majd a […]

veřejná správa HU

tg: varování tg: zranitelnost tp: malware tp: phishing tp: ransomware

· NKI Maďarsko · RIASZTÁS Magyarország Ügyészségének nevével visszaélő ransomware támadásokkal kapcsolatban

Cyber Brief 26-09 - August 2026

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

veřejná správa EU

tg: přehled

· CERT-EU – analýzy · Cyber Brief 26-09 - August 2026

5

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-83548…

KEV ✓ EPSS 0.36 CVE-2026-48710 CVE-2026-49869 CVE-2026-59822 CVE-2026-82329 CVE-2026-83548 CVE-2026-83549 CVE-2026-9586 Sangoma JFrog SonicWall BerriAI veřejná správa US

tg: zneužíváno tg: zranitelnost

· CISA Advisories · CISA Adds Seven Known Exploited Vulnerabilities to Catalog

SPOJENO PŘES CVE Závažná zranitelnost ohrožuje téměř 22 000 Microsoft Exchange serverů

Microsoft 11. srpna 2026 vydal opravu zranitelnosti CVE-2026-62911 (CVSS 8,0), přesto téměř 22 000 veřejně dostupných Exchange serverů zůstává zranitelných. V Česku Shadowserver eviduje přibližně 300 unikátních IP adres Exchange serverů, které vyhodnocuje jako zranitelné (na jednu či více zranitelností). Zranitelnost postihuje Exchange Server 2016, 2019 a Subscription Edition a může vést až k převzetí uživatelských e-mailových schránek. Exploit je již veřejně dostupný. Verze 2016 a 2019 jsou…

EPSS 0.01 CVSS 8.8 CVE-2026-62911 Microsoft finance veřejná správa CZ NL US

tg: zneužíváno tg: zranitelnost tp: identita

· CSIRT.CZ (CZ.NIC) · Závažná zranitelnost ohrožuje téměř 22 000 Microsoft Exchange serverů · NCSC-NL · NCSC-2026-0289 [1.01] [H/H] Kwetsbaarheden verholpen in Microsoft Exchange server · Microsoft Security · CVE-2026-62911 Microsoft Exchange Server Elevation of Privilege Vulnerability · Zero Day Initiative · ZDI-26-534: (Pwn2Own) Microsoft Exchange Capture-Replay Authentication Bypass Vulnerability

Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

Research by: Amit Yardeni Key Points A Chinese-speaking actor is now targeting Brazil. Check Point Research has uncovered a sustained campaign against Brazilian organizations, primarily government and educational institutions since mid-2025. We dubbed this group Gambling Goblin: a Chinese-speaking cybercrime cluster connected to a previously documented group, Earth Berberoka, that targeted gambling sites across Asia. It marks a shift from Brazil’s usual home-grown banking-trojan threats to a…

Apache veřejná správa školství IL

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Check Point Research · Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

In this article Attack chain overviewCampaign scope and targetingMitigation and protection guidanceReferencesLearn more Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of…

zdravotnictví výroba a průmysl veřejná správa školství US

tg: varování tg: rozbor tp: malware

· Microsoft Security Blog · Counterfeit installers to system compromise: Tracking a deceptive software download campaign

2

Inyección de código en el Core de Lutece

Code injection in the Lutece Core Tue, 09/01/2026 - 11:44 Aviso Affected Resources Lutece Core: versión 7.1.7 y anteriores. Description INCIBE has coordinated the disclosure of a critical-severity vulnerability in Lutece Core, an open platform that enables local authorities to share, reuse and adapt digital services. The vulnerability was discovered by I Dorian Piette (Trachinus).This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability…

EPSS 0.00 CVSS 9.4 CVE-2026-4813 Lutece veřejná správa ES

tg: zranitelnost

· INCIBE-CERT · Inyección de código en el Core de Lutece

SPOJENO PŘES CVE JetBrains Cadence Compromised via Exploitation of TeamCity Vulnerability (Incident)

Cadence uses JetBrains TeamCity to orchestrate cloud workloads, and the affected server, api.cadence.jetbrains.com, remained vulnerable to CVE-2026-63077 despite having been intended for patching. Threat actors exploited the vulnerability beginning on August 8 to gain unauthor...

KEV ✓ EPSS 0.87 CVSS 9.8 CVE-2026-63077 JetBrains veřejná správa US

tg: incident tg: zneužíváno tg: zranitelnost tg: rozbor

· Wiz Research · JetBrains Cadence Compromised via Exploitation of TeamCity Vulnerability (Incident) · Rapid7 · Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077) · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability (CVE-2026-63077)

4

SPOJENO PŘES CVE CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates…

KEV ✓ EPSS 0.04 CVSS 9.4 CVE-2026-81578 CVE-2026-82078 PaperCut veřejná správa US IT FI FR

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Two Known Exploited Vulnerabilities to Catalog · CSIRT Itálie (ACN) · PaperCut: rilevato sfruttamento in rete delle CVE-2026-82078 e CVE-2026-81578 · NCSC-FI · URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) · CERT-FR – avis · Multiples vulnérabilités dans Papercut (28 août 2026)

SPOJENO PŘES CVE Riasztás a CVE-2026-73570 Zimbra Collaboration Suite szoftvert érintő sérülékenységről

A Nemzetbiztonsági Szakszolgálat Nemzeti Kiberbiztonsági Intézet riasztást ad ki a Zimbra Collaboration Suite (ZCS) szoftvert érintő, CVE-2026-73570 azonosítón nyomon követett kritikus sérülékenység kapcsán. Intézetünkhöz megnövekedett számú bejelentés érkezett a CVE-2026-73570 sérülékenység aktív kihasználásáról. A sebezhetőség kihasználása hitelesítés nélküli támadók számára távoli kódfuttatást tehet lehetővé. A sérülékenység a Zimbra SNMP-monitorozási komponensét érinti, és akkor használható…

KEV ✓ EPSS 0.32 CVE-2026-73570 Zimbra Synacor veřejná správa HU US IT

tg: zneužíváno tg: zranitelnost

· NKI Maďarsko · Riasztás a CVE-2026-73570 Zimbra Collaboration Suite szoftvert érintő sérülékenységről · BleepingComputer · Hackers breached over 270 Zimbra servers in ongoing attacks · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability (CVE-2026-73570) · CSIRT Itálie (ACN) · Risolta vulnerabilità su Zimbra Collaboration

1

Why a cryptographic inventory is key for addressing the quantum computing threat

When quantum computers become generally available, they’ll be able to crack current public-key cryptographic algorithms, putting digitally stored and transmitted data at risk. But the threat already exists, as attackers use the "harvest now, decrypt later" tactic. Discover why building a comprehensive cryptographic inventory and executing a phased operational strategy are critical for protecting your data against quantum computing attacks.Key takeawaysQuantum computing risks are an operational…

veřejná správa US

tg: rozbor tg: návod tp: soukromí

· Tenable Research · Why a cryptographic inventory is key for addressing the quantum computing threat

3

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2023-49105 ownCloud Improper Authentication Vulnerability CVE-2026-53362 Linux Kernel Unspecified Vulnerability CVE-2026-66384 JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise…

KEV ✓ EPSS 0.43 CVE-2023-49105 CVE-2026-53362 CVE-2026-66384 ownCloud JFrog veřejná správa US

· CISA Advisories · CISA Adds Three Known Exploited Vulnerabilities to Catalog

Ebyte NA111-M

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device. The following versions of Ebyte NA111-M are affected: NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179, CVE-2026-75814, CVE-2026-76940, CVE-2026-77966, CVE-2026-73809, CVE-2026-71187, CVE-2026-75548, CVE-2026-69658, CVE-2026-76133, CVE-2026-73819, CVE-2026-77975, CVE-2026-77977) CVSS Vendor Equipment Vulnerabilities v3 9.8 Ebyte Ebyte NA111-M Missing…

EPSS 0.01 CVSS 9.8 CVE-2026-69658 CVE-2026-71187 CVE-2026-73125 CVE-2026-73809 CVE-2026-73819 CVE-2026-75548 CVE-2026-75814 CVE-2026-76133 CVE-2026-76179 CVE-2026-76940 CVE-2026-77966 CVE-2026-77975 CVE-2026-77977 Ebyte veřejná správa US

· CISA Advisories · Ebyte NA111-M