Výsledky hledání

výrobce: Google× sektor: veřejná správa× v celém archivu zrušit filtry

6 karet z 6 položek CZ · EN/orig

1

SPOJENO PŘES CVE CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-58704 Google Pixel Improper Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian…

KEV ✓ EPSS 0.00 CVE-2026-58704 Google veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · Malwarebytes Labs · Google Pixel owners urged to patch actively exploited modem flaw · CISA KEV · Google Pixel Improper Authorization Vulnerability (CVE-2026-58704)

1

SPOJENO PŘES CVE Vulnérabilité dans Microsoft Edge (10 septembre 2026)

Une vulnérabilité a été découverte dans Microsoft Edge. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Microsoft indique que la vulnérabilité CVE-2026-85046 est activement exploitée.

KEV ✓ EPSS 0.01 CVE-2026-85046 Microsoft Google veřejná správa FR CA NL US IT

tg: zneužíváno tg: zranitelnost tg: regulace

· CERT-FR – avis · Vulnérabilité dans Microsoft Edge (10 septembre 2026) · Cyber Centre Kanada · Google security advisory (AV26-883) · NCSC-NL · NCSC-2026-0341 [1.00] [M/H] Kwetsbaarheden verholpen in Google Chrome · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CSIRT Itálie (ACN) · Google: rilevato sfruttamento di vulnerabilità zero-day in Chrome · CISA KEV · Google Chromium V8 Type Confusion Vulnerability (CVE-2026-85046)

1

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel…

KEV ✓ EPSS 0.76 CVE-2025-25249 CVE-2026-19490 CVE-2026-20079 CVE-2026-87491 Fortinet Citrix Google Cisco veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Four Known Exploited Vulnerabilities to Catalog

1

ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

Cisco Talos began an investigation after observing a DLL named "verification.google" executing from WebDAV at a Ukrainian government organization. We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. Pivoting around the similar WebDAV behavior led to a second loader named "pf.ch" and allowed us to reconstruct its earlier delivery…

Google Cloudflare NetSupport veřejná správa US

tg: varování tg: rozbor tp: malware tp: phishing tp: podvod

· Cisco Talos · ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager

1

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these techniques can be found in our previous blog on UNC6293’s phishing operations. We now track an…

Microsoft Google veřejná správa obrana školství US

· Mandiant / Google TI · Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

1

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing…

Google veřejná správa obrana US

· Mandiant / Google TI · STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus