Výsledky hledání

téma: AI× typ: zranitelnost× v celém archivu zrušit filtry

29 karet z 29 položek CZ · EN/orig

1

Microsoft Azure, Cloud and AI Services — Multiple Vulnerabilities

Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-62874, CVE-2026-68791, CVE-2026-69399, CVE-2026-70009, CVE-2026-69843, CVE-2026-69865, CVE-2026-70200, CVE-2026-83944, CVE-2026-77903, CVE-2026-78501, CVE-2026-83946, CVE-2026-85878, CVE-2026-85885, CVE-2026-85887, CVE-2026-85889, CVE-2026-85917, CVE-2026-87701, CVE-2026-55946, Summary: Microsoft has addressed multiple vulnerabilities affecting Azure, Microsoft Fabric, Azure AI Foundry,…

CVSS 10.0 Microsoft FI

tg: zranitelnost tp: AI

· NCSC-FI · Microsoft Azure, Cloud and AI Services — Multiple Vulnerabilities

9

SPOJENO PŘES CVE LiteLLM: rilevato sfruttamento in rete della CVE-2026-59822

Rilevato lo sfruttamento in rete di una vulnerabilità, identificata tramite la CVE-2026-59822, in LiteLLM di BerriAI, server proxy impiegato come gateway per l'accesso a modelli linguistici di grandi dimensioni (LLM). La vulnerabilità consente a un attaccante remoto non autenticato di eludere i meccanismi di autenticazione e accedere agli strumenti MCP senza disporre di credenziali valide.

KEV ✓ EPSS 0.01 CVE-2026-59822 BerriAI IT US

tg: zneužíváno tg: zranitelnost tp: AI tp: identita

· CSIRT Itálie (ACN) · LiteLLM: rilevato sfruttamento in rete della CVE-2026-59822 · CISA KEV · BerriAI LiteLLM Improper Authentication Vulnerability (CVE-2026-59822)

MLflow dspy and statsmodels flavors bypass pickle deserialization control

Classification: Severe, Solution: Temporary Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: , Summary: A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply the control. Exploitation of this vulnerability allows for arbitrary remote code execution…

MLflow FI

tg: zranitelnost tp: AI

· NCSC-FI · MLflow dspy and statsmodels flavors bypass pickle deserialization control

Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

Classification: Severe, Solution: Workaround, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-90999, Summary: A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories. This vulnerability is tracked as CVE-2026-90999. Successful exploitation may allow arbitrary code…

EPSS 0.00 CVE-2026-90999 Sentry FI

tg: zranitelnost tp: AI

· NCSC-FI · Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment

1

ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of CrewAI crewAI. User interaction is required to exploit this vulnerability in that the target must load a malicious agent configuration from the repository. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92206.

CVSS 8.8 CVE-2026-92206 CrewAI US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability

1

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and security teams focus on deeper testing where needed while allowing high-confidence patches to move…

Microsoft US

tg: zranitelnost tg: návod tg: propagace tp: AI

· Qualys · Before You Patch. Why Patch Reliability Matters for Confident Deployment

1

14th September – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a collection containing millions of identity documents, including driver’s licenses, associated with the…

KEV ✓ EPSS 0.94 CVSS 10.0 CVE-2026-67276 CVE-2026-72898 CVE-2026-81963 CVE-2026-85046 CVE-2026-85706 CVE-2026-85880 CVE-2026-86060 Microsoft GitLab MikroTik Anthropic IL

tg: incident tg: zranitelnost tg: přehled tp: malware tp: únik dat tp: AI

· Check Point Research · 14th September – Threat Intelligence Report

4

ZDI-26-648: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19590.

EPSS 0.00 CVSS 7.8 CVE-2026-19590 OpenAI US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-648: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability

ZDI-26-649: (Pwn2Own) OpenAI Codex Improper Neutralization of Control Sequences Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must open a malicious folder. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19591.

EPSS 0.00 CVSS 7.8 CVE-2026-19591 OpenAI US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-649: (Pwn2Own) OpenAI Codex Improper Neutralization of Control Sequences Remote Code Execution Vulnerability

ZDI-26-650: (Pwn2Own) OpenAI Codex External Control of Configuration Setting Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19592.

EPSS 0.00 CVSS 7.8 CVE-2026-19592 OpenAI US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-650: (Pwn2Own) OpenAI Codex External Control of Configuration Setting Remote Code Execution Vulnerability

ZDI-26-651: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must open a malicious folder. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19593.

EPSS 0.00 CVSS 7.8 CVE-2026-19593 OpenAI US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-651: (Pwn2Own) OpenAI Codex External Control of System or Configuration Setting Remote Code Execution Vulnerability

3

NVIDIA security advisory (AV26-900)

Serial Number: AV26-900Date: September 9, 2026 As of September 8, 2026, NVIDIA is affected by vulnerabilities in the following product: Triton Inference Server Versions 0.0 to 26.03 Versions 0.0 to 26.06 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Bulletin: Triton Inference Server - September 2026 NVIDIA Product Security

NVIDIA CA

tg: zranitelnost tp: AI

· Cyber Centre Kanada · NVIDIA security advisory (AV26-900)

ZDI-26-634: Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-70477.

EPSS 0.01 CVSS 9.8 CVE-2026-70477 Flowise US

tg: zranitelnost tp: AI

· Zero Day Initiative · ZDI-26-634: Flowise CSV Agent Prompt Injection Remote Code Execution Vulnerability

Security Advisory Ivanti Neurons for ITSM (Multiple CVEs)

Classification: Critical, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.1: 9.9, CVEs: CVE-2026-12744, CVE-2026-12745, CVE-2026-12651, CVE-2026-12650, CVE-2026-12648, CVE-2026-12645, CVE-2026-12646, CVE-2026-12647, Summary: Ivanti has released updates for Ivanti Neurons for ITSM (N-ITSM) which addresses High and Critical severity vulnerabilities. We are not aware of any customers being exploited by these vulnerabilities at the time of disclosure. Additionally, it’s important for…

EPSS 0.02 CVSS 9.9 CVE-2026-12645 CVE-2026-12646 CVE-2026-12647 CVE-2026-12648 CVE-2026-12650 CVE-2026-12651 CVE-2026-12744 CVE-2026-12745 Ivanti FI

tg: zranitelnost tg: novinka v produktu tp: AI

· NCSC-FI · Security Advisory Ivanti Neurons for ITSM (Multiple CVEs)

3

China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation…

US

tg: varování tg: zranitelnost tp: AI tp: špionáž

· CISA Advisories · China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

1

Hugging Face Transformers library writes remote code to disk prior to consent check

Classification: Critical, Solution: Unavailable, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-80047, Summary: A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The library performs a remote module fetch and local cache write before evaluating the trust_remote_code consent prompt, violating the security contract enforced across other…

EPSS 0.00 CVE-2026-80047 Hugging Face FI

tg: zranitelnost tp: AI

· NCSC-FI · Hugging Face Transformers library writes remote code to disk prior to consent check

2

Infostealers are hijacking Claude accounts at users’ expense

Anthropic has warned some Claude users that criminals are using information stealers to take over their accounts. Rather than guessing passwords or intercepting two-factor authentication (2FA) codes, the attackers steal the browser sessions that prove a user is already logged in. According to a warning email shared publicly by an affected user, the attackers used common infostealer malware to copy Claude login sessions from victims’ computers. They then used those sessions to access the…

Anthropic US

tg: incident tg: varování tg: zranitelnost tp: malware tp: podvod tp: AI tp: identita

· Malwarebytes Labs · Infostealers are hijacking Claude accounts at users’ expense

2

31th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East Midlands airports, has disclosed a cyberattack that exposed data belonging to about 8.7 million customers. The compromised information includes contact details, vehicle registration numbers, and information collected through car park, lounge, fast-track, and Wi-Fi…

KEV ✓ EPSS 0.04 CVSS 10.0 CVE-2026-18885 CVE-2026-18886 CVE-2026-74820 CVE-2026-75604 CVE-2026-81578 CVE-2026-82078 PaperCut Ubiquiti Vercel ServiceNow IL

tg: incident tg: zneužíváno tg: zranitelnost tg: přehled tp: phishing tp: únik dat tp: AI

· Check Point Research · 31th August – Threat Intelligence Report

Rilevate nuove vulnerabilità in LangFlow

Rilevate 8 nuove vulnerabilità di sicurezza, di cui 2 con gravità “critica” e 4 con gravità “alta”, che interessano il software Langflow, nota piattaforma open-source che permette di costruire, testare e distribuire applicazioni e agenti basati su intelligenza artificiale.

EPSS 0.02 CVE-2026-18729 CVE-2026-18891 CVE-2026-18899 CVE-2026-18904 CVE-2026-19286 CVE-2026-19295 LangFlow IT

tg: zranitelnost tp: AI

· CSIRT Itálie (ACN) · Rilevate nuove vulnerabilità in LangFlow

1

3rd August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federal…

KEV ✓ · ransomware EPSS 0.87 CVSS 9.8 CVE-2026-20316 CVE-2026-42897 CVE-2026-59309 CVE-2026-59310 CVE-2026-59726 CVE-2026-63077 CVE-2026-66066 Cisco Broadcom JetBrains Microsoft vodárenství finance zdravotnictví telekomunikace IL

tg: incident tg: zranitelnost tg: přehled tp: phishing tp: únik dat tp: AI tp: průmyslové systémy

· Check Point Research · 3rd August – Threat Intelligence Report