Výsledky hledání

typ: regulace× v celém archivu zrušit filtry

33 karet z 33 položek CZ · EN/orig

1

SPOJENO PŘES CVE CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management…

KEV ✓ EPSS 0.01 CVE-2025-39682 Linux veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2025-39682)

5

House passes bill to equip local law enforcement with scam-fighting tools

The Guarding Unprotected Aging Retirees from Deception Act (GUARD) attempts to address a common complaint from the victims of online scams like pig butchering — that such cases typically do not rise to the level of a federal investigation but local law enforcement is unequipped to properly investigate them.

veřejná správa US

tg: vymáhání práva tg: regulace tp: podvod

· The Record · House passes bill to equip local law enforcement with scam-fighting tools

Portál NÚKIB rozšiřuje informace k povinným i dobrovolným hlášením

Dne 11. září 2026 začaly platit ohlašovací povinnosti podle článku 14 aktu o kybernetické odolnosti CRA, které se týkají hlášení aktivně zneužívaných zranitelností a závažných incidentů. Povinnost se vztahuje na výrobce produktů s digitálními prvky uváděných na trh Evropské unie. V souvislosti s tím byly na Portálu NÚKIB v sekci Chci vyřídit zveřejněny nové rozcestníky určené pro hlášení aktivně zneužívaných zranitelností a závažných incidentů podle CRA. Uživatelé zde naleznou také související…

CZ

tg: regulace tg: návod

· NÚKIB · Portál NÚKIB rozšiřuje informace k povinným i dobrovolným hlášením

Ukraine moves to crack down on scam call centers after corruption scandal

Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations.

veřejná správa US

tg: vymáhání práva tg: regulace tp: podvod tp: soukromí

· The Record · Ukraine moves to crack down on scam call centers after corruption scandal

SPOJENO PŘES CVE CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-58704 Google Pixel Improper Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian…

KEV ✓ EPSS 0.00 CVE-2026-58704 Google veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · Malwarebytes Labs · Google Pixel owners urged to patch actively exploited modem flaw · CISA KEV · Google Pixel Improper Authorization Vulnerability (CVE-2026-58704)

3

SPOJENO PŘES CVE Kritische Sicherheitslücke in Cisco Secure Email Gateway - aktiv ausgenutzt - Updates verfügbar

15. September 2026 Beschreibung In Cisco Secure Email Gateway existiert eine kritische Sicherheitslücke. Bei erfolgreicher Ausnutzung könnte diese Sicherheitslücke es nicht authentifizierten Angreifer:innen aus der Ferne ermöglichen Befehle mit Root-Rechten auf dem zugrunde liegenden Betriebssystem auszuführen. Laut Cisco wurde eine Ausnutzung der Sicherheitslücke bereits beobachtet. CVE-Nummer(n): CVE-2026-76461 CVSS Base Score: 9.8 Auswirkungen Ein Angreifer könnte diese Sicherheitslücke…

KEV ✓ EPSS 0.02 CVSS 9.8 CVE-2026-76461 Cisco veřejná správa AT SE US FI GB FR CA IT

tg: zneužíváno tg: zranitelnost tg: regulace

· CERT.at · Kritische Sicherheitslücke in Cisco Secure Email Gateway - aktiv ausgenutzt - Updates verfügbar · CERT-SE · Kritisk sårbarhet i Cisco Secure Email Gateway utnyttjas aktivt · Rapid7 · CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild · NCSC-FI · Cisco Secure Email Gateway SQL Injection Vulnerability · Sophos Threat Research · Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation · CERT-FR – avis · Multiples vulnérabilités dans les produits Cisco (15 septembre 2026) · Cyber Centre Kanada · Cisco security advisory (AV26-921) · CSIRT Itálie (ACN) · Cisco: sfuttamento in rete della CVE-2026-76461 relativa a Secure Email Gateway · Cisco PSIRT · Cisco Secure Email Gateway SQL Injection Vulnerability · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · Cisco Secure Email Gateway SQL Injection Vulnerability (CVE-2026-76461)

Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture.Key takeawaysThe Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI.The Essential…

veřejná správa US

tg: regulace tg: návod tp: AI tp: identita tp: průmyslové systémy

· Tenable Research · Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

SPOJENO PŘES CVE GitLab opravil kritickou zranitelnost umožňující čtení citlivých dat

GitLab vyzval uživatele k okamžité aktualizaci serverů kvůli kritické zranitelnosti CVE-2026-85706 typu path traversal. Chyba v rozhraní API pro revize kódu v repozitářích umožňuje za určitých podmínek neověřenému útočníkovi číst libovolná data ze zranitelného serveru, včetně přihlašovacích údajů a dalších citlivých informací. Společnost watchTowr již zaznamenala pokusy o vyhledávání neaktualizovaných serverů dostupných z internetu. GitLab zranitelnost opravil ve verzích 19.3.2, 19.2.6 a 19.1 a…

KEV ✓ EPSS 0.15 CVE-2026-85706 GitLab veřejná správa CZ NL CA US

tg: zneužíváno tg: zranitelnost tg: regulace tg: novinka v produktu

· CSIRT.CZ (CZ.NIC) · GitLab opravil kritickou zranitelnost umožňující čtení citlivých dat · NCSC-NL · NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions · Cyber Centre Kanada · GitLab security advisory (AV26-917) · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability (CVE-2026-85706)

3

CERT-SE:s veckobrev v.37

I veckans brev kan du läsa om EU:s Cyber Resilience Act (CRA), där de första kraven träder i kraft idag. Du kan även läsa om cybersäkerhetskonferensen Svensk cyber 2026 som arrangeras av NCSC i november, där årets tema är ”förmåga att agera i en föränderlig tid”.

SE

tg: regulace tg: přehled

· CERT-SE · CERT-SE:s veckobrev v.37

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant…

KEV ✓ EPSS 0.01 CVE-2026-42016 CVE-2026-42018 CVE-2026-84869 JFrog ConnectWise veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Three Known Exploited Vulnerabilities to Catalog

2

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational…

KEV ✓ EPSS 0.01 CVE-2026-67277 CVE-2026-86060 MikroTik veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Two Known Exploited Vulnerabilities to Catalog

SPOJENO PŘES CVE Vulnérabilité dans Microsoft Edge (10 septembre 2026)

Une vulnérabilité a été découverte dans Microsoft Edge. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Microsoft indique que la vulnérabilité CVE-2026-85046 est activement exploitée.

KEV ✓ EPSS 0.01 CVE-2026-85046 Microsoft Google veřejná správa FR CA NL US IT

tg: zneužíváno tg: zranitelnost tg: regulace

· CERT-FR – avis · Vulnérabilité dans Microsoft Edge (10 septembre 2026) · Cyber Centre Kanada · Google security advisory (AV26-883) · NCSC-NL · NCSC-2026-0341 [1.00] [M/H] Kwetsbaarheden verholpen in Google Chrome · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CSIRT Itálie (ACN) · Google: rilevato sfruttamento di vulnerabilità zero-day in Chrome · CISA KEV · Google Chromium V8 Type Confusion Vulnerability (CVE-2026-85046)

4

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel…

KEV ✓ EPSS 0.76 CVE-2025-25249 CVE-2026-19490 CVE-2026-20079 CVE-2026-87491 Fortinet Citrix Google Cisco veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Four Known Exploited Vulnerabilities to Catalog

The push to stop algorithms controlling social media feeds has begun

Remember when social media was filled only with posts from your friends, rather than what an algorithm decided you wanted to see? So does the Australian government, and it wants that internet back. Yesterday, the government released draft legislation outlining a Digital Duty of Care. The proposal includes a measure that Prime Minister Anthony Albanese labeled “My Feed, My Way.” It would allow Australians over 16 to switch off the algorithmic feed that social media platforms deliver…

US

tg: regulace tp: soukromí

· Malwarebytes Labs · The push to stop algorithms controlling social media feeds has begun

2

The EU CRA's Real Question: What Shipped, and When Did You Know?

The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. [...]

US

tg: regulace tg: návod tp: dodavatelský řetězec

· BleepingComputer · The EU CRA's Real Question: What Shipped, and When Did You Know?

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability CVE-2026-86218 N-able N-central Static Code Injection Vulnerability These types of vulnerabilities…

KEV ✓ EPSS 0.02 CVE-2026-75650 CVE-2026-81963 CVE-2026-85880 CVE-2026-86218 Adobe Magento Microsoft N-able veřejná správa US

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Four Known Exploited Vulnerabilities to Catalog

1

1

Your phone or computer may soon ask how old you are

First, the good news: If you use a Linux-based operating system, you may not be asked your age in a few months. The bad news is that Windows, macOS, iOS, and Android users in California will be. California has passed a law that requires a range of operating systems to start collecting your age when you first set them up. Under the state’s Digital Age Assurance Act (DAAA), signed into law in October 2025, Windows, macOS, iOS, and Android will all have to do this from January 1, 2027. Operating…

Microsoft Apple Google US

tg: regulace tp: soukromí

· Malwarebytes Labs · Your phone or computer may soon ask how old you are

1

1

SPOJENO PŘES CVE CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates…

KEV ✓ EPSS 0.04 CVSS 9.4 CVE-2026-81578 CVE-2026-82078 PaperCut veřejná správa US IT FI FR

tg: zneužíváno tg: zranitelnost tg: regulace

· CISA Advisories · CISA Adds Two Known Exploited Vulnerabilities to Catalog · CSIRT Itálie (ACN) · PaperCut: rilevato sfruttamento in rete delle CVE-2026-82078 e CVE-2026-81578 · NCSC-FI · URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) · CERT-FR – avis · Multiples vulnérabilités dans Papercut (28 août 2026)

1

1

PCI DSS 4.0.1: Application Requirements You’re Being Assessed On in 2026

Key Takeaways Since March 31, 2025, all 51 former “best practice” requirements in PCI DSS 4.0 have been fully scored. Every 2026 assessment covers them. A large share of the new weight sits in the PCI DSS 4.0.1 application requirements, concentrated in Requirements 6 and 11: inventory of custom applications and APIs, continuous protection of public-facing apps, payment page script management, authenticated scanning, and risk-based prioritization. 6.4.3 and 11.6.1 now require a complete…

Qualys finance obchod US

tg: regulace

· Qualys · PCI DSS 4.0.1: Application Requirements You’re Being Assessed On in 2026

1

1

SPOJENO PŘES CVE CISA warns of hackers exploiting critical MLflow vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]

KEV ✓ EPSS 0.16 CVE-2026-64849 MLflow veřejná správa US CA

tg: zneužíváno tg: zranitelnost tg: regulace

· BleepingComputer · CISA warns of hackers exploiting critical MLflow vulnerability · Cyber Centre Kanada · MLflow security advisory (AV26-832) · CISA Advisories · CISA Adds One Known Exploited Vulnerability to Catalog · CISA KEV · MLflow Server-Side Request Forgery Vulnerability (CVE-2026-64849)

1

SPOJENO PŘES CVE CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now

Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing the patch alone does not complete remediation, as the fix replaces a kernel driver and requires…

KEV ✓ EPSS 0.06 CVSS 7.0 CVE-2026-68820 Microsoft US FR

tg: zneužíváno tg: regulace tg: návod tg: propagace

· Qualys · CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now · CERT-FR – avis · Multiples vulnérabilités dans Microsoft Windows (12 août 2026) · Tenable Research · Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820) · Microsoft Security · CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability · CISA KEV · Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability (CVE-2026-68820)

1

Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance.Key takeaways:Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active…

Tenable telekomunikace energetika doprava finance US

tg: regulace tg: návod tg: propagace tp: průmyslové systémy

· Tenable Research · Canada’s Bill C-8 is here: Why the 72-hour reporting rule will redefine critical infrastructure security

1

1

1