Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 8.8, CVEs: CVE-2026-15579, Summary: Moxa has disclosed an out-of-bounds write vulnerability in the Web login functionality of TN-4500B Series Ethernet switches. The vulnerability can be exploited remotely without authentication by supplying an overly long username, potentially causing a buffer overflow and denial of service. Moxa has released firmware 2.1, which addresses the vulnerability. Affected…
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.6, CVEs: CVE-2026-93374, CVE-2026-93372, CVE-2026-93375, CVE-2026-93382, CVE-2026-93387, CVE-2026-93373, CVE-2026-93381, CVE-2026-93379, CVE-2026-93377, CVE-2026-93380, CVE-2026-93384, CVE-2026-93383, CVE-2026-93376, CVE-2026-93378, CVE-2026-93385, CVE-2026-93386, Summary: Google released Chrome 153.0.8010.52/.53 for Windows/Mac and 153.0.8010.52 for Linux on 17 September. The update contains 16 security…
Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements. [...]
Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. [...]
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 16 nuove vulnerabilità di sicurezza, di cui 2 con gravità “critica” e 7 con gravità “alta”.
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 9.1, CVEs: CVE-2026-81642, CVE-2026-81634, CVE-2026-82717, CVE-2026-77955, CVE-2026-78227, CVE-2026-80225, CVE-2026-82720, CVE-2026-85501, CVE-2026-77860, Summary: Fix CVE-2026-81642, Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY. Thanks to Yuqi Qiu and Xiang Li from Nankai University, AOSP Lab for the report. Fix CVE-2026-81634, Possible heap buffer overflow during DNSSEC…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by…
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing. One of them is known to be actively exploited. For more information, see Cisco…
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 42 nuove vulnerabilità di sicurezza, di cui 3 con gravità “critica” e 28 con gravità “alta”.
Serial Number: AV26-924Date: September 15, 2026 As of September 15, 2026, Mozilla is affected by vulnerabilities in the following products: Firefox ESR Versions prior to 115.41 Versions prior to 140.16 Versions prior to 153.3 Firefox Versions prior to 156 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Vulnerabilities fixed in Firefox 156 — Mozilla Security Vulnerabilities fixed in Firefox…
Executive Summary Remediation deadlines slip for reasons outside your control: a patch does not exist yet, a patch is delayed, or a remediation attempt fails. The outcome is the same either way: the host stays unpatched and stays on the network. TruRisk Eliminate closes that window by isolating the host automatically the moment your deadline passes, executed natively through the Qualys Cloud Agent with no EDR integration required. This post covers the trigger criteria, the QQL query behind a…
GitLab vyzval uživatele k okamžité aktualizaci serverů kvůli kritické zranitelnosti CVE-2026-85706 typu path traversal. Chyba v rozhraní API pro revize kódu v repozitářích umožňuje za určitých podmínek neověřenému útočníkovi číst libovolná data ze zranitelného serveru, včetně přihlašovacích údajů a dalších citlivých informací. Společnost watchTowr již zaznamenala pokusy o vyhledávání neaktualizovaných serverů dostupných z internetu. GitLab zranitelnost opravil ve verzích 19.3.2, 19.2.6 a 19.1 a…
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...]
Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever patched, but the increase is not as significant as other vendors' "post-AI" patch releases. In addition to the major "27" version, Apple also released bug-fix-only releases for the 26 branch of its operating systems and for 15 (Sequioa) for macOS. None of the vulnerabilities is…
Google is changing how some links in its search results work. Instead of linking directly to the destination, Google has started routing some search result links through opaque google.com/goto?url=... redirects. The url parameter does not show a readable version of the destination but uses a custom, Google-specific encoding. Google confirmed the rollout to Search Engine Roundtable: “We have a long history of deploying technical measures against evolving forms of abuse, and we regularly take…
OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions.On September…
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur. Microsoft indique que la vulnérabilité CVE-2026-87491 est activement exploitée.
Aggiornamenti di sicurezza rilasciati per GitLab, nota piattaforma per la gestione del ciclo di sviluppo software e della collaborazione sui progetti, sanano alcune vulnerabilità, di cui 2 con gravità "critica" e 6 con gravità "alta"
This One Goes to Sixteen!Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers!New module content (16)Elasticsearch ingest-attachment Apache Tika XFA XXE Local File ReadAuthors: Bourbon Offensive Security Services and Jean-Marie BourbonType: AuxiliaryPull request: #21739…
On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: BroadWorks CommPilot Application Software Identity Services Engine (ISE) (security hardening release) Nexus Dashboard (security hardening release) Secure Firewall Adaptive Security Appliance (ASA) (security hardening release) Secure Firewall Management Center (FMC) (security…
If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them.Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabilities to evaluating policy, depends on the answer being right. The traditional answer comes from the outside: the scan engine sends traffic to a range of ports and infers each port's state from how the host responds. That…
Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector.Key takeawaysThe Exchange Inspector combines Tenable’s exposure detection with OpenAI’s GPT Cyber models and with human oversight to rigorously vet submissions made to…
Adobe ha rilasciato aggiornamenti di sicurezza per risolvere molteplici vulnerabilità, di cui 6 con gravità “critica” e 42 con gravità “alta”, in numerosi prodotti.
Classification: Severe, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.0: 8.1, CVEs: CVE-2026-83527, Summary: Ivanti has released updates for Ivanti Sentry that address one high severity vulnerability. This vulnerability impacts deployments managed by EPMM and Ivanti Neurons for MDM. We are not aware of any customers being exploited by this vulnerability at the time of disclosure. CVE-2026-83527 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS:3.0 8.1 An Authentication Bypass…
Classification: Critical, Solution: Official Fix, Exploit Maturity: Unproven, CVSSv3.1: 9.9, CVEs: CVE-2026-12744, CVE-2026-12745, CVE-2026-12651, CVE-2026-12650, CVE-2026-12648, CVE-2026-12645, CVE-2026-12646, CVE-2026-12647, Summary: Ivanti has released updates for Ivanti Neurons for ITSM (N-ITSM) which addresses High and Critical severity vulnerabilities. We are not aware of any customers being exploited by these vulnerabilities at the time of disclosure. Additionally, it’s important for…
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv4.0: 10.0, CVEs: CVE-2026-86206, CVE-2026-86207, CVE-2026-86218, Summary: Hotfix 4 includes security fixes for CVE-2026-86218 which is a critical-CVSS-rated vulnerability that could allow for pre-authenticated remote code execution on the N-central server. Hotfix 3 includes security fixes for CVE-2026-86206 and CVE-2026-86207 which are high-CVSS-rated vulnerabilities that could allow an unauthorized party to…
Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-fueled risk. Tenable One Adversary View, the first innovation planned from this work, will debut in the coming weeks.Key takeawaysClaude Mythos 5 is coming to Tenable One. In addition to using Claude Mythos 5 for…
The new Huntress AI SIEM search feature lets you find answers in plain English, with no query language fluency required. Ask questions, get results, and skip the syntax.
Classification: Severe, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: None, CVEs: CVE-2026-85046, CVE-2026-85052, CVE-2026-85043, CVE-2026-85048, CVE-2026-85045, CVE-2026-85050, CVE-2026-85053, CVE-2026-85042, CVE-2026-85049, CVE-2026-85051, CVE-2026-85047, CVE-2026-85044, Summary: The Stable channel has been updated to 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available…
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...]
Want to know the latest from Google Cloud? Find it here in one handy location. Check back regularly for our newest updates, announcements, resources, events, learning opportunities, and more. Tip: Not sure where to find what you’re looking for on the Google Cloud blog? Start here: Google Cloud blog 101: Full list of topics, links, and resources. aside_block <ListValue: []> Aug 31 - Sept 4 Automate VM guest software lifecycle with VM Extension Manager, now GAGoogle Cloud VM Extension Manager is…
CSIRT.CZ spustil projekt Strážci internetu. Cílem Strážců je oslovit komunitu lidí, kteří chtějí být prospěšní druhým, mít dobrý pocit z toho, co dělají, a pomoci s obranou českého kyberprostoru a jeho uživatelů před útoky na bázi sociálního inženýrství. V našem blogpostu se dozvíte proč projekt vznikl, jak funguje i to, jak bude hlášení nebezpečné stránky využito.
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-20274, CVE-2026-20275, CVE-2026-20276, CVE-2026-20277, CVE-2026-20278, CVE-2026-20279, CVE-2026-20280, Summary: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered…
Google ha rilasciato un aggiornamento per il browser Chrome al fine di correggere 26 nuove vulnerabilità di sicurezza, di cui 2 con gravità “critica” e 9 con gravità “alta”.
The Huntress API has grown from six read-only endpoints into a full integration and automation platform. See what’s new, including webhooks and MCP support.
Microsoft has confirmed that mouse settings are being reverted on Windows 11 systems after installing the KB5120998 August 2026 non-security preview update. [...]
Today we’re announcing an expanded integration between GreyNoise and the CrowdStrike Falcon® platform, with new content for CrowdStrike Falcon® Next-Gen SIEM and CrowdStrike Charlotte Agentic SOAR. The expanded integration includes a purpose-built Falcon Next-Gen SIEM dashboard, correlation rules that detect allowed inbound traffic from malicious infrastructure, and SOAR playbooks that bring GreyNoise threat context into automated response workflows. Install the GreyNoise Foundry App to get…
YARA-X's 1.20.0 release brings 14 improvements and 13 bugfixes. One new CLI option is --ignore-invalid-rules that allows one to skip rules that fail to compile. There have also been new releases of YARA: YARA 4.5.6, YARA 4.5.7 and YARA 4.5.8 with 32 bugfixes in total. (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]