soc

📅 Kalender

< August 2026 >
Mo
Di
Mi
Do
Fr
Sa
So
1
2
34567
8
9
1011121314
15
16
171819
20
21
22
23
24
25
26
27
28
29
30
31
soc

CVE-2026-19478: Critical GitLab GraphQL Flaw Enables Unauthenticated Data Modification

GitLab has released an emergency security update addressing a critical vulnerability that can allow an unauthenticated remote attacker to modify or delete public projects and user data. Tracked as CVE-2026-19478, the flaw affects both GitLab Community Edition (CE) and Enterprise Edition (EE) and carries a CVSS score of 9.4. The vulnerability stems from a code […]

Mehr lesen →
soc

CVE-2026-15748: Critical Forminator WordPress Flaw Enables Unauthenticated RCE

A critical security vulnerability in the popular Forminator Forms plugin for WordPress can allow unauthenticated attackers to upload executable PHP files and potentially take complete control of vulnerable websites. Tracked as CVE-2026-15748, the arbitrary file upload flaw carries a CVSS score of 9.8 and affects Forminator versions up to and including 1.56.1. Forminator is a […]

Mehr lesen →
soc

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-64849 MLflow Server-Side Request Forgery Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates […]

Mehr lesen →
soc

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability   CVE-2026-65400 Apple macOS Improper Authentication Vulnerability These types of vulnerabilities […]

Mehr lesen →
soc

Can NVD Modernization Keep Pace With AI?

Can NVD Modernization Keep Pace With AI? AI can help security teams find vulnerabilities faster. That sounds entirely positive until we consider what happens after those vulnerabilities are found. Every new finding still

Mehr lesen →
soc

CISA Adds One Known Exploited Vulnerability to Catalog 

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates […]

Mehr lesen →
soc

Defending Against an Active Threat to Siemens S7 Series PLCs

Executive summary Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood […]

Mehr lesen →