soc

📅 Kalender

< July 2026 >
Mo
Di
Mi
Do
Fr
Sa
So
Gefiltert nach: 30. Juli 2026
soc

CVE-2026-20316: Actively Exploited Cisco FMC Flaw Exposes Sensitive Data

Cisco has released emergency hot fixes for an actively exploited vulnerability impacting Cisco Secure Firewall Management Center (FMC) Software. The issue is caused by static credentials for a low-privileged account and allows an unauthenticated remote attacker to sign in to an affected appliance and access sensitive information. Although the flaw has a CVSS score of […]

Mehr lesen →
soc

CVE-2026-66066: Critical Rails Flaw Exposes Server Files via Image Uploads

Ruby on Rails has released security updates for a critical Active Storage vulnerability that can allow an unauthenticated attacker to read arbitrary files from an application server through crafted image uploads. Tracked as CVE-2026-66066 and rated 9.5 on the CVSS scale, the flaw can expose secrets accessible to the Rails process and potentially enable remote […]

Mehr lesen →
soc

CVE-2026-47876: Critical VMware ESXi VM Escape Flaw Enables Host Code Execution

Broadcom has released emergency security updates for a critical VMware ESXi vulnerability that can allow an attacker to escape from a virtual machine and execute code on the underlying hypervisor host. Tracked as CVE-2026-47876 and rated 9.3 on the CVSS scale, the issue resides in the VMXNET3 network adapter. Successful exploitation requires the attacker to […]

Mehr lesen →
soc

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have […]

Mehr lesen →