soc

📅 Kalender

< August 2026 >
Mo
Di
Mi
Do
Fr
Sa
So
1
2
34567
8
9
101112
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
soc

Dark Web Profile: Mustang Panda

Dark Web Profile: Mustang Panda Mustang Panda is one of the most persistent China-nexus cyber espionage groups operating today. Active since at least 2012 , the group has targeted government agencies, military bodies, di

Mehr lesen →
soc

CVE-2026-48449: Adobe Campaign Classic RCE

CVE-2026-48449: Adobe Campaign Classic RCE Adobe Campaign Classic is affected by CVE-2026-48449, a critical incorrect authorization vulnerability allowing Remote Code Execution (RCE) . With a maximum severity score, this

Mehr lesen →
soc

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational […]

Mehr lesen →
soc

CVE-2026-20316: Actively Exploited Cisco FMC Flaw Exposes Sensitive Data

Cisco has released emergency hot fixes for an actively exploited vulnerability impacting Cisco Secure Firewall Management Center (FMC) Software. The issue is caused by static credentials for a low-privileged account and allows an unauthenticated remote attacker to sign in to an affected appliance and access sensitive information. Although the flaw has a CVSS score of […]

Mehr lesen →
soc

CVE-2026-66066: Critical Rails Flaw Exposes Server Files via Image Uploads

Ruby on Rails has released security updates for a critical Active Storage vulnerability that can allow an unauthenticated attacker to read arbitrary files from an application server through crafted image uploads. Tracked as CVE-2026-66066 and rated 9.5 on the CVSS scale, the flaw can expose secrets accessible to the Rails process and potentially enable remote […]

Mehr lesen →
soc

CVE-2026-47876: Critical VMware ESXi VM Escape Flaw Enables Host Code Execution

Broadcom has released emergency security updates for a critical VMware ESXi vulnerability that can allow an attacker to escape from a virtual machine and execute code on the underlying hypervisor host. Tracked as CVE-2026-47876 and rated 9.3 on the CVSS scale, the issue resides in the VMXNET3 network adapter. Successful exploitation requires the attacker to […]

Mehr lesen →
soc

CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs

CISA is currently observing a significant increase in cyber threat actors targeting programmable logic controllers (PLCs) in the Water and Wastewater Systems (WWS) Sector. CISA urges critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible. Threat actors targeting exposed PLCs have […]

Mehr lesen →
soc

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive […]

Mehr lesen →
soc

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose […]

Mehr lesen →