Vulnerability News
رفتن به کانال در Telegram
Every day new posts about vulnerabilities and cybersecurity news. Get the latest news about the cyberspace! Group: @VulnerabilityNewsGroup
نمایش بیشتر5 114
مشترکین
اطلاعاتی وجود ندارد24 ساعت
+247 روز
+12830 روز
در حال بارگیری داده...
کانالهای مشابه
ابر برچسبها
اشارات ورودی و خروجی
---
---
---
---
---
---
جذب مشترکین
ژوئیه '26
ژوئیه '26
+160
در 0 کانالها
ژوئن '26
+156
در 0 کانالها
Get PRO
مه '26
+204
در 0 کانالها
Get PRO
آوریل '26
+187
در 0 کانالها
Get PRO
مارس '26
+254
در 0 کانالها
Get PRO
فوریه '26
+116
در 0 کانالها
Get PRO
ژانویه '26
+166
در 0 کانالها
Get PRO
دسامبر '25
+134
در 0 کانالها
Get PRO
نوامبر '25
+139
در 0 کانالها
Get PRO
اکتبر '25
+8
در 0 کانالها
Get PRO
سپتامبر '25
+12
در 0 کانالها
Get PRO
اوت '25
+13
در 0 کانالها
Get PRO
ژوئیه '25
+11
در 0 کانالها
Get PRO
ژوئن '25
+12
در 0 کانالها
Get PRO
مه '25
+18
در 1 کانالها
Get PRO
آوریل '25
+14
در 0 کانالها
Get PRO
مارس '25
+21
در 0 کانالها
Get PRO
فوریه '25
+17
در 0 کانالها
Get PRO
ژانویه '25
+15
در 1 کانالها
Get PRO
دسامبر '24
+262
در 1 کانالها
Get PRO
نوامبر '24
+206
در 1 کانالها
Get PRO
اکتبر '24
+166
در 0 کانالها
Get PRO
سپتامبر '24
+146
در 0 کانالها
Get PRO
اوت '24
+137
در 0 کانالها
Get PRO
ژوئیه '24
+96
در 1 کانالها
Get PRO
ژوئن '24
+91
در 0 کانالها
Get PRO
مه '24
+95
در 0 کانالها
Get PRO
آوریل '24
+104
در 0 کانالها
Get PRO
مارس '24
+149
در 0 کانالها
Get PRO
فوریه '24
+279
در 0 کانالها
Get PRO
ژانویه '24
+395
در 0 کانالها
Get PRO
دسامبر '23
+327
در 0 کانالها
Get PRO
نوامبر '23
+38
در 0 کانالها
Get PRO
اکتبر '23
+32
در 0 کانالها
Get PRO
سپتامبر '23
+47
در 0 کانالها
Get PRO
اوت '23
+53
در 0 کانالها
Get PRO
ژوئیه '23
+51
در 0 کانالها
Get PRO
ژوئن '23
+42
در 0 کانالها
Get PRO
مه '23
+43
در 0 کانالها
Get PRO
آوریل '23
+67
در 0 کانالها
Get PRO
مارس '23
+65
در 0 کانالها
Get PRO
فوریه '23
+45
در 0 کانالها
Get PRO
ژانویه '23
+67
در 0 کانالها
Get PRO
دسامبر '22
+62
در 0 کانالها
Get PRO
نوامبر '22
+71
در 0 کانالها
Get PRO
اکتبر '22
+70
در 0 کانالها
Get PRO
سپتامبر '22
+55
در 0 کانالها
Get PRO
اوت '22
+44
در 0 کانالها
Get PRO
ژوئیه '22
+54
در 0 کانالها
Get PRO
ژوئن '22
+78
در 0 کانالها
Get PRO
مه '22
+46
در 0 کانالها
Get PRO
آوریل '22
+77
در 0 کانالها
Get PRO
مارس '22
+105
در 0 کانالها
Get PRO
فوریه '22
+48
در 0 کانالها
Get PRO
ژانویه '22
+61
در 0 کانالها
Get PRO
دسامبر '21
+99
در 0 کانالها
Get PRO
نوامبر '21
+68
در 0 کانالها
Get PRO
اکتبر '21
+170
در 0 کانالها
Get PRO
سپتامبر '21
+72
در 0 کانالها
Get PRO
اوت '21
+104
در 0 کانالها
Get PRO
ژوئیه '21
+72
در 0 کانالها
Get PRO
ژوئن '21
+292
در 0 کانالها
Get PRO
مه '21
+1 344
در 0 کانالها
| تاریخ | رشد مشترکین | اشارات | کانالها | |
| 27 ژوئیه | +2 | |||
| 26 ژوئیه | +6 | |||
| 25 ژوئیه | +6 | |||
| 24 ژوئیه | +2 | |||
| 23 ژوئیه | +10 | |||
| 22 ژوئیه | +5 | |||
| 21 ژوئیه | +6 | |||
| 20 ژوئیه | +8 | |||
| 19 ژوئیه | +4 | |||
| 18 ژوئیه | +7 | |||
| 17 ژوئیه | +3 | |||
| 16 ژوئیه | +10 | |||
| 15 ژوئیه | +9 | |||
| 14 ژوئیه | +6 | |||
| 13 ژوئیه | +5 | |||
| 12 ژوئیه | +1 | |||
| 11 ژوئیه | +6 | |||
| 10 ژوئیه | +6 | |||
| 09 ژوئیه | +5 | |||
| 08 ژوئیه | +7 | |||
| 07 ژوئیه | +9 | |||
| 06 ژوئیه | +4 | |||
| 05 ژوئیه | +7 | |||
| 04 ژوئیه | +9 | |||
| 03 ژوئیه | +10 | |||
| 02 ژوئیه | +3 | |||
| 01 ژوئیه | +4 |
پستهای کانال
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
https://www.cisa.gov/news-events/alerts/2026/07/27/cisa-adds-two-known-exploited-vulnerabilities-catalog
| 2 | Enhancing AI security through global AI red teaming
Microsoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts, EXTRA helps identify emerging AI risks, improve security testing, and strengthen the resilience of frontier AI systems.
The post Enhancing AI security through global AI red teaming appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/07/27/enhancing-ai-security-through-global-ai-red-teaming/ | 25 |
| 3 | Rethinking security for the age of AI
The physics of cybersecurity are changing. Introducing security's new cyber stack: Project Perception.
The post Rethinking security for the age of AI appeared first on Microsoft Security Blog.
https://blogs.microsoft.com/blog/2026/07/27/rethinking-security-for-the-age-of-ai/ | 17 |
| 4 | DentaQuest Data Breach Potentially Impacts Over 23 Million People
In May 2026, hackers stole personal and dental health information from DentaQuest’s computer network.
The post DentaQuest Data Breach Potentially Impacts Over 23 Million People appeared first on SecurityWeek.
https://www.securityweek.com/dentaquest-data-breach-potentially-impacts-over-23-million-people/ | 9 |
| 5 | Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits
Binary-based vulnerability scanning, penetration testing, and exploit generation are blocked in Opus 5.
The post Anthropic’s Opus 5 Nears Mythos 5 on Finding Bugs, but Falls Short on Exploits appeared first on SecurityWeek.
https://www.securityweek.com/anthropics-opus-5-nears-mythos-5-on-finding-bugs-but-falls-short-on-exploits/ | 11 |
| 6 | Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
A threat actor has been using the compromised appliances to target the Microsoft 365 accounts of traveling corporate employees.
The post Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials appeared first on SecurityWeek.
https://www.securityweek.com/hacked-public-wi-fi-gateways-used-to-harvest-corporate-credentials/ | 7 |
| 7 | What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out
The new Mobile Security Exposure Center creates SBOMs for enterprise mobile apps to uncover vulnerable components, dependencies and hidden risks.
The post What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out appeared first on SecurityWeek.
https://www.securityweek.com/whats-hiding-in-your-mobile-apps-lookout-msec-aims-to-find-out/ | 9 |
| 8 | Beelzebub Raises $3.4 Million for Hacker-Trapping Platform
The company plans to expand its research team, open new offices in Rome and San Francisco, and acquire new clients.
The post Beelzebub Raises $3.4 Million for Hacker-Trapping Platform appeared first on SecurityWeek.
https://www.securityweek.com/beelzebub-raises-3-4-million-for-hacker-trapping-platform/ | 11 |
| 9 | Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack
The Anubis cybercrime group has taken credit for the attack and is threatening to leak data.
The post Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack appeared first on SecurityWeek.
https://www.securityweek.com/coca-cola-confirms-data-breach-after-fairlife-ransomware-attack/ | 10 |
| 10 | Nvidia and Tech Giants Launch AI Security Alliance
The Nvidia-led coalition aims to give defenders more open tools for testing, auditing and protecting AI models and agents.
The post Nvidia and Tech Giants Launch AI Security Alliance appeared first on SecurityWeek.
https://www.securityweek.com/nvidia-and-tech-giants-launch-ai-security-alliance/ | 10 |
| 11 | MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
The malware-as-a-service operation launches legitimate browsers on an invisible desktop, giving attackers persistent and covert remote access to compromised Windows systems.
The post MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection appeared first on SecurityWeek.
https://www.securityweek.com/medusahvnc-malware-uses-hidden-windows-desktops-to-evade-detection/ | 7 |
| 12 | PTC Windchill Vulnerability Exploited in Ransomware Campaign
The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.
The post PTC Windchill Vulnerability Exploited in Ransomware Campaign appeared first on SecurityWeek.
https://www.securityweek.com/ptc-windchill-vulnerability-exploited-in-ransomware-campaign/ | 8 |
| 13 | New GitHub, PyPI Policies Boost Supply Chain Security
Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days.
The post New GitHub, PyPI Policies Boost Supply Chain Security appeared first on SecurityWeek.
https://www.securityweek.com/new-github-pypi-policies-boost-supply-chain-security/ | 8 |
| 14 | Shadow AI agents are multiplying. Here's how to find and secure them.
Shadow AI agents are rapidly spreading across enterprise platforms, often without IT or security visibility. Nudge Security explains how organizations can discover, assess, and govern AI agents before unmanaged permissions and autonomous actions create security risks. [...]
https://www.bleepingcomputer.com/news/security/shadow-ai-agents-are-multiplying-heres-how-to-find-and-secure-them/ | 8 |
| 15 | Ernst & Young data breach claimed by ShinyHunters extortion gang
The ShinyHunters extortion gang has claimed responsibility for a recently disclosed Ernst & Young data breach, saying it obtained credentials for some of the company's systems via a supply-chain attack. [...]
https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by-shinyhunters-extortion-gang/ | 9 |
| 16 | Coca-Cola confirms data theft in Fairlife ransomware attack
The Coca-Cola Company has confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. [...]
https://www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-ransomware-attack/ | 10 |
| 17 | Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin
Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. [...]
https://www.bleepingcomputer.com/news/apple/apple-sued-over-fake-app-store-crypto-wallet-app-stealing-18m-in-bitcoin/ | 11 |
| 18 | New Certighost PoC exploit lets attackers hijack Windows domains
A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. [...]
https://www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-lets-attackers-hijack-windows-domains/ | 12 |
| 19 | New Dysphoria DDoS botnet spreads to 200k devices worldwide
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...]
https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/ | 19 |
| 20 | Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Arista has patched a maximum-severity command injection vulnerability in on-premises VeloCloud Orchestrator deployments that is being actively exploited in attacks. [...]
https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrator-zero-day-exploited-in-attacks/ | 27 |
