ru
Feedback
Vulnerability News

Vulnerability News

Открыть в Telegram

Every day new posts about vulnerabilities and cybersecurity news. Get the latest news about the cyberspace! Group: @VulnerabilityNewsGroup

Больше
5 258
Подписчики
+924 часа
+357 дней
+10330 дней

Загрузка данных...

Привлечение подписчиков
сентябрь '26
сентябрь '26
+22
в 0 каналах
август '26
+157
в 0 каналах
Get PRO
июль '26
+185
в 0 каналах
Get PRO
июнь '26
+156
в 0 каналах
Get PRO
май '26
+204
в 0 каналах
Get PRO
апрель '26
+187
в 0 каналах
Get PRO
март '26
+254
в 0 каналах
Get PRO
февраль '26
+116
в 0 каналах
Get PRO
январь '26
+166
в 0 каналах
Get PRO
декабрь '25
+134
в 0 каналах
Get PRO
ноябрь '25
+139
в 0 каналах
Get PRO
октябрь '25
+8
в 0 каналах
Get PRO
сентябрь '25
+12
в 0 каналах
Get PRO
август '25
+13
в 0 каналах
Get PRO
июль '25
+11
в 0 каналах
Get PRO
июнь '25
+12
в 0 каналах
Get PRO
май '25
+18
в 1 каналах
Get PRO
апрель '25
+14
в 0 каналах
Get PRO
март '25
+21
в 0 каналах
Get PRO
февраль '25
+17
в 0 каналах
Get PRO
январь '25
+15
в 1 каналах
Get PRO
декабрь '24
+262
в 1 каналах
Get PRO
ноябрь '24
+206
в 1 каналах
Get PRO
октябрь '24
+166
в 0 каналах
Get PRO
сентябрь '24
+146
в 0 каналах
Get PRO
август '24
+137
в 0 каналах
Get PRO
июль '24
+96
в 1 каналах
Get PRO
июнь '24
+91
в 0 каналах
Get PRO
май '24
+95
в 0 каналах
Get PRO
апрель '24
+104
в 0 каналах
Get PRO
март '24
+149
в 0 каналах
Get PRO
февраль '24
+279
в 0 каналах
Get PRO
январь '24
+395
в 0 каналах
Get PRO
декабрь '23
+327
в 0 каналах
Get PRO
ноябрь '23
+38
в 0 каналах
Get PRO
октябрь '23
+32
в 0 каналах
Get PRO
сентябрь '23
+47
в 0 каналах
Get PRO
август '23
+53
в 0 каналах
Get PRO
июль '23
+51
в 0 каналах
Get PRO
июнь '23
+42
в 0 каналах
Get PRO
май '23
+43
в 0 каналах
Get PRO
апрель '23
+67
в 0 каналах
Get PRO
март '23
+65
в 0 каналах
Get PRO
февраль '23
+45
в 0 каналах
Get PRO
январь '23
+67
в 0 каналах
Get PRO
декабрь '22
+62
в 0 каналах
Get PRO
ноябрь '22
+71
в 0 каналах
Get PRO
октябрь '22
+70
в 0 каналах
Get PRO
сентябрь '22
+55
в 0 каналах
Get PRO
август '22
+44
в 0 каналах
Get PRO
июль '22
+54
в 0 каналах
Get PRO
июнь '22
+78
в 0 каналах
Get PRO
май '22
+46
в 0 каналах
Get PRO
апрель '22
+77
в 0 каналах
Get PRO
март '22
+105
в 0 каналах
Get PRO
февраль '22
+48
в 0 каналах
Get PRO
январь '22
+61
в 0 каналах
Get PRO
декабрь '21
+99
в 0 каналах
Get PRO
ноябрь '21
+68
в 0 каналах
Get PRO
октябрь '21
+170
в 0 каналах
Get PRO
сентябрь '21
+72
в 0 каналах
Get PRO
август '21
+104
в 0 каналах
Get PRO
июль '21
+72
в 0 каналах
Get PRO
июнь '21
+292
в 0 каналах
Get PRO
май '21
+1 344
в 0 каналах
Дата
Привлечение подписчиков
Упоминания
Каналы
03 сентября+4
02 сентября+11
01 сентября+7
Посты канала
Pattons Shipping Records Published Free With Goods Values and Delivery Details A forum actor posting as Keishell, crediting two others, has published what they describe as the myTnT shipment database belonging to pattons.com.au, an Australian business. https://darkwebinformer.com/pattons-shipping-records-published-free-with-goods-values-and-delivery-details/

2
FNIM Sites Defaced and Databases Published After a Single Server Compromise Three forum actors, led by one posting as yiranet, claim to have compromised the infrastructure of the Fédération Nationale Indépendante des Mutuelles, the French federation representing small and medium sized mutual insurers. https://darkwebinformer.com/fnim-sites-defaced-and-databases-published-after-a-single-server-compromise/
70
3
French Ministry Staff Directory and Inspector Records Published Free A forum actor posting as mondial, crediting one collaborator, has published two datasets attributed to developpement-durable.gouv.fr, the domain of France's Ministry for Ecological Transition. https://darkwebinformer.com/french-ministry-staff-directory-and-inspector-records-published-free/
46
4
Israel Science and Technology Directory Files Published, Though Most of It Was Already Public A forum actor posting as weykofa has published 16.2 MB across 450 files attributed to science.co.il, the Israel Science and Technology Directory https://darkwebinformer.com/israel-science-and-technology-directory-files-published-though-most-of-it-was-already-public/
37
5
Take-Two Narrows GTA 6 Leak Investigation as Hunt for Leakers Intensifies Take-Two Interactive appears to be narrowing its investigation into the people responsible for leaking unreleased Grand Theft Auto VI gameplay, with new court filings showing the publisher is seeking increasingly targeted information from Discord. https://darkwebinformer.com/take-two-narrows-gta-6-leak-investigation-as-hunt-for-leakers-intensifies/
24
6
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores. https://www.darkreading.com/cyberattacks-data-breaches/old-unpatched-flaws-attackers-philippines-nuclear-agency
22
7
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure. https://www.darkreading.com/cyberattacks-data-breaches/threat-gang-springs-vishing-attacks-microsoft-teams-users
21
8
AI Gives Cybercriminals a Dangerous Time Advantage Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers. https://www.darkreading.com/threat-intelligence/ai-gives-cybercriminals-dangerous-time-advantage
21
9
CISA Adds Seven Known Exploited Vulnerabilities to Catalog CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability  CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability  CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability  CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability  CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability  CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability  CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability  These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.  Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.  While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.  Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog
21
10
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek. https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/
23
11
23-Year-Old Sality P2P Botnet Disrupted The shutdown operation involved peer list manipulation and Sality payload URL takedown. The post 23-Year-Old Sality P2P Botnet Disrupted appeared first on SecurityWeek. https://www.securityweek.com/23-year-old-sality-p2p-botnet-disrupted/
26
12
Chrome and Firefox Updates Patch Dozens of Vulnerabilities The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs. The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek. https://www.securityweek.com/chrome-and-firefox-updates-patch-dozens-of-vulnerabilities/
18
13
OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems. The post OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days appeared first on SecurityWeek. https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/
18
14
Malicious Virtualizor Update Served via BGP Hijacking Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates. The post Malicious Virtualizor Update Served via BGP Hijacking appeared first on SecurityWeek. https://www.securityweek.com/malicious-virtualizor-update-served-via-bgp-hijacking/
17
15
Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards Anthropic introduced Enterprise Frontier Safeguards (EFS), a system that combines zero data retention with automated monitoring for misuse. The post Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards appeared first on SecurityWeek. https://www.securityweek.com/anthropic-details-response-to-security-incidents-unveils-enterprise-safeguards/
22
16
Exploit Published for Fresh Cleo Harmony Vulnerability The security defect allows remote attackers to bypass authentication through argument bearer manipulation. The post Exploit Published for Fresh Cleo Harmony Vulnerability appeared first on SecurityWeek. https://www.securityweek.com/exploit-published-for-fresh-cleo-harmony-vulnerability/
26
17
Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products. The post Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products appeared first on SecurityWeek. https://www.securityweek.com/rockwell-automation-patches-over-a-dozen-vulnerabilities-across-products/
26
18
UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify. The post UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure appeared first on SecurityWeek. https://www.securityweek.com/uk-moves-to-block-high-risk-tech-suppliers-from-critical-infrastructure/
25
19
OpenLeash Adds a Human Check to Risky AI Agent Actions The security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain. The post OpenLeash Adds a Human Check to Risky AI Agent Actions appeared first on SecurityWeek. https://www.securityweek.com/openleash-adds-a-human-check-to-risky-ai-agent-actions/
23
20
SonicWall warns of actively exploited SMA1000 zero-day flaws SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...] https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws/
24