Vulnerability News
Открыть в Telegram
Every day new posts about vulnerabilities and cybersecurity news. Get the latest news about the cyberspace! Group: @VulnerabilityNewsGroup
Больше5 221
Подписчики
+624 часа
+297 дней
+10530 день
Архив постов
5 221
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country.
The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&
https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html
5 221
CISA Adds Six Known Exploited Vulnerabilities to Catalog
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability
CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability
CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability
CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
https://www.cisa.gov/news-events/alerts/2026/08/26/cisa-adds-six-known-exploited-vulnerabilities-catalog
5 221
When AI infrastructure becomes the target: Securing gateways and control points
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity.
The post When AI infrastructure becomes the target: Securing gateways and control points appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/08/26/when-ai-infrastructure-becomes-target-securing-gateways-control-points/
5 221
CISA Warns of Exploited Gitea Vulnerability
CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1.
The post CISA Warns of Exploited Gitea Vulnerability appeared first on SecurityWeek.
https://www.securityweek.com/cisa-warns-of-exploited-gitea-vulnerability/
5 221
Sensitive Information Exposed in Nutex Health Data Breach
Nutex Health has informed the SEC that it recently detected unauthorized access and data exfiltration.
The post Sensitive Information Exposed in Nutex Health Data Breach appeared first on SecurityWeek.
https://www.securityweek.com/sensitive-information-exposed-in-nutex-health-data-breach/
5 221
Chrome 152 Patches Over 300 Vulnerabilities
Most of the flaws were discovered by Google using AI, but researchers are still discovering high-value Chrome vulnerabilities.
The post Chrome 152 Patches Over 300 Vulnerabilities appeared first on SecurityWeek.
https://www.securityweek.com/chrome-152-patches-over-300-vulnerabilities/
5 221
The MFA Identity Trap: When Authentication Creates a False Sense of Security
Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop.
The post The MFA Identity Trap: When Authentication Creates a False Sense of Security appeared first on SecurityWeek.
https://www.securityweek.com/the-mfa-identity-trap-when-authentication-creates-a-false-sense-of-security/
5 221
CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks
The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.
The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on SecurityWeek.
https://www.securityweek.com/cisa-over-100-internet-exposed-water-systems-targeted-in-july-cyberattacks/
5 221
Adobe and Nvidia Patch Dozens of Vulnerabilities
Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products.
The post Adobe and Nvidia Patch Dozens of Vulnerabilities appeared first on SecurityWeek.
https://www.securityweek.com/adobe-and-nvidia-patch-dozens-of-vulnerabilities/
5 221
AI Speeds Up Malware Development, Not Its Success Rate: Analysis
Palo Alto Networks Unit 42 analyzed 405 AI-linked malware samples and found only 12 reached production endpoints.
The post AI Speeds Up Malware Development, Not Its Success Rate: Analysis appeared first on SecurityWeek.
https://www.securityweek.com/ai-speeds-up-malware-development-not-its-success-rate-analysis/
5 221
Hackers now exploit critical Gitea flaw in code injection attacks
Attackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]
https://www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-gitea-flaw-in-code-injection-attacks/
5 221
Microsoft tests new privacy controls for Windows 11 desktop apps
Microsoft has begun testing new privacy controls that will let Windows 11 users choose which desktop applications can access their camera, microphone, and precise location. [...]
https://www.bleepingcomputer.com/news/microsoft/microsoft-tests-new-privacy-controls-for-windows-11-desktop-apps/
5 221
Ubiquiti patches three max severity security vulnerabilities
Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges. [...]
https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-security-vulnerabilities/
5 221
Snowflake ends service-account passwords. Now comes the hard part
Snowflake is ending password authentication for legacy service accounts, forcing organizations to migrate them to passwordless methods. Token Security explains why the harder challenge is identifying what uses each account, who owns it, and how much access it still needs. [...]
https://www.bleepingcomputer.com/news/security/snowflake-ends-service-account-passwords-now-comes-the-hard-part/
5 221
FBI disrupts proxy network enabling Chinese espionage operations
The FBI has disrupted infrastructure associated with a technical "quartermaster" that provided reconnaissance, proxy management, and operational routing capabilities for Chinese cyber espionage activities. [...]
https://www.bleepingcomputer.com/news/security/fbi-disrupts-proxy-network-enabling-chinese-espionage-operations/
5 221
Hackers target Microsoft SharePoint RCE chain with PoC exploit
Attackers are now targeting a chain of two Microsoft SharePoint vulnerabilities that can allow them to execute arbitrary code on unpatched servers, according to threat intelligence company Defused. [...]
https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-chain-with-poc-exploit/
5 221
Boston Scientific says cyberattack disrupted operations globally
Medical technology company Boston Scientific has been targeted in a cyberattack that disrupted some of its IT systems, causing operational disruptions globally. [...]
https://www.bleepingcomputer.com/news/security/boston-scientific-says-cyberattack-disrupted-operations-globally/
5 221
Meta agrees to $18 billion settlement over teen social media harms
Meta has reached a proposed settlement worth up to approximately $18 billion with a bipartisan coalition of 52 attorneys generals over allegations that Facebook and Instagram were deliberately designed to encourage compulsive use by children and teenagers. [...]
https://www.bleepingcomputer.com/news/technology/meta-agrees-to-18-billion-settlement-over-teen-social-media-harms/
5 221
New GPUThor attack defeats NVIDIA ECC protection for root access
A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. [...]
https://www.bleepingcomputer.com/news/security/new-gputhor-attack-defeats-nvidia-ecc-protection-for-root-access/
5 221
Critical Avada WordPress theme flaw enables zero-click RCE
A critical vulnerability chain in the popular Avada theme for WordPress can be exploited by an unauthenticated attacker to execute arbitrary PHP code on the server. [...]
https://www.bleepingcomputer.com/news/security/critical-avada-wordpress-theme-flaw-enables-zero-click-rce/
