One event, not three confirmations.

Dependent coverage shares its primary source’s evidence group. VTP retains the articles without inflating independence.

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

Separate evidence group
Original

[Virtual Event] Building a Secure AI Strategy for the Enterprise

Separate evidence group
Original

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.

CVE-2023-45208
Separate evidence group
Original

Kiteworks urges 6-hour server shutdown over potential zero-day attacks

Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. [...]

Separate evidence group
Original

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]

CVE-2026-42608
Separate evidence group
Original

Kiteworks urges customers to stop using platform after warning from federal intelligence agencies

Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.”

Separate evidence group
Original

Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings

Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with data security practices.

Separate evidence group
Original

AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment

When autonomous AI agents "escape the sandbox," the real story isn't rogue machines — it's the same access-control failures we've seen for decades.

Separate evidence group
Original

Elementor WordPress flaw lets attackers create admin accounts

A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]

Separate evidence group
Original

What We Missed: Google Gemini Joins the AI Escape Party

In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from Google Gemini models breaking containment to ShinyHunters ratting on TeamPCP hackers.

Separate evidence group
Original

CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. [...]

CVE-2026-5430CVE-2026-65660CVE-2026-67279CVE-2026-71362
Separate evidence group
Original

Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions

Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it's offering up to $250 in free usage credits, so more users can give it a try. [...]

Separate evidence group
Original

Crypto CEO accuses North Korea of stealing $387 million from Bitget platform

The CEO said the company has a User Protection Fund that has over $464 million and those funds will be used to cover the losses.

Separate evidence group
Original

In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul. The post In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure appeared first on SecurityWeek .

CVE-2026-42542
Separate evidence group
Original

Cyberattack hits Welsh police force, may have affected staff data

Dyfed-Powys Police in Wales said a cyberattack affecting the force disrupted some non-emergency systems and may have compromised staff information.

Separate evidence group
Original

OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex

OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out. [...]

Separate evidence group
Original

With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance

AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. [...]

Separate evidence group
Original

Stopping IT Worker Scams Requires Revamped HR Process

Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even more.

Separate evidence group
Original

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below - actions-cool/issues-helper actions-cool/maintain-one-comment Visiting either of the repositories now shows the message: "Access to this

Separate evidence group
Original

Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?

CVE-2026-18729CVE-2026-20929CVE-2026-85706
Separate evidence group
Original

North Korea Suspected in $351 Million Bitget Crypto Heist

Bitget’s security systems caught the unauthorized transfers on September 24, and some wallet addresses linked to the attacker have been frozen. The post North Korea Suspected in $351 Million Bitget Crypto Heist appeared first on SecurityWeek .

Separate evidence group
Original

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

Separate evidence group
Original

Microsoft plans to deprecate Windows Deployment Services

Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. [...]

Separate evidence group
Original

CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks

Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. The post CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks appeared first on SecurityWeek .

Separate evidence group
Original

Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court

Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services. The post Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court appeared first on SecurityWeek .

Separate evidence group
Original

Doubts grow over claims OpenAI agent hacked Australian Medicare portal

Researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visitors to an unauthenticated endpoint.

Separate evidence group
Original

Rydox marketplace admin pleads guilty, faces 22 years in prison

A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. [...]

Separate evidence group
Original

The SOC Doesn't Need to Start Over with Every Alert

Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry. The routine version looks like this. An attacker lands on a low-privilege cloud account, and the first try at privilege escalation goes nowhere. That dead end used to cost hours of documentation reading,

Separate evidence group
Original

Windows, Linux, Android File Notification Systems Leak User Activity

Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events. The post Windows, Linux, Android File Notification Systems Leak User Activity appeared first on SecurityWeek .

CVE-2025-68788
Separate evidence group
Original

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.  "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain

Separate evidence group
Original

Rapid7 Metasploit Framework corpus synchronized

The pinned corpus revision was recorded with provenance. No new or materially changed exploit-intent artifact affected a known CVE, so CVE threat scores were not changed.

Separate evidence group
Original

ProjectDiscovery nuclei-templates corpus synchronized

The pinned corpus revision was recorded with provenance. No new or materially changed exploit-intent artifact affected a known CVE, so CVE threat scores were not changed.

Separate evidence group
Original

Microsoft: Recent Windows updates cause desktop loading issues

Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. [...]

Separate evidence group
Original

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash

CVE-2025-49113CVE-2025-68461CVE-2026-48842
Separate evidence group
Original

‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks. The post ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration appeared first on SecurityWeek .

Separate evidence group
Original

Hackers steal $351.6 million in Bitget crypto exchange hack

​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. [...]

Separate evidence group
Original

Russia's Hybrid Cyber-Physical War in Europe Heats Up

A storm is raging in the form of cyber sabotage, disinformation, and drone attacks on European nations, particularly those that provide material support to Ukraine.

Separate evidence group
Original

Roundcube Webmail Vulnerability in Attackers’ Crosshairs

Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication. The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .

CVE-2024-37383CVE-2025-49113CVE-2025-68461CVE-2026-48842
Separate evidence group
Original

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got, according to Cloudflare. The company

Separate evidence group
Original

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in  WSO2 API Control Plane,

CVE-2026-5430CVE-2026-71362
Separate evidence group
Original

ProjectDiscovery nuclei-templates corpus synchronized

The pinned corpus revision was recorded with provenance. No new or materially changed exploit-intent artifact affected a known CVE, so CVE threat scores were not changed.

Separate evidence group
Original

Exploit tooling coverage changed for 23 CVEs

Greenbone Community Feed recorded exploit-tooling coverage changes for 23 CVEs in this pinned revision. 23 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2015-8279CVE-2015-8280CVE-2015-8281CVE-2017-0143CVE-2017-0144CVE-2017-0145CVE-2017-0146CVE-2017-0147CVE-2017-0148CVE-2017-14083CVE-2017-14084CVE-2017-14085CVE-2017-14086CVE-2017-14087CVE-2017-14088CVE-2017-14089CVE-2017-14396CVE-2017-16524CVE-2017-5227CVE-2017-6359CVE-2017-6360CVE-2017-6361CVE-2017-9328
Separate evidence group

ProjectDiscovery nuclei-templates corpus synchronized

The pinned corpus revision was recorded with provenance. No new or materially changed exploit-intent artifact affected a known CVE, so CVE threat scores were not changed.

Separate evidence group
Original

ProjectDiscovery nuclei-templates corpus synchronized

The pinned corpus revision was recorded with provenance. No new or materially changed exploit-intent artifact affected a known CVE, so CVE threat scores were not changed.

Separate evidence group
Original

Multiples vulnérabilités dans le noyau Linux d'Ubuntu (25 septembre 2026)

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

CVE-2022-49803CVE-2022-49961CVE-2022-50073CVE-2022-50116CVE-2022-50552CVE-2023-45896CVE-2023-52682CVE-2023-52737CVE-2023-53545CVE-2023-53596CVE-2023-53629CVE-2024-27389CVE-2024-35865CVE-2024-36898CVE-2024-36922CVE-2024-41079CVE-2024-46715CVE-2024-46770CVE-2024-47809CVE-2024-50012CVE-2024-53221CVE-2024-56557CVE-2024-56584CVE-2024-56657CVE-2024-56719CVE-2024-56727CVE-2025-10263CVE-2025-21712CVE-2025-21739CVE-2025-21863CVE-2025-22107CVE-2025-23141CVE-2025-27558CVE-2025-37786CVE-2025-38006CVE-2025-38105CVE-2025-38192CVE-2025-38250CVE-2025-38562CVE-2025-38626CVE-2025-38659CVE-2025-38710CVE-2025-39748CVE-2025-39764CVE-2025-40005CVE-2025-40016CVE-2025-40103CVE-2025-40323CVE-2025-54505CVE-2025-54518CVE-2025-68206CVE-2025-68239CVE-2025-68256CVE-2025-68307CVE-2025-68358CVE-2025-71150CVE-2025-71161CVE-2025-71221CVE-2025-71232CVE-2025-71233CVE-2025-71235CVE-2025-71236CVE-2025-71237CVE-2025-71238CVE-2025-71239CVE-2025-71265CVE-2025-71266CVE-2025-71267CVE-2025-71274CVE-2025-71287CVE-2025-71289CVE-2025-71292CVE-2025-71304CVE-2026-23031CVE-2026-23066CVE-2026-23100CVE-2026-23113CVE-2026-23141CVE-2026-23157CVE-2026-23169CVE-2026-23204CVE-2026-23220CVE-2026-23221CVE-2026-23222CVE-2026-23227CVE-2026-23228CVE-2026-23229CVE-2026-23234CVE-2026-23235CVE-2026-23236CVE-2026-23237CVE-2026-23238CVE-2026-23241CVE-2026-23242CVE-2026-23243CVE-2026-23253CVE-2026-23266CVE-2026-23270CVE-2026-23277CVE-2026-23279CVE-2026-23281CVE-2026-23286CVE-2026-23289CVE-2026-23290CVE-2026-23291CVE-2026-23293CVE-2026-23296CVE-2026-23298CVE-2026-23300CVE-2026-23303CVE-2026-23304CVE-2026-23307CVE-2026-23312CVE-2026-23318CVE-2026-23324CVE-2026-23335CVE-2026-23336CVE-2026-23339CVE-2026-23340CVE-2026-23352CVE-2026-23356CVE-2026-23357CVE-2026-23359CVE-2026-23362CVE-2026-23365CVE-2026-23367CVE-2026-23368CVE-2026-23370CVE-2026-23372CVE-2026-23379CVE-2026-23381CVE-2026-23382CVE-2026-23388CVE-2026-23391CVE-2026-23392CVE-2026-23395CVE-2026-23396CVE-2026-23397CVE-2026-23398CVE-2026-23399CVE-2026-23401CVE-2026-23420CVE-2026-23434CVE-2026-23438CVE-2026-23439CVE-2026-23442CVE-2026-23444CVE-2026-23446CVE-2026-23452CVE-2026-23454CVE-2026-23456CVE-2026-23457CVE-2026-23458CVE-2026-23460CVE-2026-23462CVE-2026-23463CVE-2026-23469CVE-2026-23474CVE-2026-31393CVE-2026-31396CVE-2026-31399CVE-2026-31400CVE-2026-31405CVE-2026-31407CVE-2026-31408CVE-2026-31409CVE-2026-31411CVE-2026-31414CVE-2026-31415CVE-2026-31416CVE-2026-31417CVE-2026-31420CVE-2026-31421CVE-2026-31422CVE-2026-31423CVE-2026-31424CVE-2026-31425CVE-2026-31427CVE-2026-31428CVE-2026-31433CVE-2026-31446CVE-2026-31447CVE-2026-31448CVE-2026-31450CVE-2026-31452CVE-2026-31454CVE-2026-31455CVE-2026-31464CVE-2026-31466CVE-2026-31467CVE-2026-31469CVE-2026-31473CVE-2026-31476CVE-2026-31480CVE-2026-31483CVE-2026-31485CVE-2026-31486CVE-2026-31489CVE-2026-31494CVE-2026-31495CVE-2026-31497CVE-2026-31498CVE-2026-31506CVE-2026-31507CVE-2026-31508CVE-2026-31509CVE-2026-31510CVE-2026-31512CVE-2026-31515CVE-2026-31518CVE-2026-31521CVE-2026-31522CVE-2026-31523CVE-2026-31524CVE-2026-31532CVE-2026-31540CVE-2026-31545CVE-2026-31546CVE-2026-31549CVE-2026-31550CVE-2026-31551CVE-2026-31552CVE-2026-31555CVE-2026-31560CVE-2026-31565CVE-2026-31570CVE-2026-31576CVE-2026-31577CVE-2026-31578CVE-2026-31580CVE-2026-31581CVE-2026-31583CVE-2026-31585CVE-2026-31586CVE-2026-31588CVE-2026-31590CVE-2026-31594CVE-2026-31596CVE-2026-31597CVE-2026-31598CVE-2026-31599CVE-2026-31602CVE-2026-31603CVE-2026-31605CVE-2026-31615CVE-2026-31616CVE-2026-31617CVE-2026-31618CVE-2026-31619CVE-2026-31622CVE-2026-31623CVE-2026-31624CVE-2026-31625CVE-2026-31626CVE-2026-31627CVE-2026-31628CVE-2026-31629CVE-2026-31630CVE-2026-31634CVE-2026-31642CVE-2026-31651CVE-2026-31656CVE-2026-31658CVE-2026-31660CVE-2026-31661CVE-2026-31662CVE-2026-31664CVE-2026-31665CVE-2026-31667CVE-2026-31670CVE-2026-31671CVE-2026-31672CVE-2026-31673CVE-2026-31674CVE-2026-31676CVE-2026-31679CVE-2026-31680CVE-2026-31681CVE-2026-31683CVE-2026-31684CVE-2026-31686CVE-2026-31687CVE-2026-31694CVE-2026-31695CVE-2026-31696CVE-2026-31697CVE-2026-31698CVE-2026-31699CVE-2026-31701CVE-2026-31705CVE-2026-31716CVE-2026-31720CVE-2026-31721CVE-2026-31726CVE-2026-31728CVE-2026-31737CVE-2026-31738CVE-2026-31747CVE-2026-31748CVE-2026-31749CVE-2026-31751CVE-2026-31752CVE-2026-31754CVE-2026-31755CVE-2026-31756CVE-2026-31758CVE-2026-31759CVE-2026-31761CVE-2026-31762CVE-2026-31763CVE-2026-31770CVE-2026-31773CVE-2026-31778CVE-2026-31780CVE-2026-31781CVE-2026-31788CVE-2026-43014CVE-2026-43015CVE-2026-43020CVE-2026-43024CVE-2026-43026CVE-2026-43027CVE-2026-43028CVE-2026-43030CVE-2026-43032CVE-2026-43035CVE-2026-43040CVE-2026-43041CVE-2026-43043CVE-2026-43046CVE-2026-43047CVE-2026-43050CVE-2026-43051CVE-2026-43052CVE-2026-43054CVE-2026-43058CVE-2026-43060CVE-2026-43061CVE-2026-43062CVE-2026-43065CVE-2026-43066CVE-2026-43068CVE-2026-43069CVE-2026-43074CVE-2026-43075CVE-2026-43076CVE-2026-43079CVE-2026-43080CVE-2026-43085CVE-2026-43089CVE-2026-43093CVE-2026-43098CVE-2026-43099CVE-2026-43103CVE-2026-43104CVE-2026-43105CVE-2026-43110CVE-2026-43111CVE-2026-43112CVE-2026-43113CVE-2026-43123CVE-2026-43124CVE-2026-43130CVE-2026-43132CVE-2026-43133CVE-2026-43134CVE-2026-43135CVE-2026-43136CVE-2026-43139CVE-2026-43140CVE-2026-43141CVE-2026-43145CVE-2026-43147CVE-2026-43148CVE-2026-43149CVE-2026-43152CVE-2026-43156CVE-2026-43158CVE-2026-43159CVE-2026-43163CVE-2026-43168CVE-2026-43171CVE-2026-43180CVE-2026-43182CVE-2026-43183CVE-2026-43184CVE-2026-43187CVE-2026-43190CVE-2026-43194CVE-2026-43196CVE-2026-43198CVE-2026-43200CVE-2026-43202CVE-2026-43203CVE-2026-43205CVE-2026-43206CVE-2026-43207CVE-2026-43209CVE-2026-43211CVE-2026-43218CVE-2026-43223CVE-2026-43225CVE-2026-43226CVE-2026-43227CVE-2026-43230CVE-2026-43231CVE-2026-43232CVE-2026-43233CVE-2026-43236CVE-2026-43241CVE-2026-43242CVE-2026-43246CVE-2026-43251CVE-2026-43255CVE-2026-43257CVE-2026-43261CVE-2026-43262CVE-2026-43264CVE-2026-43266CVE-2026-43268CVE-2026-43269CVE-2026-43270CVE-2026-43273CVE-2026-43275CVE-2026-43277CVE-2026-43279CVE-2026-43281CVE-2026-43283CVE-2026-43287CVE-2026-43289CVE-2026-43291CVE-2026-43295CVE-2026-43296CVE-2026-43302CVE-2026-43312CVE-2026-43313CVE-2026-43314CVE-2026-43315CVE-2026-43316CVE-2026-43324CVE-2026-43327CVE-2026-43328CVE-2026-43329CVE-2026-43333CVE-2026-43334CVE-2026-43336CVE-2026-43339CVE-2026-43340CVE-2026-43342CVE-2026-43343CVE-2026-43357CVE-2026-43363CVE-2026-43365CVE-2026-43370CVE-2026-43373CVE-2026-43378CVE-2026-43380CVE-2026-43381CVE-2026-43382CVE-2026-43386CVE-2026-43387CVE-2026-43405CVE-2026-43411CVE-2026-43420CVE-2026-43425CVE-2026-43426CVE-2026-43427CVE-2026-43428CVE-2026-43429CVE-2026-43430CVE-2026-43432CVE-2026-43439CVE-2026-43445CVE-2026-43449CVE-2026-43450CVE-2026-43451CVE-2026-43452CVE-2026-43453CVE-2026-43458CVE-2026-43459CVE-2026-43466CVE-2026-43469CVE-2026-43472CVE-2026-43473CVE-2026-43475CVE-2026-43476CVE-2026-43480CVE-2026-43484CVE-2026-43490CVE-2026-43492CVE-2026-43495CVE-2026-43496CVE-2026-43497CVE-2026-43498CVE-2026-43499CVE-2026-43502CVE-2026-45834CVE-2026-45835CVE-2026-45836CVE-2026-45837CVE-2026-45838CVE-2026-45839CVE-2026-45840CVE-2026-45841CVE-2026-45842CVE-2026-45843CVE-2026-45844CVE-2026-45845CVE-2026-45846CVE-2026-45847CVE-2026-45848CVE-2026-45852CVE-2026-45856CVE-2026-45857CVE-2026-45860CVE-2026-45862CVE-2026-45864CVE-2026-45866CVE-2026-45867CVE-2026-45868CVE-2026-45869CVE-2026-45870CVE-2026-45871CVE-2026-45873CVE-2026-45875CVE-2026-45879CVE-2026-45883CVE-2026-45885CVE-2026-45890CVE-2026-45891CVE-2026-45899CVE-2026-45902CVE-2026-45904CVE-2026-45911CVE-2026-45912CVE-2026-45915CVE-2026-45916CVE-2026-45919CVE-2026-45920CVE-2026-45924CVE-2026-45935CVE-2026-45936CVE-2026-45941CVE-2026-45946CVE-2026-45948CVE-2026-45954CVE-2026-45956CVE-2026-45958CVE-2026-45960CVE-2026-45964CVE-2026-45965CVE-2026-45968CVE-2026-45969CVE-2026-45970CVE-2026-45974CVE-2026-45978CVE-2026-45983CVE-2026-45984CVE-2026-45985CVE-2026-45986CVE-2026-45987CVE-2026-45994CVE-2026-46002CVE-2026-46004CVE-2026-46006CVE-2026-46009CVE-2026-46015CVE-2026-46018CVE-2026-46019CVE-2026-46022CVE-2026-46023CVE-2026-46024CVE-2026-46027CVE-2026-46033CVE-2026-46037CVE-2026-46040CVE-2026-46044CVE-2026-46046CVE-2026-46047CVE-2026-46049CVE-2026-46050CVE-2026-46051CVE-2026-46053CVE-2026-46062CVE-2026-46064CVE-2026-46070CVE-2026-46072CVE-2026-46077CVE-2026-46080CVE-2026-46082CVE-2026-46088CVE-2026-46098CVE-2026-46099CVE-2026-46101CVE-2026-46102CVE-2026-46104CVE-2026-46105CVE-2026-46106CVE-2026-46107CVE-2026-46108CVE-2026-46109CVE-2026-46110CVE-2026-46111CVE-2026-46112CVE-2026-46113CVE-2026-46114CVE-2026-46115CVE-2026-46116CVE-2026-46117CVE-2026-46118CVE-2026-46119CVE-2026-46120CVE-2026-46121CVE-2026-46122CVE-2026-46123CVE-2026-46124CVE-2026-46125CVE-2026-46126CVE-2026-46127CVE-2026-46128CVE-2026-46129CVE-2026-46130CVE-2026-46131CVE-2026-46132CVE-2026-46133CVE-2026-46134CVE-2026-46135CVE-2026-46136CVE-2026-46137CVE-2026-46138CVE-2026-46139CVE-2026-46140CVE-2026-46141CVE-2026-46142CVE-2026-46143CVE-2026-46144CVE-2026-46145CVE-2026-46146CVE-2026-46148CVE-2026-46149CVE-2026-46150CVE-2026-46151CVE-2026-46152CVE-2026-46153CVE-2026-46154CVE-2026-46155CVE-2026-46156CVE-2026-46157CVE-2026-46158CVE-2026-46159CVE-2026-46160CVE-2026-46161CVE-2026-46162CVE-2026-46163CVE-2026-46164CVE-2026-46165CVE-2026-46166CVE-2026-46167CVE-2026-46168CVE-2026-46169CVE-2026-46170CVE-2026-46171CVE-2026-46172CVE-2026-46173CVE-2026-46174CVE-2026-46175CVE-2026-46176CVE-2026-46177CVE-2026-46178CVE-2026-46179CVE-2026-46180CVE-2026-46181CVE-2026-46182CVE-2026-46183CVE-2026-46184CVE-2026-46185CVE-2026-46186CVE-2026-46187CVE-2026-46188CVE-2026-46189CVE-2026-46190CVE-2026-46191CVE-2026-46192CVE-2026-46193CVE-2026-46195CVE-2026-46196CVE-2026-46197CVE-2026-46198CVE-2026-46199CVE-2026-46200CVE-2026-46201CVE-2026-46202CVE-2026-46203CVE-2026-46204CVE-2026-46205CVE-2026-46206CVE-2026-46207CVE-2026-46208CVE-2026-46209CVE-2026-46210CVE-2026-46211CVE-2026-46212CVE-2026-46213CVE-2026-46214CVE-2026-46215CVE-2026-46216CVE-2026-46218CVE-2026-46219CVE-2026-46220CVE-2026-46221CVE-2026-46222CVE-2026-46223CVE-2026-46224CVE-2026-46225CVE-2026-46226CVE-2026-46227CVE-2026-46228CVE-2026-46229CVE-2026-46230CVE-2026-46231CVE-2026-46232CVE-2026-46233CVE-2026-46234CVE-2026-46235CVE-2026-46236CVE-2026-46238CVE-2026-46239CVE-2026-46240CVE-2026-46241CVE-2026-46242CVE-2026-46243CVE-2026-46244CVE-2026-46249CVE-2026-46250CVE-2026-46253CVE-2026-46259CVE-2026-46266CVE-2026-46267CVE-2026-46270CVE-2026-46273CVE-2026-46274CVE-2026-46275CVE-2026-46285CVE-2026-46289CVE-2026-46290CVE-2026-46291CVE-2026-46292CVE-2026-46293CVE-2026-46294CVE-2026-46295CVE-2026-46296CVE-2026-46297CVE-2026-46298CVE-2026-46299CVE-2026-46301CVE-2026-46302CVE-2026-46303CVE-2026-46304CVE-2026-46305CVE-2026-46306CVE-2026-46307CVE-2026-46308CVE-2026-46309CVE-2026-46310CVE-2026-46311CVE-2026-46312CVE-2026-46313CVE-2026-46314CVE-2026-46315CVE-2026-46316CVE-2026-46317CVE-2026-46318CVE-2026-46319CVE-2026-46320CVE-2026-46321CVE-2026-46322CVE-2026-46324CVE-2026-46328CVE-2026-46331CVE-2026-52908CVE-2026-52909CVE-2026-52910CVE-2026-52911CVE-2026-52912CVE-2026-52913CVE-2026-52914CVE-2026-52915CVE-2026-52916CVE-2026-52917CVE-2026-52918CVE-2026-52919CVE-2026-52920CVE-2026-52921CVE-2026-52922CVE-2026-52923CVE-2026-52924CVE-2026-52925CVE-2026-52926CVE-2026-52927CVE-2026-52928CVE-2026-52929CVE-2026-52930CVE-2026-52931CVE-2026-52932CVE-2026-52934CVE-2026-52935CVE-2026-52936CVE-2026-52937CVE-2026-52938CVE-2026-52939CVE-2026-52940CVE-2026-52941CVE-2026-52942CVE-2026-52943CVE-2026-52944CVE-2026-52947CVE-2026-52948CVE-2026-52949CVE-2026-52950CVE-2026-52951CVE-2026-52952CVE-2026-52953CVE-2026-52954CVE-2026-52955CVE-2026-52956CVE-2026-52957CVE-2026-52958CVE-2026-52959CVE-2026-52960CVE-2026-52961CVE-2026-52962CVE-2026-52963CVE-2026-52964CVE-2026-52965CVE-2026-52967CVE-2026-52968CVE-2026-52969CVE-2026-52970CVE-2026-52971CVE-2026-52973CVE-2026-52974CVE-2026-52975CVE-2026-52976CVE-2026-52977CVE-2026-52978CVE-2026-52979CVE-2026-52980CVE-2026-52981CVE-2026-52982CVE-2026-52983CVE-2026-52984CVE-2026-52985CVE-2026-52986CVE-2026-52987CVE-2026-52988CVE-2026-52989CVE-2026-52990CVE-2026-52991CVE-2026-52992CVE-2026-52993CVE-2026-52994CVE-2026-52995CVE-2026-52996CVE-2026-52997CVE-2026-52998CVE-2026-52999CVE-2026-53000CVE-2026-53001CVE-2026-53002CVE-2026-53003CVE-2026-53004CVE-2026-53005CVE-2026-53006CVE-2026-53007CVE-2026-53008CVE-2026-53009CVE-2026-53010CVE-2026-53011CVE-2026-53012CVE-2026-53013CVE-2026-53014CVE-2026-53015CVE-2026-53016CVE-2026-53017CVE-2026-53018CVE-2026-53019CVE-2026-53020CVE-2026-53021CVE-2026-53022CVE-2026-53023CVE-2026-53024CVE-2026-53025CVE-2026-53026CVE-2026-53027CVE-2026-53028CVE-2026-53029CVE-2026-53030CVE-2026-53031CVE-2026-53032CVE-2026-53033CVE-2026-53034CVE-2026-53035CVE-2026-53036CVE-2026-53037CVE-2026-53038CVE-2026-53039CVE-2026-53040CVE-2026-53041CVE-2026-53042CVE-2026-53043CVE-2026-53044CVE-2026-53045CVE-2026-53046CVE-2026-53047CVE-2026-53048CVE-2026-53049CVE-2026-53050CVE-2026-53051CVE-2026-53052CVE-2026-53053CVE-2026-53054CVE-2026-53055CVE-2026-53056CVE-2026-53057CVE-2026-53058CVE-2026-53059CVE-2026-53060CVE-2026-53061CVE-2026-53062CVE-2026-53063CVE-2026-53064CVE-2026-53065CVE-2026-53066CVE-2026-53067CVE-2026-53068CVE-2026-53069CVE-2026-53070CVE-2026-53071CVE-2026-53072CVE-2026-53073CVE-2026-53074CVE-2026-53075CVE-2026-53076CVE-2026-53077CVE-2026-53078CVE-2026-53079CVE-2026-53080CVE-2026-53081CVE-2026-53082CVE-2026-53083CVE-2026-53084CVE-2026-53085CVE-2026-53086CVE-2026-53087CVE-2026-53088CVE-2026-53089CVE-2026-53090CVE-2026-53091CVE-2026-53092CVE-2026-53093CVE-2026-53094CVE-2026-53095CVE-2026-53096CVE-2026-53097CVE-2026-53098CVE-2026-53099CVE-2026-53100CVE-2026-53101CVE-2026-53102CVE-2026-53103CVE-2026-53104CVE-2026-53105CVE-2026-53106CVE-2026-53107CVE-2026-53108CVE-2026-53109CVE-2026-53110CVE-2026-53111CVE-2026-53112CVE-2026-53113CVE-2026-53114CVE-2026-53115CVE-2026-53116CVE-2026-53117CVE-2026-53118CVE-2026-53119CVE-2026-53120CVE-2026-53121CVE-2026-53122CVE-2026-53123CVE-2026-53124CVE-2026-53125CVE-2026-53126CVE-2026-53127CVE-2026-53128CVE-2026-53129CVE-2026-53130CVE-2026-53131CVE-2026-53132CVE-2026-53133CVE-2026-53134CVE-2026-53135CVE-2026-53136CVE-2026-53137CVE-2026-53138CVE-2026-53139CVE-2026-53140CVE-2026-53141CVE-2026-53142CVE-2026-53143CVE-2026-53144CVE-2026-53145CVE-2026-53146CVE-2026-53147CVE-2026-53148CVE-2026-53149CVE-2026-53150CVE-2026-53151CVE-2026-53152CVE-2026-53153CVE-2026-53154CVE-2026-53155CVE-2026-53156CVE-2026-53157CVE-2026-53158CVE-2026-53159CVE-2026-53160CVE-2026-53161CVE-2026-53162CVE-2026-53163CVE-2026-53164CVE-2026-53165CVE-2026-53167CVE-2026-53168CVE-2026-53169CVE-2026-53170CVE-2026-53171CVE-2026-53172CVE-2026-53173CVE-2026-53174CVE-2026-53175CVE-2026-53176CVE-2026-53177CVE-2026-53178CVE-2026-53179CVE-2026-53180CVE-2026-53181CVE-2026-53182CVE-2026-53183CVE-2026-53184CVE-2026-53185CVE-2026-53186CVE-2026-53187CVE-2026-53188CVE-2026-53189CVE-2026-53190CVE-2026-53191CVE-2026-53192CVE-2026-53193CVE-2026-53194CVE-2026-53195CVE-2026-53196CVE-2026-53197CVE-2026-53198CVE-2026-53199CVE-2026-53200CVE-2026-53201CVE-2026-53202CVE-2026-53203CVE-2026-53204CVE-2026-53205CVE-2026-53206CVE-2026-53207CVE-2026-53208CVE-2026-53209CVE-2026-53210CVE-2026-53211CVE-2026-53212CVE-2026-53213CVE-2026-53214CVE-2026-53215CVE-2026-53216CVE-2026-53217CVE-2026-53218CVE-2026-53219CVE-2026-53220CVE-2026-53221CVE-2026-53222CVE-2026-53223CVE-2026-53224CVE-2026-53225CVE-2026-53226CVE-2026-53227CVE-2026-53228CVE-2026-53229CVE-2026-53230CVE-2026-53231CVE-2026-53232CVE-2026-53233CVE-2026-53234CVE-2026-53235CVE-2026-53236CVE-2026-53237CVE-2026-53238CVE-2026-53239CVE-2026-53240CVE-2026-53241CVE-2026-53242CVE-2026-53243CVE-2026-53244CVE-2026-53245CVE-2026-53246CVE-2026-53247CVE-2026-53248CVE-2026-53249CVE-2026-53250CVE-2026-53251CVE-2026-53252CVE-2026-53253CVE-2026-53254CVE-2026-53255CVE-2026-53256CVE-2026-53257CVE-2026-53258CVE-2026-53259CVE-2026-53260CVE-2026-53261CVE-2026-53262CVE-2026-53263CVE-2026-53264CVE-2026-53265CVE-2026-53266CVE-2026-53267CVE-2026-53268CVE-2026-53269CVE-2026-53270CVE-2026-53271CVE-2026-53272CVE-2026-53273CVE-2026-53274CVE-2026-53275CVE-2026-53276CVE-2026-53277CVE-2026-53278CVE-2026-53279CVE-2026-53280CVE-2026-53281CVE-2026-53282CVE-2026-53283CVE-2026-53284CVE-2026-53285CVE-2026-53286CVE-2026-53287CVE-2026-53288CVE-2026-53289CVE-2026-53290CVE-2026-53291CVE-2026-53292CVE-2026-53293CVE-2026-53294CVE-2026-53295CVE-2026-53296CVE-2026-53297CVE-2026-53298CVE-2026-53299CVE-2026-53300CVE-2026-53301CVE-2026-53302CVE-2026-53303CVE-2026-53304CVE-2026-53305CVE-2026-53306CVE-2026-53307CVE-2026-53308CVE-2026-53309CVE-2026-53310CVE-2026-53311CVE-2026-53312CVE-2026-53313CVE-2026-53314CVE-2026-53315CVE-2026-53316CVE-2026-53317CVE-2026-53318CVE-2026-53319CVE-2026-53320CVE-2026-53321CVE-2026-53322CVE-2026-53323CVE-2026-53324CVE-2026-53325CVE-2026-53326CVE-2026-53327CVE-2026-53328CVE-2026-53329CVE-2026-53330CVE-2026-53331CVE-2026-53332CVE-2026-53333CVE-2026-53334CVE-2026-53335CVE-2026-53336CVE-2026-53337CVE-2026-53338CVE-2026-53339CVE-2026-53340CVE-2026-53341CVE-2026-53342CVE-2026-53343CVE-2026-53344CVE-2026-53345CVE-2026-53346CVE-2026-53347CVE-2026-53348CVE-2026-53349CVE-2026-53350CVE-2026-53351CVE-2026-53352CVE-2026-53353CVE-2026-53354CVE-2026-53355CVE-2026-53356CVE-2026-53357CVE-2026-53358CVE-2026-53359CVE-2026-53360CVE-2026-53361CVE-2026-53362CVE-2026-53363CVE-2026-53364CVE-2026-53365CVE-2026-53366CVE-2026-53367CVE-2026-53368CVE-2026-53369CVE-2026-53370CVE-2026-53371CVE-2026-53372CVE-2026-53373CVE-2026-53374CVE-2026-53375CVE-2026-53376CVE-2026-53377CVE-2026-53378CVE-2026-53379CVE-2026-53380CVE-2026-53381CVE-2026-53382CVE-2026-53383CVE-2026-53384CVE-2026-53385CVE-2026-53386CVE-2026-53387CVE-2026-53388CVE-2026-53389CVE-2026-53390CVE-2026-53391CVE-2026-53392CVE-2026-53393CVE-2026-53394CVE-2026-53395CVE-2026-53396CVE-2026-53397CVE-2026-53398CVE-2026-53399CVE-2026-53400CVE-2026-53401CVE-2026-53402CVE-2026-53403CVE-2026-63794CVE-2026-63795CVE-2026-63796CVE-2026-63797CVE-2026-63798CVE-2026-63799CVE-2026-63800CVE-2026-63801CVE-2026-63802CVE-2026-63803CVE-2026-63804CVE-2026-63805CVE-2026-63806CVE-2026-63807CVE-2026-63808CVE-2026-63809CVE-2026-63810CVE-2026-63811CVE-2026-63812CVE-2026-63813CVE-2026-63814CVE-2026-63815CVE-2026-63816CVE-2026-63817CVE-2026-63818CVE-2026-63819CVE-2026-63820CVE-2026-63821CVE-2026-63822CVE-2026-63823CVE-2026-63824CVE-2026-63825CVE-2026-63826CVE-2026-63827CVE-2026-63828CVE-2026-63829CVE-2026-63830CVE-2026-63831CVE-2026-63832CVE-2026-63833CVE-2026-63834CVE-2026-63835CVE-2026-63836CVE-2026-63837CVE-2026-63838CVE-2026-63839CVE-2026-63840CVE-2026-63841CVE-2026-63842CVE-2026-63843CVE-2026-63844CVE-2026-63845CVE-2026-63846CVE-2026-63847CVE-2026-63848CVE-2026-63849CVE-2026-63850CVE-2026-63851CVE-2026-63852CVE-2026-63853CVE-2026-63854CVE-2026-63855CVE-2026-63856CVE-2026-63857CVE-2026-63858CVE-2026-63859CVE-2026-63860CVE-2026-63861CVE-2026-63862CVE-2026-63863CVE-2026-63864CVE-2026-63865CVE-2026-63866CVE-2026-63867CVE-2026-63868CVE-2026-63869CVE-2026-63870CVE-2026-63871CVE-2026-63873CVE-2026-63874CVE-2026-63875CVE-2026-63876CVE-2026-63877CVE-2026-63878CVE-2026-63879CVE-2026-63880CVE-2026-63881CVE-2026-63882CVE-2026-63883CVE-2026-63884CVE-2026-63886CVE-2026-63887CVE-2026-63888CVE-2026-63889CVE-2026-63890CVE-2026-63891CVE-2026-63892CVE-2026-63893CVE-2026-63894CVE-2026-63895CVE-2026-63896CVE-2026-63897CVE-2026-63898CVE-2026-63899CVE-2026-63900CVE-2026-63901CVE-2026-63902CVE-2026-63903CVE-2026-63904CVE-2026-63905CVE-2026-63906CVE-2026-63907CVE-2026-63908CVE-2026-63909CVE-2026-63910CVE-2026-63911CVE-2026-63912CVE-2026-63913CVE-2026-63914CVE-2026-63915CVE-2026-63916CVE-2026-63917CVE-2026-63918CVE-2026-63919CVE-2026-63920CVE-2026-63921CVE-2026-63922CVE-2026-63923CVE-2026-63924CVE-2026-63925CVE-2026-63926CVE-2026-63927CVE-2026-63928CVE-2026-63929CVE-2026-63930CVE-2026-63931CVE-2026-63932CVE-2026-63933CVE-2026-63934CVE-2026-63935CVE-2026-63936CVE-2026-63937CVE-2026-63938CVE-2026-63939CVE-2026-63940CVE-2026-63941CVE-2026-63942CVE-2026-63943CVE-2026-63944CVE-2026-63945CVE-2026-63946CVE-2026-63947CVE-2026-63948CVE-2026-63949CVE-2026-63950CVE-2026-63951CVE-2026-63952CVE-2026-63953CVE-2026-63954CVE-2026-63955CVE-2026-63956CVE-2026-63957CVE-2026-63958CVE-2026-63959CVE-2026-63960CVE-2026-63961CVE-2026-63962CVE-2026-63963CVE-2026-63964CVE-2026-63965CVE-2026-63966CVE-2026-63967CVE-2026-63968CVE-2026-63969CVE-2026-63970CVE-2026-63971CVE-2026-63972CVE-2026-63973CVE-2026-63974CVE-2026-63975CVE-2026-63976CVE-2026-63977CVE-2026-63978CVE-2026-63979CVE-2026-63980CVE-2026-63981CVE-2026-63982CVE-2026-63983CVE-2026-63984CVE-2026-63985CVE-2026-63986CVE-2026-63987CVE-2026-63988CVE-2026-63989CVE-2026-63990CVE-2026-63991CVE-2026-63992CVE-2026-63993CVE-2026-63994CVE-2026-63995CVE-2026-63996CVE-2026-63997CVE-2026-63998CVE-2026-63999CVE-2026-64000CVE-2026-64001CVE-2026-64002CVE-2026-64003CVE-2026-64004CVE-2026-64005CVE-2026-64006CVE-2026-64007CVE-2026-64008CVE-2026-64009CVE-2026-64010CVE-2026-64011CVE-2026-64012CVE-2026-64013CVE-2026-64014CVE-2026-64015CVE-2026-64017CVE-2026-64018CVE-2026-64019CVE-2026-64020CVE-2026-64021CVE-2026-64022CVE-2026-64023CVE-2026-64024CVE-2026-64025CVE-2026-64026CVE-2026-64027CVE-2026-64029CVE-2026-64030CVE-2026-64031CVE-2026-64032CVE-2026-64033CVE-2026-64034CVE-2026-64035CVE-2026-64036CVE-2026-64037CVE-2026-64038CVE-2026-64039CVE-2026-64040CVE-2026-64041CVE-2026-64042CVE-2026-64043CVE-2026-64044CVE-2026-64045CVE-2026-64046CVE-2026-64047CVE-2026-64048CVE-2026-64049CVE-2026-64050CVE-2026-64051CVE-2026-64052
Separate evidence group
Original

Multiples vulnérabilités dans les produits Elastic (25 septembre 2026)

De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

CVE-2026-72662CVE-2026-72668CVE-2026-78582CVE-2026-82294CVE-2026-82300CVE-2026-94396CVE-2026-94397CVE-2026-94398CVE-2026-94399CVE-2026-94400CVE-2026-94408
Separate evidence group
Original

Multiples vulnérabilités dans les produits IBM (25 septembre 2026)

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

CVE-2018-1109CVE-2018-1313CVE-2018-14040CVE-2018-14041CVE-2018-14042CVE-2018-14732CVE-2019-8331CVE-2020-7598CVE-2021-20066CVE-2021-23382CVE-2021-44906CVE-2022-24771CVE-2022-25883CVE-2022-2596CVE-2022-35948CVE-2022-35961CVE-2022-37620CVE-2022-46175CVE-2022-46337CVE-2023-0842CVE-2023-26158CVE-2023-44270CVE-2023-45133CVE-2024-21538CVE-2024-22195CVE-2024-29041CVE-2024-34064CVE-2024-37890CVE-2024-4067CVE-2024-4068CVE-2024-43796CVE-2024-43799CVE-2024-43800CVE-2024-45590CVE-2024-47764CVE-2024-56201CVE-2024-56326CVE-2025-12816CVE-2025-13466CVE-2025-27516CVE-2025-30359CVE-2025-30360CVE-2025-66030CVE-2025-66031CVE-2025-68146CVE-2025-68470CVE-2025-71329CVE-2025-71330CVE-2026-12185CVE-2026-12590CVE-2026-12803CVE-2026-12816CVE-2026-12860CVE-2026-13149CVE-2026-13311CVE-2026-13505CVE-2026-13506CVE-2026-13586CVE-2026-13676CVE-2026-13697CVE-2026-14257CVE-2026-14620CVE-2026-14631CVE-2026-14643CVE-2026-14682CVE-2026-14802CVE-2026-15055CVE-2026-15157CVE-2026-1527CVE-2026-16221CVE-2026-16243CVE-2026-16439CVE-2026-16440CVE-2026-16441CVE-2026-16728CVE-2026-16729CVE-2026-18149CVE-2026-18446CVE-2026-18540CVE-2026-19534CVE-2026-22701CVE-2026-2391CVE-2026-25793CVE-2026-33891CVE-2026-33894CVE-2026-33895CVE-2026-33896CVE-2026-34043CVE-2026-3449CVE-2026-41254CVE-2026-41305CVE-2026-45623CVE-2026-45736CVE-2026-45819CVE-2026-46968CVE-2026-47010CVE-2026-47021CVE-2026-47027CVE-2026-47057CVE-2026-47058CVE-2026-47059CVE-2026-47063CVE-2026-4873CVE-2026-48779CVE-2026-49356CVE-2026-49875CVE-2026-53550CVE-2026-53666CVE-2026-53668CVE-2026-53669CVE-2026-55602CVE-2026-55603CVE-2026-58059CVE-2026-58060CVE-2026-58061CVE-2026-58062CVE-2026-58063CVE-2026-59645CVE-2026-59647CVE-2026-59648CVE-2026-59650CVE-2026-59651CVE-2026-59652CVE-2026-59869CVE-2026-59878CVE-2026-60147CVE-2026-60589CVE-2026-61308CVE-2026-61487CVE-2026-6253CVE-2026-6276CVE-2026-6322CVE-2026-63379CVE-2026-63380CVE-2026-63381CVE-2026-63382CVE-2026-63383CVE-2026-63384CVE-2026-63385CVE-2026-63387CVE-2026-63388CVE-2026-63495CVE-2026-6402CVE-2026-6429CVE-2026-66010CVE-2026-67213CVE-2026-67214CVE-2026-69152CVE-2026-69153CVE-2026-69247CVE-2026-69248CVE-2026-69249CVE-2026-70907CVE-2026-71290CVE-2026-7168CVE-2026-71852CVE-2026-71870CVE-2026-72848CVE-2026-73088CVE-2026-73089CVE-2026-73646CVE-2026-75509CVE-2026-75838CVE-2026-75899CVE-2026-75931CVE-2026-75975CVE-2026-76172CVE-2026-82397CVE-2026-82417CVE-2026-82562CVE-2026-8400CVE-2026-84292CVE-2026-84375CVE-2026-84890CVE-2026-84933CVE-2026-84947CVE-2026-84961CVE-2026-85008CVE-2026-85014CVE-2026-85024CVE-2026-85062CVE-2026-8763CVE-2026-9358CVE-2026-9563CVE-2026-9595CVE-2026-9678
Separate evidence group
Original

Multiples vulnérabilités dans le noyau Linux de Debian LTS (25 septembre 2026)

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni de service.

CVE-2025-38525CVE-2025-40054CVE-2025-40074CVE-2026-43197CVE-2026-53092CVE-2026-64017CVE-2026-64216CVE-2026-64581CVE-2026-64586CVE-2026-68082CVE-2026-68118CVE-2026-68132CVE-2026-68138CVE-2026-68159CVE-2026-68166CVE-2026-68169CVE-2026-68198CVE-2026-68253CVE-2026-68254CVE-2026-68264CVE-2026-68266CVE-2026-68267CVE-2026-68273CVE-2026-68276CVE-2026-68322CVE-2026-68367CVE-2026-68431CVE-2026-68451CVE-2026-68452CVE-2026-68480CVE-2026-72111CVE-2026-74440CVE-2026-74441CVE-2026-74442CVE-2026-74443CVE-2026-74444CVE-2026-74445CVE-2026-74446CVE-2026-74447CVE-2026-74448CVE-2026-74450CVE-2026-74451CVE-2026-74452CVE-2026-74453CVE-2026-74454CVE-2026-74455CVE-2026-74456CVE-2026-74457CVE-2026-74458CVE-2026-74459CVE-2026-74460CVE-2026-74461CVE-2026-74463CVE-2026-74464CVE-2026-74465CVE-2026-74467CVE-2026-74468CVE-2026-74469CVE-2026-74470CVE-2026-74471CVE-2026-74472CVE-2026-74473CVE-2026-74474CVE-2026-74475CVE-2026-74476CVE-2026-74478CVE-2026-74479CVE-2026-74480CVE-2026-74481CVE-2026-74482CVE-2026-74483CVE-2026-74484CVE-2026-74485CVE-2026-74487CVE-2026-74488CVE-2026-74490CVE-2026-74492CVE-2026-74493CVE-2026-74494CVE-2026-74495CVE-2026-74497CVE-2026-74498CVE-2026-74499CVE-2026-74500CVE-2026-74501CVE-2026-74502CVE-2026-74503CVE-2026-74504CVE-2026-74505CVE-2026-74507CVE-2026-74508CVE-2026-74509CVE-2026-74510CVE-2026-74512CVE-2026-74514CVE-2026-74515CVE-2026-74516CVE-2026-74517CVE-2026-74518CVE-2026-74519CVE-2026-74522CVE-2026-74523CVE-2026-74524CVE-2026-74525CVE-2026-74531CVE-2026-74532CVE-2026-74535CVE-2026-74536CVE-2026-74540CVE-2026-74541CVE-2026-74543CVE-2026-74545CVE-2026-74546CVE-2026-74547CVE-2026-74548CVE-2026-74549CVE-2026-74550CVE-2026-74551CVE-2026-74552CVE-2026-74553CVE-2026-74555CVE-2026-74556CVE-2026-74557CVE-2026-74563CVE-2026-74564CVE-2026-74565CVE-2026-74566CVE-2026-74567CVE-2026-74569CVE-2026-74572CVE-2026-74574CVE-2026-74575CVE-2026-74576CVE-2026-74577CVE-2026-74579CVE-2026-74580CVE-2026-74581CVE-2026-74582CVE-2026-74583CVE-2026-74585CVE-2026-74586CVE-2026-74587CVE-2026-74588CVE-2026-74589CVE-2026-74590CVE-2026-74592CVE-2026-74594CVE-2026-74595CVE-2026-74597CVE-2026-74598CVE-2026-74599CVE-2026-74601CVE-2026-74602CVE-2026-74603CVE-2026-74604CVE-2026-74606CVE-2026-74607CVE-2026-74608CVE-2026-74609CVE-2026-74610CVE-2026-74612CVE-2026-74613CVE-2026-74614CVE-2026-74615CVE-2026-74616CVE-2026-74618CVE-2026-74619CVE-2026-74620CVE-2026-74621CVE-2026-74622CVE-2026-74623CVE-2026-74624CVE-2026-74625CVE-2026-74626CVE-2026-74628CVE-2026-74630CVE-2026-74631CVE-2026-74632CVE-2026-74634CVE-2026-74635CVE-2026-74636CVE-2026-74637CVE-2026-74641CVE-2026-74644CVE-2026-74646CVE-2026-74647CVE-2026-74648CVE-2026-74649CVE-2026-74650CVE-2026-74651CVE-2026-74653CVE-2026-74654CVE-2026-74655CVE-2026-74656CVE-2026-74657CVE-2026-74658CVE-2026-74659CVE-2026-74660CVE-2026-74661CVE-2026-74662CVE-2026-74663CVE-2026-74664CVE-2026-74665CVE-2026-74666CVE-2026-74667CVE-2026-74668CVE-2026-74669CVE-2026-74670CVE-2026-74671CVE-2026-74672CVE-2026-74673CVE-2026-74675CVE-2026-74676CVE-2026-74677CVE-2026-74678CVE-2026-74679CVE-2026-74680CVE-2026-74682CVE-2026-74683CVE-2026-74684CVE-2026-74685CVE-2026-74688CVE-2026-74689CVE-2026-74691CVE-2026-74692CVE-2026-74693CVE-2026-74694CVE-2026-74696CVE-2026-74700CVE-2026-74701CVE-2026-74704CVE-2026-74705CVE-2026-74710CVE-2026-74712CVE-2026-74714CVE-2026-74717CVE-2026-74718CVE-2026-74719CVE-2026-74720CVE-2026-74722CVE-2026-74724CVE-2026-74725CVE-2026-74726CVE-2026-74730CVE-2026-74732CVE-2026-74736CVE-2026-74737CVE-2026-74739CVE-2026-74740CVE-2026-74742CVE-2026-74743CVE-2026-74744CVE-2026-74746CVE-2026-74748CVE-2026-80522CVE-2026-80525CVE-2026-80526CVE-2026-80527CVE-2026-80528CVE-2026-80529CVE-2026-80530CVE-2026-80531CVE-2026-80532CVE-2026-80533CVE-2026-80534CVE-2026-80535CVE-2026-80536CVE-2026-80539CVE-2026-80540CVE-2026-80541CVE-2026-80547CVE-2026-80548CVE-2026-80549CVE-2026-80550CVE-2026-80551CVE-2026-80552CVE-2026-80553CVE-2026-80554CVE-2026-80555CVE-2026-80556CVE-2026-80557CVE-2026-80558CVE-2026-80559CVE-2026-80560CVE-2026-80561CVE-2026-80562CVE-2026-80563CVE-2026-80565CVE-2026-80566CVE-2026-80567CVE-2026-80568CVE-2026-80569CVE-2026-80570CVE-2026-80572CVE-2026-80573CVE-2026-80574CVE-2026-80575CVE-2026-80576CVE-2026-80577CVE-2026-80578CVE-2026-80583CVE-2026-80584CVE-2026-80585CVE-2026-80586CVE-2026-80587CVE-2026-80589CVE-2026-80590CVE-2026-80678CVE-2026-80679CVE-2026-80680CVE-2026-80681CVE-2026-80684CVE-2026-80686CVE-2026-80689CVE-2026-80691CVE-2026-80694CVE-2026-80695CVE-2026-80696CVE-2026-80700CVE-2026-80702CVE-2026-80703CVE-2026-80704CVE-2026-80706CVE-2026-80707CVE-2026-80708CVE-2026-80709CVE-2026-80710CVE-2026-80711CVE-2026-80714CVE-2026-80715CVE-2026-80716CVE-2026-80717CVE-2026-80718CVE-2026-80722CVE-2026-80723CVE-2026-80725CVE-2026-80726CVE-2026-80727CVE-2026-80728CVE-2026-80730CVE-2026-80731CVE-2026-80732CVE-2026-80733CVE-2026-80736CVE-2026-80737CVE-2026-80739CVE-2026-80742CVE-2026-80743CVE-2026-80744CVE-2026-80749CVE-2026-80752CVE-2026-80754CVE-2026-80756CVE-2026-80757CVE-2026-80759CVE-2026-80763CVE-2026-80764CVE-2026-80765CVE-2026-80767CVE-2026-80770CVE-2026-80771CVE-2026-80772CVE-2026-80779CVE-2026-80781CVE-2026-80782CVE-2026-80784CVE-2026-80788CVE-2026-80789CVE-2026-80790CVE-2026-80791CVE-2026-80792CVE-2026-80793CVE-2026-80794CVE-2026-80795CVE-2026-80797CVE-2026-80798CVE-2026-80799CVE-2026-80800CVE-2026-80801CVE-2026-80802CVE-2026-80803CVE-2026-80805CVE-2026-80808CVE-2026-80809CVE-2026-80812CVE-2026-80814CVE-2026-80815CVE-2026-80819CVE-2026-80820CVE-2026-80823CVE-2026-80887CVE-2026-80888CVE-2026-80889CVE-2026-80890CVE-2026-80891CVE-2026-80892CVE-2026-80893CVE-2026-80894CVE-2026-80901CVE-2026-80902CVE-2026-80903CVE-2026-80904CVE-2026-80906CVE-2026-80907CVE-2026-80908CVE-2026-80909CVE-2026-80910CVE-2026-80911CVE-2026-80912CVE-2026-80913CVE-2026-80915CVE-2026-80916CVE-2026-80917CVE-2026-80918
Separate evidence group
Original

Multiples vulnérabilités dans le noyau Linux de SUSE (25 septembre 2026)

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et une atteinte à la confidentialité des données.

CVE-2023-53109CVE-2024-35973CVE-2024-57841CVE-2025-39964CVE-2025-40022CVE-2025-40277CVE-2025-68214CVE-2026-23003CVE-2026-23443CVE-2026-23451CVE-2026-31483CVE-2026-31502CVE-2026-43116CVE-2026-43125CVE-2026-43134CVE-2026-43257CVE-2026-43277CVE-2026-43363CVE-2026-43416CVE-2026-43456CVE-2026-43502CVE-2026-45941CVE-2026-45968CVE-2026-46070CVE-2026-46107CVE-2026-46108CVE-2026-46128CVE-2026-46150CVE-2026-52910CVE-2026-52912CVE-2026-52920CVE-2026-52925CVE-2026-52929CVE-2026-52939CVE-2026-52946CVE-2026-52977CVE-2026-53001CVE-2026-53059CVE-2026-53061CVE-2026-53077CVE-2026-53089CVE-2026-53091CVE-2026-53149CVE-2026-53163CVE-2026-53219CVE-2026-53220CVE-2026-53223CVE-2026-53228CVE-2026-53238CVE-2026-53260CVE-2026-53264CVE-2026-53265CVE-2026-53309CVE-2026-53360CVE-2026-53374CVE-2026-53381CVE-2026-53388CVE-2026-53403CVE-2026-63801CVE-2026-63810CVE-2026-63823CVE-2026-63827CVE-2026-63860CVE-2026-63868CVE-2026-63887CVE-2026-63888CVE-2026-63890CVE-2026-63891CVE-2026-63892CVE-2026-63898CVE-2026-63920CVE-2026-63928CVE-2026-63962CVE-2026-63990CVE-2026-63992CVE-2026-64001CVE-2026-64002CVE-2026-64005CVE-2026-64007CVE-2026-64010CVE-2026-64011CVE-2026-64015CVE-2026-64047CVE-2026-64048CVE-2026-64088CVE-2026-64098CVE-2026-64103CVE-2026-64109CVE-2026-64113CVE-2026-64114CVE-2026-64115CVE-2026-64118CVE-2026-64137CVE-2026-64164CVE-2026-64178CVE-2026-64190CVE-2026-64266CVE-2026-64268CVE-2026-64304CVE-2026-64306CVE-2026-64312CVE-2026-64313CVE-2026-64315CVE-2026-64317CVE-2026-64322CVE-2026-64323CVE-2026-64332CVE-2026-64333CVE-2026-64334CVE-2026-64340CVE-2026-64341CVE-2026-64343CVE-2026-64344CVE-2026-64355CVE-2026-64380CVE-2026-64381CVE-2026-64408CVE-2026-64411CVE-2026-64412CVE-2026-64423CVE-2026-64436CVE-2026-64450CVE-2026-64470CVE-2026-64471CVE-2026-64481CVE-2026-64512CVE-2026-64513CVE-2026-64541CVE-2026-64543CVE-2026-64544CVE-2026-64547CVE-2026-64551CVE-2026-64553CVE-2026-64556CVE-2026-64561CVE-2026-64562CVE-2026-64563CVE-2026-64564CVE-2026-64567CVE-2026-64572CVE-2026-64577CVE-2026-64581CVE-2026-64582CVE-2026-64593CVE-2026-68082CVE-2026-68093CVE-2026-68111CVE-2026-68117CVE-2026-68121CVE-2026-68123CVE-2026-68129CVE-2026-68136CVE-2026-68138CVE-2026-68141CVE-2026-68143CVE-2026-68153CVE-2026-68154CVE-2026-68155CVE-2026-68156CVE-2026-68158CVE-2026-68159CVE-2026-68160CVE-2026-68188CVE-2026-68197CVE-2026-68198CVE-2026-68202CVE-2026-68234CVE-2026-68238CVE-2026-68277CVE-2026-68278CVE-2026-68279CVE-2026-68284CVE-2026-68289CVE-2026-68299CVE-2026-68300CVE-2026-68313CVE-2026-68315CVE-2026-68320CVE-2026-68325CVE-2026-68328CVE-2026-68329CVE-2026-68338CVE-2026-68349CVE-2026-68351CVE-2026-68357CVE-2026-68363CVE-2026-68397CVE-2026-68398CVE-2026-68405CVE-2026-68410CVE-2026-68417CVE-2026-68425CVE-2026-68426CVE-2026-68428CVE-2026-68432CVE-2026-68433CVE-2026-68450CVE-2026-68480CVE-2026-72017CVE-2026-72020CVE-2026-72036CVE-2026-72069CVE-2026-72072CVE-2026-72083CVE-2026-72084CVE-2026-72086CVE-2026-72108CVE-2026-72123CVE-2026-72135CVE-2026-72138CVE-2026-72142CVE-2026-72164CVE-2026-72251CVE-2026-72262CVE-2026-72282CVE-2026-72284CVE-2026-72288CVE-2026-72289CVE-2026-72296CVE-2026-72297CVE-2026-72323CVE-2026-72339CVE-2026-72389CVE-2026-72421CVE-2026-72450CVE-2026-72466CVE-2026-72487CVE-2026-72502CVE-2026-74255CVE-2026-74261CVE-2026-74265CVE-2026-74271CVE-2026-74278CVE-2026-74279CVE-2026-74296CVE-2026-74297CVE-2026-74302CVE-2026-74334CVE-2026-74341CVE-2026-74345CVE-2026-74377CVE-2026-74378CVE-2026-74382CVE-2026-74388CVE-2026-74390CVE-2026-74394CVE-2026-74406CVE-2026-74416CVE-2026-74417CVE-2026-74454CVE-2026-74479CVE-2026-74482CVE-2026-74488CVE-2026-74495CVE-2026-74496CVE-2026-74508CVE-2026-74510CVE-2026-74518CVE-2026-74519CVE-2026-74537CVE-2026-74548CVE-2026-74550CVE-2026-74556CVE-2026-74557CVE-2026-74581CVE-2026-74582CVE-2026-74584CVE-2026-74615CVE-2026-74616CVE-2026-74669CVE-2026-74673CVE-2026-74695CVE-2026-74705CVE-2026-74743CVE-2026-80534CVE-2026-80574CVE-2026-80580CVE-2026-80590CVE-2026-80603CVE-2026-80609CVE-2026-80714CVE-2026-80716CVE-2026-80722CVE-2026-80737CVE-2026-80765CVE-2026-80819CVE-2026-80909
Separate evidence group
Original

Multiples vulnérabilités dans le noyau Linux de Red Hat (25 septembre 2026)

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

CVE-2023-53781CVE-2023-54120CVE-2023-54214CVE-2025-21826CVE-2025-39964CVE-2025-40323CVE-2025-71082CVE-2026-23007CVE-2026-31539CVE-2026-31566CVE-2026-31692CVE-2026-43334CVE-2026-43370CVE-2026-45894CVE-2026-45959CVE-2026-46043CVE-2026-46117CVE-2026-46133CVE-2026-46150CVE-2026-46199CVE-2026-46204CVE-2026-46230CVE-2026-46311CVE-2026-52912CVE-2026-52918CVE-2026-52993CVE-2026-53000CVE-2026-53002CVE-2026-53005CVE-2026-53009CVE-2026-53053CVE-2026-53062CVE-2026-53185CVE-2026-53196CVE-2026-53203CVE-2026-53254CVE-2026-53256CVE-2026-53266CVE-2026-53290CVE-2026-63802CVE-2026-63823CVE-2026-63831CVE-2026-63887CVE-2026-63888CVE-2026-63947CVE-2026-63952CVE-2026-63975CVE-2026-64017CVE-2026-64053CVE-2026-64098CVE-2026-64191CVE-2026-64268CVE-2026-64368CVE-2026-64382CVE-2026-64383CVE-2026-64534CVE-2026-64564CVE-2026-64582CVE-2026-68108CVE-2026-68121CVE-2026-68155CVE-2026-68159CVE-2026-68166CVE-2026-68188CVE-2026-68201CVE-2026-68257CVE-2026-68266CVE-2026-68267CVE-2026-68273CVE-2026-68293CVE-2026-68391CVE-2026-72243CVE-2026-72261CVE-2026-74469CVE-2026-74518CVE-2026-74569CVE-2026-80714CVE-2026-80844CVE-2026-81000CVE-2026-89480CVE-2026-89846
Separate evidence group
Original

'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

Agentic AI can smuggle arbitrary instructions from the Web, across multiple apps, into trusted internal communications channels.

Separate evidence group
Original

MacSync malware uses public iCloud calendars to deliver new payloads

A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]

Separate evidence group
Original

Autonomous AI Hacks Raise Thorny Questions of Legal Accountability

The prospect of legal accountability is unclear. Lawsuits are a possibility, but some legal experts believe any criminal investigations would face an extremely high burden. The post Autonomous AI Hacks Raise Thorny Questions of Legal Accountability appeared first on SecurityWeek .

Separate evidence group
Original

SectopRAT Returns, Hiding Inside a Legitimate Application

The latest activity from the remote access Trojan (RAT) shows why organizations should monitor the behavior of applications rather than blindly trusting them, experts say.

Separate evidence group
Original

Digital forensics firm with US federal contracts covered up ties to Russia, DOJ alleges

Two executives at a data extraction and digital forensics company that sold several U.S. agencies its software were arrested for allegedly lying about the fact that its technology is made in Russia.

Separate evidence group
Original

Rapid7 Metasploit Framework corpus synchronized

The pinned corpus revision was recorded with provenance. No new or materially changed exploit-intent artifact affected a known CVE, so CVE threat scores were not changed.

Separate evidence group
Original

Lawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacks

U.S. Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday, arguing that the new effort was necessary in light of the Salt Typhoon attacks which saw Chinese hackers breach nearly all of the major telecommunications giants in the U.S.

Separate evidence group
Original

New Carbonato malware uses AI agents to hijack exposed Docker hosts

A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]

Separate evidence group
Original

Rydox cybercriminal marketplace operator pleads guilty following co-conspirator brothers’s deportation

Ardit Kutleshi, 28, was extradited from his home country of Kosovo last year after prosecutors accused him and his older brother of running Rydox — an illicit platform used by cybercriminals to sell stolen personal information, illegal access to devices and other tools for carrying out fraud.

Separate evidence group
Original

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not

Separate evidence group
Original

Trust and the enticing consultancy offer

In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem. Hubris might be the real vulnerability that the cyber industry must worry about.

Separate evidence group
Original

ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just

CVE-2023-38831CVE-2024-21412
Separate evidence group
Original

Exposed GitLab project email addresses let attackers push code

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]

Separate evidence group
Original

Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4 This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories . In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026 . <br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-76439,CVE-2026-76444,CVE-2026-76446,CVE-2026-76447

CVE-2026-76439CVE-2026-76444CVE-2026-76446CVE-2026-76447
Separate evidence group
Original

Kontext Security Emerges With $4 Million for AI Agent Runtime Controls

The startup’s runtime enforcement platform evaluates AI agents in real time to provide visibility and control over their actions. The post Kontext Security Emerges With $4 Million for AI Agent Runtime Controls appeared first on SecurityWeek .

Separate evidence group
Original

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," Manifold Security's Head of Research, Ax Sharma, said. "Unlike 'example[.]com,' third-party[.]com

Separate evidence group
Original

3 Cyber Threats That Defined the Summer of 2026

This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.

Separate evidence group
Original

OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data

Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information. The post OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data appeared first on SecurityWeek .

Separate evidence group
Original

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. "When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the

Separate evidence group
Original

How to Build a SASE Framework for Modern Cybersecurity

Securing edge computing requires organizations to fundamentally rethink security governance. This step-by-step guide to building a SASE framework provides the path forward. (Third in a three-part series.)

Separate evidence group
Original

FedRAMP VDR & VER: Daily Scans Are Only the Beginning

FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. [...]

Separate evidence group
Original

Ghost Service Accounts Enable M365 Data Theft in Chile

Even if the organization locks down employee accounts, forgotten and lost service accounts can still undo the organization's entire M365 environment.

Separate evidence group
Original

Kyiv internet providers report major outages after Russian attacks damage data centers

At least four internet providers serving Kyiv and other parts of Ukraine suffered partial connectivity losses following Wednesday’s drone attack, according to internet monitoring group NetBlocks.

Separate evidence group
Original

Hackers now exploit critical Roundcube flaw in code injection attacks

A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]

CVE-2020-12641CVE-2020-35730CVE-2021-44026CVE-2023-5631CVE-2025-49113CVE-2025-68461CVE-2026-48842
Separate evidence group
Original

Astrana latest healthcare tech firm to report data breach to SEC

The healthcare firm Astrana warned regulators that hackers accessed confidential information by impersonating company personnel.

Separate evidence group
Original

Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'

AI apps that interpret external data (read: most AI apps) need exceptionally rigorous security filters, or attackers can take advantage.

Separate evidence group
Original

When Business Email Compromise Starts Rewriting Reality

Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets. This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite. Our investigation disrupted the traditional BEC model in unexpected ways. We uncovered over 50 vulnerabilities, and found that several allow attackers not just to observe environments, but to actively rewrite them by impersonating senders without credentials, controlling inbox visibility, and altering shared documents and calendars. Business Email Compromise in action: Digital abuse of trust None of this is theoretical for Zimbra. But don’t take my word for it, just ask Russia . CISA keeps putting Zimbra bugs into the Known Exploited Vulnerabilities catalog , and the last three years make the point on their own: CVE-2024-45519 , command injection in the postjournal service, unauthenticated command execution. Proofpoint saw attackers stuffing base64 payloads into CC fields on September 28, 2024. CISA added it to KEV on October 3. CVE-2025-27915 , stored XSS in the Classic Web Client, triggered by a crafted .ICS attachment. It is used as a zero-day against Brazilian military targets to steal mail and quietly set forwarding filters. It went into KEV in October, 2025. CVE-2026-73570 , unauthenticated command injection through SNMP notification handling. CISA added it on August 21 of this year and gave federal agencies three days. Shadowserver has been counting somewhere north of 260 compromised instances while hunting for exploitation artifacts. Go back further and the pattern holds. Rapid7 tracked widespread exploitation of CVE-2022-27925 and CVE-2022-37042 in 2022, a path traversal chained with an authentication bypass that let attackers drop a JSP shell on a Zimbra server without credentials. Google's Threat Analysis Group later documented four separate threat groups working the same zero-day known as CVE-2023-37580. Each of these groups went after email, credentials, and authentication tokens. Attackers figured out a long time ago that the system sitting in the middle of everyone's communication is worth the effort. So when you find a set of bugs that let you write to that system instead of only reading from it, data theft stops being the interesting part. Send an email as your CFO without ever touching their password, and you have the front half of a very convincing BEC. Keep control of the mailbox afterward and you have the back half, too. Here, the attacker has a strategic choice. They can delete the sent message to hide their tracks, effectively wiping the trail of the fraud OR they can choose to leave the message in the Sent Items folder. By doing so, they ensure the CFO sees 'evidence' of the email they supposedly sent, creating a gaslighting scenario where the victim is left questioning their own actions. Whether the attacker cleans up or leaves the trail, they are shaping the organization’s perception of reality. In the ensuing investigation, where Finance sees a sent request and the CFO sees no such activity, the organization is trapped in a conflict of evidence. At that point, BEC looks less like traditional fraud and more like a psychological operation. Documents make it worse, as Zimbra is not just a mail server. The collaboration side holds the files employees actually use to make decisions. An attacker who can plant a fake HR memo or financial summary in an executive's enterprise drive, and make it look like it came from a peer they trust, is starting from a much better position than someone attaching a PDF to a cold email. Say a document shows up from HR about a confidential restructuring, and a few days later an email from a trusted executive references i

CVE-2022-27925CVE-2022-37042CVE-2023-37580CVE-2024-45519CVE-2025-27915CVE-2026-73570
Separate evidence group
Original

AI-Powered Campaign Targets Hundreds of Online Retailers

A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration. The post AI-Powered Campaign Targets Hundreds of Online Retailers appeared first on SecurityWeek .

Separate evidence group
Original

OpenAI agent breached Australian government health website, Albanese says

An OpenAI agent gained “unauthorized access” to “non-public files” from an Australian government health website in June, Prime Minister Anthony Albanese said.

Separate evidence group
Original

Windows 11 KB5124010 update released with 46 changes and fixes

Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. [...]

Separate evidence group
Original

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name "com.corp.mdm" Corp MDM

Separate evidence group
Original

Island Raises $400 Million at $6.4 Billion Valuation

The enterprise security firm has raised more than $1 billion since its launch in 2020; Evolution Equity Partners led the latest funding round. The post Island Raises $400 Million at $6.4 Billion Valuation appeared first on SecurityWeek .

Separate evidence group
Original

OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators

Revision 4 of NIST’s operational technology security guide is open for public comments until November 30. The post OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators appeared first on SecurityWeek .

Separate evidence group
Original

Begin at the End: How to Enable Agentic Remediation

Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. The post Begin at the End: How to Enable Agentic Remediation appeared first on SecurityWeek .

Separate evidence group
Original

Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are now connected to AI

Separate evidence group
Original

CISA: Ransomware gangs now exploiting critical TeamCity flaw

​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. [...]

CVE-2026-63077
Separate evidence group
Original

SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted

The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication. The post SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted appeared first on SecurityWeek .

CVE-2026-28324CVE-2026-28325CVE-2026-28326
Separate evidence group
Original

Astrana Health Data Breach Impacts Private, Confidential Information

Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers. The post Astrana Health Data Breach Impacts Private, Confidential Information appeared first on SecurityWeek .

Separate evidence group
Original

OpenAI hacked Australian Medicare govt site, probed data providers

OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project. [...]

Separate evidence group
Original

Exploit tooling coverage changed for 2 CVEs

ProjectDiscovery nuclei-templates recorded exploit-tooling coverage changes for 2 CVEs in this pinned revision. 2 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2025-11452CVE-2026-25703
Separate evidence group
Original

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense. Read

Separate evidence group
Original

US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks

Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims. The post US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks appeared first on SecurityWeek .

Separate evidence group
Original

Microsoft fixes bug that broke Windows File History backup feature

Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates. [...]

Separate evidence group
Original

Exploit tooling coverage changed for 3 CVEs

ProjectDiscovery nuclei-templates recorded exploit-tooling coverage changes for 3 CVEs in this pinned revision. 3 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2025-34033CVE-2025-62593CVE-2026-56681
Separate evidence group
Original

Critical WordPress Vulnerability Exploited Immediately After Disclosure

Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. The post Critical WordPress Vulnerability Exploited Immediately After Disclosure appeared first on SecurityWeek .

CVE-2026-87902
Separate evidence group
Original

OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files

An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said. The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not public, but no personal

Separate evidence group
Original

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –

Separate evidence group
Original

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file

CVE-2026-87902
Separate evidence group
Original

ProjectDiscovery nuclei-templates corpus synchronized

The pinned corpus revision was recorded with provenance. No new or materially changed exploit-intent artifact affected a known CVE, so CVE threat scores were not changed.

Separate evidence group
Original

Exploit tooling coverage changed for 2 CVEs

ProjectDiscovery nuclei-templates recorded exploit-tooling coverage changes for 2 CVEs in this pinned revision. 2 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2026-87902CVE-2026-89063
Separate evidence group
Original