Tag: vulnerability
-
Instascan erkennt Schwachstellen innerhalb weniger Minuten nach ihrer Bekanntgabe
Tags: vulnerabilityQualys stellt <> vor, eine auf Agent-Insta basierende neue Funktion innerhalb von Qualys-Enterprise -Trurisk-Management (ETM). Instascan schließt die Lücke zwischen der Offenlegung und der Erkennung von Schwachstellen, indem sie die von Unternehmen bereits erfassten Asset-Telemetriedaten in kontinuierliche Transparenz über Sicherheitsrisiken umwandelt. Die Erkennungsgeschwindigkeit der Branche ist seit 2025 ins Stocken geraten. In den ersten sieben…
-
CISA Adds Exploited N-able N-central Flaw Enabling Remote Admin Takeover to KEV
Tags: authentication, cisa, cve, cyber, cybersecurity, exploit, flaw, infrastructure, kev, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-18577, an actively exploited authentication bypass vulnerability in N-able N-central, to its Known Exploited Vulnerabilities (KEV) Catalog. This vulnerability allows unauthenticated attackers to bypass authentication and potentially take over administrative accounts on vulnerable N-central servers. CISA added this flaw to the KEV Catalog on August…
-
U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a N-able N-central flaw, tracked as CVE-2026-18577 (CVSS score of 8.2), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-18577 (CVSS 8.2) is an authentication bypass flaw caused by an…
-
When AI Agents Meet Real Infrastructure: Hype, Human Error or a Genuine New Threat?
Just days after OpenAI disclosed that one of its security research agents had escaped a testing sandbox by exploiting a previously unknown vulnerability, Anthropic revealed that its own AI models had compromised three real organisations during a cybersecurity evaluation after a configuration error inadvertently gave them internet access. The similarities between the two incidents have…
-
How Vulnerable Are Single Sign-On Systems to Modern Credential Attacks?
SSO credential attacks explained: how vishing, MFA resets, stale OAuth tokens and admin takeover break SSO, and the controls that stop each one. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/how-vulnerable-are-single-sign-on-systems-to-modern-credential-attacks/
-
How companies could share cyber risks without exposing their secrets
A cryptographic technique could let companies prove they’re vulnerable to critical flaws without revealing the sensitive data that attackers could exploit. First seen on cyberscoop.com Jump to article: cyberscoop.com/zero-knowledge-proofs-cyber-risk-sharing-op-ed/
-
Critical Gitea Flaw Lets Unauthenticated Attackers Read Server Files and Execute Code
A critical vulnerability in Gitea has been identified, potentially allowing unauthenticated remote attackers to read arbitrary files on vulnerable servers and escalate to remote code execution (RCE). This vulnerability is tracked as CVE-2026-59774 and GHSA-6v53-hr58-556r, affecting Gitea versions from 1.22.11.22.11.22.1 to 1.27.01.27.01.27.0. It has been assigned a critical CVSS score of 3.1, with an attack…
-
Critical Adobe Campaign Flaws Let Unauthenticated Attackers Execute Arbitrary Code
Adobe has released an urgent security update for Adobe Campaign Classic, addressing multiple critical vulnerabilities that could allow remote attackers to execute arbitrary code on vulnerable servers without authentication. The update is documented in bulletin APSB26-120, published on August 3, 2026, and carries Adobe’s highest Priority 111 rating. The company urges organizations that use affected…
-
macOS CUPS Flaw Lets Local Attackers Write Arbitrary Files as Root
A recently disclosed privilege-related vulnerability in the Common UNIX Printing System (CUPS) on macOS could allow an unprivileged local user to create attacker-controlled files in arbitrary locations outside the protection of System Integrity Protection (SIP), thereby gaining root ownership. This flaw, tracked as CVE-2026-39875, affects Apple devices running macOS Sonoma, Sequoia, and Tahoe versions before…
-
The U.S. Cyber Strategy Has a Scaling Problem and AI Is Exposing It
AI can discover and weaponize software vulnerabilities faster than organizations can patch them, making exploit mitigation and runtime protection essential to cybersecurity. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/the-u-s-cyber-strategy-has-a-scaling-problem-and-ai-is-exposing-it/
-
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild.The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows First seen…
-
Critical Check Point Flaw Lets Unauthenticated Attackers Execute Commands on Management Servers
Check Point has disclosed a high-severity authentication bypass vulnerability that could allow unauthenticated attackers to execute arbitrary commands on vulnerable Security Management Servers and Multi-Domain Security Management Servers (MDS). This vulnerability is tracked as CVE-2026-18574 and is detailed in Check Point Security Alert sk185222. It affects multiple legacy and current versions of their management platform.…
-
cPanel Database Privilege Escalation Flaw Enables Full Administrative Access
CVE-2026-58048 is a critical privilege-escalation vulnerability in the database management functionality of cPanel & WHM. This flaw allows an authenticated cPanel user to execute arbitrary database commands with full administrative privileges. cPanel Database Privilege Escalation Flaw All supported versions of cPanel & WHM before the recently released security updates are affected. As WebPros states, an…
-
Thermo Fisher DNA Analysis Software Flaw Lets Attackers Secretly Alter Test Data
Thermo Fisher Scientific has released security updates for a high-severity flaw in its Applied Biosystems Human Identification (HID) software. This vulnerability could allow nearly undetectable manipulation of DNA test data files before analysis. The issue, tracked as CVE-2026-17583, carries a CVSS v4 score of 8.2 and affects .fsa and .hid file outputs used in forensic…
-
CrowdStrike 2026 Threat Hunting Report: KI ist heute fester Bestandteil moderner Cyberangriffe
Cyberangreifer operationalisieren künstliche Intelligenz nicht nur, um Schwachstellen innerhalb von Stunden auszunutzen, sondern auch, um KI, die in Unternehmen eingesetzt wird, anzugreifen. Zudem nutzen Angreifer sie auch, um Angriffe entlang der Software-Lieferkette zu skalieren. CrowdStrike hat am 3. August den 2026 Threat Hunting Report veröffentlicht, der verdeutlicht, wie sehr künstliche Intelligenz mittlerweile Bestandteil von… First…
-
The End of Centralized Enrichment: What NIST’s NVD Shift Means for Vulnerability Management
There’s an assumption baked into most vulnerability management programs that nobody ever wrote down, because nobody had to. When a CVE gets published, NVD enriches it. You get a severity score, product mappings, weakness categorization. All the context your tools and workflows need to actually do something. It was just how the system worked. In..…
-
Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities
Google is testing twice-weekly Chrome security updates as AI tools uncover more vulnerabilities and the company works to shrink the browser’s patch gap. The post Google Tests Twice-Weekly Chrome Security Updates as AI Finds More Vulnerabilities appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-chrome-twice-weekly-security-updates/
-
COLDCARD-Schwachstelle: Für Bitcoin-Diebstahl von 88 Millionen Dollar verantwortlich?
Eine Schwachstelle in der Firmware der Hardware-Wallet COLDCARD steht mutmaßlich hinter dem Diebstahl von umgerechnet rund 88,6 Millionen US-Dollar in Bitcoin. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/coldcard-bitcoin-diebstahl
-
N-able N-central Vulnerability Under Active Exploitation
Threat actors are actively exploiting an N-able N-central vulnerability that can grant unauthenticated administrative access. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/n-able-n-central-vulnerability-under-active-exploitation/
-
N-Able Flaw Exposes MSPs to Worst Case Scenario
Remote Management and Monitoring Tools Widely Used by Managed Security Providers. Remote management and monitoring software developer N-Able published a second hotfix to patch a vulnerability in all versions of its N-central software being actively exploited by attackers. Many managed security providers use its software to remotely administer customers’ systems. First seen on govinfosecurity.com Jump…
-
N-able warns of N-central auth bypass flaw exploited in attacks
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/n-able-warns-of-n-central-auth-bypass-flaw-exploited-in-attacks/
-
N-able N-central Flaw Sees Exploitation: 5 Things To Know
Attackers have exploited a high-severity vulnerability in N-able’s N”‘central remote monitoring and management (RMM) platform, the company disclosed. First seen on crn.com Jump to article: www.crn.com/news/security/2026/n-able-n-central-flaw-sees-exploitation-5-things-to-know
-
China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day
Chinese actors exploited the critical React2Shell exploit inside a day, while 88% of exploited vulnerabilities in H1 2026 were compromised within 48 hours of disclosure First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/chinalinked-threat-actors/
-
Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)
Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/cve-2026-18577-n-able-n-central-vulnerability/
-
TP-Link TL-WR940N Router Flaw Lets Unauthenticated Attackers Execute Code Remotely
TP-Link has announced a high-severity security vulnerability in its TL-WR940N v6 wireless router that could allow an unauthenticated remote attacker to execute arbitrary code and potentially take full control of the affected device. This vulnerability is tracked as CVE-2026-12935 and has a CVSS v4.0 score of 8.7, categorized as high. TP-Link TL-WR940N Router Flaw According…
-
How volunteer cyber experts are helping protect rural water systems
A first-in-the-nation program is seeing promising results as it charts a path for supporting the U.S.’s most vulnerable infrastructure. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/water-cybersecurity-def-con-franklin-outcomes/826517/
-
Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers
A Chinese threat actor operating under the aliases >>knaithe<>KnYuan<< used multiple LLMs to automate cyberattacks against internet-facing systems … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/03/deepseek-ai-autonomous-cyberattacks-hermes-agent/
-
AI pentesting tools are generating more findings than security teams can validate, new survey finds
New research from Pentest-Tools.com suggests that AI-assisted penetration testing tools are generating vulnerability findings faster than most security teams can verify them, creating a validation backlog that is offsetting the time AI was meant to save. The company surveyed 158 security practitioners in June 2026, including penetration testers, security engineers, AppSec and DevSecOps professionals, consultants,…

