2026-09-16 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-17 00:20 UTC
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of NoMachine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-92210.
P5
2026-09-16 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-17 00:20 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92209.
P15
2026-09-16 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-17 00:20 UTC
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NoMachine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92208.
P20
2026-09-16 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-17 00:20 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Secure Firewall Management Center. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2026-20242.
P20
2026-09-16 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-16 15:20 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3.
P10
2026-09-16 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-16 15:20 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of MindsDB. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92207.
P20
2026-09-16 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-16 15:20 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CrewAI crewAI. User interaction is required to exploit this vulnerability in that the target must load a malicious agent configuration from the repository. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92206.
P20
2026-09-16 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-16 15:20 UTC
This vulnerability allows remote attackers to create arbitrary files on affected installations of BusyBox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-92205.
P5
2026-09-16 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-16 15:20 UTC
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92204.
P5
2026-09-16 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-16 15:20 UTC
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92203.
P5
2026-09-16 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-16 02:20 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-16 01:00 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-09-16 01:00 UTC
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.
P0
2026-09-15 22:21 UTC
Vendor Research
AWS Security Blog · Rishi Tripathy · indexed 2026-09-15 22:45 UTC
AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed policy size and the overall session token size limits with a single token size limit of 4,096 bytes. STS now reports session token size in API responses, […]
P0
2026-09-15 21:37 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-15 21:45 UTC
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]
P55
2026-09-15 20:46 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-15 21:35 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76461 this week; […]
P60
2026-09-15 20:36 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities…
P5
2026-09-15 20:34 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-08 16:35 UTC
A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software. This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI…
P5
2026-09-15 20:34 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-15 20:35 UTC
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]
P0
2026-09-15 20:24 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-15 20:40 UTC
Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.
P0
2026-09-15 20:16 UTC
Security Journalism
Dark Reading · Rob Wright · indexed 2026-09-15 20:35 UTC
You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.
P0
2026-09-15 20:01 UTC
Security Journalism
The Record · indexed 2026-09-15 20:20 UTC
Oslo-based Telenor potentially enabled crimes against humanity and violated sanctions in its dealings with the military regime that took over Myanmar in 2021, Norwegian authorities said.
P0
2026-09-15 19:30 UTC
Security Journalism
Security Week · Sravish Sridhar · indexed 2026-09-15 19:40 UTC
Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. The post “We Think the Security Control Is Working” Is No Longer Good Enough appeared first on SecurityWeek.
P0
2026-09-15 19:27 UTC
Security Journalism
Dark Reading · Black Hat Staff · indexed 2026-09-15 19:35 UTC
At Black Hat USA, OpenAI engineers reconstruct the Hugging Face incident and explore lessons learned about AI safeguards and cyber resilience.
P0
2026-09-15 19:00 UTC
Vendor Research
AWS Security Blog · Abrom Douglas · indexed 2026-09-15 19:30 UTC
Your consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and engage with your applications. As your business scales across geographies, ensuring authentication is always available becomes a core architectural requirement. However, building multi-Region authentication has traditionally required complex custom replication solutions that […]
P0
2026-09-15 18:54 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 19:10 UTC
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and
P0
2026-09-15 17:00 UTC
Vendor Research
Tenable Blog · Research Special Operations · indexed 2026-09-15 21:15 UTC
Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates.Key TakeawaysThe September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates104 issues (15.5% of all patches) were assigned a critical severity ratingOracle E-Business Suite received the highest number of patches at 159, accounting for 23.6% of all patchesBackgroundOn September 15, Oracle released its Critical Securit…
P5
2026-09-15 16:45 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-15 17:05 UTC
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.
P0
2026-09-15 16:40 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-15 16:45 UTC
CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]
P0
2026-09-15 16:29 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 17:45 UTC
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record
P0
2026-09-15 16:28 UTC
Security Journalism
The Record · indexed 2026-09-15 16:35 UTC
According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists.”
P0