Cybersecurity News & Intelligence
Curated security news aggregated from leading threat intelligence blogs, vendor advisories, and research publications. AI-summarized in English, German, Spanish, and French to keep your team informed across language barriers.
BND and Verfassungsschutz will receive more powers to actively counter threats, breaking with fundamental principles.
The Trusted Platform Module, a key component in PC trust chains, is vulnerable to attacks.
A set of 737 free VPN and proxy extensions were found to target Russian-speaking users, intercepting browser traffic and routing it through a proxy infrastructure.
Attackers crash Cisco Secure Firewall Adaptive Security Appliance after attacks, a security patch is available.
Threat actors exploit multiple vulnerabilities to breach security, analysts must connect isolated alerts to understand the full attack chain.
Attackers exploited Windows AFD.sys zero-day before Microsoft's August 2026 Patch Tuesday fix, enabling SYSTEM privilege escalation.
An attacker can exploit multiple NGINX vulnerabilities to gain elevated privileges, execute arbitrary code, bypass security measures, expose sensitive data, or trigger a Denial-of-Service state.
An anonymous attacker can exploit multiple vulnerabilities in Red Hat Enterprise Linux AI to execute arbitrary code, disclose confidential information, or trigger a Denial-of-Service state.
An attacker can exploit multiple vulnerabilities in Cacti to execute arbitrary code, enabling attacks like Cross-Site Scripting and SQL-Injection.
Attackers can exploit multiple vulnerabilities in Golang Go to cause memory damage, execute arbitrary code, bypass security measures, trigger a Denial-of-Service state, or other unspecified attacks.
An attacker can exploit multiple vulnerabilities in the Linux Kernel to perform a Denial of Service attack or other unspecified impacts.
An attacker can exploit multiple vulnerabilities in Mozilla Firefox to perform an unspecified attack. The attack is enabled by the vulnerabilities, but the specifics are not disclosed.
An attacker can exploit multiple vulnerabilities in Golang Go to gain elevated privileges, perform cross-site scripting attacks, bypass security measures, or cause a denial-of-service state.
An attacker can exploit multiple vulnerabilities in Google Chrome to cause unspecified impacts, including possible code execution, security bypass, information disclosure, or denial-of-service.
An attacker can exploit multiple vulnerabilities in IBM InfoSphere Information Server to execute arbitrary code, perform a denial of service attack, disclose information, and bypass security measures.
An authenticated attacker can exploit multiple vulnerabilities in OPNsense to execute arbitrary code, bypass security measures, and manipulate data.
An anonymous attacker can exploit multiple Linux Kernel vulnerabilities to perform an unspecified attack, potentially executing arbitrary code, disclosing information, manipulating data, or causing denial-of-service states.
Researchers recovered internal reasoning and secrets from session logs, including API keys and passwords, due to a flaw in OpenAI, Anthropic, and Google's API calls.
An attacker can exploit multiple vulnerabilities in various Microsoft Windows products to execute arbitrary code and elevate privileges.
Attackers are winning by making silent attacks, while enterprise defenses are having a strong year in prevention effectiveness.
An anonymous attacker can exploit a vulnerability in Red Hat Enterprise Linux (python-idna) to perform a Denial of Service attack. This vulnerability allows an attacker to disrupt system functionality.
An anonymous attacker can exploit a vulnerability in Microsoft Edge to execute arbitrary code.
An attacker can exploit multiple vulnerabilities in Zoom Video Communications Workplace and Rooms to execute arbitrary code, disclose sensitive data, or trigger a Denial-of-Service state.
A local attacker can exploit multiple vulnerabilities in AMD processor to elevate privileges or cause a Denial of Service.
An attacker can exploit multiple MongoDB vulnerabilities to bypass security measures, perform a Denial of Service attack, expose information, manipulate files, and execute arbitrary code.
An attacker can exploit multiple vulnerabilities in libpng to perform a Denial of Service attack. This can be done by leveraging the weaknesses in the library.
Threema's messenger experienced outages due to DDoS attacks, starting with a service provider attack on Tuesday and continuing on Wednesday.
Adobe patches three critical security vulnerabilities in ColdFusion, Commerce, and Campaign Classic with CVSS score 10.0, allowing arbitrary code execution and privilege escalation.
An authenticated attacker can exploit multiple vulnerabilities in Snipe-IT to bypass security measures, manipulate data, or trigger a Denial-of-Service state.
An anonymous attacker can exploit a vulnerability in CyberPanel to expose information. This vulnerability allows unauthorized access to sensitive data.