2026-09-07 — Kritieke RCE in voorbeeldproduct 2026-09-07 — Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gateway 2026-09-07 — Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts 2026-09-07 — Kwetsbaarheid verholpen in N-central van N-able 2026-09-07 — Hackers exploit new MikroTik RouterOS flaws to hijack routers 2026-09-07 — ConnectWise warns of new ScreenConnect flaw without patch 2026-09-07 — N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw 2026-09-07 — JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies 2026-09-07 — N-able patches max severity N-central flaw amid ongoing attacks 2026-09-06 — A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The manipulation of the argument ID results in authorization bypass. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet. 2026-09-06 — commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources. 2026-09-06 — A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. 2026-09-06 — league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting in O(K^2) time complexity for K headings that collapse to the same base slug. The vulnerable path is reached when HeadingPermalinkExtension, FootnoteExtension, or TableOfContentsExtension is registered. An unauthenticated attacker can force many headings onto a single base slug (e.g., via empty ATX headings, identical heading text, or punctuation-only headings) in a small Markdown document, consuming excessive CPU and denying service. 2026-09-06 — A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. 2026-09-06 — A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects an unknown part of the file App/Home/Model/UserModel.class.php of the component Cookie Helper. Executing a manipulation of the argument Username can lead to improper authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet. 2026-09-07 — Kritieke RCE in voorbeeldproduct 2026-09-07 — Kwetsbaarheden verholpen in Citrix NetScaler ADC en NetScaler Gateway 2026-09-07 — Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts 2026-09-07 — Kwetsbaarheid verholpen in N-central van N-able 2026-09-07 — Hackers exploit new MikroTik RouterOS flaws to hijack routers 2026-09-07 — ConnectWise warns of new ScreenConnect flaw without patch 2026-09-07 — N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw 2026-09-07 — JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies 2026-09-07 — N-able patches max severity N-central flaw amid ongoing attacks 2026-09-06 — A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Cancellation. The manipulation of the argument ID results in authorization bypass. The attack may be performed from remote. The exploit is now public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet. 2026-09-06 — commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate footnote definitions. Attackers can craft documents with duplicate footnote definitions and references to create quadratic output expansion, consuming excessive memory and CPU to exhaust server resources. 2026-09-06 — A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6610P-DTA 1.2.1_20251110. This affects the function basicstation_apply of the component Basic Station Certificate-Deletion Handler. This manipulation of the argument act causes command injection. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 1.2.4_20260821 is able to mitigate this issue. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. 2026-09-06 — league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normalize(), which restarts its numeric-suffix search from 1 on every slug collision, resulting in O(K^2) time complexity for K headings that collapse to the same base slug. The vulnerable path is reached when HeadingPermalinkExtension, FootnoteExtension, or TableOfContentsExtension is registered. An unauthenticated attacker can force many headings onto a single base slug (e.g., via empty ATX headings, identical heading text, or punctuation-only headings) in a small Markdown document, consuming excessive CPU and denying service. 2026-09-06 — A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. 2026-09-06 — A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects an unknown part of the file App/Home/Model/UserModel.class.php of the component Cookie Helper. Executing a manipulation of the argument Username can lead to improper authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.

Perceptive moderniseert SOC's voor de wereld van morgen.

Perceptive Security biedt gespecialiseerde cybersecurity-consultancy en diensten voor Security Operations Centers. Perceptive versterkt SOC-capaciteiten door moderne SIEM-oplossingen te implementeren, aangevuld met XDR-, SOAR- en AI-technologie. Dit zorgt voor vroegtijdige dreigingsdetectie en een efficiëntere incidentrespons met behulp van de nieuwste technologieën.

GRATIS Cyber Security Early Warning Service
SIEM
Perceptive Security ontwerpt en implementeert geavanceerde SIEM-oplossingen, verbindt al uw logbronnen en integreert moeiteloos met externe systemen om een SOC te voorzien van snelle, efficiënte en toekomstgerichte beveiligingsmonitoring.
EDR/XDR
Omdat traditionele logbronnen onvoldoende zicht bieden op geavanceerde dreigingen, is XDR-technologie essentieel. Perceptive helpt organisaties met de implementatie en fijnregeling van XDR-oplossingen voor snellere detectie en effectievere respons.
SOAR
SOAR neemt repetitieve incidentrespons-taken uit handen, zodat analisten zich kunnen richten op wat écht telt. Perceptive helpt bij de implementatie en automatisering, waardoor uw SOC sneller, slimmer en effectiever reageert.
Threat Intel
Door threat intelligence-platforms te integreren met SIEM- en SOAR-tools krijgen SOC-teams bruikbare inzichten in opkomende aanvalstechnieken, gedrag van criminelen en kwetsbaarheden.
Detection Engineering
Ons team kan de dreigingsdetectie optimaliseren zodat cyberaanvallen zo snel mogelijk worden ontdekt. We kunnen helpen met gap-analyses voor een omgeving en aanvullende detectielogica schrijven om het risico te minimaliseren.
AI / ML
Door AI te koppelen aan SIEM- en SOAR-platformen automatiseren we routinematige analyses, verrijken we meldingen met diepere context en stellen we analisten in staat dreigingspatronen veel sneller te doorzien.

email: info@perceptivesecurity.com
of bel +31202246506