Overzicht van binnengekomen advisories.
1553 resultaten gevonden
Combodo iTop, a web-based IT service management tool, was found to contain a Reflected Cross-Site Scripting (XSS) vulnerability in its foreign key search criteria API. The vulnerability affects versions prior to 3.2.3. Reflected XSS vulnerabilities allow attackers to inject malicious scripts into web pages viewed by other users, potentially leading to session hijacking, credential theft, or other client-side attacks. The issue has been assigned CVE-2026-33240 and was fixed in version 3.2.3. A patch commit is available on GitHub along with a security advisory. Users are advised to upgrade to iTop 3.2.3 or later to mitigate this risk.
Bekijk origineel advisory →A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in Combodo iTop, a web-based IT service management tool. The vulnerability exists in the dashboard save functionality and affects versions prior to 3.2.3. Reflected XSS vulnerabilities allow attackers to inject malicious scripts that are reflected off the web server to the victim's browser. The flaw could be exploited to steal session cookies, redirect users, or perform actions on behalf of authenticated users. The issue has been addressed and patched in iTop version 3.2.3. A fix has been committed to the official GitHub repository and a security advisory has been published. Users are strongly advised to upgrade to version 3.2.3 or later. The vulnerability is tracked under CVE-2026-30865 and has an associated GitHub Security Advisory GHSA-8j4q-ccr6-wpmj.
Bekijk origineel advisory →Socket has expanded its security coverage to Firefox, scanning over 97,000 extensions in Mozilla's official directory for malicious behavior, risky updates, and supply chain threats. Research identified 77 linked malicious Firefox extension identities active from March through August 2026, with 40 confirmed malicious and 37 deceptive shells. These extensions delivered wallet-phishing pages, stole crypto recovery phrases and private keys, and exfiltrated credentials and clipboard contents. A key attack pattern involved legitimate-looking extensions being repurposed via automatic updates to deliver malware without triggering new permission prompts. Some malicious extensions transitioned from sports-score or utility tools to Rabby-style wallet stealers. Socket's platform provides visibility, threat detection, update monitoring, and ecosystem context to help enterprise security teams track extension behavior changes. The Firefox extension protection feature is now available in experimental status for Socket enterprise customers.
Bekijk origineel advisory →Three suspected Russian cyber espionage clusters β UNC6293, UNC7005, and UNC5976 β have been observed abusing legitimate authentication flows, including Google OAuth and WhatsApp linking, to hijack accounts. The threat actors are targeting individuals in academia, aerospace and defense, government, and think tanks across Europe and the United States. The clusters engage in persistent and adaptive tactics to gain unauthorized access. The use of legitimate authentication mechanisms makes detection significantly more difficult. This campaign reflects a broader trend of state-sponsored actors exploiting trusted platforms to conduct espionage operations.
Bekijk origineel advisory →Attackers compromised the maintainer account of the widely used Rust crate 'arrayref' to inject malicious code that executes during the compilation process on developers' systems. The attack represents a supply chain compromise targeting the Rust ecosystem, where developers unknowingly pull in malicious code as a dependency. The malware delivered is classified as an infostealer, designed to harvest sensitive information from affected developer machines. This type of attack is particularly dangerous because it targets the build pipeline, meaning any project depending on arrayref could have been silently compromised. The incident highlights ongoing risks in open-source package ecosystems where account takeover can lead to widespread downstream impact. Developers using the arrayref crate are advised to audit their dependencies and check for unauthorized changes to the package.
Bekijk origineel advisory →This weekly cybersecurity roundup covers multiple high-impact threats including a remote code execution vulnerability in Gogs 10.0, workflow-to-RCE in n8n, a $10M reward announcement, and AI-assisted exploit research using GLM-5.3. The article highlights a recurring theme of trusted components being weaponized, including signed drivers turned against defenses and legitimate applications used to blend in malware. A weak header check vulnerability is noted as enabling code execution. The piece also references exposed systems, unpatched legacy bugs, and novel evasion techniques. AI-assisted exploit research is identified as a key trend lowering the barrier for attackers. The overall tone signals a broad and diverse threat landscape with multiple active attack surfaces.
Bekijk origineel advisory →The U.S. government issued a warning about an active threat campaign targeting critical infrastructure using AI-generated exploit scripts. The activity focuses on Siemens S7 Series Programmable Logic Controllers (PLCs), conducting reconnaissance and capability development. The threat actors are using AI-generated scripts disguised as legitimate monitoring tools to evade detection. The campaign represents a novel use of AI in offensive cyber operations against industrial control systems. The targeting of PLCs in critical infrastructure raises significant concerns about potential disruption to essential services. This activity highlights the growing intersection of AI technology and nation-state or sophisticated threat actor operations.
Bekijk origineel advisory →Malicious versions of the arrayref Rust crate and other packages were found executing a backdoor at compile time, targeting developers through the Rust ecosystem. The campaign's infrastructure shows significant overlap with known North Korean (DPRK) supply chain attacks, including those involving the Mastra and axios packages. The attack is a compile-time supply chain compromise, meaning the malicious code runs during the build process rather than at runtime. This technique makes detection harder as traditional runtime security tools may miss it. The campaign is attributed to DPRK-linked threat actors based on infrastructure overlaps with prior operations. Developers using affected crates may have unknowingly executed malicious code during their build pipelines.
Bekijk origineel advisory →Three legitimate Rust crates (arrayref@0.3.10, internment@0.8.7, append-only-vec@0.1.9) maintained by David Roundy were compromised by a threat actor who injected a malicious dependency called proc-macro1, a typosquat of the legitimate proc-macro2 crate. The malicious build.rs script executed automatically during Cargo builds, downloading and executing cross-platform malware targeting Linux, macOS, and Windows. The stage-2 backdoor profiled hosts, inventoried browsers, established persistence, and beaconed to a C2 at 23.254.165.112. The threat actor also yanked older legitimate arrayref releases to steer dependency resolution toward the malicious version. Socket's AI Scanner detected the attack on August 20, 2026, and the Rust Security Response Team removed affected releases and locked the maintainer account. Any system that built one of the malicious versions should be treated as potentially compromised, with credentials rotated and persistence mechanisms investigated.
Bekijk origineel advisory →A critical vulnerability has been discovered in the Elementor Pro WordPress plugin that could allow attackers to upload executable files to vulnerable servers. This flaw enables remote code execution (RCE), posing a severe risk to WordPress sites using the plugin. Attackers exploiting this vulnerability could gain full control over affected servers. The issue is classified as critical due to the ease of exploitation and the widespread use of Elementor Pro across WordPress installations. Website administrators are urged to update the plugin immediately to mitigate the risk. No CVE identifier is explicitly mentioned in the available content.
Bekijk origineel advisory →A critical security vulnerability (GHSA-864f-rcv7-6rh4) has been disclosed in isolated-vm, a widely-used open-source JavaScript sandbox library with over 2,900 GitHub stars. The flaw affects all versions up to and including 7.0.0 and has not yet been assigned a CVE identifier. The vulnerability allows attackers to escape the isolated sandbox environment and potentially execute code on the host system, enabling remote code execution (RCE). Isolated-vm is commonly used by developers to safely run untrusted JavaScript code in Node.js applications. The sandbox escape nature of this flaw makes it particularly severe, as it undermines the core security guarantee of the library. Users and organizations relying on isolated-vm for security isolation are urged to review their usage and apply patches as they become available.
Bekijk origineel advisory →Citrix has released security updates addressing two vulnerabilities in NetScaler ADC and NetScaler Gateway. The most severe is a critical authentication bypass flaw affecting customer-managed deployments. The vulnerability impacts certain FIPS and NDcPP builds as well as SecurAccess configurations. Both NetScaler ADC and NetScaler Gateway products are affected. The flaws are specific to customer-managed environments rather than Citrix-managed cloud services. Organizations running affected versions are urged to apply the patches immediately given the critical severity rating. Authentication bypass vulnerabilities in gateway and AAA servers pose significant risk as they can allow unauthorized access to protected resources.
Bekijk origineel advisory →A patched security vulnerability in Zimbra Collaboration (ZCS), tracked as CVE-2026-73570 with a CVSS score of 8.9, is being actively exploited in the wild. The flaw is a command injection vulnerability that enables unauthenticated remote code execution. The active exploitation was reported by CERT Polska (Polish Computer Emergency Response Team). The vulnerability resides in Zimbra's SNMP component and allows remote attackers to execute arbitrary commands without authentication. Organizations running affected versions of Zimbra Collaboration are urged to apply the available patch immediately. The high CVSS score reflects the critical nature of the flaw, given its unauthenticated and remote exploitability.
Bekijk origineel advisory →Researchers disclosed two denial-of-service attacks dubbed 'CDN Tsunami' that exploit how major CDNs translate HTTP/3 client traffic into HTTP/1.1 requests forwarded to origin servers. The attack achieves up to 350x amplification of low-bandwidth request streams against origin servers. The vulnerability was evaluated against major CDN providers including Alibaba and Baidu. The attack abuses the protocol translation layer inherent in CDN architectures, allowing attackers to generate disproportionately large traffic volumes at the origin with minimal effort. This represents a significant threat to websites relying on CDNs for traffic management and DDoS protection. The findings highlight a systemic weakness in how CDNs handle HTTP/3 to HTTP/1.1 conversion, potentially affecting a wide range of CDN-dependent services globally.
Bekijk origineel advisory →A new Android malware strain called Manic has been discovered actively targeting Ukrainian banks, government agencies, identity services, and messaging apps, as well as Russian and European financial institutions, global fintech and cryptocurrency platforms, and military communications. Manic combines capabilities of both banking malware and mobile spyware, enabling financial fraud alongside surveillance. A particularly notable feature is its ability to exfiltrate data from offline phones by leveraging nearby infected devices, suggesting advanced peer-to-peer or proximity-based communication mechanisms. The malware represents a sophisticated threat actor operation with geopolitical dimensions, given its focus on Ukrainian and Russian targets amid ongoing conflict. Its dual-purpose nature makes it especially dangerous for both financial and national security contexts.
Bekijk origineel advisory →CVE-2026-72530 is a code injection vulnerability affecting TrueConf Server that allows an unauthorized remote attacker with network access via port 4307/TCP to execute arbitrary code on the host system. The attacker can use a specially crafted script to break out of the server's isolated environment and gain access to the underlying host. This vulnerability does not require authentication, making it particularly dangerous for exposed deployments. The issue has been documented by Kaspersky ICS-CERT and is tracked by CISA, with fixes and advisories published by TrueConf. The vulnerability falls under CISA's BOD 26-04 directive, which prioritizes security updates based on risk, and forensic triage requirements have been outlined. Organizations running TrueConf Server are urged to apply available security fixes immediately.
Bekijk origineel advisory →CVE-2026-72529 is a missing authentication for critical function vulnerability affecting TrueConf Server. A remote, unauthenticated attacker with network access via port 4307/TCP can exploit this vulnerability to execute arbitrary scripts. The vulnerability is classified as critical due to its unauthenticated remote exploitation potential. It is tracked by CISA and listed in advisories from Kaspersky ICS-CERT and TrueConf's own security blog. The vulnerability is subject to CISA's BOD 26-04 directive, which prioritizes security updates based on risk. Forensics triage requirements are also outlined under the BOD 26-04 implementation guidance. Organizations running TrueConf Server are urged to apply available security fixes immediately.
Bekijk origineel advisory →A stack-based buffer overflow vulnerability has been identified in Comfast CF-N1-S version 2.6.0.1. The flaw exists in the function sub_44B50C within the Web Management component, specifically via the /cgi-bin/mbox-config?method=SET§ion=ptest_channel endpoint. An attacker can exploit this vulnerability remotely without requiring physical access to the device. The vulnerability allows manipulation of input data leading to a stack-based buffer overflow condition. A public exploit has already been released, increasing the risk of active exploitation. This affects network/IoT devices running the affected firmware version. The vulnerability has been assigned CVE-2026-77148 and is tracked by NVD and VulDB. Users of the Comfast CF-N1-S 2.6.0.1 firmware should apply patches or mitigations as soon as they become available.
Bekijk origineel advisory →A SQL injection vulnerability has been identified in CodeAstro Apartment Visitor Management System version 1.0. The vulnerability exists in the password-recovery.php file, where manipulation of the email argument allows SQL injection attacks. The flaw can be exploited remotely without requiring physical access to the system. A public exploit is already available, increasing the risk of active exploitation. The vulnerability affects an unknown functionality within the password recovery flow. Attackers could potentially extract or manipulate database contents through this vector. The issue has been catalogued under CVE-2026-77020 and reported via VulDB and GitHub.
Bekijk origineel advisory →CVE-2026-18835 affects IBM AIX versions 7.2 and 7.3, as well as IBM PowerVM VIOS 4.1. The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the affected system. The root cause is improper neutralization of special elements used in OS commands, classified as a command injection vulnerability. Successful exploitation could lead to full system compromise by an authenticated remote attacker. IBM has published a support advisory with remediation guidance. The vulnerability carries a high severity rating given its remote exploitability and potential for arbitrary command execution.
Bekijk origineel advisory →