Bron & ernst

Uw branche
AI Security Medium
31 jul 2026

[Security.NL] Anthropic zegt verantwoordelijk te zijn voor het hacken van drie bedrijven

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Anthropic zegt verantwoordelijk te zijn voor het hacken van drie bedrijven en het uploaden van malware naar de Python Package ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
31 jul 2026

Multiples vulnérabilités dans les produits IBM (31 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
28 jul 2026

IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
8 jul 2026

[webapps] Krayin CRM v2.2.x - Authenticated Remote Code Execution

Industrie & Productie

Krayin CRM v2.2.x - Authenticated Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
30 jul 2026

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

Financieel & VerzekeringenTransport & Logistiek

Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Hoog
22 jul 2026

LG to Ban Residential Proxies from Smart TV Apps

Industrie & ProductieTransport & Logistiek

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Kritiek
30 jul 2026

Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Grou…

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
30 jul 2026

CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Updated an acknowledgement. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Medium
31 jul 2026

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

Zorg & GezondheidFinancieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential t…

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NL Medium
31 jul 2026

NCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk

Financieel & VerzekeringenIndustrie & ProductieEnergie & Nutsbedrijven

SolarWinds heeft een kwetsbaarheid verholpen in SolarWinds Web Help Desk. De kwetsbaarheid betreft een authenticatiebypass in de SAML 2.0 authenticatie van SolarWinds Web Help Desk. Deze kwetsbaarheid treedt op in systemen waarbij SAML-authenticatie is ingeschakeld.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
23 jul 2026

UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerce

GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
10 jul 2026

CVE-2026-59792 — CVSS 9.6 CRITICAL

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerce

In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
31 jul 2026

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

Financieel & VerzekeringenRetail & E-commerce

Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
SANS ISC Hoog
29 jul 2026

Apple Patches Everything (July 2026), (Wed, Jul 29th)

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only covered the current 26 versions.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Medium
31 jul 2026

Onderzoekers waarschuwen voor vooraf besmette Android tv-sticks

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Onderzoekers waarschuwen voor Android tv-sticks die ook in Nederland worden verkocht en vooraf met malware zijn geïnfecteerd. ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Medium
31 jul 2026

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Medium
30 jul 2026

[The Hacker News] ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway,

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
31 jul 2026

Multiples vulnérabilités dans le noyau Linux de Red Hat (31 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
23 jul 2026

Don’t swing at everything

Financieel & Verzekeringen

Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
8 jul 2026

[webapps] Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure

Retail & E-commerce

Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
30 jul 2026

Toy Ghouls’ new toy: the GenieLocker ransomware

Industrie & ProductieIT & Technologie

Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Medium
14 jul 2026

Microsoft Patches a Record 570 Security Flaws

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
Mandiant Hoog
24 jul 2026

Updated Cyber Threat Actor Naming System

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerce

Update (July 30): A table listing the new names of select prominent threat actors was appended to this post. Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Why are we Adopting a Different Naming System? …

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
30 jul 2026

CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Acknowledgement Updated

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Hoog
27 jul 2026

Rethinking security for the age of AI

Financieel & VerzekeringenIndustrie & ProductieRetail & E-commerceIT & Technologie

The physics of cybersecurity are changing. Introducing security's new cyber stack: Project Perception. The post Rethinking security for the age of AI appeared first on Microsoft Security Blog.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
31 jul 2026

NCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic

Financieel & Verzekeringen

Adobe heeft kwetsbaarheden verholpen in Adobe Campaign Classic (ACC). De eerste kwetsbaarheid betreft een Incorrect Authorization in de core authorization mechanismen van ACC, waardoor een aanvaller arbitrary code kan uitvoeren zonder enige gebruikersinteractie. Dit betekent dat de aanvaller acties kan uitvoeren buiten de bedoelde permissies.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
13 jul 2026

UK and Allies urge critical sectors to improve defences against Russian intelligence targeting

Financieel & VerzekeringenIT & Technologie

New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
9 jul 2026

CVE-2026-47826 — CVSS 9.1 CRITICAL

Transport & Logistiek

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
30 jul 2026

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Financieel & VerzekeringenRetail & E-commerce

Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
SANS ISC Hoog
28 jul 2026

AutoIT Payload Injector , (Tue, Jul 28th)

Industrie & ProductieTransport & Logistiek

For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you'll see below.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Medium
31 jul 2026

Anthropic zegt verantwoordelijk te zijn voor het hacken van drie bedrijven

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Anthropic zegt verantwoordelijk te zijn voor het hacken van drie bedrijven en het uploaden van malware naar de Python Package ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Medium
31 jul 2026

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
29 jul 2026

[The Hacker News] Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Industrie & ProductieTransport & Logistiek

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
31 jul 2026

Multiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans Progress MOVEit Transfer. Elles permettent à un attaquant de provoquer une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
23 jul 2026

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Financieel & Verzekeringen

The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
8 jul 2026

[webapps] Langflow 1.9.0 - RCE

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Langflow 1.9.0 - RCE

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
28 jul 2026

Mirage Kitten targets Middle East and Africa region with new malware

Financieel & Verzekeringen

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Kritiek
8 jul 2026

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Financieel & VerzekeringenTransport & Logistiek

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Mandiant Kritiek
16 jul 2026

Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration …

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
30 jul 2026

CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Updated an acknowledgement. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Medium
23 jul 2026

Email threat landscape: Q2 2026 trends and insights

Financieel & VerzekeringenIndustrie & ProductieRetail & E-commerceIT & Technologie

In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-stage attack chains. The post Email threat landscape: Q2 2026 trends and insights appeared first on Mi…

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NL Medium
31 jul 2026

NCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerce

JFrog heeft meerdere kwetsbaarheden verholpen in JFrog Artifactory De kwetsbaarheden betreffen verschillende onderdelen van JFrog Artifactory. - Er is een privilege-escalatie mogelijk doordat het systeem de scope van tokens niet controleert, waardoor een aanvaller zijn rechten kan verhogen.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
22 jun 2026

The AI shift in cyber risk: why leaders must act now

Financieel & VerzekeringenTransport & Logistiek

Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
9 jul 2026

CVE-2026-56291 — CVSS 9.8 CRITICAL

Financieel & Verzekeringen

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Kritiek
17 jul 2026

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

Industrie & ProductieTransport & LogistiekRetail & E-commerce

A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Security.NL Medium
30 jul 2026

'Advertentiebedrijf Adform gehackt, verspreidde cryptostelende malware'

Transport & Logistiek

Aanvallers zijn erin geslaagd om advertentiebedrijf Adform te hacken en vervolgens op allerlei websites cryptostelende malware ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Hoog
31 jul 2026

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

Financieel & VerzekeringenOnderwijs & OnderzoekIT & Technologie

An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session. The findings have been released by a group of researchers from Singapore's Nanyang Technological University

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Medium
29 jul 2026

[The Hacker News] Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Retail & E-commerce

Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
31 jul 2026

Multiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
16 jul 2026

Begun, the Patch Wars have

Financieel & Verzekeringen

Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
8 jul 2026

[webapps] Joomla Page Builder CK 3.5.10 - Arbitrary File Upload

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Joomla Page Builder CK 3.5.10 - Arbitrary File Upload

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
16 jul 2026

GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

Overheid & Publieke SectorIndustrie & Productie

Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Hoog
18 jun 2026

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a "residential proxy" provider operated by the publicly-traded Israeli firm Ala…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
15 jul 2026

The Risk of Exposed Cloud Functions and How to Harden

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remo…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
30 jul 2026

CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Medium
17 jul 2026

Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks

Financieel & VerzekeringenRetail & E-commerceIT & Technologie

Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception. The post Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks appeared first on Microsoft Security Blog.

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NL Medium
30 jul 2026

NCSC-2026-0271 [1.00] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Center

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieIT & Technologie

Cisco heeft een kwetsbaarheid verholpen in Cisco Secure Firewall Management Center. De kwetsbaarheid bevindt zich in de webinterface van Cisco Secure Firewall Management Center en betreft een hard-coded, statisch wachtwoord voor een laaggeprivilegieerd account.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
18 jun 2026

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
9 jul 2026

CVE-2026-58459 — CVSS 7.8 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnup…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Kritiek
15 jul 2026

The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)

Transport & LogistiekRetail & E-commerceOnderwijs & Onderzoek

Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Security.NL Medium
30 jul 2026

Ontwikkelaar en aanbieder van phishingsites veroordeeld tot 2 jaar cel

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

De rechtbank Rotterdam heeft een 24-jarige man wegens het ontwikkelen en verkopen van phishingsites, alsmede het witwassen van ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Medium
31 jul 2026

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Financieel & VerzekeringenTransport & Logistiek

Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn't originally

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Kritiek
28 jul 2026

[The Hacker News] JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

Financieel & VerzekeringenRetail & E-commerce

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
CERT-FR Hoog
31 jul 2026

Vulnérabilité dans Microsoft Azure (31 juillet 2026)

Transport & LogistiekIT & Technologie

Une vulnérabilité a été découverte dans Microsoft Azure. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
14 jul 2026

Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities

Financieel & VerzekeringenIT & Technologie

Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical."

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
7 jul 2026

[webapps] MCPJam Inspector - Remote Code Execution

Industrie & Productie

MCPJam Inspector - Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
15 jul 2026

OkoBot: new sophisticated malware framework targets cryptocurrency users

Financieel & VerzekeringenIndustrie & Productie

Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Hoog
10 jun 2026

Who Runs the Ransomware Group ‘The Gentlemen?’

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerce

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
7 jul 2026

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to a…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
30 jul 2026

CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability

IT & Technologie

Informational Change. CVE ID stays the same.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Medium
16 jul 2026

ACR Stealer: Two observed intrusion chains amid increased threat activity

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerceIT & Technologie

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments. The post ACR Stealer: Two observed intrusion chains amid increased threat activity appeared first on Mi…

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NL Medium
30 jul 2026

NCSC-2026-0270 [1.00] [M/M] Kwetsbaarheden verholpen in GitLab door GitLab Inc.

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

GitLab Inc. heeft meerdere kwetsbaarheden verholpen in GitLab, specifiek in versies voorafgaand aan 19.0.5, 19.1.3 en 19.2.1, inclusief GitLab Enterprise Edition (EE) versies binnen deze reeksen.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
17 jun 2026

NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems

Financieel & Verzekeringen

Dr Richard Horne highlighted the scale of cyber threats against the UK’s critical infrastructure at RUSI’s Annual Security Lecture.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
9 jul 2026

CVE-2026-59214 — CVSS 7.3 CRITICAL

Financieel & VerzekeringenTransport & Logistiek

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and XMLHttpRequest APIs to issue authenticated same-origin requests when a victim clicks Run, which can reach admin-only endpoints and ex…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
10 jul 2026

No Manners Here: The Ruthless Rise of The Gentlemen Ransomware

Financieel & VerzekeringenRetail & E-commerce

Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Medium
29 jul 2026

Advertorial: Serverbeheer als beveiligingsrisico: wat organisaties over het hoofd zien

Financieel & VerzekeringenIT & Technologie

De meeste organisaties investeren fors in endpoint-beveiliging, firewalls en bewustwording rond phishing. Begrijpelijk, want ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Hoog
31 jul 2026

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Financieel & Verzekeringen

Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan,

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Medium
28 jul 2026

[The Hacker News] Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost

Financieel & VerzekeringenIT & Technologie

Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
31 jul 2026

Multiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni de service.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
14 jul 2026

The serpent’s tongue: Luring the Python out of its den

Financieel & VerzekeringenRetail & E-commerce

This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
7 jul 2026

[local] ProtonVPN v4.4.1 - Unquoted Service Path

Industrie & ProductieIT & Technologie

ProtonVPN v4.4.1 - Unquoted Service Path

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
7 jul 2026

Threat landscape for industrial automation systems. Q1 2026

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Hoog
9 jun 2026

A Record-Breaking Patch Tuesday for June 2026

Financieel & VerzekeringenIT & Technologie

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploit code for at least three of the weaknesses is now publicly available.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
2 jul 2026

Google’s Continued Disruption of Malicious Residential Proxy Networks

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the …

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
28 jul 2026

CVE-2026-50422 Windows NTFS Elevation of Privilege Vulnerability

IT & Technologie

Updated an acknowledgement. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
29 jul 2026

NCSC-2026-0269 [1.01] [M/H] Kwetsbaarheden verholpen in VMware producten

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

VMware heeft kwetsbaarheden verholpen in VMware vCenter en VMware ESX producten. VMware vCenter bevat een kritieke authentication-bypass kwetsbaarheid in de Directory Service met kenmerk CVE-2026-59309.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
23 apr 2026

NCSC: Leave passwords in the past - passkeys are the future

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
9 jul 2026

CVE-2026-59216 — CVSS 7.7 CRITICAL

Financieel & VerzekeringenIndustrie & Productie

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the session was connected, allowing authenticated users who learned another socket ID through ydoc:document:join to run code interpreter Python or tools in that user …

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
1 jul 2026

Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerce

Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more. The post Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Kritiek
29 jul 2026

Kritieke VMware-lekken geven aanvallers toegang tot vCenter-servers

Industrie & ProductieIT & Technologie

VMware waarschuwt klanten vandaag voor twee kritieke kwetsbaarheden waardoor aanvallers toegang tot vCenter-servers kunnen ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Medium
30 jul 2026

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

Financieel & Verzekeringen

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
27 jul 2026

[The Hacker News] NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
31 jul 2026

Multiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
9 jul 2026

WolfSSL, GeoVision, VTK vulnerabilities

Retail & E-commerceIT & Technologie

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM.The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy. For

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
7 jul 2026

[webapps] Flowise 3.1.3 - arbitrary code execution

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Flowise 3.1.3 - arbitrary code execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
29 jun 2026

The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: James Sadowski, Alden Wahlstrom Introduction Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert info…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
28 jul 2026

CVE-2026-47301 Configuration Manager Elevation of Privilege Vulnerability

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Corrected Build Number in the Security Updates table. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
29 jul 2026

NCSC-2026-0268 [1.00] [M/H] Kwetsbaarheid verholpen in SQLite door SQLite Consortium

Industrie & ProductieTransport & Logistiek

SQLite Consortium heeft een kwetsbaarheid verholpen in SQLite versie 3.41. De kwetsbaarheid betreft een use-after-free in de expression evaluation logic van SQLite. Een aanvaller kan deze kwetsbaarheid op afstand misbruiken door speciaal vervaardigde kwaadaardige SQL-statements aan te bieden.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
23 apr 2026

International cyber agencies share fresh advice to defend against China-linked covert networks

Industrie & Productie

New advisory highlights how to defend against attacker tactics believed to be used by China-linked actors to hide malicious cyber activity.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
9 jul 2026

CVE-2026-0284 — CVSS 9.9 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
25 jun 2026

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

Financieel & VerzekeringenOverheid & Publieke SectorRetail & E-commerce

Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Hoog
29 jul 2026

Italiaanse overheid meldt bestaan van exploitcode voor 7-Zip RCE-lek

Financieel & VerzekeringenOverheid & Publieke Sector

Voor een kwetsbaarheid in de populaire archiveringssoftware 7-Zip is exploitcode online verschenen, zo meldt het Computer ...

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
30 jul 2026

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway,

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Medium
27 jul 2026

[The Hacker News] ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

Financieel & VerzekeringenIndustrie & ProductieRetail & E-commerceIT & Technologie

Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped. That is the mood. Here is the full recap. ⚡ Threat of the Week OpenAI Says Its AI Agent Went Rogue

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
31 jul 2026

Multiples vulnérabilités dans PHP (31 juillet 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer une injection SQL (SQLi), un déni de service et un problème de sécurité non spécifié par l'éditeur.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
7 jul 2026

UAT-7810 continues building ORB networks using new malware

Financieel & Verzekeringen

Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
7 jul 2026

[remote] Hydra - Stack Buffer Overflow

Industrie & Productie

Hydra - Stack Buffer Overflow

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
25 jun 2026

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizati…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
28 jul 2026

CVE-2026-59117 Windows Terminal Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Change the name of the affected software from **Microsoft Power Apps** to **Microsoft Power Apps Desktop Client**. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
28 jul 2026

NCSC-2026-0267 [1.00] [M/H] Kwetsbaarheden verholpen in Apple MacOS

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

Apple heeft meerdere kwetsbaarheden verholpen in MacOS, specifiek in de versies Sequoia 15.7.8, Sonoma 14.8.8 en Tahoe 26.x. De kwetsbaarheden betreffen diverse beveiligingsproblemen in macOS, waaronder onvoldoende sandbox restricties waardoor applicaties mogelijk ongeautoriseerd toegang kunnen krijgen tot gevoelige gebruikersdata.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
23 apr 2026

Executive Summary: Defending against China-nexus covert networks of compromised devices

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Organisations should map and baseline their edge device traffic, especially VPN and remote access connections, and adopt dynamic threat feed filtering that includes known covert network indicators.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
9 jul 2026

CVE-2026-53963 — CVSS 7.3 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation dialog, allowing stored cross-site scripting when an administrator impersonated that account. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
23 jun 2026

OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

Financieel & VerzekeringenRetail & E-commerce

Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud. The post OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Hoog
29 jul 2026

MikroTik-routers door RouterOS-lek kwetsbaar voor bruteforce-aanvallen

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

MikroTik-routers zijn door een lek in RouterOS, het besturingssysteem dat op de apparaten draait, kwetsbaar voor ...

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
30 jul 2026

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

Financieel & VerzekeringenRetail & E-commerceIT & Technologie

A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
24 jul 2026

[Microsoft MSRC] CVE-2026-48561 Microsoft Edge Copilot Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Corrected the CVE description and title. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
30 jul 2026

Vulnérabilité dans Ruby on Rails activestorage (30 juillet 2026)

Transport & Logistiek

Une vulnérabilité a été découverte dans Ruby on Rails activestorage. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance et une atteinte à la confidentialité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
7 jul 2026

[webapps] Discuz! X5.0 - Authentication Bypass

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Discuz! X5.0 - Authentication Bypass

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Kritiek
24 jun 2026

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Zorg & GezondheidFinancieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-leve…

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
28 jul 2026

Chromium: CVE-2026-13032 Use after free in WebGL

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
28 jul 2026

NCSC-2026-0266 [1.00] [M/H] Kwetsbaarheden verholpen in Apple iOS en iPadOS

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

Apple heeft meerdere kwetsbaarheden verholpen in diverse versies van iOS en iPadOS. Er zijn diverse geheugenbeheerfouten zoals use-after-free, buffer overflows, out-of-bounds reads en writes, integer overflows, race conditions en insufficient input validation opgelost.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
23 apr 2026

Defending against China-nexus covert networks of compromised devices

Financieel & VerzekeringenIndustrie & Productie

Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
8 jul 2026

CVE-2026-60002 — CVSS 7.7 CRITICAL

Financieel & VerzekeringenIT & Technologie

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
22 jun 2026

The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration

Financieel & VerzekeringenRetail & E-commerce

Unit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs. The post The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Medium
29 jul 2026

Backdoor ontdekt in Advanced Responsive Video Embedder voor WordPress

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

In de Advanced Responsive Video Embedder plug-in voor WordPress is een backdoor ontdekt waardoor aanvallers volledige ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Medium
30 jul 2026

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

Financieel & Verzekeringen

South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors. A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
23 jul 2026

[Microsoft MSRC] CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
30 jul 2026

Vulnérabilité dans CPython (30 juillet 2026)

Transport & Logistiek

Une vulnérabilité a été découverte dans CPython. Elle permet à un attaquant de provoquer un déni de service à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
7 jul 2026

[webapps] Tenable Nessus 10.12.1 - SQL Injection

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Tenable Nessus 10.12.1 - SQL Injection

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
15 jun 2026

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally …

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
28 jul 2026

Chromium: CVE-2026-13028 Use after free in WebGL

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
27 jul 2026

NCSC-2026-0265 [1.00] [M/H] Kwetsbaarheden verholpen in SolarWinds Serv-U

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenIT & Technologie

SolarWinds heeft meerdere kwetsbaarheden verholpen in Serv-U. De kwetsbaarheden in SolarWinds Serv-U betreffen voornamelijk insecure direct object reference (IDOR) en broken access control.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
22 apr 2026

World-first NCSC-engineered device secures vulnerable display links

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

SilentGlass, a plug-and-play device, actively blocks any unexpected or malicious HDMI and Display Port connections.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
8 jul 2026

CVE-2026-58480 — CVSS 9.8 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerce

Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension file…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Kritiek
29 jul 2026

Kritiek lek in forumsoftware vBulletin maakt remote code execution mogelijk

Industrie & Productie

Een kritieke kwetsbaarheid in forumsoftware vBulletin maakt remote code execution door ongeauthenticeerde aanvallers mogelijk. ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Medium
30 jul 2026

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

Financieel & VerzekeringenIndustrie & Productie

The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos 4.0) for persistent remote access. "In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Kritiek
16 jul 2026

[Mandiant] Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration …

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
CERT-FR Hoog
30 jul 2026

Multiples vulnérabilités dans les produits VMware (30 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
7 jul 2026

[webapps] WordPress Bricks Builder Theme - RCE

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

WordPress Bricks Builder Theme - RCE

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Kritiek
11 jun 2026

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8)…

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
28 jul 2026

Chromium: CVE-2026-13030 Uninitialized Use in GPU

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
24 jul 2026

NCSC-2026-0264 [1.00] [M/H] Kwetsbaarheden verholpen in Check Point Security Management producten

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Check Point heeft kwetsbaarheden verholpen in SmartConsole, Gaia Portal, Security Management en Multi-Domain Security Management. De kwetsbaarheden betreffen authenticatiebypasses en privilege-escalaties binnen verschillende Check Point managementcomponenten.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
21 apr 2026

Cyber chief: UK faces "perfect storm" for cyber security

Financieel & Verzekeringen

As the technology landscape develops, the definition of cyber security is expanding with it.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
8 jul 2026

CVE-2026-3144 — CVSS 8.1 CRITICAL

IT & Technologie

IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Medium
28 jul 2026

Fraudehelpdesk waarschuwt voor phishingaanval na boeking via Booking.com

Financieel & Verzekeringen

De Fraudehelpdesk waarschuwt mensen die via Booking.com en andere verhuurplatforms hebben geboekt om alert te zijn op ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Medium
30 jul 2026

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieIT & Technologie

The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
14 jul 2026

[Microsoft MSRC] CVE-2026-47282 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability

Industrie & ProductieIT & Technologie

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
30 jul 2026

Multiples vulnérabilités dans GitLab (30 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
7 jul 2026

[remote] iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter

Industrie & Productie

iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
5 jun 2026

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in …

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
28 jul 2026

Chromium: CVE-2026-13037 Use after free in WebView

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
24 jul 2026

NCSC-2026-0263 [1.00] [M/H] Kwetsbaarheid verholpen in ManageEngine ADAudit Plus van ZohoCorp

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

ZohoCorp heeft een kwetsbaarheid verholpen in ManageEngine ADAudit Plus. De kwetsbaarheid bevindt zich in de agent API van ManageEngine ADAudit Plus versies eerder dan 8606. Door onjuiste validatie in de API kunnen aanvallers zonder authenticatie op afstand willekeurige code uitvoeren.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
7 apr 2026

APT28 exploit routers to enable DNS hijacking operations

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

Russian cyber actor APT28 exploit vulnerable routers to hijack DNS, enabling adversary‑in‑the‑middle attacks and theft of passwords and authentication tokens.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
8 jul 2026

CVE-2026-9074 — CVSS 9.1 CRITICAL

Transport & LogistiekIT & Technologie

IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Kritiek
28 jul 2026

Servers aangevallen via kritiek RCE-lek in Java-library FastJson

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Aanvallers maken actief misbruik van een kritieke kwetsbaarheid in de Java-library FastJson voor het aanvallen van servers, zo ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Kritiek
30 jul 2026

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieRetail & E-commerceIT & Technologie

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security Hoog
14 jul 2026

[Microsoft MSRC] CVE-2026-50510 GitHub Copilot Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
30 jul 2026

Vulnérabilité dans Cisco Firewall Management Center (30 juillet 2026)

Transport & LogistiekIT & Technologie

Une vulnérabilité a été découverte dans Cisco Firewall Management Center. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité. Cisco indique que la vulnérabilité CVE-2026-20316 est activement exploitée.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
6 jul 2026

[webapps] Joomla Extension 4.1.4 - PHP Object injection

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Joomla Extension 4.1.4 - PHP Object injection

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Kritiek
25 mei 2026

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (…

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
27 jul 2026

CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege Vulnerability

IT & Technologie

Updated an acknowledgement. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 jul 2026

NCSC-2026-0262 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle MySQL Server en MySQL Cluster

Industrie & ProductieIT & Technologie

Oracle heeft meerdere kwetsbaarheden verholpen in Oracle MySQL Server en MySQL Cluster. De kwetsbaarheden betreffen verschillende versies van Oracle MySQL Server en MySQL Cluster.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
7 apr 2026

UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerceIT & Technologie

New advisory warns cyber threat group APT28 have exploited vulnerable edge devices to support malicious operations.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
8 jul 2026

CVE-2026-29009 — CVSS 8.2 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing …

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Medium
28 jul 2026

Autoriteit Persoonsgegevens zag vorig jaar meer ransomware-aanvallen

Transport & Logistiek

De Autoriteit Persoonsgegevens (AP) zag vorig jaar meer ransomware-aanvallen dan in 2024, zo laat de privacytoezichthouder in ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Hoog
29 jul 2026

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Transport & LogistiekRetail & E-commerce

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
14 jul 2026

[Microsoft MSRC] CVE-2026-55145 Outlook Copilot Tampering Vulnerability

Financieel & VerzekeringenIndustrie & Productie

Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
30 jul 2026

Multiples vulnérabilités dans Node.js (30 juillet 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans Node.js. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
6 jul 2026

[webapps] Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
25 mei 2026

2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & Onderzoek

While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that …

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
27 jul 2026

CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerability

IT & Technologie

Updated an acknowledgement. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 jul 2026

NCSC-2026-0261 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Java SE

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Oracle heeft meerdere kwetsbaarheden verholpen in Java SE (inclusief Oracle GraalVM en JavaFX componenten).

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
31 mrt 2026

NCSC warns of messaging app targeting

Financieel & VerzekeringenTransport & Logistiek

The NCSC has issued actions for individuals at risk of targeted attacks against messaging apps.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
8 jul 2026

CVE-2026-8649 — CVSS 6.4 CRITICAL

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Medium
28 jul 2026

Belgische overheid: Gelekte gegevens massaal ingezet voor spearphishing

Financieel & VerzekeringenOverheid & Publieke SectorTransport & Logistiek

Persoonsgegevens die bij bedrijven en organisaties worden gestolen en gelekt op internet, worden op massale schaal ingezet voor ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Hoog
29 jul 2026

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Industrie & ProductieTransport & Logistiek

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
14 jul 2026

[Microsoft MSRC] CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability

Industrie & ProductieIT & Technologie

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
30 jul 2026

Multiples vulnérabilités dans Google Chrome (30 juillet 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
6 jul 2026

[local] MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
15 mei 2026

Welcome to BlackFile: Inside a Vishing Extortion Operation

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) tech…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
27 jul 2026

CVE-2026-50343 Microsoft Install Service Elevation of Privilege Vulnerability

IT & Technologie

Updated an acknowledgement. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 jul 2026

NCSC-2026-0260 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle PeopleSoft Enterprise

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft 84 kwetsbaarheden verholpen in verschillende modules van Oracle PeopleSoft Enterprise, waaronder HCM Talent Acquisition Manager, In-Memory Project Discovery, FIN Expenses, SCM eProcurement, CC Common Application Objects, SCM Order Management, CRM Common Objects en FIN Program Management, allen versie 9.2.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
30 mrt 2026

Vulnerability affecting F5 BIG-IP APM

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

The NCSC is encouraging UK organisations to mitigate an unauthenticated remote code execution vulnerability affecting F5 BIG-IP Access Policy Manager.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
8 jul 2026

CVE-2026-8801 — CVSS 3.5 CRITICAL

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Kritiek
28 jul 2026

Arista waarschuwt voor actief misbruik van kritiek lek in VeloCloud Orchestrator

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Aanvallers maken actief misbruik van een kritieke kwetsbaarheid in VeloCloud Orchestrator (VCO), een beheerplatform voor het ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Hoog
29 jul 2026

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Financieel & VerzekeringenIT & Technologie

Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
14 jul 2026

[Microsoft MSRC] CVE-2026-58617 M365 Copilot for iOS Elevation of Privilege Vulnerability

Industrie & ProductieIT & Technologie

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
29 jul 2026

Multiples vulnérabilités dans Xen (29 juillet 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans Xen. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
6 jul 2026

[webapps] KeepInMind 0.8.4.2 - Stored XSS

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

KeepInMind 0.8.4.2 - Stored XSS

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
23 apr 2026

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceIT & Technologie

Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in r…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
27 jul 2026

CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability

Industrie & Productie

Updated an acknowledgement. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 jul 2026

NCSC-2026-0259 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Analytics

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Oracle heeft meerdere kwetsbaarheden verholpen in Oracle BI Publisher (versies 8.2.0.0.0, 12.2.1.4.0 en 26.01.0.0.0) en Oracle Business Intelligence Enterprise Edition (versies 8.2.0.0.0 en 26.01.0.0.0).

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
25 mrt 2026

Vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

UK organisations encouraged to take immediate action to mitigate two recently disclosed vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
8 jul 2026

CVE-2026-54527 — CVSS 9.0 CRITICAL

Financieel & Verzekeringen

JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history, allowing a crafted filename to execute JavaScript when a victim views the rename diff in the Git History tab. This issue is fixed in version 0.54.0.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Kritiek
27 jul 2026

TeamCity-servers via kritieke kwetsbaarheid op afstand over te nemen

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Een kritieke kwetsbaarheid maakt het mogelijk voor ongeauthenticeerde aanvallers om TeamCity-servers op afstand over te nemen. ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Medium
29 jul 2026

Mythos Asks the Right Question. It Doesn't Answer It.

Financieel & Verzekeringen

AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change? The honest answer is

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Kritiek
8 jul 2026

[Krebs on Security] Felons, Fraudsters Flog Offensive Cybersecurity Startup

Financieel & VerzekeringenTransport & Logistiek

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
CERT-FR Hoog
29 jul 2026

Multiples vulnérabilités dans Citrix XenServer (29 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans Citrix XenServer. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un problème de sécurité non spécifié par l'éditeur.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
6 jul 2026

[webapps] KNX visualisering - Broken Access Control

Financieel & Verzekeringen

KNX visualisering - Broken Access Control

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Kritiek
16 apr 2026

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

Zorg & GezondheidFinancieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As…

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
27 jul 2026

CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 jul 2026

NCSC-2026-0258 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Financial Services

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft kwetsbaarheden verholpen in diverse Financial Services modules. Ook heeft Oracle updates voor diverse third-party-producten verwerkt.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
24 mrt 2026

NCSC CEO: Seize 'disruptive' vibe coding opportunity to make software more secure

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Dr Richard Horne delivered a keynote about cyber risks and opportunities at the RSAC Conference in San Francisco

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
8 jul 2026

CVE-2026-55471 — CVSS 9.1 CRITICAL

Zorg & GezondheidFinancieel & Verzekeringen

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() without ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET restrictions, allowing an attacker who controls or can tamper with transformed XML to trigger X…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
29 jul 2026

Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

Financieel & Verzekeringen

Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. "No settings or additional user interaction are required," Eten Zou,

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
2 jul 2026

[Microsoft MSRC] CVE-2026-45499 Azure OpenAI Elevation of Privilege Vulnerability

IT & Technologie

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
29 jul 2026

Vulnérabilité dans Apache Tomcat (29 juillet 2026)

Transport & Logistiek

Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un attaquant de provoquer un déni de service à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
6 jul 2026

[local] Windows Defender (MsMpEng.exe) - Race Condition

IT & Technologie

Windows Defender (MsMpEng.exe) - Race Condition

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
15 apr 2026

The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & Onderzoek

Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previousl…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
27 jul 2026

CVE-2024-14040 net: nexthop: Increase weight to u16

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 jul 2026

NCSC-2026-0257 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Enterprise Manager

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Oracle heeft meerdere kwetsbaarheden verholpen in Oracle Enterprise Manager Base Platform versies 13.5 en 24.1.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
12 mrt 2026

International security chiefs to convene in Glasgow for flagship CYBERUK conference

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

CYBERUK will be delivered by the NCSC and sponsors across four distinct tracks of activity: Resilience, Technology, Threat, and Ecosystem.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
7 jul 2026

CVE-2026-13020 — CVSS 8.1 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Kritiek
29 jul 2026

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Financieel & Verzekeringen

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security Hoog
2 jul 2026

[Microsoft MSRC] CVE-2026-41106 Microsoft 365 Copilot Elevation of Privilege Vulnerability

Industrie & ProductieIT & Technologie

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
29 jul 2026

Multiples vulnérabilités dans Microsoft Edge (29 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données et un problème de sécurité non spécifié par l'éditeur.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
6 jul 2026

[webapps] WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)

Financieel & Verzekeringen

WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
2 apr 2026

vSphere and BRICKSTORM Malware: A Defender's Guide

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Stuart Carrera Introduction Building on recent BRICKSTORM research from Google Threat Intelligence Group (GTIG), this post explores the evolving threats facing virtualized environments. These operations directly target the VMware vSphere ecosystem, specifically the vCenter Server Appliance (VCSA) and ESXi hypervisors. To help organizations stay ahead of these risks, we will focus on th…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
27 jul 2026

CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 jul 2026

NCSC-2026-0256 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Communications

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft kwetsbaarheden verholpen in Communications producten en onderliggende third party software. Het betreft een totaal van 213 kwetsbaarheden, waarvan 67 zich bevinden in Oracle producten en 146 in third-party producten waar eerder updates voor zijn verschenen en welke in deze Oracle updates zijn verwerkt.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
2 mrt 2026

Alert: NCSC advises UK organisations to take action following conflict in the Middle East

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerce

In response to the evolving events in the Middle East, the NCSC is advising that UK organisations review their cyber security posture.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
6 jul 2026

CVE-2026-40139 — CVSS 9.8 CRITICAL

Financieel & VerzekeringenIndustrie & Productie

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Hoog
29 jul 2026

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

Industrie & ProductieTransport & LogistiekRetail & E-commerce

Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
1 jul 2026

[Palo Alto Unit 42] Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerce

Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more. The post Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
28 jul 2026

Multiples vulnérabilités dans Samba (28 juillet 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans Samba. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
8 jun 2026

[webapps] OpenEMR 7.0.2 - Arbitrary File Read

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

OpenEMR 7.0.2 - Arbitrary File Read

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
27 jul 2026

CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 jul 2026

NCSC-2026-0255 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Commerce Platform

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Oracle heeft 39 kwetsbaarheden verholpen in Oracle Commerce Platform en Oracle Commerce Guided Search/Experience Manager, beide versies 11.4.0. 11 van deze kwetsbaarheden hebben een CVSS score van 9 en hoger gekregen en zijn hieronder samengevat.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
25 feb 2026

Exploitation of Cisco Catalyst SD-WAN

Industrie & ProductieIT & Technologie

Agencies strongly encourage immediate investigation of potential compromise of Cisco Catalyst SD-WAN.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
6 jul 2026

CVE-2026-40141 — CVSS 9.9 CRITICAL

Financieel & VerzekeringenIndustrie & Productie

A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Hoog
29 jul 2026

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Financieel & VerzekeringenIndustrie & Productie

Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in China. The kit supports payment-password

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
23 jun 2026

[Palo Alto Unit 42] OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

Financieel & VerzekeringenRetail & E-commerce

Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud. The post OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
28 jul 2026

Multiples vulnérabilités dans les produits Apple (28 juillet 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans les produits Apple. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et une atteinte à la confidentialité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
5 jun 2026

[webapps] WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
27 jul 2026

CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()

Transport & Logistiek

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 jul 2026

NCSC-2026-0254 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle database producten

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft 158 kwetsbaarheden verholpen in Oracle Database Server, APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer en TimesTen In-Memory Database.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Kritiek
6 jul 2026

CVE-2026-54763 — CVSS 10.0 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can i…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
29 jul 2026

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Industrie & ProductieTransport & Logistiek

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/components@4.0.0-rc24-2773-beta.4 The two packages "contain an import-time JavaScript implant that resolves encrypted code

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
18 jun 2026

[Microsoft MSRC] CVE-2026-42895 Microsoft Copilot Tampering Vulnerability

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
27 jul 2026

Bulletin d'actualité CERTFR-2026-ACT-032 (27 juillet 2026)

Transport & Logistiek

Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
1 jun 2026

[webapps] Drupal Core 10.5.5 - Error-Based SQL Injection

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Drupal Core 10.5.5 - Error-Based SQL Injection

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 jul 2026

Chromium: CVE-2026-16804 Use after free in Input

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 jul 2026

NCSC-2026-0253 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle E-Business Suite componenten

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft meerdere kwetsbaarheden verholpen in Oracle E-Business Suite, inclusief diverse modules zoals Work in Process, Application Object Library, HRMS, Applications Framework, Advanced Collections, Advanced Outbound Telephony, Advanced Pricing, Applications DBA, Bills of Material, Customer Care, Enterprise Asset Management, Enterprise Command

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Kritiek
4 jul 2026

CVE-2026-14535 — CVSS 8.8 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. This call registers the shortened code representation in the shared AnalysisContext.reported_shortened_code set. When the MLAllowlist analysis pass subsequen…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
29 jul 2026

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Retail & E-commerce

Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
18 jun 2026

[Microsoft MSRC] CVE-2026-54130 M365 Copilot Information Disclosure Vulnerability

Financieel & VerzekeringenIndustrie & Productie

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
27 jul 2026

Multiples vulnérabilités dans les produits Atlassian (27 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
1 jun 2026

[webapps] WordPress OrderConvo 14 - Path Traversal

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

WordPress OrderConvo 14 - Path Traversal

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 jul 2026

Chromium: CVE-2026-16805 Use after free in Blink

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 jul 2026

NCSC-2026-0252 [1.00] [H/H] Kwetsbaarheden verholpen in Oracle Fusion middleware

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft een groot aantal kwetsbaarheden verholpen in verschillende Oracle middleware producten, waaronder Oracle Data Integrator, Oracle Coherence, Oracle Access Manager, Oracle Unified Directory, Oracle WebLogic Server Proxy Plug-in, Oracle Fusion Middleware Service Delivery Platform (Messaging Enabler) en Oracle WebCenter Content.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Kritiek
3 jul 2026

CVE-2026-47898 — CVSS 9.8 CRITICAL

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Hoog
28 jul 2026

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force. Tengu supports 25 distributed denial-of-service (

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
18 jun 2026

[Microsoft MSRC] CVE-2026-47645 Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability

Industrie & ProductieIT & Technologie

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
27 jul 2026

Vulnérabilité dans Traefik (27 juillet 2026)

Transport & Logistiek

Une vulnérabilité a été découverte dans Traefik. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
30 mei 2026

[remote] Notepad++ 8.9.6 - Arbitrary Code Execution

Industrie & Productie

Notepad++ 8.9.6 - Arbitrary Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 jul 2026

Chromium: CVE-2026-16806 Use after free in WebMCP

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
21 jul 2026

NCSC-2026-0237 [1.02] [H/H] Kwetsbaarheden verholpen in Microsoft Office

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Microsoft heeft kwetsbaarheden verholpen in diverse Office producten, zoals Word, Excel, Powerpoint en SharePoint. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot categorieën schade, zoals benoemd in onderstaande tabel.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Kritiek
3 jul 2026

CVE-2026-12481 — CVSS 9.8 CRITICAL

Financieel & Verzekeringen

A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the safe-mode guard when `safe_mode` is set to `None`, which is the default value when `from_config()` is called outside of a `SafeModeScope` context. This logic er…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Kritiek
28 jul 2026

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

Financieel & VerzekeringenRetail & E-commerce

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security Hoog
10 jun 2026

[Microsoft MSRC] CVE-2026-45482 Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability

Industrie & ProductieIT & Technologie

Updated the Security Updates Build Number and Title as the Chat extention is now merged into Visual Studio Code

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
27 jul 2026

Multiples vulnérabilités dans Microsoft Edge (27 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
30 mei 2026

[webapps] YAMCS yamcs-core 5.12.7 - No Rate Limiting

Financieel & Verzekeringen

YAMCS yamcs-core 5.12.7 - No Rate Limiting

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 jul 2026

Chromium: CVE-2026-16807 Out of bounds write in Codecs

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
21 jul 2026

NCSC-2026-0251 [1.00] [M/H] Kwetsbaarheden verholpen in IBM Langflow OSS

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

IBM heeft meerdere kwetsbaarheden verholpen in IBM Langflow OSS versies 1.0.0 tot en met 1.10.0.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Kritiek
3 jul 2026

CVE-2026-57983 — CVSS 8.7 CRITICAL

IT & Technologie

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Hoog
28 jul 2026

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

Industrie & ProductieIT & Technologie

OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
9 jun 2026

[Microsoft MSRC] CVE-2026-41100 Microsoft 365 Copilot for Android Spoofing Vulnerability

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Added Microsoft Excel for Android, Microsoft Word for Android, Microsoft Loop for Android, Microsoft PowerPoint for Android and Microsoft OneNote for Android softwares to the Security Updates table. Customers that are running supported version of these products are encouraged to update to the indicated versions to be protected from this vulnerability.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
27 jul 2026

Multiples vulnérabilités dans GLPI (27 juillet 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans GLPI. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à l'intégrité des données et une injection SQL (SQLi).

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
30 mei 2026

[webapps] YAMCS yamcs-core 5.12.7 - User Enumeration

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

YAMCS yamcs-core 5.12.7 - User Enumeration

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
24 jul 2026

CVE-2026-62835 Azure Portal Information Disclosure Vulnerability

IT & Technologie

Corrected the CVE description and title. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
2 jul 2026

CVE-2026-54408 — CVSS 8.6 CRITICAL

Financieel & VerzekeringenIndustrie & Productie

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
28 jul 2026

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
4 jun 2026

[Microsoft MSRC] CVE-2026-42824 M365 Copilot Information Disclosure Vulnerability

Industrie & Productie

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
24 jul 2026

Multiples vulnérabilités dans le noyau Linux de Debian LTS (24 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
30 mei 2026

[webapps] YAMCS yamcs-core 5.12.7 - LDAP Injection

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

YAMCS yamcs-core 5.12.7 - LDAP Injection

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
24 jul 2026

CVE-2026-48561 Microsoft Edge Copilot Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Corrected the CVE description and title. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
2 jul 2026

CVE-2026-55115 — CVSS 9.9 CRITICAL

Industrie & Productie

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Hoog
28 jul 2026

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

Financieel & VerzekeringenTransport & Logistiek

JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
4 jun 2026

[Microsoft MSRC] CVE-2026-45497 Microsoft M365 Copilot Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
24 jul 2026

Multiples vulnérabilités dans le noyau Linux de Debian (24 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[remote] Microsoft - NTLMv2 Hash Capture

Industrie & ProductieIT & Technologie

Microsoft - NTLMv2 Hash Capture

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
24 jul 2026

CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
2 jul 2026

CVE-2026-55116 — CVSS 9.0 CRITICAL

Financieel & VerzekeringenTransport & Logistiek

A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
28 jul 2026

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

Industrie & ProductieTransport & LogistiekIT & Technologie

STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem.Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and speed up exploit development. This is local

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
4 jun 2026

[Microsoft MSRC] CVE-2026-47644 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Industrie & ProductieIT & Technologie

Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
24 jul 2026

Multiples vulnérabilités dans le noyau Linux d'Ubuntu (24 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[webapps] MikroORM 7.0.13 - SQL Injection

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

MikroORM 7.0.13 - SQL Injection

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
24 jul 2026

CVE-2026-59677 Process Kill Attack Vector in killall() in seunshare

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
2 jul 2026

CVE-2026-26145 — CVSS 4.8 CRITICAL

IT & Technologie

Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
28 jul 2026

Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost

Financieel & VerzekeringenIT & Technologie

Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
12 mei 2026

[Microsoft MSRC] CVE-2026-41614 M365 Copilot for Desktop Spoofing Vulnerability

Financieel & VerzekeringenIndustrie & Productie

Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
24 jul 2026

Multiples vulnérabilités dans les produits ESET (24 juillet 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans les produits ESET. Elles permettent à un attaquant de provoquer une élévation de privilèges.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[webapps] Prodigy Commerce 3.3.0 - Local File Inclusion

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Prodigy Commerce 3.3.0 - Local File Inclusion

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
24 jul 2026

CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
2 jul 2026

CVE-2026-41106 — CVSS 9.3 CRITICAL

Industrie & Productie

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Kritiek
28 jul 2026

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

Financieel & VerzekeringenTransport & Logistiek

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution. "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security Hoog
12 mei 2026

[Microsoft MSRC] CVE-2026-33833 Azure Machine Learning Notebook Spoofing Vulnerability

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
24 jul 2026

Multiples vulnérabilités dans les produits IBM (24 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[webapps] Langflow 1.3.0 - Remote Code Execution

Industrie & Productie

Langflow 1.3.0 - Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-56167 Azure AI Search Elevation of Privilege Vulnerability

IT & Technologie

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Hoog
27 jul 2026

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
12 mei 2026

[Microsoft MSRC] CVE-2026-42893 Microsoft Outlook for iOS Tampering Vulnerability

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
24 jul 2026

Multiples vulnérabilités dans le noyau Linux de Red Hat (24 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[webapps] Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution

Industrie & Productie

Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-56163 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

Financieel & VerzekeringenIT & Technologie

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Hoog
27 jul 2026

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

Financieel & VerzekeringenIndustrie & Productie

Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt. CNCERT, China's national computer emergency response team, and XLab, the threat-intelligence lab of Chinese

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
7 mei 2026

[Microsoft MSRC] CVE-2026-26164 M365 Copilot Information Disclosure Vulnerability

Industrie & Productie

Improper neutralization of special elements in output used by a downstream component ('injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
24 jul 2026

Multiples vulnérabilités dans le noyau Linux de SUSE (24 juillet 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[local] ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-56165 Microsoft Account Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
27 jul 2026

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

Industrie & Productie

Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not give a lower version

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
7 mei 2026

[Microsoft MSRC] CVE-2026-26129 M365 Copilot Information Disclosure Vulnerability

Industrie & Productie

Improper neutralization of special elements in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
24 jul 2026

Vulnérabilité dans les produits Moxa (24 juillet 2026)

Transport & Logistiek

Une vulnérabilité a été découverte dans les produits Moxa. Elle permet à un attaquant de provoquer une élévation de privilèges.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[local] ZTE Routers - Unauthenticated Denial of Service

IT & Technologie

ZTE Routers - Unauthenticated Denial of Service

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-54120 Microsoft Surface Remote Code Execution Vulnerability

Industrie & ProductieOnderwijs & OnderzoekIT & Technologie

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
27 jul 2026

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

Financieel & VerzekeringenIndustrie & ProductieRetail & E-commerceIT & Technologie

Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped. That is the mood. Here is the full recap. ⚡ Threat of the Week OpenAI Says Its AI Agent Went Rogue

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
7 mei 2026

[Microsoft MSRC] CVE-2026-33111 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Industrie & ProductieIT & Technologie

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
23 jul 2026

Vulnérabilité dans Moodle (23 juillet 2026)

Transport & LogistiekOnderwijs & Onderzoek

Une vulnérabilité a été découverte dans Moodle. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[local] ZTE ZXHN H188A V6 - Authentication Bypass

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

ZTE ZXHN H188A V6 - Authentication Bypass

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-56160 Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability

IT & Technologie

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
27 jul 2026

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another bypass. The affected ranges are <2.31.5 and >=2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
7 mei 2026

[Microsoft MSRC] CVE-2026-32207 Azure Machine Learning Notebook Spoofing Vulnerability

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
9 jul 2026

Multiples vulnérabilités dans Traefik (09 juillet 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[local] ZTE H298A / H108N - Unauthenticated Credential Exposure

Retail & E-commerce

ZTE H298A / H108N - Unauthenticated Credential Exposure

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-35425 Azure API Management (APIM) Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
27 jul 2026

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools. "The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened," ZeroBEC said in

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
11 jun 2026

Vulnérabilité dans Traefik (11 juin 2026)

Transport & Logistiek

Une vulnérabilité a été découverte dans Traefik. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[local] Linux Kernel - Local Privilege Escalation

IT & Technologie

Linux Kernel - Local Privilege Escalation

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-49159 Microsoft Graph Information Disclosure Vulnerability

Retail & E-commerceIT & Technologie

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
27 jul 2026

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra. According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
31 mrt 2026

Vulnérabilité dans F5 BIG-IP Access Policy Manager (31 mars 2026)

Transport & Logistiek

Le 15 octobre 2025, F5 a publié un avis de sécurité concernant entre autres la vulnérabilité CVE-2025-53521. Celle-ci affecte BIG-IP APM et permet à un attaquant non authentifié d'exécuter du code à distance. Le 29 mars 2026, l'éditeur indique que cette vulnérabilité est exploitée activement. Le...

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[webapps] MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution

Industrie & Productie

MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
19 mrt 2026

Multiples vulnérabilités dans Roundcube (19 mars 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans Roundcube. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une falsification de requêtes côté serveur (SSRF) et une injection de code indirecte à distance (XSS).

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[remote] Wing FTP Server 8.1.3 - Authenticated Remote Code Execution

Financieel & VerzekeringenIndustrie & Productie

Wing FTP Server 8.1.3 - Authenticated Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-56191 Microsoft Exchange Online Tampering Vulnerability

Financieel & VerzekeringenIT & Technologie

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
30 jan 2026

[MàJ] Multiples vulnérabilités dans Ivanti Endpoint Manager Mobile (30 janvier 2026)

Transport & LogistiekRetail & E-commerce

[Mise à jour du 09 février 2026] Le 6 février 2026, Ivanti a mis à disposition des scripts RPM de détection d'indicateurs de compromission, à utiliser en fonction de la version d'EPMM installée. L'éditeur a également mis son guide d'analyse à jour (cf. section Documentation). [Mise à jour du 02...

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[webapps] CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)

Financieel & Verzekeringen

CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-57106 Data Quality Elevation of Privilege Vulnerability

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[remote] strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow

Industrie & Productie

strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-62825 Azure Key Vault Elevation of Privilege Vulnerability

IT & Technologie

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
29 mei 2026

[dos] strongSwan 5.9.13 - DoS

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

strongSwan 5.9.13 - DoS

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability

IT & Technologie

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
27 mei 2026

[local] Linux Kernel - Local Privilege Escalation

IT & Technologie

Linux Kernel - Local Privilege Escalation

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-58275 Azure DNS Elevation of Privilege Vulnerability

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
27 mei 2026

[webapps] Casdoor 3.54.1 - Arbitrary File Write via Path Traversal

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Casdoor 3.54.1 - Arbitrary File Write via Path Traversal

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-47729 Squid: Memory disclosure in FTP gateway

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
27 mei 2026

[webapps] EspoCRM 9.3.3 - SSRF

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

EspoCRM 9.3.3 - SSRF

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

Financieel & VerzekeringenIndustrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
27 mei 2026

[webapps] scramble - Remote Code Execution

Industrie & Productie

scramble - Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-63140 Reachable Assertion in Elasticsearch Leading to Denial of Service

Financieel & VerzekeringenIndustrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
27 mei 2026

[hardware] MeiG Smart FORGE_SLT711 - OS Command Injection

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

MeiG Smart FORGE_SLT711 - OS Command Injection

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

Financieel & VerzekeringenIndustrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
27 mei 2026

[local] Realtek rtl819x - Local Privilege

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Realtek rtl819x - Local Privilege

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-53910 Heap-based Buffer Overflow in GNU diffutils

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
27 mei 2026

[webapps] OpenCATS 0.9.7.4 - SQL Injection

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

OpenCATS 0.9.7.4 - SQL Injection

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-55973 'dns-error-reporting: yes' leads to stack buffer overflow

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
26 mei 2026

[webapps] Grav CMS 2.0.0-beta.2 - Remote Code Execution

Industrie & Productie

Grav CMS 2.0.0-beta.2 - Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-50248 BOGUS configured primary hostname accepted for XFR in auth/rpz zones

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-55708 Privacy/configuration issue when adding local data in views through 'unbound-control'

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-44621 Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated

Transport & Logistiek

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-55717 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-40691 Packet of death for DNSCrypt over TCP

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass

Industrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path

Financieel & VerzekeringenIndustrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled out

Industrie & ProductieRetail & E-commerce

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-55990 Packet of death for a DNSCrypt misconfigured Unbound

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-55991 Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2

Industrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-50251 Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-50252 Possible cache poisoning attack by mapping source port population per thread

Financieel & VerzekeringenRetail & E-commerce

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-63308 Helm Files.Lines Denial of Service via Empty Chart Files

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root

Industrie & ProductieTransport & Logistiek

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candida

Industrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candida

Industrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-50012 Squid: Memory corruption in cache_digest reply handling

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-54171 Excon: redact additional sensitive/risky headers when following redirects

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-63263 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

Financieel & VerzekeringenIndustrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin

Industrie & ProductieTransport & Logistiek

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-50045 'max-global-quota' reset by DNSSEC validation restarts

Industrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-44690 Cross-zone wildcard cache poisoning via RRSIG.labels manipulation

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-52863 Memory corruption could lead to crash and denial of service

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name

Transport & LogistiekRetail & E-commerce

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-56444 Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-54478 DNS Cookie bypass when combined with proxy-protocol use

Industrie & ProductieTransport & Logistiek

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-14586 Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-41637 Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
23 jul 2026

CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candida

Industrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
22 jul 2026

CVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header

Financieel & VerzekeringenTransport & Logistiek

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
22 jul 2026

CVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations

Industrie & ProductieTransport & Logistiek

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
22 jul 2026

CVE-2026-59884 pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
22 jul 2026

CVE-2026-59886 pyasn1: Uncontrolled resource consumption when converting decoded REAL values

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
22 jul 2026

CVE-2026-42533 NGINX Map directive and Regex matching vulnerability

Financieel & Verzekeringen

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
22 jul 2026

CVE-2026-56434 NGINX ngx_http_ssi_module vulnerability

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
22 jul 2026

CVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c

Industrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
22 jul 2026

CVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
22 jul 2026

CVE-2026-64189 netfilter: ipset: fix race between dump and ip_set_list resize

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
22 jul 2026

CVE-2026-64188 net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
22 jul 2026

CVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS

Financieel & VerzekeringenIndustrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
22 jul 2026

CVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass

Financieel & VerzekeringenIndustrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
22 jul 2026

CVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering

Financieel & VerzekeringenIndustrie & Productie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
🔍 Geen advisories gevonden voor deze combinatie. Probeer een ander filter.
Disclaimer: Deze advisories zijn afkomstig van publieke bronnen waaronder NCSC NL, CISA, CISA KEV, NVD (NIST), MITRE CVE, Exploit-DB, Mandiant, Microsoft MSRC, Cisco Talos, Kaspersky, ENISA en BleepingComputer. De samenvattingen zijn bedoeld als eerste oriëntatie. Raadpleeg altijd de originele bronnen voor volledige technische details. SOC Continu is niet aansprakelijk voor beslissingen genomen op basis van deze samenvatting.