Bron & ernst

Uw branche
AI Security Medium
28 sep 2026

[The Hacker News] RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

Financieel & VerzekeringenTransport & Logistiek

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
28 sep 2026

Bulletin d'actualité CERTFR-2026-ACT-041 (28 septembre 2026)

Transport & Logistiek

Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
24 sep 2026

Trust and the enticing consultancy offer

Financieel & Verzekeringen

In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem. Hubris might be the real vulnerability that the cyber industry must worry about.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
11 sep 2026

[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

Industrie & Productie

CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
24 sep 2026

MacSync under the microscope: new delivery methods and a new payload

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Medium
28 sep 2026

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Financieel & VerzekeringenTransport & Logistiek

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
Mandiant Kritiek
25 sep 2026

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Introduction As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. In June, the threat actor exploited this vulnerability as a zero-day predominan…

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
28 sep 2026

CVE-2026-81355 Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability

Industrie & Productie

Updated an acknowledgement. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Medium
28 sep 2026

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerceIT & Technologie

Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations. The post NeedyMantis: Unpacking a post-compromise malware family used in targeted operations appeared first on Microsoft Security Blog.

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NL Medium
27 sep 2026

NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Citrix heeft 8 kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Kritiek
28 sep 2026

Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
NVD Kritiek
6 sep 2026

CVE-2026-86218 — CVSS 9.8 CRITICAL

Industrie & Productie

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Kritiek
28 sep 2026

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

Retail & E-commerceIT & Technologie

Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42.

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
SANS ISC Hoog
28 sep 2026

Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)

Financieel & VerzekeringenIndustrie & Productie

Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today&#;x26;#;39;s update for the current "27" branch does not address security issues, but fixes some functional issues that got caught after…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Kritiek
28 sep 2026

Citrix waarschuwt voor misbruikte kwetsbaarheden: 'Zo snel mogelijk updaten'

IT & Technologie

Citrix waarschuwt voor twee kritieke kwetsbaarheden in Citrix NetScaler ADC en Gateway waar aanvallers actief misbruik van ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Hoog
29 sep 2026

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerce

Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Medium
28 sep 2026

[The Hacker News] ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
28 sep 2026

Multiples vulnérabilités dans Citrix NetScaler ADC et Gateway (28 septembre 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans Citrix NetScaler ADC et Gateway. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité. Citrix indique que les...

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
22 sep 2026

The Closed Quorum: Inside the first reported autonomous AI C2 implant

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
3 sep 2026

[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)

Industrie & Productie

FreePBX 17.0.2 - Remote Code Execution (RCE)

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
21 sep 2026

Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

Financieel & VerzekeringenIT & Technologie

Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Hoog
16 sep 2026

Data Broker Radaris Loses Domains in Privacy Fight

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement off…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
24 sep 2026

Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Introduction The landscape of software supply chain security has undergone a significant shift. Recent campaigns demonstrate that sophisticated threat actors are systematically targeting the engineering lifecycle by compromising trusted security and programming tools. These intrusions reveal three key tactics: Attackers target trusted security scanners, utility libraries, and AI developer tools to…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

CVE-2026-69522 .NET and Visual Studio Remote Code Execution Vulnerability

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Security Updates table updated provide links to the KB articles and download center updates. Microsoft recommends installing the updates.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Hoog
25 sep 2026

Storm-3168: Agentic-driven cloud attacks using compromised service principals

Financieel & VerzekeringenRetail & E-commerceIT & Technologie

Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. The post Storm-3168: Agentic-driven cloud attacks using compromised service principals appeared first on Microsoft Security Blog.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
24 sep 2026

NCSC-2026-0389 [1.01] [M/H] Kwetsbaarheid verholpen in WordPress

Financieel & VerzekeringenIndustrie & Productie

De ontwikkelaars van WordPress hebben een kwetsbaarheid verholpen in WordPress. Een kwaadwillende kan de kwetsbaarheid met kenmerk CVE-2026-87902 misbruiken, om zonder authenticatie een lokaal PHP-bestand buiten de actieve themamappen door WordPress te laten inladen.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
15 sep 2026

Iranian cyber targeting of dissidents, activists and journalists

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
5 sep 2026

CVE-2026-67278 — CVSS 9.1 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue ce…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
25 sep 2026

3 Consulting Myths Debunked by Unit 42 Experts

Financieel & VerzekeringenRetail & E-commerce

Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths Debunked by Unit 42 Experts appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
SANS ISC Hoog
27 sep 2026

Wireshark 4.6.9 Released, (Sun, Sep 27th)

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Wireshark release 4.6.9 fixes 19 vulnerabilities and 16 bugs.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Kritiek
25 sep 2026

NCSC meldt actief misbruik van kritiek WordPress-lek: 'Update nu'

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Aanvallers maken actief misbruik van een kritieke path traversal-kwetsbaarheid in WordPress waardoor websites zijn over te ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Medium
29 sep 2026

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Overheid & Publieke SectorTransport & LogistiekOnderwijs & OnderzoekIT & Technologie

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
28 sep 2026

[The Hacker News] Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
28 sep 2026

Multiples vulnérabilités dans MongoDB (28 septembre 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans MongoDB. Elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
22 sep 2026

Introducing CAIRN: Frontier tracking for AI-integrated malware

Financieel & Verzekeringen

Talos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
3 sep 2026

[webapps] Metabase 0.61.0 - Authenticated Remote Code Execution

Industrie & Productie

Metabase 0.61.0 - Authenticated Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
4 sep 2026

Angry Birds: Toy Ghouls’ new toys

Financieel & VerzekeringenIndustrie & Productie

Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Medium
8 sep 2026

Microsoft Plugs Nearly 1,000 Security Holes

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and d…

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
Mandiant Kritiek
8 sep 2026

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defe…

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
25 sep 2026

CVE-2026-78510 Microsoft Outlook and Word Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Updated CVE title and CVSS Score. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Hoog
24 sep 2026

Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Financieel & VerzekeringenRetail & E-commerceIT & Technologie

Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment. The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments appeared first on Microsoft S…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
24 sep 2026

NCSC-2026-0393 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic

Financieel & VerzekeringenIndustrie & Productie

Adobe heeft 18 kritieke kwetsbaarheden verholpen in Adobe Campaign Classic. De kwetsbaarheden betreffen onder meer code- en OS-command-injectie, SQL-injectie, onvoldoende autorisatie, onvoldoende invoervalidatie en Server-Side Request Forgery (SSRF).

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
15 sep 2026

UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists

Transport & LogistiekRetail & E-commerce

UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
5 sep 2026

CVE-2026-86060 — CVSS 9.8 CRITICAL

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
16 sep 2026

Atomic macOS (AMOS) Stealer Activity

Retail & E-commerce

Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
SANS ISC Hoog
25 sep 2026

A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)

Financieel & Verzekeringen

Introduction

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Medium
24 sep 2026

'Android-malware gebruikt vaker vpn voor blokkeren van Google Play Protect'

Industrie & ProductieIT & Technologie

Android-malware gebruikt steeds vaker een vpn-service voor het blokkeren van Google Play Protect om zo detectie door de ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Hoog
28 sep 2026

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

IT & Technologie

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Medium
26 sep 2026

[The Hacker News] Zero Trust for AI Agents Starts With Fixing Zero Visibility

Financieel & VerzekeringenTransport & Logistiek

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
28 sep 2026

Multiples vulnérabilités dans Citrix NetScaler ADC et Gateway (28 septembre 2026)

Transport & LogistiekIT & Technologie

Le 27 septembre 2026, Citrix a publié un avis de sécurité concernant plusieurs vulnérabilités qui affectent NetScaler ADC et Gateway. Parmi celles-ci, les vulnérabilités CVE-2026-88771 et CVE-2026-88772 permettent une exécution de code arbitraire à distance par un attaquant non authentifié. Ces...

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
17 sep 2026

Should you care about an “AI slowdown?”

Financieel & VerzekeringenIndustrie & Productie

In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
2 sep 2026

[dos] EVerest 2025.9.0 - DoS

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

EVerest 2025.9.0 - DoS

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
1 sep 2026

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Financieel & VerzekeringenIndustrie & Productie

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Hoog
1 sep 2026

FBI Probes Service Selling 153M+ Drivers Licenses

Financieel & VerzekeringenOverheid & Publieke SectorTransport & Logistiek

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity a…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
1 sep 2026

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceIT & Technologie

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. Thi…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

CVE-2026-85921 Windows Secure Kernel Mode Elevation of Privilege Vulnerability

IT & Technologie

Updated an acknowledgement. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Medium
22 sep 2026

Unmasking EvilTokens: Getting to the root of device code phishing

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations. The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on…

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NL Medium
23 sep 2026

NCSC-2026-0392 [1.00] [M/H] Kwetsbaarheden verholpen in IBM Langflow OSS en IBM MQ Appliance

Industrie & ProductieIT & Technologie

IBM heeft 12 kwetsbaarheden verholpen in IBM MQ, IBM MQ Appliance en Langflow OSS. De kwetsbaarheden kunnen leiden tot het uitvoeren van willekeurige code of commando's. Vier kwetsbaarheden zijn als kritiek aangemerkt en kunnen zonder authenticatie en gebruikersinteractie op afstand worden misbruikt.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
27 aug 2026

Disruptive cyber activity highlights risk from internet-exposed systems and edge devices

Industrie & ProductieRetail & E-commerce

Owners of operational technology encouraged to address avoidable vulnerabilities, and build long-term cyber resilience.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
4 sep 2026

CVE-2026-85594 — CVSS 9.8 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
10 sep 2026

The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

Industrie & ProductieRetail & E-commerce

Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
SANS ISC Hoog
24 sep 2026

One URL, Three Different Tricks, (Thu, Sep 24th)

Financieel & Verzekeringen

Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link:

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Medium
24 sep 2026

Verdachte achter ransomware-aanvallen moet 1,2 miljoen dollar betalen

Industrie & ProductieTransport & Logistiek

Een 35-jarige Armeense man is in de Verenigde Staten wegens het uitvoeren van ransomware-aanvallen veroordeeld tot een ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Medium
28 sep 2026

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

Financieel & VerzekeringenTransport & Logistiek

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
24 sep 2026

[Microsoft MSRC] CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability

Financieel & VerzekeringenIndustrie & Productie

Updated the fixed version information and download link. The fix was previously believed to be included in Dynamics 365 Server (on-premises) version 6.2; however, it has been confirmed that the fix is included in Dynamics 365 Server v9.1 (on-premises) Update 1.45 (version 9.1.0045.0011). The download link, release notes, and build number has been updated accordingly in the Security Updates table. …

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
25 sep 2026

Multiples vulnérabilités dans les produits IBM (25 septembre 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
17 sep 2026

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Financieel & Verzekeringen

Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
2 sep 2026

[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting

Financieel & Verzekeringen

Bludit CMS 3.20.0 - Reflected Cross-Site Scripting

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
31 aug 2026

ValleyRAT masquerading as adware

Financieel & Verzekeringen

Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Hoog
27 aug 2026

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & Productie

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
20 aug 2026

Going with the Flow(s): Distinct Clusters Target Individuals of Interest to Russia

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Gabby Roncone, Wesley Shields Overview Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. Examples of these tec…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-87489: Memory corruption in V8

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Medium
10 sep 2026

Detect and disrupt AI-themed attacks with Microsoft Defender

Financieel & VerzekeringenRetail & E-commerceIT & Technologie

See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NL Medium
23 sep 2026

NCSC-2026-0386 [1.01] [H/H] Kwetsbaarheid verholpen in F5 Networks BIG-IP Access Policy Manager

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

F5 Networks heeft een kwetsbaarheid verholpen in BIG-IP Access Policy Manager (APM). De kwetsbaarheid stelt een ongeauthenticeerde kwaadwillende in staat om malafide code uit te voeren. Hiertoe dient de kwaadwillende malafide netwerkverkeer naar het kwetsbare systeem te versturen.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
4 aug 2026

NCSC statement in response to recent incidents resulting from frontier AI evaluations

Financieel & VerzekeringenTransport & Logistiek

A statement from Ollie Whitehouse, Chief Technology Officer at the NCSC, on AI security following recent incidents.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
4 sep 2026

CVE-2026-85595 — CVSS 9.8 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or pas…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
9 sep 2026

Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

Financieel & VerzekeringenRetail & E-commerce

An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
SANS ISC Hoog
23 sep 2026

Macfinger ClickFix campaign, (Tue, Sep 22nd)

Financieel & Verzekeringen

Introduction

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Kritiek
24 sep 2026

Check Point meldt actief misbruik van kritieke vpn-kwetsbaarheid

IT & Technologie

Cybersecuritybedrijf Check Point waarschuwt voor actief misbruik van een kritieke kwetsbaarheid in de vpn-producten die het ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Medium
28 sep 2026

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Medium
22 sep 2026

[Microsoft Security Blog] Unmasking EvilTokens: Getting to the root of device code phishing

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations. The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on…

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
25 sep 2026

Multiples vulnérabilités dans le noyau Linux d'Ubuntu (25 septembre 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
16 sep 2026

Securing the unpatchable in an age of AI-driven vulnerabilities

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerce

Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensatory layer.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
2 sep 2026

[webapps] PodcastGenerator 3.2.9 - Stored XSS

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

PodcastGenerator 3.2.9 - Stored XSS

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
27 aug 2026

Threat landscape for industrial automation systems. Q2 2026

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Kritiek
11 aug 2026

Microsoft Plugs Nearly 400 Security Holes

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Mandiant Kritiek
18 aug 2026

Staying Ahead of Adversarial AI Through Agentic Source Code Review

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Alex Tselevich, Michael Maturi Introduction Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them. By structuring the analysis process, enforcing skeptical validation steps, and injecting …

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-87536: Use after free in V8

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
23 sep 2026

NCSC-2026-0391 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Connect en Adobe Connect Android Mobile App

Financieel & VerzekeringenIndustrie & Productie

Adobe heeft 9 kwetsbaarheden verholpen in Adobe Connect en de Adobe Connect Android Mobile App. De kwetsbaarheden zijn verholpen in Adobe Connect 12.12 en Adobe Connect Android Mobile App 4.5.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
23 jul 2026

UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerce

GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
4 sep 2026

CVE-2026-85596 — CVSS 9.8 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the nginx.ingress.kubernetes.io/auth-tls-secret annotation was named after the Ingress namespace and name. As a result, two Ingress objects sharing the same host, the same client CA secret, and the same client-authentication mode prod…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
31 aug 2026

Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerceIT & Technologie

Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Medium
24 sep 2026

Microsoft schakelt AI cybercrimeplatform "EvilTokens" grotendeels uit

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Microsoft heeft een phishing as a service (PhaaS) platform, bekend onder de naam "EvilTokens", grotendeels weten uit te ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Hoog
28 sep 2026

Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
22 sep 2026

[Cisco Talos] Introducing CAIRN: Frontier tracking for AI-integrated malware

Financieel & Verzekeringen

Talos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
25 sep 2026

Multiples vulnérabilités dans le noyau Linux de Debian LTS (25 septembre 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni de service.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
10 sep 2026

We've got one word for it, and it's usually the wrong one

Financieel & VerzekeringenIndustrie & Productie

In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
2 sep 2026

[webapps] Ghost_CMS 6.19.0 - Remote Code Execution

Industrie & Productie

Ghost_CMS 6.19.0 - Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
26 aug 2026

Exploits and vulnerabilities in Q2 2026

Industrie & Productie

This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
6 aug 2026

UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments

Zorg & GezondheidFinancieel & VerzekeringenIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Tyler McLellan, Austin Larsen Introduction Google Threat Intelligence Group (GTIG) continues to track UNC6671 actively conducting compromises leading to data theft extortion, despite the alleged announced retirement of the BlackFile extortion brand in May 2026. Telemetry and infrastructure analysis reveal that rather than disbanding, UNC6671 has diversified its operations across multip…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-87601: Race condition in V8

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
23 sep 2026

NCSC-2026-0390 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager Forms JEE

Financieel & VerzekeringenIndustrie & Productie

Adobe heeft 6 kwetsbaarheden verholpen in Adobe Experience Manager (AEM) Forms op Java Enterprise Edition (JEE), waaronder AEM 6.5 Forms en AEM 6.5 LTS Forms.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
13 jul 2026

UK and Allies urge critical sectors to improve defences against Russian intelligence targeting

Financieel & VerzekeringenIT & Technologie

New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
4 sep 2026

CVE-2026-85597 — CVSS 9.1 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS req…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
25 aug 2026

The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Financieel & VerzekeringenIndustrie & ProductieRetail & E-commerce

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Kritiek
24 sep 2026

Wordpress 7.1.2 verhelpt kritieke kwetsbaarheid

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

WordPress heeft versie 7.1.2 uitgebracht waarin een Path Traversal kwetsbaarheid is verholpen die onder bepaalde omstandigheden ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Hoog
28 sep 2026

JADEPUFFER-Linked Attackers Used Compromised Service Principals to Delete Azure Resources

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

The threat actor known as JADEPUFFER has been observed orchestrating destructive actions within a Microsoft Azure environment using compromised service principals. Microsoft, which is tracking the activity under the name Storm-3168, has called it an evolution of the threat actor's tradecraft. The attack took place in early June 2026 over a period of about 18 hours. "The destructive operations

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
17 sep 2026

[Microsoft MSRC] CVE-2026-55946 Microsoft Copilot Information Disclosure Vulnerability

Industrie & ProductieIT & Technologie

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
25 sep 2026

Multiples vulnérabilités dans les produits Elastic (25 septembre 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans les produits Elastic. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
9 sep 2026

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Financieel & VerzekeringenIT & Technologie

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
2 sep 2026

[webapps] Langflow 1.10.0 - RCE

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Langflow 1.10.0 - RCE

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
21 aug 2026

The invisible passenger in your car

Industrie & Productie

Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Kritiek
30 jul 2026

Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Grou…

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-87612: Type confusion in V8

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
23 sep 2026

NCSC-2026-0388 [1.00] [M/H] Kwetsbaarheden verholpen in SolarWinds Observability Self-Hosted

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekEnergie & Nutsbedrijven

SolarWinds heeft kwetsbaarheden verholpen in SolarWinds Observability Self-Hosted. De kwetsbaarheden maken ongeauthenticeerde remote code execution mogelijk. Eén kwetsbaarheid ontstaat door deserialisatie van onbetrouwbare data tijdens het gebruik van een specifieke communicatiemodus binnen de software.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
22 jun 2026

The AI shift in cyber risk: why leaders must act now

Financieel & VerzekeringenTransport & Logistiek

Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
4 sep 2026

CVE-2026-85695 — CVSS 9.4 CRITICAL

Transport & Logistiek

FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can register malicious workers under victim model names to intercept user prompts, images, and responses, or probe internal network ports across the worker mesh.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
21 aug 2026

Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain

Financieel & VerzekeringenIndustrie & ProductieRetail & E-commerce

Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Kritiek
24 sep 2026

Adobe dicht kritieke kwetsbaarheden in Connect en AEM Forms

Financieel & Verzekeringen

Adobe heeft beveiligingsupdates uitgebracht voor kritieke kwetsbaarheden in Adobe Connect en Adobe Experience Manager (AEM) ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Hoog
28 sep 2026

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

Financieel & VerzekeringenOverheid & Publieke SectorIT & Technologie

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-88771 (CVSS score: 9.5) - An improper input validation vulnerability that could allow an unauthenticated attacker to

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
17 sep 2026

[Microsoft MSRC] CVE-2026-68791 Azure Machine Learning Information Disclosure Vulnerability

Financieel & VerzekeringenIT & Technologie

Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
25 sep 2026

Multiples vulnérabilités dans le noyau Linux de SUSE (25 septembre 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et une atteinte à la confidentialité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
8 sep 2026

Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities

Financieel & VerzekeringenIT & Technologie

Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
2 sep 2026

[hardware] Fullhan FH8626V100 - Multiple Vulnerabilities

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Fullhan FH8626V100 - Multiple Vulnerabilities

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
24 jul 2026

Updated Cyber Threat Actor Naming System

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerce

Update (July 30): A table listing the new names of select prominent threat actors was appended to this post. Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Why are we Adopting a Different Naming System? …

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-87625: Use after free in V8

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
23 sep 2026

NCSC-2026-0365 [1.01] [H/H] Kwetsbaarheden verholpen in Check Point VPN-producten

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Check Point heeft twee kritieke kwetsbaarheden verholpen in Quantum Security Gateway en Security Management. De kwetsbaarheid met kenmerk CVE-2026-85102 heeft een CVSS-score van 9,8. De kwetsbaarheid bevindt zich in het VPN-onderhandelingsproces van de Quantum Security Gateway en wordt veroorzaakt door onjuiste validatie van certificaatvertrouwen.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
18 jun 2026

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
4 sep 2026

CVE-2026-77822 — CVSS 8.2 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

IBM ContextForge MCP Gateway could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery via DNS rebinding.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Kritiek
23 sep 2026

NCSC waarschuwt voor actief misbruikt zerodaylek in F5 BIG-IP

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Het Nationaal Cyber Security Centrum (NCSC) waarschuwt organisaties voor een ernstige kwetsbaarheid in F5 BIG-IP Access Policy ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Kritiek
27 sep 2026

Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws. One of the two affects every deployment on an affected version, including those in the default configuration. The bulletin came a day after security firm watchTowr

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security Hoog
17 sep 2026

[Microsoft MSRC] CVE-2026-85885 Microsoft 365 Copilot Elevation of Privilege Vulnerability

Industrie & ProductieIT & Technologie

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
25 sep 2026

Multiples vulnérabilités dans le noyau Linux de Red Hat (25 septembre 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
8 sep 2026

ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

Financieel & VerzekeringenIT & Technologie

Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
2 sep 2026

[webapps] Marimo 0.20.4 - RCE

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Marimo 0.20.4 - RCE

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Kritiek
16 jul 2026

Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration …

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95274: Improper output encoding in DevTools

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
23 sep 2026

NCSC-2026-0387 [1.00] [M/H] Kwetsbaarheid verholpen in Check Point Security Management en Log Servers

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

Check Point heeft een kwetsbaarheid verholpen in Security Management en Log Servers. De kwetsbaarheid betreft een pre-authentication directory-traversal-kwetsbaarheid in de Check Point Management Web Service, waarmee ongeauthenticeerde aanvallers scripts vanaf een willekeurig pad kunnen uitvoeren.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
17 jun 2026

NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems

Financieel & Verzekeringen

Dr Richard Horne highlighted the scale of cyber threats against the UK’s critical infrastructure at RUSI’s Annual Security Lecture.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
4 sep 2026

CVE-2026-17057 — CVSS 6.5 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and affect data integrity due to missing authentication for critical functions.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Kritiek
22 sep 2026

D-Link waarschuwt voor kritieke kwetsbaarheid in wifi-router

IT & Technologie

D-Link waarschuwt voor een kritieke kwetsbaarheid in de DIR-822A wifi-routers waar op dit moment nog geen patch voor ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Medium
26 sep 2026

Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

Financieel & VerzekeringenTransport & Logistiek

The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aimed at targeting Ukrainian-speaking users. "The attack chain begins with a fake CAPTCHA page and

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
17 sep 2026

[Microsoft MSRC] CVE-2026-78501 Microsoft 365 Copilot Business Chat Information Disclosure Vulnerability

Industrie & ProductieIT & Technologie

Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
24 sep 2026

Multiples vulnérabilités dans Papercut (24 septembre 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans Papercut. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
27 aug 2026

“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend

Financieel & VerzekeringenTransport & Logistiek

In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
1 sep 2026

[webapps] Wolf CMS 0.8.3.1 - RCE v

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Wolf CMS 0.8.3.1 - RCE v

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
15 jul 2026

The Risk of Exposed Cloud Functions and How to Harden

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remo…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95275: Incorrect reference resolution in MediaStream

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 sep 2026

NCSC-2026-0385 [1.00] [M/H] Kwetsbaarheid verholpen in VeloCloud Orchestrator (VCO) on-premises

Financieel & VerzekeringenIndustrie & Productie

VeloCloud heeft een kwetsbaarheid verholpen in VeloCloud Orchestrator (VCO) on-premises. De kwetsbaarheid in VCO stelt externe aanvallers in staat om toegang te krijgen tot geprivilegieerde interne functionaliteit, wat de vertrouwelijkheid, integriteit en beschikbaarheid kan aantasten.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
23 apr 2026

NCSC: Leave passwords in the past - passkeys are the future

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
4 sep 2026

CVE-2026-17207 — CVSS 6.5 CRITICAL

Industrie & ProductieIT & Technologie

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and compromise integrity due to a buffer overflow.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Kritiek
26 sep 2026

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution. The vulnerability was first exploited as a zero-day

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security Hoog
17 sep 2026

[Microsoft MSRC] CVE-2026-85887 M365 Copilot Information Disclosure Vulnerability

Industrie & Productie

Incorrect permission assignment for critical resource in M365 Copilot allows an authorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
24 sep 2026

Multiples vulnérabilités dans LibreNMS (24 septembre 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans LibreNMS. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
27 aug 2026

JavaScript obfuscation: From party trick to phishing kit

Financieel & VerzekeringenIndustrie & Productie

Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
1 sep 2026

[webapps] Payload CMS 3.72.0 - Blind SQL Injection

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Payload CMS 3.72.0 - Blind SQL Injection

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
7 jul 2026

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to a…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95276: Improper input validation in Themes

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
18 sep 2026

NCSC-2026-0384 [1.00] [M/H] Kwetsbaarheid verholpen in Check Point's Security Management and Log Servers

Industrie & ProductieTransport & Logistiek

Check Point heeft een kwetsbaarheid verholpen in Check Point's Security Management and Log Servers. De kwetsbaarheid betreft een stack overflow die optreedt tijdens het ongeauthenticeerde inlogproces. Een aanvaller kan deze kwetsbaarheid op afstand misbruiken om willekeurige code uit te voeren met rootrechten.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
23 apr 2026

International cyber agencies share fresh advice to defend against China-linked covert networks

Industrie & Productie

New advisory highlights how to defend against attacker tactics believed to be used by China-linked actors to hide malicious cyber activity.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
4 sep 2026

CVE-2026-18221 — CVSS 8.1 CRITICAL

Industrie & ProductieIT & Technologie

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to gain unauthorized access due to improper validation of client-supplied authentication parameters.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
26 sep 2026

Zero Trust for AI Agents Starts With Fixing Zero Visibility

Financieel & VerzekeringenTransport & Logistiek

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
16 sep 2026

[Cisco Talos] Securing the unpatchable in an age of AI-driven vulnerabilities

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerce

Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensatory layer.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
24 sep 2026

Multiples vulnérabilités dans Zabbix Agent (24 septembre 2026)

Industrie & ProductieTransport & Logistiek

De multiples vulnérabilités ont été découvertes dans Zabbix Agent. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
1 sep 2026

[webapps] Bludit CMS - Stored XSS

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Bludit CMS - Stored XSS

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
2 jul 2026

Google’s Continued Disruption of Malicious Residential Proxy Networks

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the …

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95277: Use after free in Views

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
17 sep 2026

NCSC-2026-0383 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle VM VirtualBox

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft 19 kwetsbaarheden verholpen in Oracle VM VirtualBox. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle VM VirtualBox, waaronder mogelijkheden voor lokale en geauthenticeerde kwaadwillenden om ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van laag tot hoog.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
23 apr 2026

Executive Summary: Defending against China-nexus covert networks of compromised devices

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Organisations should map and baseline their edge device traffic, especially VPN and remote access connections, and adopt dynamic threat feed filtering that includes known covert network indicators.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
4 sep 2026

CVE-2026-84961 — CVSS 7.4 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer who…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Hoog
26 sep 2026

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Medium
10 sep 2026

[Microsoft Security Blog] Detect and disrupt AI-themed attacks with Microsoft Defender

Financieel & VerzekeringenRetail & E-commerceIT & Technologie

See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
24 sep 2026

Multiples vulnérabilités dans PHP (24 septembre 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
1 sep 2026

[webapps] Grav CMS 2.0.7 - RCE

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Grav CMS 2.0.7 - RCE

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
29 jun 2026

The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: James Sadowski, Alden Wahlstrom Introduction Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert info…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95278: Missing authorization in WakeLock

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
17 sep 2026

NCSC-2026-0382 [1.00] [H/H] Kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE)

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Cisco heeft 21 kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE) en Cisco ISE Passive Identity Connector (ISE-PIC).

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
23 apr 2026

Defending against China-nexus covert networks of compromised devices

Financieel & VerzekeringenIndustrie & Productie

Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
4 sep 2026

CVE-2026-57162 — CVSS 9.1 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

PJSIP is a free and open source multimedia communication library written in C. Prior to commit a1b707c, a stack buffer overflow exists in the SRTP/SDES media transport when processing a=crypto attributes during SDP offer/answer (sdes_encode_sdp() in transport_srtp_sdes.c). This affects applications with SRTP enabled (use_srtp optional or mandatory, using SDES keying). During media negotiation, the…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Kritiek
26 sep 2026

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieIT & Technologie

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security Hoog
9 sep 2026

[Microsoft MSRC] CVE-2026-45499 Azure OpenAI Elevation of Privilege Vulnerability

IT & Technologie

Updated an acknowledgement. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
24 sep 2026

Multiples vulnérabilités dans GitLab (24 septembre 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
1 sep 2026

[webapps] miniOrange 5.4.3 - Unauthenticated Auth Bypass

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

miniOrange 5.4.3 - Unauthenticated Auth Bypass

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
25 jun 2026

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizati…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95279: UI misrepresentation in Omnibox

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
16 sep 2026

NCSC-2026-0381 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle PeopleSoft Enterprise

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft 16 kwetsbaarheden verholpen in diverse Oracle PeopleSoft-producten, waaronder PeopleSoft Enterprise PeopleTools, PeopleSoft Enterprise PRTL Interaction Hub en PeopleSoft Enterprise CC Common Application Objects.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
22 apr 2026

World-first NCSC-engineered device secures vulnerable display links

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

SilentGlass, a plug-and-play device, actively blocks any unexpected or malicious HDMI and Display Port connections.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
4 sep 2026

CVE-2026-57163 — CVSS 9.1 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieRetail & E-commerce

PJSIP is a free and open source multimedia communication library written in C. Prior to commit c4a151a, a stack buffer overflow exists in the GnuTLS TLS backend when parsing the Subject Alternative Name extension of a peer certificate (tls_cert_get_info() in ssl_sock_gtls.c). Only GnuTLS builds are affected (--with-gnutls); OpenSSL and Apple SecureTransport/Network.framework builds are not affecte…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
25 sep 2026

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerceIT & Technologie

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below - actions-cool/issues-helper actions-cool/maintain-one-comment Visiting either of the repositories now shows the message: "Access to this

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
8 sep 2026

[Microsoft MSRC] CVE-2026-81380 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability

Industrie & ProductieIT & Technologie

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
24 sep 2026

Multiples vulnérabilités dans Wireshark (24 septembre 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans Wireshark. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un déni de service à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
1 sep 2026

[webapps] EasyAppointments 1.5.1 - Blind SQL Injection

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

EasyAppointments 1.5.1 - Blind SQL Injection

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Kritiek
24 jun 2026

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

Zorg & GezondheidFinancieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-leve…

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95280: Race condition in V8

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
16 sep 2026

NCSC-2026-0380 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Java SE

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft 3 kwetsbaarheden verholpen in Oracle Java SE, waaronder Oracle GraalVM for JDK en Oracle GraalVM Enterprise Edition. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle Java SE-producten, waarbij niet-geauthenticeerde kwaadwillenden via netwerktoegang kwetsbaarheden in de Compiler-component kunnen misbruiken.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
21 apr 2026

Cyber chief: UK faces "perfect storm" for cyber security

Financieel & Verzekeringen

As the technology landscape develops, the definition of cyber security is expanding with it.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
3 sep 2026

CVE-2026-85031 — CVSS 9.9 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieRetail & E-commerce

A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attack is possible.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
25 sep 2026

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Financieel & Verzekeringen

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
8 sep 2026

[Microsoft MSRC] CVE-2026-81381 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability

Industrie & ProductieIT & Technologie

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
24 sep 2026

Vulnérabilité dans Microsoft Office (24 septembre 2026)

Transport & LogistiekIT & Technologie

Une vulnérabilité a été découverte dans Microsoft Office. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
31 aug 2026

[webapps] C-MOR 6.0104 - Directory Traversal

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

C-MOR 6.0104 - Directory Traversal

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
15 jun 2026

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally …

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95281: Buffer overflow in ANGLE

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
16 sep 2026

NCSC-2026-0379 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Analytics

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft 50 kwetsbaarheden verholpen in diverse Oracle Analytics-producten, waaronder Oracle Business Intelligence Enterprise Edition en Oracle BI Publisher.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
7 apr 2026

APT28 exploit routers to enable DNS hijacking operations

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

Russian cyber actor APT28 exploit vulnerable routers to hijack DNS, enabling adversary‑in‑the‑middle attacks and theft of passwords and authentication tokens.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
3 sep 2026

CVE-2026-85165 — CVSS 9.9 CRITICAL

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerce

n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects through expression evaluation, with changes persisting process-wide until restart.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Kritiek
25 sep 2026

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Financieel & VerzekeringenTransport & Logistiek

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security Hoog
8 sep 2026

[Microsoft MSRC] CVE-2026-80098 Copilot Studio Elevation of Privilege Vulnerability

Industrie & Productie

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
23 sep 2026

Multiples vulnérabilités dans Apache Tomcat (23 septembre 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans Apache Tomcat. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
31 aug 2026

[webapps] C-MOR 6.0104 - Cross-Site Scripting (XSS)

Financieel & Verzekeringen

C-MOR 6.0104 - Cross-Site Scripting (XSS)

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
5 jun 2026

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in …

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95282: Use after free in Platform

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
16 sep 2026

NCSC-2026-0378 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Financial Services

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft 6 kwetsbaarheden verholpen in diverse Oracle Financial Services Applications-producten, waaronder Oracle Banking Branch, Oracle Banking Corporate Lending, Oracle Banking Origination, Oracle Banking Treasury Management en Oracle Banking Corporate Lending Process Management.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
7 apr 2026

UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerceIT & Technologie

New advisory warns cyber threat group APT28 have exploited vulnerable edge devices to support malicious operations.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
3 sep 2026

CVE-2026-85183 — CVSS 9.3 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitrary domains and invoke state variable modifications and action callbacks without CSRF protection.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
25 sep 2026

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

Financieel & VerzekeringenIndustrie & Productie

A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got, according to Cloudflare. The company

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Kritiek
8 sep 2026

[Mandiant] GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defe…

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
CERT-FR Hoog
23 sep 2026

Multiples vulnérabilités dans les produits FoxIT (23 septembre 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans les produits FoxIT. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et une atteinte à la confidentialité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
31 aug 2026

[webapps] CubeCart 6.7.4 - SQL injection

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

CubeCart 6.7.4 - SQL injection

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Kritiek
25 mei 2026

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (…

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95283: Buffer overflow in Tint

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
16 sep 2026

NCSC-2026-0377 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Enterprise Manager

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft 7 kwetsbaarheden verholpen in diverse Oracle Enterprise Manager-producten, waaronder Oracle Enterprise Manager Base Platform, Oracle Enterprise Manager for Fusion Middleware en Oracle Enterprise Manager for Oracle Database.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
31 mrt 2026

NCSC warns of messaging app targeting

Financieel & VerzekeringenTransport & Logistiek

The NCSC has issued actions for individuals at risk of targeted attacks against messaging apps.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
3 sep 2026

CVE-2026-85216 — CVSS 9.8 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficient validation of user-supplied credentials. The custom LdapAuthenticate and LinOTPAuthenticate components replace CakePHP's FormAuthenticate implementation but did not replicate its credential validation checks. As a result, empty or non-string values could reach the underlying a…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Hoog
25 sep 2026

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

Financieel & VerzekeringenOverheid & Publieke SectorRetail & E-commerceIT & Technologie

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
2 sep 2026

[Microsoft MSRC] CVE-2026-70335 GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability

Industrie & ProductieIT & Technologie

Affected software updated with new package information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
23 sep 2026

Multiples vulnérabilités dans SolarWinds Observability Self-Hosted (23 septembre 2026)

Transport & LogistiekEnergie & Nutsbedrijven

De multiples vulnérabilités ont été découvertes dans SolarWinds Observability Self-Hosted. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
31 aug 2026

[webapps] CubeCart 6.7.4 - SQL

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

CubeCart 6.7.4 - SQL

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95284: Buffer overflow in ANGLE

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
16 sep 2026

NCSC-2026-0376 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle E-Business Suite

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

Oracle heeft 159 kwetsbaarheden verholpen in diverse Oracle E-Business Suite-producten, waaronder Oracle Applications Framework, Oracle Document Management and Collaboration, Oracle Mobile Application Server, Oracle Alert, Oracle Application Object Library, Oracle Applications Manager, Oracle Bills of Material, Oracle Complex Maintenance, Repair an

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
30 mrt 2026

Vulnerability affecting F5 BIG-IP APM

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

The NCSC is encouraging UK organisations to mitigate an unauthenticated remote code execution vulnerability affecting F5 BIG-IP Access Policy Manager.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
3 sep 2026

CVE-2026-85221 — CVSS 9.1 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property was not explicitly initialized and therefore defaulted to null. When passed to cURL, this value effectively disabled TLS peer verification unless the calling code explicitly enabled it. As a result, HTTPS connections made through affected CurlClient instances could accept certif…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
24 sep 2026

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
28 aug 2026

[Microsoft MSRC] CVE-2026-70331 Microsoft Edge for iOS Spoofing Vulnerability

Financieel & VerzekeringenIT & Technologie

Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
23 sep 2026

Vulnérabilité dans WordPress (23 septembre 2026)

Transport & Logistiek

Une vulnérabilité a été découverte dans WordPress. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
31 aug 2026

[webapps] CubeCart 6.7.4 - Stored XSS

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

CubeCart 6.7.4 - Stored XSS

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95285: Missing authorization in WebView

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
16 sep 2026

NCSC-2026-0375 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Communications

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft 31 kwetsbaarheden verholpen in diverse Oracle Communications-producten, waaronder Oracle Communications Unified Assurance, Oracle Communications Cloud Native Core Security Edge Protection Proxy, Oracle Communications MetaSolv Solution Module - ASR, Oracle Communications Service Catalog and Design en Oracle Communications Operations Mon

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Kritiek
3 sep 2026

CVE-2026-62916 — CVSS 9.1 CRITICAL

Financieel & VerzekeringenIT & Technologie

Authentication bypass using an alternate path or channel in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
24 sep 2026

ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

Financieel & VerzekeringenRetail & E-commerce

This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
28 aug 2026

[Microsoft MSRC] CVE-2026-58616 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
23 sep 2026

Multiples vulnérabilités dans Mattermost Server (23 septembre 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans Mattermost Server. Elles permettent à un attaquant de provoquer un déni de service à distance et une atteinte à la confidentialité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
31 aug 2026

[webapps] CubeCart 6.7.4 - Cross-Site Scripting

Financieel & Verzekeringen

CubeCart 6.7.4 - Cross-Site Scripting

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95286: Type confusion in Bindings

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
16 sep 2026

NCSC-2026-0374 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Commerce Platform

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft 27 kwetsbaarheden verholpen in Commerce Platform, waaronder Oracle Commerce Guided Search en Oracle Commerce Experience Manager, waaronder de componenten Experience Manager, Forge en Endeca Application Controller.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Kritiek
3 sep 2026

CVE-2026-65818 — CVSS 8.5 CRITICAL

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Server-side request forgery (ssrf) in Power Automate allows an authorized attacker to elevate privileges over a network.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
24 sep 2026

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

Financieel & VerzekeringenIndustrie & ProductieRetail & E-commerceIT & Technologie

The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," Manifold Security's Head of Research, Ax Sharma, said. "Unlike 'example[.]com,' third-party[.]com

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
26 aug 2026

[Kaspersky] Exploits and vulnerabilities in Q2 2026

Industrie & Productie

This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
23 sep 2026

Multiples vulnérabilités dans les produits HPE Aruba Networking (23 septembre 2026)

Financieel & VerzekeringenTransport & Logistiek

De multiples vulnérabilités ont été découvertes dans les produits HPE Aruba Networking. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
31 aug 2026

[webapps] Linksys E1200_2.0.04 - Unauthenticated OS Command Injection

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Linksys E1200_2.0.04 - Unauthenticated OS Command Injection

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95287: Missing authorization in Navigation

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
16 sep 2026

NCSC-2026-0373 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Database Producten

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft 16 kwetsbaarheden verholpen in diverse Database producten, waaronder Database Server, Autonomous Health Framework en Application Testing Suite.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Kritiek
3 sep 2026

CVE-2026-80098 — CVSS 9.3 CRITICAL

Industrie & Productie

Improper verification of cryptographic signature in Copilot Studio allows an unauthorized attacker to elevate privileges over a network.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
24 sep 2026

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

Financieel & VerzekeringenIT & Technologie

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. "When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
25 aug 2026

[Microsoft MSRC] CVE-2026-24301 Microsoft Copilot Information Disclosure Vulnerability

Industrie & ProductieIT & Technologie

Acknowledgement Updated

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
23 sep 2026

Multiples vulnérabilités dans Google Chrome (23 septembre 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
31 aug 2026

[webapps] Langflow 1.8.4 - Path Traversal to Remote Code Execution

Industrie & Productie

Langflow 1.8.4 - Path Traversal to Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95288: UI misrepresentation in Mobile

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
16 sep 2026

NCSC-2026-0372 [1.00] [H/H] Kwetsbaarheden verholpen in Oracle Fusion Middleware

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Oracle heeft 153 kwetsbaarheden verholpen in diverse Oracle Fusion Middleware-producten, waaronder Helidon, Oracle Access Manager, Oracle Coherence, Oracle Data Integrator, Oracle Forms, Oracle Fusion Middleware Control, Oracle Identity Manager, Oracle Identity Manager Connector, Oracle Internet Directory, Oracle JDeveloper, Oracle Managed File Tra

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Kritiek
1 sep 2026

CVE-2026-84135 — CVSS 9.8 CRITICAL

Industrie & Productie

Other issue in Firefox Focus for Android. This vulnerability was fixed in Firefox 155.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
24 sep 2026

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

Financieel & VerzekeringenTransport & Logistiek

ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense. Read

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
25 aug 2026

[Palo Alto Unit 42] The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution

Financieel & VerzekeringenIndustrie & ProductieRetail & E-commerce

Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
23 sep 2026

Vulnérabilité dans Check Point Security Management Server (23 septembre 2026)

Transport & Logistiek

Une vulnérabilité a été découverte dans Check Point Security Management Server. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance et une atteinte à l'intégrité des données. L'éditeur indique que la vulnérabilité CVE-2026-93616 est activement exploitée. Check...

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
25 aug 2026

[remote] CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

Industrie & ProductieRetail & E-commerce

CVE-2026-42167 - ProFTPD mod_sql post-authentication SQLi - RCE

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95289: Incorrect authorization in Scroll

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
15 sep 2026

NCSC-2026-0371 [1.00] [M/H] Kwetsbaarheden verholpen in Apple macOS en Samba door Apple en Samba

Financieel & VerzekeringenIndustrie & Productie

Apple heeft meerdere kwetsbaarheden verholpen in macOS (Specifiek voor Golden Gate 27, Sequoia 15.8, Tahoe 26.7).

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Kritiek
1 sep 2026

CVE-2026-84140 — CVSS 9.8 CRITICAL

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Site isolation issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Hoog
24 sep 2026

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Financieel & VerzekeringenRetail & E-commerceIT & Technologie

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
20 aug 2026

[Microsoft MSRC] CVE-2026-69855 Microsoft Copilot in Azure Information Disclosure Vulnerability

Industrie & ProductieIT & Technologie

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
23 sep 2026

Vulnérabilité dans F5 BIG-IP (23 septembre 2026)

Transport & Logistiek

Une vulnérabilité a été découverte dans F5 BIG-IP. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. L'éditeur indique que la vulnérabilité CVE-2026-94127 est activement exploitée. Des indicateurs de compromission sont disponibles dans l'avis de l'éditeur.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
18 aug 2026

[remote] PCMan 2.0.7 - Buffer Overflow

Industrie & Productie

PCMan 2.0.7 - Buffer Overflow

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95290: Missing authorization in NFC

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
1 sep 2026

CVE-2026-84141 — CVSS 9.8 CRITICAL

Industrie & Productie

Integer overflow in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 155, Firefox ESR 153.2, Thunderbird 155, and Thunderbird 153.2.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Hoog
24 sep 2026

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Industrie & Productie

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Kritiek
18 aug 2026

[Mandiant] Staying Ahead of Adversarial AI Through Agentic Source Code Review

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Alex Tselevich, Michael Maturi Introduction Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them. By structuring the analysis process, enforcing skeptical validation steps, and injecting …

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
CERT-FR Hoog
22 sep 2026

Multiples vulnérabilités dans Moodle (22 septembre 2026)

Transport & LogistiekOnderwijs & Onderzoek

De multiples vulnérabilités ont été découvertes dans Moodle. Elles permettent à un attaquant de provoquer une injection SQL (SQLi) et un contournement de la politique de sécurité.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
18 aug 2026

[dos] NanaZip 6.5 - DoS

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

NanaZip 6.5 - DoS

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95291: UI misrepresentation in SecurityIndicators

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
1 sep 2026

CVE-2026-84142 — CVSS 9.8 CRITICAL

Industrie & Productie

Internally found bugs present in Thunderbird 154. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155 and Thunderbird 155.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
23 sep 2026

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Financieel & VerzekeringenRetail & E-commerceIT & Technologie

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
11 aug 2026

[Microsoft MSRC] CVE-2026-59118 Copilot Cowork Elevation of Privilege Vulnerability

Industrie & Productie

Corrected CVE title. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
22 sep 2026

Vulnérabilité dans SolarWinds Access Rights Manager (22 septembre 2026)

Transport & LogistiekEnergie & Nutsbedrijven

Une vulnérabilité a été découverte dans SolarWinds Access Rights Manager. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
18 aug 2026

[webapps] flyto-core 2.26.7 - Arbitrary File Write

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

flyto-core 2.26.7 - Arbitrary File Write

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95292: Incorrect authorization in Safebrowsing

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
1 sep 2026

CVE-2026-84143 — CVSS 9.8 CRITICAL

Industrie & Productie

Internally found bugs present in Thunderbird 154, Thunderbird ESR 153.1 and Thunderbird ESR 140.14. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we presume that with enough effort some of these could have been exploited. This vulnerability was fixed in Firefox 155, Firefox ESR 140.15, Firefox ESR 153.2, Thunderbird 155, Thunderbird 140.15, and Thu…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
23 sep 2026

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project." Mail sent to it opens an issue in that project, authored

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
4 aug 2026

[NCSC UK] NCSC statement in response to recent incidents resulting from frontier AI evaluations

Financieel & VerzekeringenTransport & Logistiek

A statement from Ollie Whitehouse, Chief Technology Officer at the NCSC, on AI security following recent incidents.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
21 sep 2026

Bulletin d'actualité CERTFR-2026-ACT-040 (21 septembre 2026)

Transport & Logistiek

Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
18 aug 2026

[webapps] Nodemailer 9.0.0 - File Read/ SSRF

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Nodemailer 9.0.0 - File Read/ SSRF

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95293: Uninitialized resource in GPU

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
1 sep 2026

CVE-2026-73749 — CVSS 9.8 CRITICAL

Financieel & VerzekeringenIndustrie & Productie

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
23 sep 2026

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Industrie & ProductieRetail & E-commerceIT & Technologie

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
24 jul 2026

[Microsoft MSRC] CVE-2026-48561 Microsoft Edge Copilot Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Corrected the CVE description and title. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
21 sep 2026

Multiples vulnérabilités dans Microsoft Edge (21 septembre 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une élévation de privilèges et un problème de sécurité non spécifié par l'éditeur.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
18 aug 2026

[webapps] Linuxfabrik monitoring_plugins_6.0.0 - SSRF

Financieel & VerzekeringenIT & Technologie

Linuxfabrik monitoring_plugins_6.0.0 - SSRF

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95294: UI misrepresentation in Browser

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
1 sep 2026

CVE-2026-73778 — CVSS 8.1 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieRetail & E-commerce

A vulnerability exists in the Credential Manager component that may allow for unauthorized administrative access. An unauthenticated remote attacker could exploit this vulnerability on a device in its factory-default or post-ZTP state before any administrator has configured credentials by providing a predictable factory-default password. Successful exploitation could result in full administrative …

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
23 sep 2026

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

Industrie & ProductieIT & Technologie

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
23 jul 2026

[Microsoft MSRC] CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
21 sep 2026

Multiples vulnérabilités dans Synology DSM (21 septembre 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans Synology DSM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
17 aug 2026

[dos] NanaZip 6.5 - DoS

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

NanaZip 6.5 - DoS

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95295: Information leak in Mobile

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
23 sep 2026

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts. cPanel has released fixed versions for both,

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Kritiek
16 jul 2026

[Mandiant] Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration …

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
CERT-FR Hoog
21 sep 2026

Multiples vulnérabilités dans les produits Mattermost (21 septembre 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans les produits Mattermost. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
17 aug 2026

[webapps] flyto_core 2.26.7 - Server-Side Request Forgery

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

flyto_core 2.26.7 - Server-Side Request Forgery

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95296: Missing authorization in Core

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
23 sep 2026

Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
14 jul 2026

[Microsoft MSRC] CVE-2026-47282 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability

Industrie & ProductieIT & Technologie

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
18 sep 2026

Multiples vulnérabilités dans les produits IBM (18 septembre 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
17 aug 2026

[webapps] Probo 0.222.2 - IDOR

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Probo 0.222.2 - IDOR

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95297: Missing authorization in Contextual Tasks

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Kritiek
23 sep 2026

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security Hoog
14 jul 2026

[Microsoft MSRC] CVE-2026-50510 GitHub Copilot Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
18 sep 2026

Vulnérabilité dans les produits Moxa (18 septembre 2026)

Transport & Logistiek

Une vulnérabilité a été découverte dans les produits Moxa. Elle permet à un attaquant de provoquer un déni de service à distance.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
17 aug 2026

[webapps] webpack_devserver 5.2.5 - CSRF

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

webpack_devserver 5.2.5 - CSRF

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95298: Use after free in Browser

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Kritiek
23 sep 2026

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

Financieel & VerzekeringenIT & Technologie

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security Hoog
14 jul 2026

[Microsoft MSRC] CVE-2026-55145 Outlook Copilot Tampering Vulnerability

Financieel & VerzekeringenIndustrie & Productie

Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
22 jul 2026

Multiples vulnérabilités dans Microsoft Sharepoint (22 juillet 2026)

Transport & LogistiekIT & Technologie

Le 14 juillet 2026, à l'occasion de sa mise à jour mensuelle, Microsoft a publié, entre autres, des correctifs pour deux vulnérabilités critiques affectant SharePoint. Les vulnérabilités CVE-2026-50522 et CVE-2026-58644 permettent à un attaquant non authentifié d'exécuter du code arbitraire à...

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
17 aug 2026

[remote] phpSysInfo 3.4.5 - IP Allowlist Bypass

Industrie & Productie

phpSysInfo 3.4.5 - IP Allowlist Bypass

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95374: Incorrect authorization in Network

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Hoog
23 sep 2026

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

Industrie & Productie

A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
14 jul 2026

[Microsoft MSRC] CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability

Industrie & ProductieIT & Technologie

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
26 mei 2026

Multiples vulnérabilités dans Roundcube (26 mai 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans Roundcube. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
17 aug 2026

[dos] Nmap 7.99 - Extension Header Integer Underflow

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Nmap 7.99 - Extension Header Integer Underflow

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95375: Incorrect authorization in BrowserTag

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Kritiek
22 sep 2026

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security Hoog
14 jul 2026

[Microsoft MSRC] CVE-2026-58617 M365 Copilot for iOS Elevation of Privilege Vulnerability

Industrie & ProductieIT & Technologie

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
17 aug 2026

[webapps] Duplicati 2.2.0.3 - JWT Signing Key Leak

Financieel & Verzekeringen

Duplicati 2.2.0.3 - JWT Signing Key Leak

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95376: Externally controlled reference in DevTools

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Hoog
22 sep 2026

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

Financieel & Verzekeringen

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Hoog
2 jul 2026

[Microsoft MSRC] CVE-2026-41106 Microsoft 365 Copilot Elevation of Privilege Vulnerability

Industrie & ProductieIT & Technologie

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
17 aug 2026

[webapps] Joomla JCE_2.9.15 - Remote Code Execution

Industrie & Productie

Joomla JCE_2.9.15 - Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95380: Type confusion in V8

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
17 aug 2026

[remote] ipTIME A3004T - Remote Code Execution

Industrie & Productie

ipTIME A3004T - Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95381: Improper input validation in Printing

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
17 aug 2026

[remote] D-Link DNS_340L - OS Command Injection

Industrie & Productie

D-Link DNS_340L - OS Command Injection

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95382: Improper input validation in Auth

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
17 aug 2026

[webapps] WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload

Retail & E-commerce

WooCommerce 1.5.0 - Unauthenticated Arbitrary File Upload

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95384: Race condition in Transactions Platform

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
11 aug 2026

[webapps] Apache Gravitino 1.2.1 - SSRF

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Apache Gravitino 1.2.1 - SSRF

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95385: Inappropriate implementation in PlatformIntegration

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
11 aug 2026

[webapps] Blocksy Companion 2.1.46 - RCE

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Blocksy Companion 2.1.46 - RCE

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

CVE-2026-69439 .NET and Visual Studio Elevation of Privilege Vulnerability

Financieel & VerzekeringenIT & Technologie

Security Updates table updated provide links to the KB articles and download center updates. Microsoft recommends installing the updates.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
11 aug 2026

[remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution

Industrie & Productie

PraisonAI praisonaiagents 1.6.77 - Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

CVE-2026-69304 ASP.NET Core Denial of Service Vulnerability

Financieel & VerzekeringenIT & Technologie

Security Updates table updated provide links to the KB articles and download center updates. Microsoft recommends installing the updates.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
11 aug 2026

[remote] mcp-server-kubernetes 3.8.x - Argument Injection

Industrie & ProductieIT & Technologie

mcp-server-kubernetes 3.8.x - Argument Injection

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

CVE-2026-71328 .NET and Visual Studio Remote Code Execution Vulnerability

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Security Updates table updated provide links to the KB articles and download center updates. Microsoft recommends installing the updates.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
11 aug 2026

[dos] LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting

Financieel & Verzekeringen

LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

CVE-2026-69806 .NET Elevation of Privilege Vulnerability

Financieel & VerzekeringenIT & Technologie

Security Updates table updated provide links to the KB articles and download center updates. Microsoft recommends installing the updates.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
11 aug 2026

[webapps] Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95299: Use after free in GPU

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
11 aug 2026

[webapps] Ray 2.56.0 - Directory Traversal & Local File Inclusion

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Ray 2.56.0 - Directory Traversal & Local File Inclusion

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95300: Missing authorization in DevTools

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
10 aug 2026

[webapps] OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution

Industrie & Productie

OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95301: Missing authorization in Extensions

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
10 aug 2026

[local] Microsoft Edge 150.0.4078.48 - RCE

IT & Technologie

Microsoft Edge 150.0.4078.48 - RCE

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95302: Incorrect authorization in WebAPKs

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95303: Incomplete cleanup in SmartCard

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95304: Out of bounds write in V8

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95305: UI misrepresentation in Chromoting

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95306: Type confusion in V8

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95307: UI misrepresentation in ExtensionsMenu

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95308: Integer overflow in Metrics

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95309: UI misrepresentation in Mobile

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95310: Use after free in AdFilter

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95311: Free of non-heap memory in Fonts

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95312: Information leak in Passwords

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95313: Use after free in Fullscreen

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95314: Incorrect authorization in HID

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95315: Use after free in Aura

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95316: Unchecked return value in Performance

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95317: Incorrect authorization in MediaCapture

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95318: Buffer overflow in Video

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95319: Use after free in Printing

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95320: Missing authorization in Navigation

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95321: UI misrepresentation in Payments

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95322: Out of bounds write in GPU

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95323: UI misrepresentation in Chromium

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95324: Uninitialized resource in GPU

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95325: Use after free in ANGLE

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95326: Incomplete cleanup in Bluetooth

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95327: Information leak in Networking

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95328: Confused deputy in Mobile

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95329: Out of bounds write in WebGL

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95330: Improper state validation in Downloads

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95331: Out of bounds write in ANGLE

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95332: Use of uninitialized variable in Tint

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95333: Use after free in Metrics

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95334: Incorrect reference resolution in WebProtect

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95335: Use after free in HID

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95336: Information leak in Transactions Platform

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95337: UI misrepresentation in Messages

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95338: Use after free in PDFium

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95339: Use after free in ServiceWorker

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95340: Incorrect authorization in PictureInPicture

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95341: Improper input validation in Desktop

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95342: Missing authorization in V8

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95343: Use after free in WebAudio

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95344: Race condition in DevTools

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95345: Use after free in Actor

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95346: UI misrepresentation in Chromoting

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95347: Use after free in Updater

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95348: Use after free in Bluetooth

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95349: Buffer overflow in WebGL

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95350: Buffer overflow in ANGLE

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95351: Use after free in Views

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-95352: Incorrect authorization in DevTools

Financieel & VerzekeringenIT & Technologie

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
🔍 Geen advisories gevonden voor deze combinatie. Probeer een ander filter.
Disclaimer: Deze advisories zijn afkomstig van publieke bronnen waaronder NCSC NL, CISA, CISA KEV, NVD (NIST), MITRE CVE, Exploit-DB, Mandiant, Microsoft MSRC, Cisco Talos, Kaspersky, ENISA en BleepingComputer. De samenvattingen zijn bedoeld als eerste oriëntatie. Raadpleeg altijd de originele bronnen voor volledige technische details. SOC Continu is niet aansprakelijk voor beslissingen genomen op basis van deze samenvatting.