Actuele dreigingen en kwetsbaarheden uit meer dan 10 publieke bronnen: NCSC NL, CISA, CISA KEV, NVD, MITRE, Exploit-DB, Mandiant, Microsoft, Cisco Talos, Kaspersky en meer — vertaald naar begrijpelijke actie. Selecteer uw branche voor een gepersonaliseerd overzicht.
Bijgewerkt op 1 aug 2026, 06:00 UTC
Bron & ernst
Uw branche
AI SecurityMedium
31 jul 2026
[Security.NL] Anthropic zegt verantwoordelijk te zijn voor het hacken van drie bedrijven
Anthropic zegt verantwoordelijk te zijn voor het hacken van drie bedrijven en het uploaden van malware naar de Python Package ...
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FRHoog
31 jul 2026
Multiples vulnérabilités dans les produits IBM (31 juillet 2026)
Transport & LogistiekIT & Technologie
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco TalosHoog
28 jul 2026
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
KasperskyHoog
30 jul 2026
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
Financieel & VerzekeringenTransport & Logistiek
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on SecurityHoog
22 jul 2026
LG to Ban Residential Proxies from Smart TV Apps
Industrie & ProductieTransport & Logistiek
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a…
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
MandiantKritiek
30 jul 2026
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Grou…
Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRCHoog
30 jul 2026
CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability
Industrie & ProductieIT & Technologie
Updated an acknowledgement. This is an informational change only.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security BlogMedium
31 jul 2026
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential t…
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NLMedium
31 jul 2026
NCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk
SolarWinds heeft een kwetsbaarheid verholpen in SolarWinds Web Help Desk. De kwetsbaarheid betreft een authenticatiebypass in de SAML 2.0 authenticatie van SolarWinds Web Help Desk. Deze kwetsbaarheid treedt op in systemen waarbij SAML-authenticatie is ingeschakeld.
Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UKHoog
23 jul 2026
UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations
GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
In JetBrains IntelliJ IDEA before 2026.1.4,
2026.2 code execution via path traversal in project workspace ID handling was possible
Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42Hoog
31 jul 2026
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
Financieel & VerzekeringenRetail & E-commerce
Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
SANS ISCHoog
29 jul 2026
Apple Patches Everything (July 2026), (Wed, Jul 29th)
I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only covered the current 26 versions.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NLMedium
31 jul 2026
Onderzoekers waarschuwen voor vooraf besmette Android tv-sticks
Onderzoekers waarschuwen voor Android tv-sticks die ook in Nederland worden verkocht en vooraf met malware zijn geïnfecteerd. ...
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker NewsMedium
31 jul 2026
HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
Financieel & VerzekeringenTransport & LogistiekIT & Technologie
Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI SecurityMedium
30 jul 2026
[The Hacker News] ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway,
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FRHoog
31 jul 2026
Multiples vulnérabilités dans le noyau Linux de Red Hat (31 juillet 2026)
Transport & LogistiekIT & Technologie
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco TalosHoog
23 jul 2026
Don’t swing at everything
Financieel & Verzekeringen
Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DBHoog
8 jul 2026
[webapps] Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure
Retail & E-commerce
Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
KasperskyHoog
30 jul 2026
Toy Ghouls’ new toy: the GenieLocker ransomware
Industrie & ProductieIT & Technologie
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on SecurityMedium
14 jul 2026
Microsoft Patches a Record 570 Security Flaws
Financieel & VerzekeringenIndustrie & ProductieIT & Technologie
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
Update (July 30): A table listing the new names of select prominent threat actors was appended to this post. Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Why are we Adopting a Different Naming System? …
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRCHoog
30 jul 2026
CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability
Industrie & ProductieIT & Technologie
Acknowledgement Updated
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security BlogHoog
27 jul 2026
Rethinking security for the age of AI
Financieel & VerzekeringenIndustrie & ProductieRetail & E-commerceIT & Technologie
The physics of cybersecurity are changing. Introducing security's new cyber stack: Project Perception. The post Rethinking security for the age of AI appeared first on Microsoft Security Blog.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NLMedium
31 jul 2026
NCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic
Financieel & Verzekeringen
Adobe heeft kwetsbaarheden verholpen in Adobe Campaign Classic (ACC). De eerste kwetsbaarheid betreft een Incorrect Authorization in de core authorization mechanismen van ACC, waardoor een aanvaller arbitrary code kan uitvoeren zonder enige gebruikersinteractie. Dit betekent dat de aanvaller acties kan uitvoeren buiten de bedoelde permissies.
Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UKHoog
13 jul 2026
UK and Allies urge critical sectors to improve defences against Russian intelligence targeting
Financieel & VerzekeringenIT & Technologie
New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVDKritiek
9 jul 2026
CVE-2026-47826 — CVSS 9.1 CRITICAL
Transport & Logistiek
The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information.
Affected versions: BOSH CLI tool versions prior to v7.10.4.
Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42Hoog
30 jul 2026
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Financieel & VerzekeringenRetail & E-commerce
Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
SANS ISCHoog
28 jul 2026
AutoIT Payload Injector , (Tue, Jul 28th)
Industrie & ProductieTransport & Logistiek
For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you'll see below.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NLMedium
31 jul 2026
Anthropic zegt verantwoordelijk te zijn voor het hacken van drie bedrijven
Anthropic zegt verantwoordelijk te zijn voor het hacken van drie bedrijven en het uploaden van malware naar de Python Package ...
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker NewsMedium
31 jul 2026
Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined
Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie
Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI SecurityHoog
29 jul 2026
[The Hacker News] Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Industrie & ProductieTransport & Logistiek
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FRHoog
31 jul 2026
Multiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)
Transport & Logistiek
De multiples vulnérabilités ont été découvertes dans Progress MOVEit Transfer. Elles permettent à un attaquant de provoquer une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco TalosHoog
23 jul 2026
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
Financieel & Verzekeringen
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
MandiantKritiek
16 jul 2026
Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management
Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration …
Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRCHoog
30 jul 2026
CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability
Industrie & ProductieIT & Technologie
Updated an acknowledgement. This is an informational change only.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security BlogMedium
23 jul 2026
Email threat landscape: Q2 2026 trends and insights
Financieel & VerzekeringenIndustrie & ProductieRetail & E-commerceIT & Technologie
In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-stage attack chains. The post Email threat landscape: Q2 2026 trends and insights appeared first on Mi…
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NLMedium
31 jul 2026
NCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory
JFrog heeft meerdere kwetsbaarheden verholpen in JFrog Artifactory De kwetsbaarheden betreffen verschillende onderdelen van JFrog Artifactory. - Er is een privilege-escalatie mogelijk doordat het systeem de scope van tokens niet controleert, waardoor een aanvaller zijn rechten kan verhogen.
Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVDKritiek
9 jul 2026
CVE-2026-56291 — CVSS 9.8 CRITICAL
Financieel & Verzekeringen
Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42Kritiek
17 jul 2026
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.
Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Aanvallers zijn erin geslaagd om advertentiebedrijf Adform te hacken en vervolgens op allerlei websites cryptostelende malware ...
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker NewsHoog
31 jul 2026
Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw
Financieel & VerzekeringenOnderwijs & OnderzoekIT & Technologie
An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session. The findings have been released by a group of researchers from Singapore's Nanyang Technological University
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI SecurityMedium
29 jul 2026
[The Hacker News] Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Retail & E-commerce
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FRHoog
31 jul 2026
Multiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)
Transport & LogistiekIT & Technologie
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco TalosHoog
16 jul 2026
Begun, the Patch Wars have
Financieel & Verzekeringen
Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DBHoog
8 jul 2026
[webapps] Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
Joomla Page Builder CK 3.5.10 - Arbitrary File Upload
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
KasperskyHoog
16 jul 2026
GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
Overheid & Publieke SectorIndustrie & Productie
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
MandiantHoog
15 jul 2026
The Risk of Exposed Cloud Functions and How to Harden
Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remo…
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRCHoog
30 jul 2026
CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability
Industrie & ProductieIT & Technologie
Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security BlogMedium
17 jul 2026
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks
Financieel & VerzekeringenRetail & E-commerceIT & Technologie
Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception. The post Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks appeared first on Microsoft Security Blog.
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NLMedium
30 jul 2026
NCSC-2026-0271 [1.00] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Center
Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieIT & Technologie
Cisco heeft een kwetsbaarheid verholpen in Cisco Secure Firewall Management Center. De kwetsbaarheid bevindt zich in de webinterface van Cisco Secure Firewall Management Center en betreft een hard-coded, statisch wachtwoord voor een laaggeprivilegieerd account.
Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnup…
Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42Kritiek
15 jul 2026
The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)
Transport & LogistiekRetail & E-commerceOnderwijs & Onderzoek
Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.
Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Security.NLMedium
30 jul 2026
Ontwikkelaar en aanbieder van phishingsites veroordeeld tot 2 jaar cel
De rechtbank Rotterdam heeft een 24-jarige man wegens het ontwikkelen en verkopen van phishingsites, alsmede het witwassen van ...
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker NewsMedium
31 jul 2026
6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Financieel & VerzekeringenTransport & Logistiek
Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn't originally
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI SecurityKritiek
28 jul 2026
[The Hacker News] JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
Financieel & VerzekeringenRetail & E-commerce
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud
Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
CERT-FRHoog
31 jul 2026
Vulnérabilité dans Microsoft Azure (31 juillet 2026)
Transport & LogistiekIT & Technologie
Une vulnérabilité a été découverte dans Microsoft Azure. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco TalosHoog
14 jul 2026
Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities
Financieel & VerzekeringenIT & Technologie
Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical."
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
KasperskyHoog
15 jul 2026
OkoBot: new sophisticated malware framework targets cryptocurrency users
Financieel & VerzekeringenIndustrie & Productie
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
MandiantHoog
7 jul 2026
The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI
Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to a…
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRCHoog
30 jul 2026
CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability
IT & Technologie
Informational Change. CVE ID stays the same.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security BlogMedium
16 jul 2026
ACR Stealer: Two observed intrusion chains amid increased threat activity
Financieel & VerzekeringenTransport & LogistiekRetail & E-commerceIT & Technologie
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments. The post ACR Stealer: Two observed intrusion chains amid increased threat activity appeared first on Mi…
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NLMedium
30 jul 2026
NCSC-2026-0270 [1.00] [M/M] Kwetsbaarheden verholpen in GitLab door GitLab Inc.
Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie
GitLab Inc. heeft meerdere kwetsbaarheden verholpen in GitLab, specifiek in versies voorafgaand aan 19.0.5, 19.1.3 en 19.2.1, inclusief GitLab Enterprise Edition (EE) versies binnen deze reeksen.
Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVDKritiek
9 jul 2026
CVE-2026-59214 — CVSS 7.3 CRITICAL
Financieel & VerzekeringenTransport & Logistiek
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and XMLHttpRequest APIs to issue authenticated same-origin requests when a victim clicks Run, which can reach admin-only endpoints and ex…
Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42Hoog
10 jul 2026
No Manners Here: The Ruthless Rise of The Gentlemen Ransomware
Financieel & VerzekeringenRetail & E-commerce
Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NLMedium
29 jul 2026
Advertorial: Serverbeheer als beveiligingsrisico: wat organisaties over het hoofd zien
Financieel & VerzekeringenIT & Technologie
De meeste organisaties investeren fors in endpoint-beveiliging, firewalls en bewustwording rond phishing. Begrijpelijk, want ...
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker NewsHoog
31 jul 2026
Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
Financieel & Verzekeringen
Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan,
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI SecurityMedium
28 jul 2026
[The Hacker News] Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost
Financieel & VerzekeringenIT & Technologie
Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved
Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FRHoog
31 jul 2026
Multiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)
Transport & LogistiekIT & Technologie
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni de service.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco TalosHoog
14 jul 2026
The serpent’s tongue: Luring the Python out of its den
Financieel & VerzekeringenRetail & E-commerce
This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DBHoog
7 jul 2026
[local] ProtonVPN v4.4.1 - Unquoted Service Path
Industrie & ProductieIT & Technologie
ProtonVPN v4.4.1 - Unquoted Service Path
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
KasperskyHoog
7 jul 2026
Threat landscape for industrial automation systems. Q1 2026
Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the …
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRCHoog
28 jul 2026
CVE-2026-50422 Windows NTFS Elevation of Privilege Vulnerability
IT & Technologie
Updated an acknowledgement. This is an informational change only.
Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NLMedium
29 jul 2026
NCSC-2026-0269 [1.01] [M/H] Kwetsbaarheden verholpen in VMware producten
Financieel & VerzekeringenIndustrie & ProductieIT & Technologie
VMware heeft kwetsbaarheden verholpen in VMware vCenter en VMware ESX producten. VMware vCenter bevat een kritieke authentication-bypass kwetsbaarheid in de Directory Service met kenmerk CVE-2026-59309.
Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
🔍 Geen advisories gevonden voor deze combinatie. Probeer een ander filter.