Source & severity

Your sector
AI Security Medium
31 Jul 2026

[Security.NL] Anthropic zegt verantwoordelijk te zijn voor het hacken van drie bedrijven

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Anthropic zegt verantwoordelijk te zijn voor het hacken van drie bedrijven en het uploaden van malware naar de Python Package ...

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR High
31 Jul 2026

Multiples vulnérabilités dans les produits IBM (31 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos High
28 Jul 2026

IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

Talos IR's Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
8 Jul 2026

[webapps] Krayin CRM v2.2.x - Authenticated Remote Code Execution

Industry & Manufacturing

Krayin CRM v2.2.x - Authenticated Remote Code Execution

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky High
30 Jul 2026

OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia

Financial services & InsuranceTransport & Logistics

Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security High
22 Jul 2026

LG to Ban Residential Proxies from Smart TV Apps

Industry & ManufacturingTransport & Logistics

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a…

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Critical
30 Jul 2026

Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise

Financial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Written by: Kelli Vanderlee, Stuart Carrera For years, the cybersecurity industry's understanding of software supply chain compromise has been anchored by a few watershed events, including Russian cyber espionage actor ICE RELIC’s (formerly known as APT29) 2020 compromise of SolarWinds and North Korean cyber espionage actor UNC4736's 2023 compromise of 3CX. However, Google Threat Intelligence Grou…

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC High
30 Jul 2026

CVE-2026-54128 Windows DHCP Client Remote Code Execution Vulnerability

Industry & ManufacturingIT & Technology

Updated an acknowledgement. This is an informational change only.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Medium
31 Jul 2026

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

HealthcareFinancial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerceIT & Technology

Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch. The post CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential t…

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NL Medium
31 Jul 2026

NCSC-2026-0274 [1.00] [M/H] Kwetsbaarheid verholpen in SolarWinds Web Help Desk

Financial services & InsuranceIndustry & ManufacturingEnergy & Utilities

SolarWinds heeft een kwetsbaarheid verholpen in SolarWinds Web Help Desk. De kwetsbaarheid betreft een authenticatiebypass in de SAML 2.0 authenticatie van SolarWinds Web Help Desk. Deze kwetsbaarheid treedt op in systemen waarbij SAML-authenticatie is ingeschakeld.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
23 Jul 2026

UK and partners expose Russian state-supported actors for new ‘zero-click’ phishing campaign targeting Western organisations

Financial services & InsuranceTransport & LogisticsRetail & E-commerce

GCHQ’s National Cyber Security Centre and international partners issue warning as ‘LAUNDRY BEAR’ cyber threat group exposed for targeted phishing campaign

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
10 Jul 2026

CVE-2026-59792 — CVSS 9.6 CRITICAL

Financial services & InsuranceTransport & LogisticsRetail & E-commerce

In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 High
31 Jul 2026

The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

Financial services & InsuranceRetail & E-commerce

Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic. The post The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version appeared first on Unit 42.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
SANS ISC High
29 Jul 2026

Apple Patches Everything (July 2026), (Wed, Jul 29th)

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

I am a bit late with this summary, but this week Apple released updates to all its operating systems and Safari. The Safari update, as usual, targets macOS prior to macOS 26. macOS updates covered the two older versions (14 and 15), while other operating system patches only covered the current 26 versions.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Medium
31 Jul 2026

Onderzoekers waarschuwen voor vooraf besmette Android tv-sticks

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Onderzoekers waarschuwen voor Android tv-sticks die ook in Nederland worden verkocht en vooraf met malware zijn geïnfecteerd. ...

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Medium
31 Jul 2026

HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm

Financial services & InsuranceTransport & LogisticsIT & Technology

Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka. According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted archive, which holds a Windows Shortcut (LNK). Executing the file triggers a multi-stage chain that

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Medium
30 Jul 2026

[The Hacker News] ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerceIT & Technology

A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway,

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR High
31 Jul 2026

Multiples vulnérabilités dans le noyau Linux de Red Hat (31 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos High
23 Jul 2026

Don’t swing at everything

Financial services & Insurance

Thorsten explores Q2 2026 stats, the artificial buffer zone of 2026, and why smart, prioritized patching is more critical than ever.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
8 Jul 2026

[webapps] Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure

Retail & E-commerce

Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky High
30 Jul 2026

Toy Ghouls’ new toy: the GenieLocker ransomware

Industry & ManufacturingIT & Technology

Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Medium
14 Jul 2026

Microsoft Patches a Record 570 Security Flaws

Financial services & InsuranceIndustry & ManufacturingIT & Technology

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
Mandiant High
24 Jul 2026

Updated Cyber Threat Actor Naming System

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerce

Update (July 30): A table listing the new names of select prominent threat actors was appended to this post. Introduction Today, Google Threat Intelligence Group (GTIG) will begin rolling out a unified naming schema for tracking threat actors. This new naming taxonomy represents an effort to standardize tracking across platforms and public reporting. Why are we Adopting a Different Naming System? …

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
30 Jul 2026

CVE-2026-55129 Microsoft Office Remote Code Execution Vulnerability

Industry & ManufacturingIT & Technology

Acknowledgement Updated

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog High
27 Jul 2026

Rethinking security for the age of AI

Financial services & InsuranceIndustry & ManufacturingRetail & E-commerceIT & Technology

The physics of cybersecurity are changing. Introducing security's new cyber stack: Project Perception. The post Rethinking security for the age of AI appeared first on Microsoft Security Blog.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
31 Jul 2026

NCSC-2026-0273 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic

Financial services & Insurance

Adobe heeft kwetsbaarheden verholpen in Adobe Campaign Classic (ACC). De eerste kwetsbaarheid betreft een Incorrect Authorization in de core authorization mechanismen van ACC, waardoor een aanvaller arbitrary code kan uitvoeren zonder enige gebruikersinteractie. Dit betekent dat de aanvaller acties kan uitvoeren buiten de bedoelde permissies.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
13 Jul 2026

UK and Allies urge critical sectors to improve defences against Russian intelligence targeting

Financial services & InsuranceIT & Technology

New advisory highlights Russian state cyber actors’ global exploitation of poorly configured routers

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
9 Jul 2026

CVE-2026-47826 — CVSS 9.1 CRITICAL

Transport & Logistics

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information. Affected versions: BOSH CLI tool versions prior to v7.10.4.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 High
30 Jul 2026

Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks

Financial services & InsuranceRetail & E-commerce

Unit 42 details a Chinese speaking threat actor combining autonomous AI scanning across seven vulnerabilities with manual exploitation. Read more. The post Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks appeared first on Unit 42.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
SANS ISC High
28 Jul 2026

AutoIT Payload Injector , (Tue, Jul 28th)

Industry & ManufacturingTransport & Logistics

For a long time, AutoIT[1] has been pretty common in the malware ecosystem. Threat actors still use it because it's easy to write and powerful. Indeed, it can perform all the required actions to inject a payload into a remote process as you'll see below.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Medium
31 Jul 2026

Anthropic zegt verantwoordelijk te zijn voor het hacken van drie bedrijven

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Anthropic zegt verantwoordelijk te zijn voor het hacken van drie bedrijven en het uploaden van malware naar de Python Package ...

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Medium
31 Jul 2026

Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsIT & Technology

Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined. Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security High
29 Jul 2026

[The Hacker News] Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Industry & ManufacturingTransport & Logistics

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
31 Jul 2026

Multiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)

Transport & Logistics

De multiples vulnérabilités ont été découvertes dans Progress MOVEit Transfer. Elles permettent à un attaquant de provoquer une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos High
23 Jul 2026

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Financial services & Insurance

The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
8 Jul 2026

[webapps] Langflow 1.9.0 - RCE

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Langflow 1.9.0 - RCE

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky High
28 Jul 2026

Mirage Kitten targets Middle East and Africa region with new malware

Financial services & Insurance

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Critical
8 Jul 2026

Felons, Fraudsters Flog Offensive Cybersecurity Startup

Financial services & InsuranceTransport & Logistics

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Mandiant Critical
16 Jul 2026

Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management

Financial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration …

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC High
30 Jul 2026

CVE-2026-56197 Windows Admin Center (WAC) Remote Code Execution Vulnerability

Industry & ManufacturingIT & Technology

Updated an acknowledgement. This is an informational change only.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Medium
23 Jul 2026

Email threat landscape: Q2 2026 trends and insights

Financial services & InsuranceIndustry & ManufacturingRetail & E-commerceIT & Technology

In the second quarter of 2026, the continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained declines in several major phishing techniques, while threat actors expanded into Teams-based social engineering and employed increasingly automated and multi-stage attack chains. The post Email threat landscape: Q2 2026 trends and insights appeared first on Mi…

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NL Medium
31 Jul 2026

NCSC-2026-0272 [1.00] [M/H] Kwetsbaarheden verholpen in JFrog Artifactory

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerce

JFrog heeft meerdere kwetsbaarheden verholpen in JFrog Artifactory De kwetsbaarheden betreffen verschillende onderdelen van JFrog Artifactory. - Er is een privilege-escalatie mogelijk doordat het systeem de scope van tokens niet controleert, waardoor een aanvaller zijn rechten kan verhogen.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
22 Jun 2026

The AI shift in cyber risk: why leaders must act now

Financial services & InsuranceTransport & Logistics

Five Eyes cyber security agencies urge organisations to act on rapidly transforming cyber risk.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
9 Jul 2026

CVE-2026-56291 — CVSS 9.8 CRITICAL

Financial services & Insurance

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Critical
17 Jul 2026

Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

Industry & ManufacturingTransport & LogisticsRetail & E-commerce

A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access. The post Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy appeared first on Unit 42.

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Security.NL Medium
30 Jul 2026

'Advertentiebedrijf Adform gehackt, verspreidde cryptostelende malware'

Transport & Logistics

Aanvallers zijn erin geslaagd om advertentiebedrijf Adform te hacken en vervolgens op allerlei websites cryptostelende malware ...

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News High
31 Jul 2026

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

Financial services & InsuranceEducation & ResearchIT & Technology

An academic study has disclosed a "widespread class" of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS) attacks and even session hijacking, allowing an attacker to seize control of a user's network session. The findings have been released by a group of researchers from Singapore's Nanyang Technological University

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Medium
29 Jul 2026

[The Hacker News] Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Retail & E-commerce

Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR High
31 Jul 2026

Multiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos High
16 Jul 2026

Begun, the Patch Wars have

Financial services & Insurance

Long foretold, the Great Patching has begun and it’s a doozy. Buckle in as Joe takes you through the story.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
8 Jul 2026

[webapps] Joomla Page Builder CK 3.5.10 - Arbitrary File Upload

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Joomla Page Builder CK 3.5.10 - Arbitrary File Upload

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky High
16 Jul 2026

GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration

Government & Public sectorIndustry & Manufacturing

Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security High
18 Jun 2026

‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a "residential proxy" provider operated by the publicly-traded Israeli firm Ala…

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant High
15 Jul 2026

The Risk of Exposed Cloud Functions and How to Harden

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerceIT & Technology

Written by: Corné de Jong Introduction Mandiant security assessments frequently identify publicly exposed serverless applications that lack authentication, often as a result of specific business requirements. Serverless deployments typically run custom-developed code that incorporates third-party packages, making them targets for a wide range of application-level attacks, including: Local and Remo…

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
30 Jul 2026

CVE-2026-66803 Azure Cosmos DB Remote Code Execution Vulnerability

Industry & ManufacturingIT & Technology

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Medium
17 Jul 2026

Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks

Financial services & InsuranceRetail & E-commerceIT & Technology

Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception. The post Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks appeared first on Microsoft Security Blog.

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NL Medium
30 Jul 2026

NCSC-2026-0271 [1.00] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Center

Financial services & InsuranceGovernment & Public sectorIndustry & ManufacturingIT & Technology

Cisco heeft een kwetsbaarheid verholpen in Cisco Secure Firewall Management Center. De kwetsbaarheid bevindt zich in de webinterface van Cisco Secure Firewall Management Center en betreft een hard-coded, statisch wachtwoord voor een laaggeprivilegieerd account.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
18 Jun 2026

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways

Financial services & InsuranceTransport & LogisticsIT & Technology

Organisations using Fortinet services are being urged to take action following a campaign affecting firewalls and VPN gateways.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
9 Jul 2026

CVE-2026-58459 — CVSS 7.8 CRITICAL

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to execute arbitrary shell commands by embedding backtick payloads in the gnuplot plot title without proper escaping. The subtype field sourced from a DEVICES JSON log entry or NMEA PGRMT sentence is written into a generated gnup…

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Critical
15 Jul 2026

The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)

Transport & LogisticsRetail & E-commerceEducation & Research

Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) appeared first on Unit 42.

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Security.NL Medium
30 Jul 2026

Ontwikkelaar en aanbieder van phishingsites veroordeeld tot 2 jaar cel

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

De rechtbank Rotterdam heeft een 24-jarige man wegens het ontwikkelen en verkopen van phishingsites, alsmede het witwassen van ...

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Medium
31 Jul 2026

6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026

Financial services & InsuranceTransport & Logistics

Device code phishing - the abuse of the OAuth 2.0 device authorization grant to steal access tokens - has evolved from a niche red-team technique to an industrial-scale threat in under six months. Designed for input-constrained devices like smart TVs, printers, and so on, the device authorization login flow has been adopted by a wide range of apps and use-cases that it wasn't originally

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Critical
28 Jul 2026

[The Hacker News] JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

Financial services & InsuranceRetail & E-commerce

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
CERT-FR High
31 Jul 2026

Vulnérabilité dans Microsoft Azure (31 juillet 2026)

Transport & LogisticsIT & Technology

Une vulnérabilité a été découverte dans Microsoft Azure. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos High
14 Jul 2026

Microsoft Patch Tuesday for July 2026 — Snort rules and prominent vulnerabilities

Financial services & InsuranceIT & Technology

Microsoft has released its monthly security update for July 2026, which includes 622 vulnerabilities affecting a range of products, including 57 that Microsoft marked as "critical."

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
7 Jul 2026

[webapps] MCPJam Inspector - Remote Code Execution

Industry & Manufacturing

MCPJam Inspector - Remote Code Execution

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky High
15 Jul 2026

OkoBot: new sophisticated malware framework targets cryptocurrency users

Financial services & InsuranceIndustry & Manufacturing

Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security High
10 Jun 2026

Who Runs the Ransomware Group ‘The Gentlemen?’

Financial services & InsuranceTransport & LogisticsRetail & E-commerce

A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant High
7 Jul 2026

The ‘Ghost’ in the Database: Recovering Active ADFS Signing Keys via Machine DPAPI

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerceEducation & ResearchIT & Technology

Written by: Shebin Mathew Introduction The "Golden SAML" technique, first described by CyberArk researchers in 2017, and further detailed by Mandiant researchers in 2021, remains one of the most effective methods for threat actors to forge identity assertions in the Microsoft ecosystem. By obtaining the private key of an ADFS token-signing certificate, an attacker can authenticate as any user to a…

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
30 Jul 2026

CVE-2026-24304 Azure Resource Manager Elevation of Privilege Vulnerability

IT & Technology

Informational Change. CVE ID stays the same.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Medium
16 Jul 2026

ACR Stealer: Two observed intrusion chains amid increased threat activity

Financial services & InsuranceTransport & LogisticsRetail & E-commerceIT & Technology

From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication tokens, and sensitive documents from enterprise environments. The post ACR Stealer: Two observed intrusion chains amid increased threat activity appeared first on Mi…

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NL Medium
30 Jul 2026

NCSC-2026-0270 [1.00] [M/M] Kwetsbaarheden verholpen in GitLab door GitLab Inc.

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsIT & Technology

GitLab Inc. heeft meerdere kwetsbaarheden verholpen in GitLab, specifiek in versies voorafgaand aan 19.0.5, 19.1.3 en 19.2.1, inclusief GitLab Enterprise Edition (EE) versies binnen deze reeksen.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
17 Jun 2026

NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK's critical systems

Financial services & Insurance

Dr Richard Horne highlighted the scale of cyber threats against the UK’s critical infrastructure at RUSI’s Annual Security Lecture.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
9 Jul 2026

CVE-2026-59214 — CVSS 7.3 CRITICAL

Financial services & InsuranceTransport & Logistics

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web worker, allowing stored chat payloads that use pyodide.http.pyfetch or the js module fetch and XMLHttpRequest APIs to issue authenticated same-origin requests when a victim clicks Run, which can reach admin-only endpoints and ex…

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 High
10 Jul 2026

No Manners Here: The Ruthless Rise of The Gentlemen Ransomware

Financial services & InsuranceRetail & E-commerce

Unit 42 explores The Gentlemen ransomware operations, revealing the affiliate model driving its rapid growth. Learn more here. The post No Manners Here: The Ruthless Rise of The Gentlemen Ransomware appeared first on Unit 42.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Medium
29 Jul 2026

Advertorial: Serverbeheer als beveiligingsrisico: wat organisaties over het hoofd zien

Financial services & InsuranceIT & Technology

De meeste organisaties investeren fors in endpoint-beveiliging, firewalls en bewustwording rond phishing. Begrijpelijk, want ...

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News High
31 Jul 2026

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Financial services & Insurance

Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no further operator input in the session. The operator, tracked through the aliases knaithe and KnYuan,

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Medium
28 Jul 2026

[The Hacker News] Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost

Financial services & InsuranceIT & Technology

Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR High
31 Jul 2026

Multiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni de service.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos High
14 Jul 2026

The serpent’s tongue: Luring the Python out of its den

Financial services & InsuranceRetail & E-commerce

This blog examines the full lifecycle of a Python package, from hosting on repositories such as PyPI or custom web servers, through source and wheel distribution formats, to the final installation into virtual or system-wide Python environments.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
7 Jul 2026

[local] ProtonVPN v4.4.1 - Unquoted Service Path

Industry & ManufacturingIT & Technology

ProtonVPN v4.4.1 - Unquoted Service Path

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky High
7 Jul 2026

Threat landscape for industrial automation systems. Q1 2026

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security High
9 Jun 2026

A Record-Breaking Patch Tuesday for June 2026

Financial services & InsuranceIT & Technology

Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bugs earned Microsoft's most dire "critical" rating, and exploit code for at least three of the weaknesses is now publicly available.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant High
2 Jul 2026

Google’s Continued Disruption of Malicious Residential Proxy Networks

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerceIT & Technology

Background Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks. Actions Taken As a part of this disruption we took the …

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
28 Jul 2026

CVE-2026-50422 Windows NTFS Elevation of Privilege Vulnerability

IT & Technology

Updated an acknowledgement. This is an informational change only.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
29 Jul 2026

NCSC-2026-0269 [1.01] [M/H] Kwetsbaarheden verholpen in VMware producten

Financial services & InsuranceIndustry & ManufacturingIT & Technology

VMware heeft kwetsbaarheden verholpen in VMware vCenter en VMware ESX producten. VMware vCenter bevat een kritieke authentication-bypass kwetsbaarheid in de Directory Service met kenmerk CVE-2026-59309.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
23 Apr 2026

NCSC: Leave passwords in the past - passkeys are the future

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
9 Jul 2026

CVE-2026-59216 — CVSS 7.7 CRITICAL

Financial services & InsuranceIndustry & Manufacturing

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id after checking only that the session was connected, allowing authenticated users who learned another socket ID through ydoc:document:join to run code interpreter Python or tools in that user …

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 High
1 Jul 2026

Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

Financial services & InsuranceTransport & LogisticsRetail & E-commerce

Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more. The post Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector appeared first on Unit 42.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Critical
29 Jul 2026

Kritieke VMware-lekken geven aanvallers toegang tot vCenter-servers

Industry & ManufacturingIT & Technology

VMware waarschuwt klanten vandaag voor twee kritieke kwetsbaarheden waardoor aanvallers toegang tot vCenter-servers kunnen ...

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Medium
30 Jul 2026

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

Financial services & Insurance

Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is that bogus macOS software update screen stealthily

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security High
27 Jul 2026

[The Hacker News] NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsIT & Technology

NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
31 Jul 2026

Multiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos High
9 Jul 2026

WolfSSL, GeoVision, VTK vulnerabilities

Retail & E-commerceIT & Technology

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed three vulnerabilities in WolfSSF, fourteen in GeoVision, and one vulnerability in VTK-DICOM.The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy. For

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
7 Jul 2026

[webapps] Flowise 3.1.3 - arbitrary code execution

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Flowise 3.1.3 - arbitrary code execution

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant High
29 Jun 2026

The Bear Necessities: A Look at the Drivers, Dynamics, and Applications of the Pro-Russia Influence Ecosystem

Financial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Written by: James Sadowski, Alden Wahlstrom Introduction Four years into Russia’s full-scale invasion of Ukraine, the pro-Russia influence ecosystem has evolved from a tool of war back into a global strategic asset. Since the mobilization of this ecosystem to support frontline objectives, we have witnessed the expedited development of new influence assets linked to multiple, expansive, covert info…

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
28 Jul 2026

CVE-2026-47301 Configuration Manager Elevation of Privilege Vulnerability

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Corrected Build Number in the Security Updates table. This is an informational change only.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
29 Jul 2026

NCSC-2026-0268 [1.00] [M/H] Kwetsbaarheid verholpen in SQLite door SQLite Consortium

Industry & ManufacturingTransport & Logistics

SQLite Consortium heeft een kwetsbaarheid verholpen in SQLite versie 3.41. De kwetsbaarheid betreft een use-after-free in de expression evaluation logic van SQLite. Een aanvaller kan deze kwetsbaarheid op afstand misbruiken door speciaal vervaardigde kwaadaardige SQL-statements aan te bieden.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
23 Apr 2026

International cyber agencies share fresh advice to defend against China-linked covert networks

Industry & Manufacturing

New advisory highlights how to defend against attacker tactics believed to be used by China-linked actors to hide malicious cyber activity.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
9 Jul 2026

CVE-2026-0284 — CVSS 9.9 CRITICAL

Financial services & InsuranceIndustry & ManufacturingIT & Technology

An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data. Panorama, Cloud NGFW, and Prisma® Access are not impacted by this vulnerability.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 High
25 Jun 2026

CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure

Financial services & InsuranceGovernment & Public sectorRetail & E-commerce

Government entities and critical infrastructure were targeted for espionage in SE Asia by attackers using a hybrid toolkit, including custom TinyRCT backdoor. The post CL-STA-1062 Targets Southeast Asian Governments and Critical Infrastructure appeared first on Unit 42.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL High
29 Jul 2026

Italiaanse overheid meldt bestaan van exploitcode voor 7-Zip RCE-lek

Financial services & InsuranceGovernment & Public sector

Voor een kwetsbaarheid in de populaire archiveringssoftware 7-Zip is exploitcode online verschenen, zo meldt het Computer ...

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
30 Jul 2026

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerceIT & Technology

A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway,

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Medium
27 Jul 2026

[The Hacker News] ⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

Financial services & InsuranceIndustry & ManufacturingRetail & E-commerceIT & Technology

Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped. That is the mood. Here is the full recap. ⚡ Threat of the Week OpenAI Says Its AI Agent Went Rogue

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR High
31 Jul 2026

Multiples vulnérabilités dans PHP (31 juillet 2026)

Transport & Logistics

De multiples vulnérabilités ont été découvertes dans PHP. Certaines d'entre elles permettent à un attaquant de provoquer une injection SQL (SQLi), un déni de service et un problème de sécurité non spécifié par l'éditeur.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos High
7 Jul 2026

UAT-7810 continues building ORB networks using new malware

Financial services & Insurance

Talos’ latest findings on UAT-7810 indicate that the threat actor continues to develop their custom-made malware.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
7 Jul 2026

[remote] Hydra - Stack Buffer Overflow

Industry & Manufacturing

Hydra - Stack Buffer Overflow

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant High
25 Jun 2026

STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus

Financial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Written by: Jordan Jones Introduction Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizati…

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
28 Jul 2026

CVE-2026-59117 Windows Terminal Remote Code Execution Vulnerability

Industry & ManufacturingIT & Technology

Change the name of the affected software from **Microsoft Power Apps** to **Microsoft Power Apps Desktop Client**. This is an informational change only.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
28 Jul 2026

NCSC-2026-0267 [1.00] [M/H] Kwetsbaarheden verholpen in Apple MacOS

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

Apple heeft meerdere kwetsbaarheden verholpen in MacOS, specifiek in de versies Sequoia 15.7.8, Sonoma 14.8.8 en Tahoe 26.x. De kwetsbaarheden betreffen diverse beveiligingsproblemen in macOS, waaronder onvoldoende sandbox restricties waardoor applicaties mogelijk ongeautoriseerd toegang kunnen krijgen tot gevoelige gebruikersdata.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
23 Apr 2026

Executive Summary: Defending against China-nexus covert networks of compromised devices

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsIT & Technology

Organisations should map and baseline their edge device traffic, especially VPN and remote access connections, and adopt dynamic threat feed filtering that includes known covert network indicators.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
9 Jul 2026

CVE-2026-53963 — CVSS 7.3 CRITICAL

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

Discourse is an open-source discussion platform. Prior to 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5, a malicious second factor name on an attacker-controlled account was not escaped in the delete confirmation dialog, allowing stored cross-site scripting when an administrator impersonated that account. This issue is fixed in versions 2026.6.0, 2026.5.1, 2026.4.2, and 2026.1.5.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 High
23 Jun 2026

OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

Financial services & InsuranceRetail & E-commerce

Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud. The post OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat appeared first on Unit 42.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL High
29 Jul 2026

MikroTik-routers door RouterOS-lek kwetsbaar voor bruteforce-aanvallen

Financial services & InsuranceIndustry & ManufacturingIT & Technology

MikroTik-routers zijn door een lek in RouterOS, het besturingssysteem dat op de apparaten draait, kwetsbaar voor ...

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
30 Jul 2026

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

Financial services & InsuranceRetail & E-commerceIT & Technology

A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security High
24 Jul 2026

[Microsoft MSRC] CVE-2026-48561 Microsoft Edge Copilot Remote Code Execution Vulnerability

Industry & ManufacturingIT & Technology

Corrected the CVE description and title. This is an informational change only.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
30 Jul 2026

Vulnérabilité dans Ruby on Rails activestorage (30 juillet 2026)

Transport & Logistics

Une vulnérabilité a été découverte dans Ruby on Rails activestorage. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance et une atteinte à la confidentialité des données.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
7 Jul 2026

[webapps] Discuz! X5.0 - Authentication Bypass

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Discuz! X5.0 - Authentication Bypass

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Critical
24 Jun 2026

Zero-Day Exploitation of Vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN Manager

HealthcareFinancial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerceEducation & ResearchIT & Technology

Written by: Chester Sng, Pete Boonyakarn, Logeswaran Nadarajan, Lukasz Lamparski Introduction In early 2026, Mandiant identified a threat actor targeting SD-WAN infrastructure at a service provider. After gaining initial access, the threat actor exploited a zero-day vulnerability (CVE-2026-20245) in Cisco Catalyst SD-WAN to escalate privileges from a compromised administrative account to root-leve…

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC High
28 Jul 2026

Chromium: CVE-2026-13032 Use after free in WebGL

Financial services & InsuranceIT & Technology

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
28 Jul 2026

NCSC-2026-0266 [1.00] [M/H] Kwetsbaarheden verholpen in Apple iOS en iPadOS

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

Apple heeft meerdere kwetsbaarheden verholpen in diverse versies van iOS en iPadOS. Er zijn diverse geheugenbeheerfouten zoals use-after-free, buffer overflows, out-of-bounds reads en writes, integer overflows, race conditions en insufficient input validation opgelost.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
23 Apr 2026

Defending against China-nexus covert networks of compromised devices

Financial services & InsuranceIndustry & Manufacturing

Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
8 Jul 2026

CVE-2026-60002 — CVSS 7.7 CRITICAL

Financial services & InsuranceIT & Technology

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 High
22 Jun 2026

The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration

Financial services & InsuranceRetail & E-commerce

Unit 42 research details how attackers could exploit global name uniqueness in bucket hijacking to redirect cloud data streams across major CSPs. The post The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltration appeared first on Unit 42.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Medium
29 Jul 2026

Backdoor ontdekt in Advanced Responsive Video Embedder voor WordPress

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

In de Advanced Responsive Video Embedder plug-in voor WordPress is een backdoor ontdekt waardoor aanvallers volledige ...

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Medium
30 Jul 2026

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

Financial services & Insurance

South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors. A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security High
23 Jul 2026

[Microsoft MSRC] CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability

Industry & ManufacturingIT & Technology

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
30 Jul 2026

Vulnérabilité dans CPython (30 juillet 2026)

Transport & Logistics

Une vulnérabilité a été découverte dans CPython. Elle permet à un attaquant de provoquer un déni de service à distance.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
7 Jul 2026

[webapps] Tenable Nessus 10.12.1 - SQL Injection

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Tenable Nessus 10.12.1 - SQL Injection

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant High
15 Jun 2026

Public and Private Medical Community Targeted by China-Nexus Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerceEducation & ResearchIT & Technology

Written by: Patrick Whitsell, John McGuiness, Muhammad Umair Google Threat Intelligence Group (GTIG) has identified a sophisticated campaign attributed to UNC6508, a People's Republic of China (PRC)-nexus threat actor, targeting institutions in the North American academic, medical, and military research community. While remaining undetected for over a year, the threat actor compromised externally …

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
28 Jul 2026

Chromium: CVE-2026-13028 Use after free in WebGL

Financial services & InsuranceIT & Technology

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
27 Jul 2026

NCSC-2026-0265 [1.00] [M/H] Kwetsbaarheden verholpen in SolarWinds Serv-U

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesIT & Technology

SolarWinds heeft meerdere kwetsbaarheden verholpen in Serv-U. De kwetsbaarheden in SolarWinds Serv-U betreffen voornamelijk insecure direct object reference (IDOR) en broken access control.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
22 Apr 2026

World-first NCSC-engineered device secures vulnerable display links

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

SilentGlass, a plug-and-play device, actively blocks any unexpected or malicious HDMI and Display Port connections.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
8 Jul 2026

CVE-2026-58480 — CVSS 9.8 CRITICAL

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerce

Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension file…

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Critical
29 Jul 2026

Kritiek lek in forumsoftware vBulletin maakt remote code execution mogelijk

Industry & Manufacturing

Een kritieke kwetsbaarheid in forumsoftware vBulletin maakt remote code execution door ongeauthenticeerde aanvallers mogelijk. ...

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Medium
30 Jul 2026

SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT

Financial services & InsuranceIndustry & Manufacturing

The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos 4.0) for persistent remote access. "In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Critical
16 Jul 2026

[Mandiant] Demystifying AI Exploits: A Blueprint for AI-Assisted Vulnerability Management

Financial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Written by: Jules Czarniak Introduction As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration …

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
CERT-FR High
30 Jul 2026

Multiples vulnérabilités dans les produits VMware (30 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
7 Jul 2026

[webapps] WordPress Bricks Builder Theme - RCE

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

WordPress Bricks Builder Theme - RCE

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Critical
11 Jun 2026

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Introduction Mandiant and Google Threat Intelligence Group (GTIG) have identified an active compromise and extortion campaign attributed to UNC6240 (ShinyHunters) targeting Oracle PeopleSoft application infrastructure. The activity was observed between May 27, 2026, and June 9, 2026 and is consistent with the exploitation of CVE-2026-35273, a critical remote code execution vulnerability (CVSS 9.8)…

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC High
28 Jul 2026

Chromium: CVE-2026-13030 Uninitialized Use in GPU

Financial services & InsuranceIT & Technology

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
24 Jul 2026

NCSC-2026-0264 [1.00] [M/H] Kwetsbaarheden verholpen in Check Point Security Management producten

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsIT & Technology

Check Point heeft kwetsbaarheden verholpen in SmartConsole, Gaia Portal, Security Management en Multi-Domain Security Management. De kwetsbaarheden betreffen authenticatiebypasses en privilege-escalaties binnen verschillende Check Point managementcomponenten.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
21 Apr 2026

Cyber chief: UK faces "perfect storm" for cyber security

Financial services & Insurance

As the technology landscape develops, the definition of cyber security is expanding with it.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
8 Jul 2026

CVE-2026-3144 — CVSS 8.1 CRITICAL

IT & Technology

IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application before the system enforces a credential update.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Medium
28 Jul 2026

Fraudehelpdesk waarschuwt voor phishingaanval na boeking via Booking.com

Financial services & Insurance

De Fraudehelpdesk waarschuwt mensen die via Booking.com en andere verhuurplatforms hebben geboekt om alert te zijn op ...

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Medium
30 Jul 2026

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingIT & Technology

The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security High
14 Jul 2026

[Microsoft MSRC] CVE-2026-47282 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability

Industry & ManufacturingIT & Technology

Insufficiently protected credentials in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
30 Jul 2026

Multiples vulnérabilités dans GitLab (30 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans GitLab. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une injection de code indirecte à distance (XSS).

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
7 Jul 2026

[remote] iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter

Industry & Manufacturing

iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant High
5 Jun 2026

Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Written by: Chad Reams, Tufail Ahmed, Keith Knapp, Ashley Frazer, Tyler McLellan Introduction From January through May 2026, Mandiant identified a financially motivated data theft extortion campaign executed by the threat cluster UNC3753 (also tracked as "Luna Moth," “Chatty Spider,” and "Silent Ransom Group") targeting dozens of organizations across professional, legal, and financial services in …

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
28 Jul 2026

Chromium: CVE-2026-13037 Use after free in WebView

Financial services & InsuranceIT & Technology

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
24 Jul 2026

NCSC-2026-0263 [1.00] [M/H] Kwetsbaarheid verholpen in ManageEngine ADAudit Plus van ZohoCorp

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

ZohoCorp heeft een kwetsbaarheid verholpen in ManageEngine ADAudit Plus. De kwetsbaarheid bevindt zich in de agent API van ManageEngine ADAudit Plus versies eerder dan 8606. Door onjuiste validatie in de API kunnen aanvallers zonder authenticatie op afstand willekeurige code uitvoeren.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
7 Apr 2026

APT28 exploit routers to enable DNS hijacking operations

Financial services & InsuranceTransport & LogisticsIT & Technology

Russian cyber actor APT28 exploit vulnerable routers to hijack DNS, enabling adversary‑in‑the‑middle attacks and theft of passwords and authentication tokens.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
8 Jul 2026

CVE-2026-9074 — CVSS 9.1 CRITICAL

Transport & LogisticsIT & Technology

IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset functionality.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Critical
28 Jul 2026

Servers aangevallen via kritiek RCE-lek in Java-library FastJson

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Aanvallers maken actief misbruik van een kritieke kwetsbaarheid in de Java-library FastJson voor het aanvallen van servers, zo ...

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Critical
30 Jul 2026

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

Financial services & InsuranceGovernment & Public sectorIndustry & ManufacturingRetail & E-commerceIT & Technology

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation. The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security High
14 Jul 2026

[Microsoft MSRC] CVE-2026-50510 GitHub Copilot Remote Code Execution Vulnerability

Industry & ManufacturingIT & Technology

Improper restriction of names for files and other resources in Github Copilot allows an unauthorized attacker to execute code locally.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
30 Jul 2026

Vulnérabilité dans Cisco Firewall Management Center (30 juillet 2026)

Transport & LogisticsIT & Technology

Une vulnérabilité a été découverte dans Cisco Firewall Management Center. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité. Cisco indique que la vulnérabilité CVE-2026-20316 est activement exploitée.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
6 Jul 2026

[webapps] Joomla Extension 4.1.4 - PHP Object injection

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Joomla Extension 4.1.4 - PHP Object injection

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Critical
25 May 2026

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerceIT & Technology

Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver. KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (…

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC High
27 Jul 2026

CVE-2026-50333 Windows Spaceport.sys Elevation of Privilege Vulnerability

IT & Technology

Updated an acknowledgement. This is an informational change only.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 Jul 2026

NCSC-2026-0262 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle MySQL Server en MySQL Cluster

Industry & ManufacturingIT & Technology

Oracle heeft meerdere kwetsbaarheden verholpen in Oracle MySQL Server en MySQL Cluster. De kwetsbaarheden betreffen verschillende versies van Oracle MySQL Server en MySQL Cluster.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
7 Apr 2026

UK exposes Russian military intelligence hijacking vulnerable routers for cyber attacks

Financial services & InsuranceTransport & LogisticsRetail & E-commerceIT & Technology

New advisory warns cyber threat group APT28 have exploited vulnerable edge devices to support malicious operations.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
8 Jul 2026

CVE-2026-29009 — CVSS 8.2 CRITICAL

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to overflow the 2048-byte nfs_path_buff buffer by returning multiple relative symlink targets that are appended without cumulative length validation. Attackers can send two or more READLINK responses containing …

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Medium
28 Jul 2026

Autoriteit Persoonsgegevens zag vorig jaar meer ransomware-aanvallen

Transport & Logistics

De Autoriteit Persoonsgegevens (AP) zag vorig jaar meer ransomware-aanvallen dan in 2024, zo laat de privacytoezichthouder in ...

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News High
29 Jul 2026

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Transport & LogisticsRetail & E-commerce

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security High
14 Jul 2026

[Microsoft MSRC] CVE-2026-55145 Outlook Copilot Tampering Vulnerability

Financial services & InsuranceIndustry & Manufacturing

Improper neutralization of special elements used in a command ('command injection') in Outlook Copilot allows an authorized attacker to perform tampering over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
30 Jul 2026

Multiples vulnérabilités dans Node.js (30 juillet 2026)

Transport & Logistics

De multiples vulnérabilités ont été découvertes dans Node.js. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
6 Jul 2026

[webapps] Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant High
25 May 2026

2 PhaaS 2 Furious: The Evolution of Chinese-Language Phishing Services

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerceEducation & Research

While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that …

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
27 Jul 2026

CVE-2026-50697 Windows Common Log File System Driver Elevation of Privilege Vulnerability

IT & Technology

Updated an acknowledgement. This is an informational change only.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 Jul 2026

NCSC-2026-0261 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Java SE

Financial services & InsuranceIndustry & ManufacturingIT & Technology

Oracle heeft meerdere kwetsbaarheden verholpen in Java SE (inclusief Oracle GraalVM en JavaFX componenten).

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
31 Mar 2026

NCSC warns of messaging app targeting

Financial services & InsuranceTransport & Logistics

The NCSC has issued actions for individuals at risk of targeted attacks against messaging apps.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
8 Jul 2026

CVE-2026-8649 — CVSS 6.4 CRITICAL

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Medium
28 Jul 2026

Belgische overheid: Gelekte gegevens massaal ingezet voor spearphishing

Financial services & InsuranceGovernment & Public sectorTransport & Logistics

Persoonsgegevens die bij bedrijven en organisaties worden gestolen en gelekt op internet, worden op massale schaal ingezet voor ...

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News High
29 Jul 2026

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Industry & ManufacturingTransport & Logistics

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security High
14 Jul 2026

[Microsoft MSRC] CVE-2026-41109 GitHub Copilot and Visual Studio Code Security Feature Bypass Vulnerability

Industry & ManufacturingIT & Technology

Improper neutralization of special elements in output used by a downstream component ('injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to bypass a security feature over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
30 Jul 2026

Multiples vulnérabilités dans Google Chrome (30 juillet 2026)

Transport & Logistics

De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
6 Jul 2026

[local] MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant High
15 May 2026

Welcome to BlackFile: Inside a Vishing Extortion Operation

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerceIT & Technology

Written by: Austin Larsen, Tyler McLellan, Genevieve Stark, Dan Ebreo Introduction Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the "BlackFile" brand, that targets organizations via sophisticated voice phishing (vishing) and single sign-on (SSO) compromise. By leveraging adversary-in-the-middle (AiTM) tech…

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
27 Jul 2026

CVE-2026-50343 Microsoft Install Service Elevation of Privilege Vulnerability

IT & Technology

Updated an acknowledgement. This is an informational change only.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 Jul 2026

NCSC-2026-0260 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle PeopleSoft Enterprise

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsIT & Technology

Oracle heeft 84 kwetsbaarheden verholpen in verschillende modules van Oracle PeopleSoft Enterprise, waaronder HCM Talent Acquisition Manager, In-Memory Project Discovery, FIN Expenses, SCM eProcurement, CC Common Application Objects, SCM Order Management, CRM Common Objects en FIN Program Management, allen versie 9.2.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
30 Mar 2026

Vulnerability affecting F5 BIG-IP APM

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

The NCSC is encouraging UK organisations to mitigate an unauthenticated remote code execution vulnerability affecting F5 BIG-IP Access Policy Manager.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
8 Jul 2026

CVE-2026-8801 — CVSS 3.5 CRITICAL

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Critical
28 Jul 2026

Arista waarschuwt voor actief misbruik van kritiek lek in VeloCloud Orchestrator

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Aanvallers maken actief misbruik van een kritieke kwetsbaarheid in VeloCloud Orchestrator (VCO), een beheerplatform voor het ...

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News High
29 Jul 2026

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Financial services & InsuranceIT & Technology

Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security High
14 Jul 2026

[Microsoft MSRC] CVE-2026-58617 M365 Copilot for iOS Elevation of Privilege Vulnerability

Industry & ManufacturingIT & Technology

Improper access control in Microsoft 365 Copilot for iOS allows an unauthorized attacker to elevate privileges over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
29 Jul 2026

Multiples vulnérabilités dans Xen (29 juillet 2026)

Transport & Logistics

De multiples vulnérabilités ont été découvertes dans Xen. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
6 Jul 2026

[webapps] KeepInMind 0.8.4.2 - Stored XSS

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

KeepInMind 0.8.4.2 - Stored XSS

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant High
23 Apr 2026

Snow Flurries: How UNC6692 Employed Social Engineering to Deploy a Custom Malware Suite

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceIT & Technology

Written by: JP Glab, Tufail Ahmed, Josh Kelley, Muhammad Umair Introduction Google Threat Intelligence Group (GTIG) identified a multistage intrusion campaign by a newly tracked threat group, UNC6692, that leveraged persistent social engineering, a custom modular malware suite, and deft pivoting inside the victim’s environment to achieve deep network penetration. As with many other intrusions in r…

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
27 Jul 2026

CVE-2026-56159 DHCP Server Service Remote Code Execution Vulnerability

Industry & Manufacturing

Updated an acknowledgement. This is an informational change only.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 Jul 2026

NCSC-2026-0259 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Analytics

Financial services & InsuranceIndustry & ManufacturingIT & Technology

Oracle heeft meerdere kwetsbaarheden verholpen in Oracle BI Publisher (versies 8.2.0.0.0, 12.2.1.4.0 en 26.01.0.0.0) en Oracle Business Intelligence Enterprise Edition (versies 8.2.0.0.0 en 26.01.0.0.0).

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
25 Mar 2026

Vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway

Financial services & InsuranceTransport & LogisticsIT & Technology

UK organisations encouraged to take immediate action to mitigate two recently disclosed vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
8 Jul 2026

CVE-2026-54527 — CVSS 9.0 CRITICAL

Financial services & Insurance

JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames directly to innerHTML when rendering renamed files in commit history, allowing a crafted filename to execute JavaScript when a victim views the rename diff in the Git History tab. This issue is fixed in version 0.54.0.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Security.NL Critical
27 Jul 2026

TeamCity-servers via kritieke kwetsbaarheid op afstand over te nemen

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Een kritieke kwetsbaarheid maakt het mogelijk voor ongeauthenticeerde aanvallers om TeamCity-servers op afstand over te nemen. ...

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Medium
29 Jul 2026

Mythos Asks the Right Question. It Doesn't Answer It.

Financial services & Insurance

AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is here. Exploit timelines are collapsing. Does the vulnerability management playbook need to change? The honest answer is

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Critical
8 Jul 2026

[Krebs on Security] Felons, Fraudsters Flog Offensive Cybersecurity Startup

Financial services & InsuranceTransport & Logistics

A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
CERT-FR High
29 Jul 2026

Multiples vulnérabilités dans Citrix XenServer (29 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans Citrix XenServer. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un problème de sécurité non spécifié par l'éditeur.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
6 Jul 2026

[webapps] KNX visualisering - Broken Access Control

Financial services & Insurance

KNX visualisering - Broken Access Control

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Critical
16 Apr 2026

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

HealthcareFinancial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerceEducation & ResearchIT & Technology

Introduction Advances in AI model-powered exploitation have demonstrated that general-purpose AI models can excel at vulnerability discovery, even without being purpose-built for the task. Eventually, capabilities such as these will be integrated directly into the development cycle, and code will be more difficult to exploit than ever; however, this transition creates a critical window of risk. As…

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC High
27 Jul 2026

CVE-2026-16277 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 Jul 2026

NCSC-2026-0258 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Financial Services

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsIT & Technology

Oracle heeft kwetsbaarheden verholpen in diverse Financial Services modules. Ook heeft Oracle updates voor diverse third-party-producten verwerkt.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
24 Mar 2026

NCSC CEO: Seize 'disruptive' vibe coding opportunity to make software more secure

Financial services & InsuranceIndustry & ManufacturingIT & Technology

Dr Richard Horne delivered a keynote about cyber risks and opportunities at the RSAC Conference in San Francisco

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
8 Jul 2026

CVE-2026-55471 — CVSS 9.1 CRITICAL

HealthcareFinancial services & Insurance

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxon.TransformerFactoryImpl() without ACCESS_EXTERNAL_DTD or ACCESS_EXTERNAL_STYLESHEET restrictions, allowing an attacker who controls or can tamper with transformed XML to trigger X…

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
29 Jul 2026

Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

Financial services & Insurance

Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. "No settings or additional user interaction are required," Eten Zou,

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security High
2 Jul 2026

[Microsoft MSRC] CVE-2026-45499 Azure OpenAI Elevation of Privilege Vulnerability

IT & Technology

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
29 Jul 2026

Vulnérabilité dans Apache Tomcat (29 juillet 2026)

Transport & Logistics

Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un attaquant de provoquer un déni de service à distance.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
6 Jul 2026

[local] Windows Defender (MsMpEng.exe) - Race Condition

IT & Technology

Windows Defender (MsMpEng.exe) - Race Condition

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant High
15 Apr 2026

The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscape

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerceEducation & Research

Written by: Jamie Collier, Robin Grunewald Germany has reclaimed its position as a primary focus for cyber extortion in Europe. While data leak site (DLS) posts rose almost 50% globally in 2025, Google Threat Intelligence (GTI) data shows that the surge is hitting German infrastructure harder and faster than its regional neighbors, marking a significant return to the high-pressure levels previousl…

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
27 Jul 2026

CVE-2024-14040 net: nexthop: Increase weight to u16

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 Jul 2026

NCSC-2026-0257 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Enterprise Manager

Financial services & InsuranceIndustry & ManufacturingIT & Technology

Oracle heeft meerdere kwetsbaarheden verholpen in Oracle Enterprise Manager Base Platform versies 13.5 en 24.1.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
12 Mar 2026

International security chiefs to convene in Glasgow for flagship CYBERUK conference

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

CYBERUK will be delivered by the NCSC and sponsors across four distinct tracks of activity: Resilience, Technology, Threat, and Ecosystem.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
7 Jul 2026

CVE-2026-13020 — CVSS 8.1 CRITICAL

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsIT & Technology

A Weak Password Recovery Mechanism for Forgotten Password exists in Esri Portal for ArcGIS versions 12.1 and earlier on Windows, Linux and Kubernetes. A remote, unauthorized attacker may assume ownership of a user’s account by manipulating this mechanism. ArcGIS Administrators should configure an email server with ArcGIS Enterprise to facilitate user self-service password recovery. The ability for…

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Critical
29 Jul 2026

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Financial services & Insurance

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security High
2 Jul 2026

[Microsoft MSRC] CVE-2026-41106 Microsoft 365 Copilot Elevation of Privilege Vulnerability

Industry & ManufacturingIT & Technology

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
29 Jul 2026

Multiples vulnérabilités dans Microsoft Edge (29 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données et un problème de sécurité non spécifié par l'éditeur.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
6 Jul 2026

[webapps] WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)

Financial services & Insurance

WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant High
2 Apr 2026

vSphere and BRICKSTORM Malware: A Defender's Guide

Financial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsRetail & E-commerceEducation & ResearchIT & Technology

Written by: Stuart Carrera Introduction Building on recent BRICKSTORM research from Google Threat Intelligence Group (GTIG), this post explores the evolving threats facing virtualized environments. These operations directly target the VMware vSphere ecosystem, specifically the vCenter Server Appliance (VCSA) and ESXi hypervisors. To help organizations stay ahead of these risks, we will focus on th…

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
27 Jul 2026

CVE-2026-64530 net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 Jul 2026

NCSC-2026-0256 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Communications

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsIT & Technology

Oracle heeft kwetsbaarheden verholpen in Communications producten en onderliggende third party software. Het betreft een totaal van 213 kwetsbaarheden, waarvan 67 zich bevinden in Oracle producten en 146 in third-party producten waar eerder updates voor zijn verschenen en welke in deze Oracle updates zijn verwerkt.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
2 Mar 2026

Alert: NCSC advises UK organisations to take action following conflict in the Middle East

Financial services & InsuranceTransport & LogisticsRetail & E-commerce

In response to the evolving events in the Middle East, the NCSC is advising that UK organisations review their cyber security posture.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
6 Jul 2026

CVE-2026-40139 — CVSS 9.8 CRITICAL

Financial services & InsuranceIndustry & Manufacturing

A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated privileges. Exploitation requires a specific authentication configuration to be enabled.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News High
29 Jul 2026

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

Industry & ManufacturingTransport & LogisticsRetail & E-commerce

Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security High
1 Jul 2026

[Palo Alto Unit 42] Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector

Financial services & InsuranceTransport & LogisticsRetail & E-commerce

Attackers can exploit LLM domain hallucinations through phantom squatting to target supply chains. Read the analysis to learn more. The post Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector appeared first on Unit 42.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
28 Jul 2026

Multiples vulnérabilités dans Samba (28 juillet 2026)

Transport & Logistics

De multiples vulnérabilités ont été découvertes dans Samba. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
8 Jun 2026

[webapps] OpenEMR 7.0.2 - Arbitrary File Read

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

OpenEMR 7.0.2 - Arbitrary File Read

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
27 Jul 2026

CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 Jul 2026

NCSC-2026-0255 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Commerce Platform

Financial services & InsuranceIndustry & ManufacturingIT & Technology

Oracle heeft 39 kwetsbaarheden verholpen in Oracle Commerce Platform en Oracle Commerce Guided Search/Experience Manager, beide versies 11.4.0. 11 van deze kwetsbaarheden hebben een CVSS score van 9 en hoger gekregen en zijn hieronder samengevat.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK High
25 Feb 2026

Exploitation of Cisco Catalyst SD-WAN

Industry & ManufacturingIT & Technology

Agencies strongly encourage immediate investigation of potential compromise of Cisco Catalyst SD-WAN.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
6 Jul 2026

CVE-2026-40141 — CVSS 9.9 CRITICAL

Financial services & InsuranceIndustry & Manufacturing

A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources or data beyond their authorization scope. Exploitation is restricted to accounts…

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News High
29 Jul 2026

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Financial services & InsuranceIndustry & Manufacturing

Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a fake "公安一网通办" Public Security service application targeting Android users in China. The kit supports payment-password

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security High
23 Jun 2026

[Palo Alto Unit 42] OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat

Financial services & InsuranceRetail & E-commerce

Unit 42's analysis of ClawHub revealed evasive malicious skills bypassing automated scanners to deploy infostealers and execute agentic financial fraud. The post OpenClaw’s Skill Marketplace and the Emerging AI Supply Chain Threat appeared first on Unit 42.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
28 Jul 2026

Multiples vulnérabilités dans les produits Apple (28 juillet 2026)

Transport & Logistics

De multiples vulnérabilités ont été découvertes dans les produits Apple. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et une atteinte à la confidentialité des données.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
5 Jun 2026

[webapps] WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
27 Jul 2026

CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()

Transport & Logistics

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 Jul 2026

NCSC-2026-0254 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle database producten

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsIT & Technology

Oracle heeft 158 kwetsbaarheden verholpen in Oracle Database Server, APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer en TimesTen In-Memory Database.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Critical
6 Jul 2026

CVE-2026-54763 — CVSS 10.0 CRITICAL

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can i…

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
29 Jul 2026

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Industry & ManufacturingTransport & Logistics

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/components@4.0.0-rc24-2773-beta.4 The two packages "contain an import-time JavaScript implant that resolves encrypted code

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security High
18 Jun 2026

[Microsoft MSRC] CVE-2026-42895 Microsoft Copilot Tampering Vulnerability

Financial services & InsuranceIndustry & ManufacturingIT & Technology

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
27 Jul 2026

Bulletin d'actualité CERTFR-2026-ACT-032 (27 juillet 2026)

Transport & Logistics

Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
1 Jun 2026

[webapps] Drupal Core 10.5.5 - Error-Based SQL Injection

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Drupal Core 10.5.5 - Error-Based SQL Injection

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
25 Jul 2026

Chromium: CVE-2026-16804 Use after free in Input

Financial services & InsuranceIT & Technology

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 Jul 2026

NCSC-2026-0253 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle E-Business Suite componenten

Financial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsIT & Technology

Oracle heeft meerdere kwetsbaarheden verholpen in Oracle E-Business Suite, inclusief diverse modules zoals Work in Process, Application Object Library, HRMS, Applications Framework, Advanced Collections, Advanced Outbound Telephony, Advanced Pricing, Applications DBA, Bills of Material, Customer Care, Enterprise Asset Management, Enterprise Command

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Critical
4 Jul 2026

CVE-2026-14535 — CVSS 8.8 CRITICAL

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as unsafe. This call registers the shortened code representation in the shared AnalysisContext.reported_shortened_code set. When the MLAllowlist analysis pass subsequen…

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
29 Jul 2026

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

Retail & E-commerce

Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security High
18 Jun 2026

[Microsoft MSRC] CVE-2026-54130 M365 Copilot Information Disclosure Vulnerability

Financial services & InsuranceIndustry & Manufacturing

Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
27 Jul 2026

Multiples vulnérabilités dans les produits Atlassian (27 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans les produits Atlassian. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
1 Jun 2026

[webapps] WordPress OrderConvo 14 - Path Traversal

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

WordPress OrderConvo 14 - Path Traversal

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
25 Jul 2026

Chromium: CVE-2026-16805 Use after free in Blink

Financial services & InsuranceIT & Technology

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
22 Jul 2026

NCSC-2026-0252 [1.00] [H/H] Kwetsbaarheden verholpen in Oracle Fusion middleware

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsIT & Technology

Oracle heeft een groot aantal kwetsbaarheden verholpen in verschillende Oracle middleware producten, waaronder Oracle Data Integrator, Oracle Coherence, Oracle Access Manager, Oracle Unified Directory, Oracle WebLogic Server Proxy Plug-in, Oracle Fusion Middleware Service Delivery Platform (Messaging Enabler) en Oracle WebCenter Content.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Critical
3 Jul 2026

CVE-2026-47898 — CVSS 9.8 CRITICAL

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta00018. Users are recommended to upgrade to version 4.8.0-beta00018, which fixes the issue.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News High
28 Jul 2026

Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process

Financial services & InsuranceIndustry & ManufacturingIT & Technology

A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force. Tengu supports 25 distributed denial-of-service (

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security High
18 Jun 2026

[Microsoft MSRC] CVE-2026-47645 Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability

Industry & ManufacturingIT & Technology

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
27 Jul 2026

Vulnérabilité dans Traefik (27 juillet 2026)

Transport & Logistics

Une vulnérabilité a été découverte dans Traefik. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
30 May 2026

[remote] Notepad++ 8.9.6 - Arbitrary Code Execution

Industry & Manufacturing

Notepad++ 8.9.6 - Arbitrary Code Execution

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
25 Jul 2026

Chromium: CVE-2026-16806 Use after free in WebMCP

Financial services & InsuranceIT & Technology

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
21 Jul 2026

NCSC-2026-0237 [1.02] [H/H] Kwetsbaarheden verholpen in Microsoft Office

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsIT & Technology

Microsoft heeft kwetsbaarheden verholpen in diverse Office producten, zoals Word, Excel, Powerpoint en SharePoint. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot categorieën schade, zoals benoemd in onderstaande tabel.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Critical
3 Jul 2026

CVE-2026-12481 — CVSS 9.8 CRITICAL

Financial services & Insurance

A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to enforce the safe-mode guard when `safe_mode` is set to `None`, which is the default value when `from_config()` is called outside of a `SafeModeScope` context. This logic er…

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Critical
28 Jul 2026

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

Financial services & InsuranceRetail & E-commerce

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved laterally until they reached an internet-connected node. JFrog says it has since developed and released fixes for cloud

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security High
10 Jun 2026

[Microsoft MSRC] CVE-2026-45482 Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability

Industry & ManufacturingIT & Technology

Updated the Security Updates Build Number and Title as the Chat extention is now merged into Visual Studio Code

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
27 Jul 2026

Multiples vulnérabilités dans Microsoft Edge (27 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
30 May 2026

[webapps] YAMCS yamcs-core 5.12.7 - No Rate Limiting

Financial services & Insurance

YAMCS yamcs-core 5.12.7 - No Rate Limiting

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
25 Jul 2026

Chromium: CVE-2026-16807 Out of bounds write in Codecs

Financial services & InsuranceIT & Technology

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
21 Jul 2026

NCSC-2026-0251 [1.00] [M/H] Kwetsbaarheden verholpen in IBM Langflow OSS

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsRetail & E-commerceIT & Technology

IBM heeft meerdere kwetsbaarheden verholpen in IBM Langflow OSS versies 1.0.0 tot en met 1.10.0.

Recommended action
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Critical
3 Jul 2026

CVE-2026-57983 — CVSS 8.7 CRITICAL

IT & Technology

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News High
28 Jul 2026

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

Industry & ManufacturingIT & Technology

OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security High
9 Jun 2026

[Microsoft MSRC] CVE-2026-41100 Microsoft 365 Copilot for Android Spoofing Vulnerability

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsIT & Technology

Added Microsoft Excel for Android, Microsoft Word for Android, Microsoft Loop for Android, Microsoft PowerPoint for Android and Microsoft OneNote for Android softwares to the Security Updates table. Customers that are running supported version of these products are encouraged to update to the indicated versions to be protected from this vulnerability.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
27 Jul 2026

Multiples vulnérabilités dans GLPI (27 juillet 2026)

Transport & Logistics

De multiples vulnérabilités ont été découvertes dans GLPI. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à l'intégrité des données et une injection SQL (SQLi).

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
30 May 2026

[webapps] YAMCS yamcs-core 5.12.7 - User Enumeration

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

YAMCS yamcs-core 5.12.7 - User Enumeration

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
24 Jul 2026

CVE-2026-62835 Azure Portal Information Disclosure Vulnerability

IT & Technology

Corrected the CVE description and title. This is an informational change only.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
2 Jul 2026

CVE-2026-54408 — CVSS 8.6 CRITICAL

Financial services & InsuranceIndustry & Manufacturing

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
28 Jul 2026

Nimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert Relays

Financial services & InsuranceTransport & LogisticsIT & Technology

The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve the use of a previously undocumented Windows backdoor called NightLedger and two custom WebSocket tunnelers,

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security High
4 Jun 2026

[Microsoft MSRC] CVE-2026-42824 M365 Copilot Information Disclosure Vulnerability

Industry & Manufacturing

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
24 Jul 2026

Multiples vulnérabilités dans le noyau Linux de Debian LTS (24 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian LTS. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
30 May 2026

[webapps] YAMCS yamcs-core 5.12.7 - LDAP Injection

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

YAMCS yamcs-core 5.12.7 - LDAP Injection

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
24 Jul 2026

CVE-2026-48561 Microsoft Edge Copilot Remote Code Execution Vulnerability

Industry & ManufacturingIT & Technology

Corrected the CVE description and title. This is an informational change only.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
2 Jul 2026

CVE-2026-55115 — CVSS 9.9 CRITICAL

Industry & Manufacturing

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News High
28 Jul 2026

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

Financial services & InsuranceTransport & Logistics

JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security High
4 Jun 2026

[Microsoft MSRC] CVE-2026-45497 Microsoft M365 Copilot Remote Code Execution Vulnerability

Industry & ManufacturingIT & Technology

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
24 Jul 2026

Multiples vulnérabilités dans le noyau Linux de Debian (24 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[remote] Microsoft - NTLMv2 Hash Capture

Industry & ManufacturingIT & Technology

Microsoft - NTLMv2 Hash Capture

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
24 Jul 2026

CVE-2026-59676 Local File Deletion Attack Vector in rm_rf() in seunshare

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
2 Jul 2026

CVE-2026-55116 — CVSS 9.0 CRITICAL

Financial services & InsuranceTransport & Logistics

A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
28 Jul 2026

Researcher Says AI Helped Develop Linux Traffic-Control Race Into Root Exploit

Industry & ManufacturingTransport & LogisticsIT & Technology

STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem.Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and speed up exploit development. This is local

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security High
4 Jun 2026

[Microsoft MSRC] CVE-2026-47644 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Industry & ManufacturingIT & Technology

Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
24 Jul 2026

Multiples vulnérabilités dans le noyau Linux d'Ubuntu (24 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[webapps] MikroORM 7.0.13 - SQL Injection

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

MikroORM 7.0.13 - SQL Injection

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
24 Jul 2026

CVE-2026-59677 Process Kill Attack Vector in killall() in seunshare

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
2 Jul 2026

CVE-2026-26145 — CVSS 4.8 CRITICAL

IT & Technology

Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Medium
28 Jul 2026

Microsoft Says New Cybersecurity AI Model Helps MDASH Score 95.95% at Half the Cost

Financial services & InsuranceIT & Technology

Microsoft has launched its first cybersecurity-specific model inside MDASH, its multi-model vulnerability identification and remediation harness. The company says MDASH, using MAI-Cyber-1-Flash and GPT-5.4, scored 95.95% on CyberGym. It also claims the configuration costs 50% less than its current best MDASH combination of GPT-5.4, GPT-5.4 mini, and GPT-5.3 Codex. Access is limited to approved

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security High
12 May 2026

[Microsoft MSRC] CVE-2026-41614 M365 Copilot for Desktop Spoofing Vulnerability

Financial services & InsuranceIndustry & Manufacturing

Improper access control in M365 Copilot for Desktop allows an unauthorized attacker to perform spoofing locally.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
24 Jul 2026

Multiples vulnérabilités dans les produits ESET (24 juillet 2026)

Transport & Logistics

De multiples vulnérabilités ont été découvertes dans les produits ESET. Elles permettent à un attaquant de provoquer une élévation de privilèges.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[webapps] Prodigy Commerce 3.3.0 - Local File Inclusion

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Prodigy Commerce 3.3.0 - Local File Inclusion

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
24 Jul 2026

CVE-2026-64600 xfs: resample the data fork mapping after cycling ILOCK

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Critical
2 Jul 2026

CVE-2026-41106 — CVSS 9.3 CRITICAL

Industry & Manufacturing

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Recommended action
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
The Hacker News Critical
28 Jul 2026

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

Financial services & InsuranceTransport & Logistics

A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution. "VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue

Recommended action
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
AI Security High
12 May 2026

[Microsoft MSRC] CVE-2026-33833 Azure Machine Learning Notebook Spoofing Vulnerability

Financial services & InsuranceIndustry & ManufacturingIT & Technology

Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
24 Jul 2026

Multiples vulnérabilités dans les produits IBM (24 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[webapps] Langflow 1.3.0 - Remote Code Execution

Industry & Manufacturing

Langflow 1.3.0 - Remote Code Execution

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-56167 Azure AI Search Elevation of Privilege Vulnerability

IT & Technology

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News High
27 Jul 2026

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

Financial services & InsuranceIndustry & ManufacturingTransport & LogisticsIT & Technology

NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security High
12 May 2026

[Microsoft MSRC] CVE-2026-42893 Microsoft Outlook for iOS Tampering Vulnerability

Financial services & InsuranceIndustry & ManufacturingIT & Technology

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to perform tampering over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
24 Jul 2026

Multiples vulnérabilités dans le noyau Linux de Red Hat (24 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[webapps] Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution

Industry & Manufacturing

Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-56163 Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability

Financial services & InsuranceIT & Technology

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News High
27 Jul 2026

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

Financial services & InsuranceIndustry & Manufacturing

Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt. CNCERT, China's national computer emergency response team, and XLab, the threat-intelligence lab of Chinese

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security High
7 May 2026

[Microsoft MSRC] CVE-2026-26164 M365 Copilot Information Disclosure Vulnerability

Industry & Manufacturing

Improper neutralization of special elements in output used by a downstream component ('injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
24 Jul 2026

Multiples vulnérabilités dans le noyau Linux de SUSE (24 juillet 2026)

Transport & LogisticsIT & Technology

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[local] ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-56165 Microsoft Account Remote Code Execution Vulnerability

Industry & ManufacturingIT & Technology

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
27 Jul 2026

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

Industry & Manufacturing

Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not give a lower version

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security High
7 May 2026

[Microsoft MSRC] CVE-2026-26129 M365 Copilot Information Disclosure Vulnerability

Industry & Manufacturing

Improper neutralization of special elements in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
24 Jul 2026

Vulnérabilité dans les produits Moxa (24 juillet 2026)

Transport & Logistics

Une vulnérabilité a été découverte dans les produits Moxa. Elle permet à un attaquant de provoquer une élévation de privilèges.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[local] ZTE Routers - Unauthenticated Denial of Service

IT & Technology

ZTE Routers - Unauthenticated Denial of Service

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-54120 Microsoft Surface Remote Code Execution Vulnerability

Industry & ManufacturingEducation & ResearchIT & Technology

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
27 Jul 2026

⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More

Financial services & InsuranceIndustry & ManufacturingRetail & E-commerceIT & Technology

Monday starts with the usual promise that everything is under control. Then the logs wake up. This week, trusted tools crossed lines, old flaws found new work, exposed systems stayed exposed, and attackers kept hiding inside normal-looking services. Nothing looked strange at first. That helped. That is the mood. Here is the full recap. ⚡ Threat of the Week OpenAI Says Its AI Agent Went Rogue

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security High
7 May 2026

[Microsoft MSRC] CVE-2026-33111 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Industry & ManufacturingIT & Technology

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
23 Jul 2026

Vulnérabilité dans Moodle (23 juillet 2026)

Transport & LogisticsEducation & Research

Une vulnérabilité a été découverte dans Moodle. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[local] ZTE ZXHN H188A V6 - Authentication Bypass

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

ZTE ZXHN H188A V6 - Authentication Bypass

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-56160 Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability

IT & Technology

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
27 Jul 2026

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

Financial services & InsuranceIndustry & ManufacturingTransport & Logistics

n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another bypass. The affected ranges are <2.31.5 and >=2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security High
7 May 2026

[Microsoft MSRC] CVE-2026-32207 Azure Machine Learning Notebook Spoofing Vulnerability

Financial services & InsuranceIndustry & ManufacturingIT & Technology

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
9 Jul 2026

Multiples vulnérabilités dans Traefik (09 juillet 2026)

Transport & Logistics

De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[local] ZTE H298A / H108N - Unauthenticated Credential Exposure

Retail & E-commerce

ZTE H298A / H108N - Unauthenticated Credential Exposure

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-35425 Azure API Management (APIM) Remote Code Execution Vulnerability

Industry & ManufacturingIT & Technology

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
27 Jul 2026

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Financial services & InsuranceIndustry & ManufacturingIT & Technology

Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools. "The victim was directed through compromised web infrastructure to a counterfeit Microsoft Store page claiming that Microsoft Teams had to be updated before the shared document could be opened," ZeroBEC said in

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR High
11 Jun 2026

Vulnérabilité dans Traefik (11 juin 2026)

Transport & Logistics

Une vulnérabilité a été découverte dans Traefik. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[local] Linux Kernel - Local Privilege Escalation

IT & Technology

Linux Kernel - Local Privilege Escalation

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-49159 Microsoft Graph Information Disclosure Vulnerability

Retail & E-commerceIT & Technology

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
The Hacker News Medium
27 Jul 2026

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

Financial services & InsuranceIndustry & ManufacturingIT & Technology

The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra. According to a new analysis by Proofpoint, Cruciferra has been utilized by various unrelated cybercriminal threat clusters to deliver a wide array of remote

Recommended action
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR High
31 Mar 2026

Vulnérabilité dans F5 BIG-IP Access Policy Manager (31 mars 2026)

Transport & Logistics

Le 15 octobre 2025, F5 a publié un avis de sécurité concernant entre autres la vulnérabilité CVE-2025-53521. Celle-ci affecte BIG-IP APM et permet à un attaquant non authentifié d'exécuter du code à distance. Le 29 mars 2026, l'éditeur indique que cette vulnérabilité est exploitée activement. Le...

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[webapps] MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution

Industry & Manufacturing

MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-50517 Microsoft M365 Copilot Remote Code Execution Vulnerability

Industry & ManufacturingIT & Technology

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
19 Mar 2026

Multiples vulnérabilités dans Roundcube (19 mars 2026)

Transport & Logistics

De multiples vulnérabilités ont été découvertes dans Roundcube. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une falsification de requêtes côté serveur (SSRF) et une injection de code indirecte à distance (XSS).

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[remote] Wing FTP Server 8.1.3 - Authenticated Remote Code Execution

Financial services & InsuranceIndustry & Manufacturing

Wing FTP Server 8.1.3 - Authenticated Remote Code Execution

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-56191 Microsoft Exchange Online Tampering Vulnerability

Financial services & InsuranceIT & Technology

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR High
30 Jan 2026

[MàJ] Multiples vulnérabilités dans Ivanti Endpoint Manager Mobile (30 janvier 2026)

Transport & LogisticsRetail & E-commerce

[Mise à jour du 09 février 2026] Le 6 février 2026, Ivanti a mis à disposition des scripts RPM de détection d'indicateurs de compromission, à utiliser en fonction de la version d'EPMM installée. L'éditeur a également mis son guide d'analyse à jour (cf. section Documentation). [Mise à jour du 02...

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[webapps] CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)

Financial services & Insurance

CubeCart < 6.7.0 - Reflected Cross-Site Scripting (XSS) (Unauthenticated)

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-57106 Data Quality Elevation of Privilege Vulnerability

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[remote] strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow

Industry & Manufacturing

strongSwan 5.9.13 - libsimaka EAP-SIM/AKA heap buffer overflow

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-62825 Azure Key Vault Elevation of Privilege Vulnerability

IT & Technology

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
29 May 2026

[dos] strongSwan 5.9.13 - DoS

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

strongSwan 5.9.13 - DoS

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-58630 Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability

IT & Technology

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
27 May 2026

[local] Linux Kernel - Local Privilege Escalation

IT & Technology

Linux Kernel - Local Privilege Escalation

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-58275 Azure DNS Elevation of Privilege Vulnerability

Financial services & InsuranceTransport & LogisticsIT & Technology

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
27 May 2026

[webapps] Casdoor 3.54.1 - Arbitrary File Write via Path Traversal

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Casdoor 3.54.1 - Arbitrary File Write via Path Traversal

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-47729 Squid: Memory disclosure in FTP gateway

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
27 May 2026

[webapps] EspoCRM 9.3.3 - SSRF

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

EspoCRM 9.3.3 - SSRF

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-56145 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

Financial services & InsuranceIndustry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
27 May 2026

[webapps] scramble - Remote Code Execution

Industry & Manufacturing

scramble - Remote Code Execution

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-63140 Reachable Assertion in Elasticsearch Leading to Denial of Service

Financial services & InsuranceIndustry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
27 May 2026

[hardware] MeiG Smart FORGE_SLT711 - OS Command Injection

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

MeiG Smart FORGE_SLT711 - OS Command Injection

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-63136 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

Financial services & InsuranceIndustry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
27 May 2026

[local] Realtek rtl819x - Local Privilege

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Realtek rtl819x - Local Privilege

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-53910 Heap-based Buffer Overflow in GNU diffutils

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
27 May 2026

[webapps] OpenCATS 0.9.7.4 - SQL Injection

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

OpenCATS 0.9.7.4 - SQL Injection

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-55973 'dns-error-reporting: yes' leads to stack buffer overflow

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB High
26 May 2026

[webapps] Grav CMS 2.0.0-beta.2 - Remote Code Execution

Industry & Manufacturing

Grav CMS 2.0.0-beta.2 - Remote Code Execution

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-50248 BOGUS configured primary hostname accepted for XFR in auth/rpz zones

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-55708 Privacy/configuration issue when adding local data in views through 'unbound-control'

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-44621 Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated

Transport & Logistics

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-55717 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-40691 Packet of death for DNSCrypt over TCP

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass

Industry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path

Financial services & InsuranceIndustry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled out

Industry & ManufacturingRetail & E-commerce

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-55990 Packet of death for a DNSCrypt misconfigured Unbound

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-55991 Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2

Industry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-50251 Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-50252 Possible cache poisoning attack by mapping source port population per thread

Financial services & InsuranceRetail & E-commerce

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-63308 Helm Files.Lines Denial of Service via Empty Chart Files

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-15588 Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-26080 HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-26081 HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-15788 WCOW cache mount source selector resolves NTFS junctions outside of cache root

Industry & ManufacturingTransport & Logistics

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-12080 Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-44509 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43619. Reason: This candidate is a duplicate of CVE-2026-43619. Notes: All CVE users should reference CVE-2026-43619 instead of this candida

Industry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-44508 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43618. Reason: This candidate is a duplicate of CVE-2026-43618. Notes: All CVE users should reference CVE-2026-43618 instead of this candida

Industry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-50012 Squid: Memory corruption in cache_digest reply handling

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-54171 Excon: redact additional sensitive/risky headers when following redirects

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-38753 A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-38752 A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-63263 Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service

Financial services & InsuranceIndustry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin

Industry & ManufacturingTransport & Logistics

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-50045 'max-global-quota' reset by DNSSEC validation restarts

Industry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-44690 Cross-zone wildcard cache poisoning via RRSIG.labels manipulation

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-52863 Memory corruption could lead to crash and denial of service

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name

Transport & LogisticsRetail & E-commerce

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-56444 Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-54478 DNS Cookie bypass when combined with proxy-protocol use

Industry & ManufacturingTransport & Logistics

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-14586 Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-41637 Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
23 Jul 2026

CVE-2026-44510 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43620. Reason: This candidate is a duplicate of CVE-2026-43620. Notes: All CVE users should reference CVE-2026-43620 instead of this candida

Industry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
22 Jul 2026

CVE-2026-15028 Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header

Financial services & InsuranceTransport & Logistics

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
22 Jul 2026

CVE-2026-57219 RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations

Industry & ManufacturingTransport & Logistics

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
22 Jul 2026

CVE-2026-59884 pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
22 Jul 2026

CVE-2026-59886 pyasn1: Uncontrolled resource consumption when converting decoded REAL values

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
22 Jul 2026

CVE-2026-42533 NGINX Map directive and Regex matching vulnerability

Financial services & Insurance

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
22 Jul 2026

CVE-2026-56434 NGINX ngx_http_ssi_module vulnerability

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
22 Jul 2026

CVE-2026-26197 Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c

Industry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
22 Jul 2026

CVE-2026-64192 bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
22 Jul 2026

CVE-2026-64189 netfilter: ipset: fix race between dump and ip_set_list resize

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
22 Jul 2026

CVE-2026-64188 net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()

HealthcareFinancial services & InsuranceGovernment & Public sectorIndustry & ManufacturingTransport & LogisticsEnergy & UtilitiesRetail & E-commerceEducation & ResearchIT & Technology

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
22 Jul 2026

CVE-2026-57220 RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS

Financial services & InsuranceIndustry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
22 Jul 2026

CVE-2026-57217 RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass

Financial services & InsuranceIndustry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC High
22 Jul 2026

CVE-2026-57213 RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering

Financial services & InsuranceIndustry & Manufacturing

Information published.

Recommended action
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
🔍 No advisories found for this combination. Try a different filter.
Disclaimer: These advisories are sourced from public feeds including NCSC NL, CISA, CISA KEV, NVD (NIST), MITRE CVE, Exploit-DB, Mandiant, Microsoft MSRC, Cisco Talos, Kaspersky, ENISA and BleepingComputer. The summaries are intended as a first orientation. Always consult the original sources for full technical details. SOC Continu is not liable for decisions made on the basis of this summary.