News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
32733 risultati
CVE ID :CVE-2026-68868 Published : Aug. 12, 2026, 10:27 a.m. | 4 minutes ago Description :The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Variables: the caller's `team_name` was accepted by the backend but dropped at the internal call boundary, so every lookup resolved against the team-agnostic secret name. In a deployment running multi-team mode with this backend, a task or Dag belonging to one team resolved another team's Connection or Variable, obtaining its credentials in full. No unusual configuration is required beyond enabling multi-team mode and using this backend. Users are advised to upgrade to apache-airflow-providers-google 22.3.0 or later, which builds and applies the team-scoped secret name. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-67284 Published : Aug. 12, 2026, 10:17 a.m. | 15 minutes ago Description :Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-64951 Published : Aug. 12, 2026, 10:17 a.m. | 15 minutes ago Description :A rogue Velociraptor client can upload a malformed sparse file such that if the GUI attempts to expand the file, a panic occurs which may crash the server process. The problem is a Divide by Zero bug in the ShouldPadFile() function. Severity: 3.5 | LOW Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-64955 Published : Aug. 12, 2026, 10:17 a.m. | 15 minutes ago Description :When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. Velociraptor fails to sanitize such cells when exporting to CSV from various places such as the GUI, offline collector or data exports. It is not clear if the vulnerability is actually in Microsoft Excel treating a CSV data file as executable content, or if Velociraptor should be sanitizing the data to prevent Excel from executing it. However, since this is such a common use case for Velociraptor we decided to highlight it in an advisory. Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-64952 Published : Aug. 12, 2026, 10:17 a.m. | 15 minutes ago Description :The hunt_delete() VQL function allows deleting hunts. Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned to the "investigator" role) instead of the "DELETE_RESULTS" permission (usually only assigned to "administrators"). Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18663 Published : Aug. 12, 2026, 10:17 a.m. | 15 minutes ago Description :A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control rejection path without clearing the SLAPI_REQCONTROLS pblock slot. Operation teardown then frees the same pointer again, causing a double-free. An unauthenticated remote attacker can trigger this with a single BIND request carrying a critical Session Tracking control, resulting in heap corruption and potential denial of service. Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-18652 Published : Aug. 12, 2026, 10:17 a.m. | 15 minutes ago Description :Velociraptor allows reading Stacked result sets from the GUI. Velociraptor's multi-tenant design stores sub orgs within the datastore directory. The path requested by the GUI is not correctly checked against the prefix deny list, allowing result sets to read from denied prefixes. In particular, a user with read access to the root org can access result sets from child orgs. Severity: 4.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
'Europese defensiesector aangevallen via nep-vacatures en Windows-zeroday' Europese defensiebedrijven zijn recentelijk het doelwit van cyberaanvallen geworden, waarbij nep-vacatures en een zerodaylek in Windows werden gecombineerd om systemen met een rootkit en backdoor te i ... Read more Published Date: Aug 12, 2026 (1 hour, 30 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-68820
CVE ID :CVE-2026-67282 Published : Aug. 12, 2026, 9:17 a.m. | 1 hour, 15 minutes ago Description :Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik Severity: 10.0 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-67283 Published : Aug. 12, 2026, 9:17 a.m. | 1 hour, 15 minutes ago Description :Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud Severity: 6.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-19566 Published : Aug. 12, 2026, 9:17 a.m. | 1 hour, 15 minutes ago Description :Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The _encode method accepts any prefix length matching `(0|[1-9][0-9]*)` and passes it to _width2bits(), which builds the mask as `'1' x ($width + 8)`, one character per bit. The _inc() method then unpacks the packed mask into a Perl array of one scalar per byte, so the prefix length alone sets the allocation size: `::/100000000` builds a 100 MB string and a 12.5 million element array. The value being tested is parsed, not just the configured ranges: contains() builds a set from its argument, and _guess_coder() tries the IPv4 coder and then the IPv6 coder, so an IPv4-only set expands an oversized IPv6 prefix length before the mixed address width check rejects it. Any caller that passes untrusted input to contains() or add() can exhaust process memory. A prefix length above 128 is also stored as a range that does not match the requested block: 2001:db8::/129 stringifies back unchanged, contains() of its own base address returns false, and removing it from a set drops the base address while the set still prints as covering it. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-5931 ... Read more Published Date: Aug 12, 2026 (2 hours, 21 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-59310 CVE-2026-59309
Pagina 1 di 2728