News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
37916 risultati
Kritiek beveiligingslek op GitHub.com gaf toegang tot miljoenen repositories Een kritieke kwetsbaarheid op GitHub.com maakte het mogelijk om toegang tot miljoenen publieke en private repositories te krijgen. Hetzelfde beveiligingslek maakte het ook mogelijk om in het geval van ... Read more Published Date: Apr 29, 2026 (22 hours, 56 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-3854
GitHub: Woah, a genuinely helpful AI-assisted bug report that isn't total slop. Here, Wiz, take this wad of cash Wiz researchers are set for a tidy payday thanks to their discovery of a high-severity flaw in GitHub's git infrastructure that handed remote attackers full read/write access to private GitHub reposit ... Read more Published Date: Apr 29, 2026 (23 hours, 23 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-3854
Label Leak: Hardcoded Credentials in Snap One WattBox Devices Open Door to Root Access A critical vulnerability has been identified in the Snap One WattBox 800 and 820 series power controllers. The flaw, tracked as CVE-2026-41446 with a CVSS score of 9.2, reveals that diagnostic endpoin ... Read more Published Date: Apr 29, 2026 (23 hours, 37 minutes ago) Vulnerabilities has been mentioned in this article.
Cursor AI Coding Agent Vulnerability Allow Attackers to Execute Code on Developer’s Machine A high-severity vulnerability in Cursor, one of the most widely used AI-powered coding environments today, has put developers at direct risk of remote code execution. Tracked as CVE-2026-26268, the fl ... Read more Published Date: Apr 29, 2026 (23 hours, 41 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-26268
NVIDIA FLARE Alert: Critical SDK Vulnerabilities Open Doors to Full System Takeover NVIDIA has issued an urgent software update for the NVIDIA FLARE SDK, addressing multiple security vulnerabilities that could allow attackers to bypass authentication, execute malicious code, and tamp ... Read more Published Date: Apr 29, 2026 (22 hours, 24 minutes ago) Vulnerabilities has been mentioned in this article.
CVE ID :CVE-2026-42249 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Ollama for Windows contains a Remote Code Execution vulnerability in its update mechanism due to improper handling of attacker‑controlled HTTP response headers. When downloading updates, the application constructs local file paths using values derived from HTTP headers without validation. These values are passed directly to filepath.Join, allowing path traversal sequences (../) to be resolved and enabling files to be written outside the intended update staging directory. An attacker who can influence update responses can exploit this flaw to write arbitrary executables to attacker‑chosen locations accessible to the current user, including the Windows Startup directory. This allows execution of arbitrary executables. Critically, when chained with CVE‑2026‑42248 (Missing Signature Verification for Updates), an attacker can deliver malicious payloads that are written to sensitive locations and executed automatically. Because Ollama for Windows performs silent automatic updates and executes staged binaries without user interaction, this results in automatic and persistent code execution without user awareness. Maintainers of this project were notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Versions from 0.12.10 to 0.17.5 were tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-42248 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Ollama for Windows does not perform integrity or authenticity verification of downloaded update executables. Unlike other platforms, the Windows implementation of the update verification routine unconditionally returns success so no digital signature or trust validation is performed before staging or executing update payloads, enabling attacker‑supplied executables to be accepted and later executed by the application. Critically, Ollama for Windows performs silent automatic updates, so the malicious payload may be installed automatically without user awareness. Maintainers of this project were notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Versions from 0.12.10 to 0.17.5 were tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable. Severity: 7.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CISA Warns Microsoft Windows Shell 0-click Vulnerability Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical zero-day vulnerability in Microsoft Windows. On April 28, 2026, the agency officially adde ... Read more Published Date: Apr 29, 2026 (22 hours, 49 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-32202
CVE ID :CVE-2026-22745 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is serving static resources from the file system * the application is running on a Windows platform When all the conditions above are met, the attacker can send malicious requests that are slow to resolve and that can keep HTTP connections in use. This can cause a Denial of Service on the application. Severity: 5.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Hugging Face LeRobot Vulnerability Enables Unauthenticated RCE Attacks A critical, currently unpatched remote code execution (RCE) vulnerability has been disclosed in LeRobot, Hugging Face’s popular open-source machine learning framework for real-world robotics. Tracked ... Read more Published Date: Apr 29, 2026 (22 hours, 52 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-25874
CVE ID :CVE-2026-22741 Published : April 29, 2026, 12:16 p.m. | 2 hours, 1 minute ago Description :Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. More precisely, an application can be vulnerable when all the following are true: * the application is using Spring MVC or Spring WebFlux * the application is configuring the resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources.html#page-title with caching enabled * the application adds support for encoded resources resolution * the resource cache must be empty when the attacker has access to the application When all the conditions above are met, the attacker can send malicious requests and poison the resource cache with resources using the wrong encoding. This can cause a denial of service by breaking the front-end application for clients. Severity: 0.0 | NONE Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Critical Chrome Vulnerabilities Enables Remote Code Execution Attacks Google has released a critical security update for its Chrome desktop browser to address 30 security vulnerabilities, including four severe flaws that could enable Remote Code Execution (RCE) attacks. ... Read more Published Date: Apr 29, 2026 (21 hours, 3 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2026-7363 CVE-2026-7361 CVE-2026-7344 CVE-2026-7343 CVE-2026-7333
Pagina 2010 di 3160