News & Sicurezza
Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.
39344 risultati
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped bein ... Read more Published Date: Mar 30, 2026 (1 day, 16 hours ago) Vulnerabilities has been mentioned in this article.
Citrix NetScaler bug exploited in days, may be multiple flaws in a trench coat In-the-wild exploitation of a critical Citrix NetScaler bug has begun less than a week after disclosure, with researchers warning that attackers are already poking and pillaging vulnerable boxes. Last ... Read more Published Date: Mar 30, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-3055
CVE ID :CVE-2026-3321 Published : March 30, 2026, 2:16 p.m. | 1 hour, 37 minutes ago Description :A vulnerability of authorization bypass through user-controlled key in the 'console-survey/api/v1/answer/{EVENTID}/{TIMESTAMP}/' endpoint. Exploiting this vulnerability would allow an unauthenticated attacker to enumerate event IDs and obtain the complete Q&A history. This publicly exposed data may include IDs, private URLs, private messages, internal references, or other sensitive information that should only be exposed to authenticated users. In addition, the leaked content could be exploited to facilitate other malicious activities, such as reconnaissance for lateral movement, exploitation of related systems, or unauthorised access to internal applications referenced in the content of chat messages. Severity: 8.7 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4266 Published : March 30, 2026, 1:16 p.m. | 2 hours, 37 minutes ago Description :An Insecure Deserialization vulnerability in WatchGuard Fireware OS allows an attacker that has obtained write access to the local filesystem through another vulnerability to execute arbitrary code in the context of the portald user.This issue affects Fireware OS: 12.1 through 12.11.8 and 2025.1 through 2026.1.2. Note, this vulnerability does not affect Firebox platforms that do not support the Access Portal feature, including the T-15 and T-35. Severity: 8.4 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID :CVE-2026-4315 Published : March 30, 2026, 1:16 p.m. | 2 hours, 37 minutes ago Description :A Cross-Site Request Forgery (CSRF) vulnerability in the WatchGuard Fireware OS WebUI could allow a remote attacker to trigger a denial-of-service (DoS) condition in the Fireware Web UI by convincing an authenticated administrator into visiting a malicious web page.This issue affects Fireware OS: 11.8 through 11.12.4+541730, 12.0 through 12.11.8, and 2025.1 through 2026.1.2. Severity: 7.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Micropatches released for Arbitrary Registry Key Delete As Local System With Consolidator Scheduled Task (CVE-2025-59512) November 2025 Windows Updates brought a patch for CVE-2025-59512, a local privilege escalation vulnerability in Customer Experience Improvement Program, allowing a low-privileged Windows user to delet ... Read more Published Date: Mar 30, 2026 (1 day, 17 hours ago) Vulnerabilities has been mentioned in this article. CVE-2025-59512 CVE-2025-59201
Critical 9.3 CVSS RCE Vulnerability Hit in OpenTelemetry Java Agent A critical vulnerability has been uncovered in the OpenTelemetry Instrumentation for Java, a popular tool used by developers to gather performance data without changing a single line of application co ... Read more Published Date: Mar 30, 2026 (1 day, 11 hours ago) Vulnerabilities has been mentioned in this article.
Critical Fortinet FortiClient EMS bug under active attack (CVE-2026-21643) A critical SQL injection vulnerability (CVE-2026-21643) in Fortinet FortiClient Endpoint Management Server (EMS), a management server for FortiClient endpoint agents on various platforms, is under act ... Read more Published Date: Mar 30, 2026 (1 day, 12 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33634 CVE-2026-33017 CVE-2026-21643 CVE-2025-53521
CVE ID :CVE-2026-4425 Published : March 30, 2026, 12:16 p.m. | 3 hours, 37 minutes ago Description :Rejected reason: Reserved for EastLink case, but no need for CVE anymore Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Core FTP/SFTP Server 1.2 contains a buffer overflow vulnerability that allows attackers to crash the service by supplying an excessively long string in the User domain field. Attackers can paste a malicious payload containing 7000 bytes of data into the domain configuration to trigger an application crash and deny service.
The 30-Year Glitch: RCE and ARM Exploits Uncovered in libpng Reference Library Security researchers have disclosed two significant vulnerabilities in libpng, the official reference library for Portable Network Graphics (PNG). The flaws, which impact versions spanning decades of ... Read more Published Date: Mar 30, 2026 (1 day, 8 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-33701 CVE-2026-33636 CVE-2026-33416 CVE-2026-2441 CVE-2026-25646
Critical Grafana Vulnerabilities Let Attackers Achieve Remote Code Execution Urgent security updates for Grafana version 12.4.2 address two critical vulnerabilities that could allow attackers to achieve full remote code execution (RCE) and execute denial-of-service (DoS) attac ... Read more Published Date: Mar 30, 2026 (1 day, 5 hours ago) Vulnerabilities has been mentioned in this article. CVE-2026-27880 CVE-2026-27876
Pagina 2577 di 3279