LIVE FEED
4274 events · 13 sources · newest first
Events in view
4274
all sources
Critical
1864
severity
Active sources
13
collectors
Last sync
2026-08-31 00:00
UTC
All sources
NVD CVE · 1814CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-08-26
News
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations ↗
◈ 2 sources · orig. thehackernews.com
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive...
chinacritical-infrastructuredata-theftdisruptiondojfbihacking-platformsnanjings-xinjiuwei-networks-technology-company
2026-08-26
News
The DOJ said it disrupted Chinese state-backed tools used to scan, infect and exploit IoT devices for attacks on federal agencies and multiple industries.
chinese-hacking-toolscyber-operationscyber-threatsdoj-enforcementfederal-agenciesfederal-reservesincident-responseiots-security
2026-08-26
News
Researchers said they identified servers and domains associated with several countries in Europe and the Middle East, potentially pointing to a broader targeting profile for an Iranian hacking group.
adversaries-infrastructurescyber-attackscyber-espionagecyber-intelligencecyber-operationscyber-threatsdomain-monitoringeuropean-cybersecurity
2026-08-26
News
<p><a href="https://breakingdefense.com/2026/08/shifted-our-whole-mentality-army-long-range-ew-system-to-go-into-production-in-2027/"><img width="799" height="449"...
armybreaking-defensedefense-technologydodelectromagnetic-warfareelectronic-warfarelong-range-systemsnews
2026-08-26
News
<p><a href="https://breakingdefense.com/2026/08/spain-signs-off-on-6-3-billion-budget-for-joint-mrtt-buy-with-poland/"><img width="1024" height="577"...
a330-mrttaircraftbudgetdefensedefense-acquisitionsdefense-contractingdefense-industrydefense-spending
2026-08-26
News
<p>Shasta County registrar Clint Curtis told CyberScoop he needs Peters to help manage the county’s 2026 elections and he’s not concerned about her past conviction.</p>
<p>The post <a...
2026-electionbackground-checksclint-curtisconsultantconvictioncyberscoopelections-securitynews
2026-08-26
News
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing ↗
◈ 2 sources · orig. CISA advisory
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it...
cisacompromisecritical-infrastructurecybersecuritydomain-compromiseincident-responsenewsred-team
2026-08-26
News
<p>The Israeli firm’s new C-TEK product triages data from mobile phones, SIM cards, computers, drones and other portable media.</p>
<p>The post <a...
c-tekcellebritecomputerdata-extractiondefense-industrydefense-scoopdigital-evidencedrone
2026-08-26
News
<p>The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks.</p>
<p>The post <a...
cisacritical-infrastructurecyberattackcybersecurityincident-responseinternet-exposureiran-linked-hackersnews
2026-08-26
News
Hackers now exploit critical Gitea flaw in code injection attacks ↗
◈ 2 sources · orig. CISA KEV
Attackers are now exploiting a critical-severity vulnerability in the Gitea self-hosted Git service, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]
cisacode-injectioncritical-vulnerabilitygit-servicegiteahackernewssecurity-alert
2026-08-26
News
Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload ↗
◈ 3 sources · orig. CISA advisory
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea.
The vulnerability in question is...
actives-exploitationsarbitrary-code-executioncisacritical-vulnerabilitycve-2026-60004giteamalwarenews
2026-08-26
News
<p>Americans for Responsible Innovation (ARI) released a report warning that the growing integration of artificial intelligence across health...</p>
<p>The post <a...
aiamericanaricritical-infrastructurecyber-risksdesignationhealthcarenews
2026-08-26
News
<p>Cybersecurity defenses that operate as isolated functions can leave organizations with costly blind spots even as spending on...</p>
<p>The post <a...
ai-cyberattacksai-threatattackers-breakout-timecyber-threat-landscapecyber-threatscybersecurity-blind-spotcybersecurity-defensecybersecurity-fragmentation
2026-08-26
News
<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published an advisory based on red team assessments at two...</p>
<p>The post <a...
advisorycisacritical-infrastructurecybersecurityincident-responsenewsot-securitiesred-team-assessment
2026-08-26
News
<p>Gurobi Optimization, vendor of decision intelligence technology, and Carahsoft Technology Corp. announced a partnership on Tuesday. Under the...</p>
<p>The post <a...
carahsoftdecisions-intelligencegurobinewsoptimizationpartnershippublic-sectortechnology-access
2026-08-26
News
CISA Warns of Exploited Gitea Vulnerability ↗
◈ 3 sources · orig. CISA advisory
<p>CVE-2026-60004 is a remote code execution vulnerability patched by Gitea developers in late July with the release of version 1.27.1.</p>
<p>The post <a...
cisacve-2026-60004giteanewspatchremote-code-executionsecurity-weekvulnerability
2026-08-26
NVD CVE
CVE-2026-75896: Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technolog
CRITICAL
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute Liderahenk allows Try Common or Default Usernames and Passwords.
This issue affects Liderahenk: before 3.5.5.
authentication-vulnerabilitybefore-3-5-5credentials-vulnerabilitycve-2026-75896default-credentialsdefault-usernamehard-coded-credentialsliderahenk
2026-08-26
CISA KEV
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
HIGH
◈ 2 sources · orig. NVD CVE
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL)...
ajaxnetajaxnet-professionalajaxprocisa-kevcve-2021-23758deserializationendlife
2026-08-26
NVD CVE
CVE-2026-80428: ILIAS deserialises stored session data for an unauthenticated caller. The Shibbo
CRITICAL
ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components/ILIAS/AuthShibboleth/resources/shib_logout.php runs in a context that ilInitialisation exempts...
applications-vulnerabilitiesauthentication-bypasscode-executioncve-2026-80428deserializationfile-writeilialtus-authentication
2026-08-26
CISA advisory
<p>Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable...
ai-enabled-vulnerability-discoverybinding-operational-directive-26-04cisa-advisorycisa-vulnerabilities-reviewscyber-threats-actorsdesignexploitable-vulnerabilitiesknown-exploit-vulnerability-catalog
2026-08-26
NVD CVE
CVE-2026-81032: NebulaGraph exposes its runtime configuration over an unauthenticated HTTP servi
CRITICAL
NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service defined in src/webservice/WebService.cpp, whose bind address defaults to all interfaces, and...
certificate-exposurecve-2026-81032daemongflagincident-responsenebulagraphnvd-cvepassword-file-exposure
2026-08-26
CISA KEV
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
authenticate-usercisa-kevcves-2015-3246denialfile-corruptionlibuserlocal-userspasswd
2026-08-26
CISA KEV
Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable...
abrtcisa-kevcve-2015-5287discontinue-useendfilelifelocal-users
2026-08-26
CISA KEV
Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
HIGH
◈ 2 sources · orig. NVD CVE
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
boundcisa-kevcitrixcve-2026-8452denialimproper-restrictioninfrastructures-vulnerabilitiesmemory-buffer
2026-08-26
NIST
<h4>Summary</h4>
<p>Following the publication of draft revision <i>IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements, </i>NIST <a...
cybersecurity-frameworks-csf-2-0iot-devices-cybersecurityiot-guidelineiot-sub-systemsiot-threat-landscapeiot-use-caseiots-capabilityiots-deployment
2026-08-26
NVD CVE
CVE-2026-80203: The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope
CRITICAL
The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management endpoints. The check uses...
2faapi-keyapi-key-scopeauthenticationauthorizationcve-2026-80203gravgrav-plugin-api
2026-08-26
NVD CVE
CVE-2026-18431: The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versi
CRITICAL
The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16. This is...
arbitrary-file-writeauthorization-weaknessesavadas-themecve-2026-18431fusion-builderinput-validation-weaknessesnvd-cvephp-execution
2026-08-26
CISA KEV
Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
bound-writecisa-kevcve-2022-0995denialexploitkernel-buglinux-kernellocal-privileges-escalation
2026-08-26
CISA KEV
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
attackcisa-kevcve-2019-1068cybersecuritydatabasedefenseexploitincident-response
2026-08-26
CISA advisory
<p>CISA has added six new vulnerabilities to its <a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active...
bod-26-04cisacisa-advisorycitrixcve-2015-5287cve-2019-1068cve-2021-23758cve-2022-0995
2026-08-26
NVD CVE
CVE-2026-19632: The TranslatePress – Translate Multilingual sites with AI Translation plugin for
CRITICAL
The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.3.1 via the...
administrator-accounts-takeoverajax-actionautomatic-strings-savingcve-2026-19632login-parameternvd-cvepassword-resetplaintext-reset-keys
2026-08-25
News
<p>The point, according to the NETCOM commander, was so that “theaters in crisis can focus on the crisis, and theaters outside of that crisis can focus on delivering the network and the services.”</p>
<p>The post <a...
armies-netcomcommands-and-controlcrisis-managementdefense-scoopiran-warmilitary-networksnetwork-operationnetwork-service
2026-08-25
News
Moving ECMA away from the Army's chief information officer aims to more closely integrate cloud management and cyber defenses.
armychief-information-officerscloud-managementcloud-securitycmmccyber-commandcyber-defensecybersecurity
2026-08-25
News
CISA's new guide will help agencies meet a November deadline for submitting cyber logging plans that need to prioritize quality, instead of just quantity.
cisacompliancecyber-data-loggingcyber-incidents-responsescyber-loggingcyber-securitydata-loggingdeadline
2026-08-25
News
<p>A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience.</p>
<p>The post <a...
cyber-attackscyber-intelligencecyberscoopcybersecuritydata-breachesdata-theftextortionextortion-playbook
2026-08-25
News
<p>DHS’s inspector general found that the agency spent millions to develop inadequate tools amid a shift toward immigration enforcement and away from drug investigations. </p>
<p>The post <a...
agencies-spendingcisacmmcdfardhdoddrug-investigationfedramp
2026-08-25
News
Interpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe.
argentinaarrestblack-axecrimecybercrimeinternational-law-enforcementinterpolmoney-laundering
2026-08-25
News
<p>The Air Force is moving its fragmented scheduling, training and readiness systems into a single enterprise platform known as the Aerospace Readiness Enterprise System.</p>
<p>The post <a...
aerospace-readiness-enterprise-systemsai-enabled-platformair-forceair-force-awardartificial-intelligencedefense-scoopdefense-technologyenterprise-architecture
2026-08-25
News
<p>The General Services Administration is conducting market research to boost its fraud protection and bot detection as fraud attempts grow in “sophistication and volume.”</p>
<p>The post <a...
ai-agentbot-detectiondevice-fingerprintingfedscoopfraudgeneral-services-administrationgsamarket-research
2026-08-25
News
<p>SAA-LT is billed as a next-generation “standoff delivery system” for anti-submarine warfare.</p>
<p>The post <a...
airs-launched-torpedoanti-submarines-warfaredefense-innovationdefense-programsdefense-scoopmilitary-technologynaval-weaponrynavy