LIVE FEED
4274 events · 13 sources · newest first
Events in view
4274
all sources
Critical
1864
severity
Active sources
13
collectors
Last sync
2026-08-31 00:00
UTC
All sources
NVD CVE · 1814CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-08-25
CISA KEV
Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the...
cisa-kevcode-injectioncve-2026-60004diffpatch-apiexecutable-git-hookgit-hookgiteamalicious-patches
2026-08-25
NVD CVE
CVE-2026-78477: The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versio
CRITICAL
The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
administrator-privilegescve-2026-78477jawn-themenvd-cveprivileges-escalationsecurity-bulletinthemes-vulnerabilityunauthenticated-attacks
2026-08-25
NVD CVE
CVE-2026-63586: The web-based management interface uses a modified uhttpd server with CGI shell
CRITICAL
The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a...
arbitrary-command-executioncgicommand-injectioncooeys-clubcve-2026-63586http-basic-authenticationnvd-cveroot-privileges-escalation
2026-08-25
NVD CVE
CVE-2026-78570: The Total Donations plugin for WordPress is vulnerable to Privilege Escalation i
CRITICAL
The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to elevate their privileges to that of...
cve-2026-78570nvd-cveplugins-securityplugins-vulnerabilitiesprivileges-escalationsecurity-vulnerabilitytotals-donationsunauthenticated-attacks
2026-08-25
CISA advisory
A Tale of Two SOCs: Insights From Two Red Team Assessments ↗
◈ 2 sources · orig. CISA advisory
<h2><strong>Advisory at a Glance</strong></h2>
<table>
<tbody>
<tr>
<th>Title</th>
<td>A Tale of Two SOCs: Insights From Two Red Team Assessments</td>
</tr>
<tr>
<th>Original Publication </th>
<td><strong>August...
active-directorycisa-advisoriescisa-advisorycloud-securityconditional-accessescredentials-theftcritical-infrastructuredetection-tool
2026-08-25
CISA advisory
<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-04.json"><strong>View CSAF</strong></a></p>
<h2>Summary</h2>
<p><strong>Successful exploitation of this vulnerability...
cisacisa-advisorycommercial-facilitycontrol-systemcve-2026-18965cwe-862denialhigh-severity
2026-08-25
NVD CVE
CVE-2026-56710: Grav Login plugin versions before 1.0.16 fail to validate the target account's p
CRITICAL
Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAction unlock handler. An attacker with api.users.write permission can clear login lockout...
accounts-securitiesadmin-super-accountapi-user-writeauthenticationbrute-force-protectioncve-2026-56710gravgrav-login-plugin
2026-08-25
NVD CVE
CVE-2026-56705: Adminer before 5.4.3 fails to sanitize the server field before constructing a PD
CRITICAL
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn...
adminercode-executioncve-2026-56705nvd-cveodbcpdophpremote-code-execution
2026-08-25
NVD CVE
CVE-2026-78676: GitPython before 3.1.59 fails to safely re-serialize multi-line git-config value
CRITICAL
GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config...
arbitrary-code-executioncode-injectionconfigs-corruptionscve-2026-78676directivegitgit-configgitpython
2026-08-25
NVD CVE
CVE-2026-78683: NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deseria
CRITICAL
NLTK before 3.10.0 (affected versions <=3.9.4) contains an unsafe pickle deserialization vulnerability in the TransitionParser.parse() method (nltk/parse/transitionparser.py). The method calls pickle_load() with the...
arbitrary-code-executioncve-2026-78683deserializations-attacknltknvd-cvepickle-deserializationpickle-gadgetpython
2026-08-25
NVD CVE
CVE-2026-78568: The Total Donations plugin for WordPress is vulnerable to SQL Injection in all v
CRITICAL
The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on...
cve-2026-78568database-securitydatum-exfiltrationinsufficient-escapingnvd-cveplugins-vulnerabilitiesquery-preparationsql-injection
2026-08-24
News
The U.S. sanctioned several Iranian nationals for cyberattacks on critical infrastructure just days after reports emerged of a cyber intrusion on a small power plant in the United Kingdom.
critical-infrastructurecritical-infrastructure-attackscyber-intrusioncyber-intrusion-ukcyberattackcybersecurityinfrastructure-attacksiran
2026-08-24
News
<p>The 6-3 decision dismisses one lawsuit brought by states, saying they have no standing to sue because the disputed sections “neither requires nor forbids anything of anyone outside the executive...
administrative-lawballotelections-securityexecutive-branchinjunctionlitigationmailnews
2026-08-24
News
One year in, America’s counter-drone task force still has ‘a ton of work to do’ ↗
◈ 2 sources · orig. defensescoop.com
<p>JIATF-401 leaders met to discuss inroads made and what’s next as pressure mounts to mitigate domestic UAS threats.</p>
<p>The post <a...
counter-dronecounter-uadefense-scoopdefense-task-forcedomestic-securitydomestic-threatjiatfjiatf-401
2026-08-24
News
One year in, America’s counter-drone task force still has ‘a ton of work to do’ ↗
◈ 2 sources · orig. defensescoop.com
<p>JIATF-401 leaders met to discuss inroads made and what’s next as pressure mounts to mitigate domestic UAS threats.</p>
<p>The post <a...
counter-dronecounter-uadefense-scoopdefense-task-forcedomestic-securitydomestic-threatjiatfjiatf-401
2026-08-24
News
Exploited Zimbra Flaw Highlights Shrinking Window to Patch ↗
◈ 2 sources · orig. bleepingcomputer.com
CISA has issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications.
agencycisacommunicationcve-2026-73570deadlinefull-takeovernewspatch
2026-08-24
News
<p>Corcos will now lead GSA’s Technology Transformation Services, and help oversee the Federal Acquisition Service and Login-dot-gov, in addition to serving as Treasury’s top IT official.</p>
<p>The post <a...
agencies-mergersagencies-portfoliosagency-appointmentciodoefederal-acquisition-servicesfederal-agencies-leadershipfedscoop
2026-08-24
News
<p>Andrew Magliochetti has been appointed deputy assistant secretary of the Navy for the defense industrial base.</p>
<p>The post <a...
cmmcdefense-industrial-basedefense-scoopdefense-sourcingdeputy-assistant-secretarydibs-officedodfedramp
2026-08-24
News
GSA is updating its Federal Identity, Credential and Access Management architecture as Treasury launches a new task force for the financial sector.
access-managementarchitecturecredentials-managementcybersecurityfederal-agenciesfederal-agencies-initiativesfederal-identity-credentials-and-access-managementfinancial-sector
2026-08-24
News
The legislation would mandate that high-risk social media platforms such as Instagram, TikTok, Snapchat and Facebook take “reasonable steps” to ensure users are over age 16 by using tools like facial age estimation,...
age-verificationchilddigital-idfacebookfacial-age-estimationhigh-risk-platforminstagramlegislation
2026-08-24
News
<p>The lawmakers pushed Fed Chair Kevin Warsh to include U.S. workforce perspectives on a panel that currently features three individuals with “direct financial ties to the AI industry.”</p>
<p>The post <a...
ai-industryai-industry-tiesai-policyai-regulationai-task-forcedemocratfederal-agenciesfederal-reserve-chairs
2026-08-24
News
The question is no longer simply whether our data is secure. It is whether it is built to remain secure, writes Darren Guccione, CEO of Keeper Security.
cmmccompliancecybersecuritydata-securitydesigndodfedrampincident-response
2026-08-24
News
<p><a href="https://breakingdefense.com/2026/08/navy-reveals-new-long-range-air-to-air-missile-dubbed-malice/"><img width="1024" height="577"...
4th-generation-aircraft5th-generation-aircraft6th-generation-aircraftair-to-air-missileaircraft-platformsbreaking-defensedefense-industrylong-range-missiles
2026-08-24
News
<p>It’s a follow-up to an indictment the Justice Department unsealed last week against people affiliated with the Mabna Institute.</p>
<p>The post <a...
cyber-attackscyber-intelligencecyber-operationscyber-sanctionscyber-threatscyberscoopeconomic-ddaysforeign-threat
2026-08-24
News
<p>Under the bill, FERC would consider cyber threats from quantum computers and post-quantum cryptography in its reliability standards for the energy sector. </p>
<p>The post <a...
bipartisan-billcyber-threatscybersecurityelectric-gridenergy-sectorfercnewspost-quantum-cryptography
2026-08-24
News
Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly ↗
A Jersey City resident is facing charges for his alleged role as a money mule for overseas cyberscammers who stole millions from elderly New Yorkers.
arrestchargecyber-scamselderly-fraudelderly-targetsfinancial-fraudfraudjersey-city
2026-08-24
News
<p><a href="https://breakingdefense.com/2026/08/saab-shows-off-loyal-wingman-drone-it-hopes-to-offer-swedish-air-force/"><img width="1024" height="577"...
a3aerospaceair-forceaircraft-developmentsdefense-contractdefense-industrydefense-programsdefense-technology
2026-08-24
News
<p><a href="https://breakingdefense.com/2026/08/army-cyber-created-an-integrated-fire-cell-for-epic-fury/"><img width="1024" height="577"...
army-cyberbreaking-defensecommandercyber-defensecyber-environmentcyber-improvementcyber-operationscyber-skills
2026-08-24
News
<p><a href="https://breakingdefense.com/2026/08/polish-firm-mesko-signs-2b-deal-to-arm-4-nato-nations-with-manpads/"><img width="1024" height="576"...
armamentdefense-contractdefense-dealdefense-industryedirpaeulatvialithuania
2026-08-24
News
<p><a href="https://breakingdefense.com/2026/08/australia-identifies-future-defense-precinct-site-for-aukus-sub-sustainment/"><img width="1024" height="582"...
aukuaustralia-defensedefense-industrydefense-infrastructuredefense-precinct-announcementdefense-precinct-developmentsdefense-precinct-planningdefense-shipbuilding
2026-08-24
News
<p>The event, dubbed GroundBreaker 1, is slated for mid-October at Camp Grafton, North Dakota.</p>
<p>The post <a...
autonomous-vehiclecamp-graftondefense-scoopdefense-technologydodground-vehiclegroundbreaker-1military-demo
2026-08-24
News
<p><a href="https://breakingdefense.com/2026/08/turkish-fnss-unveils-unmanned-amphibious-assault-vehicle/"><img width="1024" height="576"...
amphibious-vehiclesassault-vehicledefense-technologyfnssmarines-assault-vehiclemum-tnaval-forcesnews
2026-08-24
News
<p>Hackers linked to Iran reportedly forced a small British power generator offline for four days in July, marking...</p>
<p>The post <a...
critical-infrastructurecyber-threatscyberattackcybersecurityenergy-sectorenergy-securityindustrial-cyberiran-linked
2026-08-24
News
<p><a href="https://breakingdefense.com/2026/08/pentagon-counter-drone-task-force-preps-shoot-off-for-directed-energy-prototypes/"><img width="1024" height="576"...
armybrigadier-generalscounter-dronedefense-technologydirected-energiesfield-deploymentjiaf-401matt-ross
2026-08-24
News
Hackers infecting Android car systems to build proxy botnet ↗
◈ 2 sources · orig. bleepingcomputer.com
A new strain of malware is being used to infect Android-based car systems, turning the devices into part of a botnet.
androidautomotivebotnetcar-systemchinacybersecurityincident-responsemalware
2026-08-24
News
<p>A new report from the U.S. Government Accountability Office (GAO) has urged the National Aeronautics and Space Administration...</p>
<p>The post <a...
cyber-riskscyber-threatscybersecuritygao-reportgovernment-accountability-officesnasanewsrisk-management
2026-08-24
News
CISA orders urgent patching of actively exploited Zimbra flaw ↗
◈ 2 sources · orig. bleepingcomputer.com
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]
actively-exploitcisacollaboration-suitecybersecuritygovernments-agenciesinfrastructure-securitynewspatch-management
2026-08-24
News
<p>Embracing AI capabilities at a quicker pace is more important than choosing the perfect model.</p>
<p>The post <a href="https://fedscoop.com/enabling-ai-faster-should-be-the-federal-governments-focus/">Enabling AI...
aiartificial-intelligencecmmccompliancecybersecuritydata-protectiondigital-transformationdod
2026-08-24
News
<p>The U.K. National Cyber Security Centre (NCSC) urged organizations deploying agentic artificial intelligence to match the level of...</p>
<p>The post <a...
agentics-aiai-agentai-deploymentai-governanceai-riskartificial-intelligenceautonomous-agentscyber-control
2026-08-24
News
<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) published last week Logging Reference Architecture (LRA) to support Office...</p>
<p>The post <a...
cisacontinuous-monitoringcybersecurityfederal-agenciesinfrastructure-securitylogging-reference-architecturemonitoringnews