LIVE FEED
4274 events · 13 sources · newest first
Events in view
4274
all sources
Critical
1864
severity
Active sources
13
collectors
Last sync
2026-08-31 00:00
UTC
All sources
NVD CVE · 1814CISA KEV · 1686News · 444CISA advisory · 124eCFR · 98DoD CIO CMMC · 21DC3 DCISE · 19DOJ FCA · 16NIST · 15Fed. Register · 14DCSA · 11Cyber AB docs · 10OIRA · 2
2026-08-21
News
<p>Lastwall, vendor of identity security and quantum resilience solutions, announced it has achieved Cybersecurity Maturity Model Certification (CMMC)...</p>
<p>The post <a...
certificationcmmc-certificationcmmc-level-2cuicybersecuritydefense-supply-chainfciidentity-security
2026-08-21
News
CyberSheath report finds growing credibility gap in CMMC compliance as contractor confidence falls ↗
<p>A new CyberSheath report identified a troubling credibility gap that has emerged within the Pentagon’s cybersecurity compliance framework....</p>
<p>The post <a...
cmmccompliancecompliance-frameworkcontractors-confidencecredibility-gapscybersecuritycybersecurity-frameworkscybersecurity-report
2026-08-21
News
<p>The Operational Technology Cybersecurity Coalition (OTCC) announced that SANS Institute (SANS) has joined the coalition as its newest...</p>
<p>The post <a...
coalitioncritical-infrastructurecybersecuritycybersecurity-workforce-developmentinfrastructurenewsoperational-technologiesotcc
2026-08-21
NVD CVE
CVE-2026-77776: Headroom's LLM proxy derives the memory owner from the x-headroom-user-id reques
CRITICAL
Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and...
allowlistauthenticationauthorizationcve-2026-77776datum-planedocker-composesheaders-injectionidentity-management
2026-08-21
CISA KEV
Microsoft Entra ID formerly known as Azure Active Directory contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.
code-executioncve-2026-69836deserializationentra-ididentity-managementmicrosoftmicrosofts-entrasnetworks-attacks
2026-08-21
NVD CVE
CVE-2026-77683: A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this
CRITICAL
A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method=SET§ion=ntp_timezone. The manipulation of the argument timestr...
argumentcf-n1-scgi-bincomfastcommand-injectioncve-2026-77683exploitfile-system
2026-08-21
NIST
<p>NIST Internal Report (IR) 8613 ipd (initial public draft), <i>Multi-Cloud Architecture Challenges</i>, identifies, categorizes, and analyzes the security and compliance challenges that are unique to or...
atoauthorization-to-operatecloud-orchestrationcloud-securitycloud-silosclouds-nativescomplianceconfigurations-and-change-management
2026-08-21
NVD CVE
CVE-2026-77086: SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar insta
CRITICAL
SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to perform path traversal via directory traversal sequences. Attackers...
arbitrary-file-writeauthenticate-administratorauthenticates-accessesbazaarcode-executioncve-2026-77086directories-deletiondirectories-traversal
2026-08-21
CISA KEV
Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary...
arbitrary-command-executioncisa-kevcollaboration-suitecve-2026-73570email-serveros-command-injectionsecurity-vulnerabilitysmtp
2026-08-20
News
The secretive satellite agency’s work with prime contractors to address supply chain issues could inform broader federal efforts to address supplier risks.
acquisitions-policiescontractorfederal-effortsfederal-newsnetworknewsnrosatellitesuppliers-risks
2026-08-20
News
<p>The initiative marks the unit’s latest move under Owen West’s leadership to rapidly supply measurable combat power to the joint force.</p>
<p>The post <a...
bridges-programscombat-powerscommercial-technologiesdefense-acquisitionsdefense-industrydefense-scoopdiufrontline-technologies
2026-08-20
News
Bill James, a former deputy assistant secretary for DevOps at the VA, calls on agency leadership to appoint a permanent CISO and address cyber risks.
agencies-leadershipagency-cisoscisocompliancecyber-riskscybersecuritycybersecurity-leadershipdevop
2026-08-20
News
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script...
append-onlies-vecarrayrefbuild-scriptscompromised-accountscrate-iocveincident-responseinternment
2026-08-20
News
<p><a href="https://breakingdefense.com/2026/08/army-network-needs-digital-twin-for-training-testing-cybersecurity-netcom-chief/"><img width="798" height="449"...
aiai-modelarmy-network-commandcybersecuritydigital-twingaps-analysesmilitary-networksnetcom
2026-08-20
News
"knowing that that these things are happening within minutes... and at a larger, greater capacity, we don't really have a choice," said Glen Deskin.
aiautomated-threatscyber-attackscyber-defensecyber-operationscyber-resiliencecyber-securitycybersecurity
2026-08-20
News
<p>The answer is to modernize accountability through an enterprise model that combines a formalized independent assessment, continuous external monitoring, and shared remediation support where small suppliers cannot...
accountabilityassessmentcmmccompliancecontinuous-monitoringdefense-industrial-basedefense-scoopenterprise-model
2026-08-20
News
<p>Kyle Spitze led an offshoot of the violent extremist collective and victimized dozens of girls, coercing them to degrade themselves under threats of doxing and swatting.</p>
<p>The post <a...
coercioncybercrimedoxingextremists-collectivenewsprison-sentenceprison-termsentencing
2026-08-20
News
<p><a href="https://breakingdefense.com/2026/08/drone-companies-trump-admin-leaders-meet-for-first-white-house-done-dominance-meeting/"><img width="1024" height="577"...
cavalrydefense-industrydefense-researchdronedrone-dominancedrone-sufficiencydrones-parityemil-michael
2026-08-20
News
<p><a href="https://breakingdefense.com/2026/08/no-new-starts-no-problem-armys-plan-to-get-new-ew-capability-in-the-hands-of-soldiers/"><img width="1024" height="574"...
acquisitionarmycapabilitycommercial-off-shelfcommercial-systemsdefenseelectronic-capabilitieselectronic-warfare
2026-08-20
News
<p>A new Government Accountability Office report highlights issues with the Army's Next Generation Command and Control (NGC2) project.</p>
<p>The post <a...
armybattlefield-networksdefense-scoopga-reportgovernment-accountability-officesinformation-gapsnetworks-modernizationnews
2026-08-20
News
The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts.
The activity is targeting...
active-threatai-generate-exploit-scriptsai-generate-scriptscapabilities-developmentcritical-infrastructureincident-responselegitimate-monitoring-toolnews
2026-08-20
News
Uncle Sam is looking for a few good hackers. Time for a quick double-click on something that may have slipped past you in all the news. The Trump administration just opened the door to a new kind of cyber warfare:...
cyber-operationscyber-vigilantecyber-warfarecybersecurityexecutives-ordersgovernment-policynational-defensenational-security
2026-08-20
News
<p>The Combating Organized Retail Crime Act has won a big House vote and could be on the fast track in the Senate — and supporters say it could help fight cybercrime. </p>
<p>The post <a...
combating-organized-retail-crime-actcorcacybercrimecyberscoophouse-voteicenewsretail-theft
2026-08-20
News
<p>The designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security.</p>
<p>The post <a...
ai-critical-infrastructurecisas-reportcyberscoopeconomic-securityfederal-servicesnational-securitynewspolicymaker
2026-08-20
News
<p>Palantir, Microsoft, Nvidia and other tech giants have major issues with the potential exclusion of open-source AI, “unbiased AI principles” and more.</p>
<p>The post <a...
ai-regulationcisacmmcdodfederal-acquisitionfedrampgsa-ai-clauseindustry-concern
2026-08-20
News
<p>“Each and every day, we sit down as a group, we figure out the guardrails we're going to apply to these agents, [and] we ask ourselves: Is it risk that a human should be answering, or is it risk that an agent can...
ai-agentai-riskai-task-forcearmyartificial-intelligenceautonomous-agentscyber-chiefscyber-hunting
2026-08-20
NVD CVE
CVE-2026-66788: A flaw was found in Lighthouse. A remote attacker, by compromising a spoke clust
CRITICAL
A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for resource injection is derived from an attacker-controlled label or...
attackers-controlledclustercve-2026-66788endpoints-sliceskubes-systemslighthousenamespacenvd-cve
2026-08-20
NVD CVE
CVE-2026-18832: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap-based buffer overflow.
2026-08-20
NVD CVE
CVE-2026-18670: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to c
HIGH
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service and potentially disclose sensitive information due to an integer underflow.
2026-08-20
NVD CVE
CVE-2026-17136: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to e
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability.
aixcve-2026-17136format-string-vulnerabilityibmibm-aixibm-powervmnvd-cvepowervm
2026-08-20
NVD CVE
CVE-2026-69400: Improper limitation of a pathname to a restricted directory ('path traversal') i
CRITICAL
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
attackerazureazure-logic-appscve-2026-69400improper-limitationnetwork-securitynvd-cvepath-traversal
2026-08-20
NVD CVE
CVE-2026-69555: Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate
CRITICAL
Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
attackerazure-arcscve-2026-69555elevate-privilegeincorrect-authorizationmicrosoftnetwork-securitynvd-cve
2026-08-20
NVD CVE
CVE-2026-68789: Improper neutralization of special elements used in an sql command ('sql injecti
CRITICAL
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
attackerauthorize-attackersazure-sql-databasecve-2026-68789database-securityelevate-privilegeimproper-neutralizationnetwork
2026-08-20
NVD CVE
CVE-2026-69836: Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized a
CRITICAL
◈ 2 sources · orig. NVD CVE
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
code-executioncve-2026-69836deserializationentra-ididentity-managementmicrosoftmicrosofts-entrasnetworks-attacks
2026-08-20
NVD CVE
CVE-2026-69851: Server-side request forgery (ssrf) in Azure Active Directory allows an authorize
CRITICAL
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
attackerauthorized-accessazureazure-active-directorycloud-securitycve-2026-69851identity-managementmicrosoft
2026-08-20
NVD CVE
CVE-2026-65770: Improper neutralization of argument delimiters in a command ('argument injection
CRITICAL
Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network.
apache-cassandraargument-injectionazureazure-managed-instancecisacmmccode-executioncve-2026-65770
2026-08-20
NVD CVE
CVE-2026-63509: Relative path traversal in Microsoft Fabric allows an authorized attacker to ele
CRITICAL
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
authorize-attackerscve-2026-63509elevate-privilegefabricmicrosoftnetwork-securitynvd-cveprivileges-escalation
2026-08-20
NVD CVE
CVE-2026-65801: Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauth
CRITICAL
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
cve-2026-65801exchange-onlinemicrosoftmicrosoft-exchange-onlinenetwork-securitynvd-cveprivileges-escalationservers-sides-requests-forgery
2026-08-20
NVD CVE
CVE-2026-65816: Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorize
CRITICAL
Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
azureazure-arcscve-2026-65816incident-responsemicrosoftnetwork-securitynvd-cveprivileges-escalation
2026-08-20
NVD CVE
CVE-2026-18835: IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated
CRITICAL
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
aixauthenticationcommand-injectioncve-2026-18835ibmnvd-cveoperating-systemspowervm