CYBERSECURITY INTEL FREE'Dself-hosted CTI

LATEST // SURFACE WEB

Aggregated cybersecurity reporting, advisories and research. 406 matching records.
AUTO-POLL // 2026-08-16 05:25 UTC
SURFACE WEB DARK / DEEP WEB
RESET
2026-08-05 16:00 UTC
Vendor Research
TIER 1

Cisco IOS XE Software Security Hardening Release: August 2026

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single …

AppleVulnerabilities CVE-2026-20267CVE-2026-20268CVE-2026-20269CVE-2026-20270CVE-2026-20271CVE-2026-20272CVE-2026-20273
P30
2026-08-05 16:00 UTC
Vendor Research
TIER 1

Cisco Integrated Management Controller Argument Injection Vulnerabilities

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/c…

Vulnerabilities CVE-2026-20200CVE-2026-20288
P5
2026-08-05 16:00 UTC
Vendor Research
TIER 1

Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewall rules associated with a different user in the system. Cisco has released software updates that add…

Network SecurityVulnerabilities CVE-2026-20028
P5
2026-08-05 16:00 UTC
Vendor Research
TIER 1

Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a s…

Vulnerabilities CVE-2026-20303CVE-2026-20304CVE-2026-20310CVE-2026-20312CVE-2026-20313
P30
2026-08-05 16:00 UTC
Vendor Research
TIER 1

Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive. Cisco has released software updates that address this vulnerability. There ar…

AppleVulnerabilities CVE-2026-20308
P5
2026-08-05 15:48 UTC
Vendor Research
TIER 2

From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

Microsoft Security Blog · Microsoft Security Research and Srinivasan Govindarajan · indexed 2026-08-16 02:02 UTC

A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving defenders new hunting opportunities. The post From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide appeared first on Microsoft Security Blog.

AppleMalwareMicrosoft
P0
2026-08-05 14:37 UTC
Vendor Research
TIER 1

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

Cisco Security Advisories · indexed 2026-08-16 02:02 UTC

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. Note: If t…

Network SecurityVulnerabilities CVE-2026-20079
P15
2026-08-05 12:45 UTC
Vendor Research
TIER 2

Tenable Hexa AI: Automating exposure remediation with agentic routines

Tenable Blog · Ziga Cerkovnik · indexed 2026-08-16 02:02 UTC

Discover how Tenable Hexa AI closes the gap between exposure management and endpoint patching using intent-driven routines, smart guardrails, and human approval.Key takeawaysThe problem: A slow handoff between security workflows creates a days-long remediation gap. The solution: Tenable Hexa AI bridges this gap using intent-driven Routines that automate scoping, deployment, and verification across integrated platforms like Jamf. Safety and control: Autonomy is governed by the harness built into Tenable One, ensuring the AI operates strictly within defined user permissions and guardrails.Find …

AppleVulnerabilities
P25
2026-08-05 08:00 UTC
Security Journalism
TIER 3

Angola's Largest Telco Breached Hours Before IPO

Dark Reading · Robert Lemos · indexed 2026-08-16 02:02 UTC

Unitel, Angola's dominant mobile operator, continues to recover from a cyberattack that caused outages the day of the government-owned telco's public offering.

P0
2026-08-04 23:46 UTC
Vendor Research
TIER 2

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

Microsoft Security Blog · Microsoft Security Research, Ravikant Tiwari, Sagar Patil and Suriyaraj Natarajan · indexed 2026-08-16 02:02 UTC

A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and practical guidance for detection, hunting, and remediation. The post ChainDrop supply chain compromise: Anatomy of a self-propagating worm appeared first on Microsoft Security Blog.

Microsoft
P0
2026-08-04 17:54 UTC
Vendor Research
TIER 2

128 Seconds to disruption: Microsoft Defender stops ransomware at QNET

Microsoft Security Blog · Microsoft Security Research, David Shiran and Ayelet Artzi · indexed 2026-08-16 02:02 UTC

Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET appeared first on Microsoft Security Blog.

MicrosoftRansomware
P15
2026-08-04 17:22 UTC
Vendor Research
TIER 2

Spring 2026 PCI DSS and PCI 3DS compliance packages for AWS now available

AWS Security Blog · Will Black · indexed 2026-08-16 02:02 UTC

Amazon Web Services (AWS) is pleased to announce the successful completion of our Payment Card Industry (PCI) Data Security Standard (DSS) and Three Domain Secure (3DS) certifications. As part of this renewal, we have expanded the scope to include three additional AWS services and one additional AWS Region: Newly added AWS services: Amazon Bedrock AgentCore […]

Cloud Security
P0
2026-08-04 13:00 UTC
Vendor Research
TIER 2

The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software

Palo Alto Networks Unit 42 · Xu Zou · indexed 2026-08-16 02:02 UTC

Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain. The post The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software appeared first on Unit 42.

Vulnerabilities
P25
2026-08-04 12:50 UTC
Vendor Research
TIER 2

Almost Half of Malware Samples Communicate Direct to IP

Palo Alto Networks Unit 42 · Shu Wang and Daiping Liu · indexed 2026-08-16 02:02 UTC

Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42.

Malware
P0
2026-08-04 11:11 UTC
Vendor Research
TIER 2

CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild

Rapid7 · Rapid7 · indexed 2026-08-16 02:02 UTC

OverviewOn August 2, 2026, N-able published a security advisory for CVE-2026-18577, an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication and obtain administrative control of vulnerable N-central servers in affected deployments.N-able N-central is a widely deployed Remote Monitoring and Management (RMM) platform used by managed service providers (MSPs) and enterpri…

DFIRMicrosoftThreat IntelligenceVulnerabilities CVE-2026-18556CVE-2026-18577
P65
2026-08-03 20:42 UTC
Security Journalism
TIER 3

New Tool Traces AI Videos Back to Their Source

Dark Reading · Arielle Waldman · indexed 2026-08-16 02:02 UTC

Researchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.

P0
2026-08-03 17:11 UTC
Vendor Research
TIER 2

Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)

Rapid7 · Jonah Burgess · indexed 2026-08-16 02:02 UTC

OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are < 7.2.3.2, >= 8.0, < 8.0.5.1, and >= 8.1, < 8.1.3.1. Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips.Our Emergent Threat Response blog covers the affected versions, mitigation guidance, and current exploitation…

LinuxMalwareVulnerabilities CVE-2026-66066
P20
2026-08-03 15:00 UTC
Government
TIER 1

Cyber Brief 26-08 - July 2026

CERT-EU Threat Intelligence · indexed 2026-08-16 02:02 UTC

Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.

P0
2026-08-03 14:48 UTC
Vendor Research
TIER 2

Metasploit Pro 5.1 Released

Rapid7 · The Metasploit Team · indexed 2026-08-16 02:02 UTC

Today marks the release of Metasploit Pro 5.1 - building upon the foundation laid in 5.0, adding new evasion primitives for HTTP Meterpreter payloads, support for tracking service hierarchies, a deeper and more interactive Network Topology view, and continuing our commitment to a modern, consistent UI. This release is powered by Metasploit Framework 6.5.Malleable C2 ProfilesOne of the most requested capabilities in modern red-team engagements is the ability to blend Meterpreter's network traffic into legitimate-looking patterns. Metasploit Pro 5.1 brings full Malleable C2 profile support, pow…

LinuxMicrosoftVulnerabilities
P0
2026-08-03 14:00 UTC
Security Journalism
TIER 3

Is There Really a Fix for CISO Fatigue?

Dark Reading · Dirk Schrader · indexed 2026-08-16 02:02 UTC

Accountability without any real authority is driving CISO burnout, and organizations need to take notice.

P0
2026-08-03 10:00 UTC
Vendor Research
TIER 2

Pass the Passkey: A Novel Attack Surface in Passwordless Authentication

Palo Alto Networks Unit 42 · Arie Olshtein · indexed 2026-08-16 02:02 UTC

Explore how passkey implementation gaps undermine security when relying parties fail to validate the User Verified flag, reducing MFA to a single factor. The post Pass the Passkey: A Novel Attack Surface in Passwordless Authentication appeared first on Unit 42.

P0
56789