24h | 7d | 30d

Overview

  • Palo Alto Networks
  • Cloud NGFW

13 May 2026
Published
09 Jun 2026
Updated

CVSS v4.0
HIGH (7.8)
EPSS
18.58%

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Statistics

  • 10 Posts
  • 2 Interactions

Last activity: 7 hours ago

Fediverse

Profile picture fallback

: if you are using Palo Alto VPN be aware that CVE-2026-0257 vulnerability allowing attackers to bypass authentication and establish VPN connections is now under active exploitation. Check your logs for IOCs:
👇
thehackernews.com/2026/06/palo

  • 1
  • 1
  • 1
  • 13h ago
Profile picture fallback

Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect portals that allows attackers to establish unauthorized VPN connections. Organizations are urged to patch their systems or apply recommended mitigations immediately to prevent potential network access by threat actors.
securityaffairs.com/193638/sec

  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

En las últimas 24 horas se han detectado explotaciones críticas en PAN-OS GlobalProtect VPN que permiten accesos no autorizados, un malware NarwhalRAT avanzado de APT37 que usa scripts LNK y PowerShell para infiltrarse, y una vulnerabilidad en MacOS que eleva privilegios vía Python, además de técnicas para identificar empresas fantasma y evitar fraudes. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 15/06/26 📆 |====

🔐 ALERTA POR EXPLOTACIÓN ACTIVA DE VULNERABILIDAD EN PAN-OS GLOBALPROTECT VPN

Palo Alto Networks ha detectado una explotación activa de la vulnerabilidad CVE-2026-0257 en su sistema PAN-OS GlobalProtect VPN. Esta falla permite evadir la autenticación estándar y crear sesiones VPN no autorizadas, poniendo en riesgo la red corporativa. Es fundamental actualizar y reforzar las configuraciones de seguridad para evitar accesos indebidos y posibles brechas de datos.

Descubre cómo proteger tu infraestructura ante esta amenaza crítica aquí 👉 djar.co/m4Ku5

🦈 ANÁLISIS PROFUNDO DEL MALWARE NARWHALRAT DE APT37

El grupo APT37 utiliza un sofisticado malware basado en Python llamado NarwhalRAT que se propaga mediante archivos LNK maliciosos que ejecutan scripts de PowerShell y comandos por lotes. Esta campaña combina técnicas avanzadas de phishing temático, comandos C2 en modo sigiloso y persistencia, afectando a múltiples entornos empresariales. Comprender su modus operandi es clave para implementar defensas efectivas.

Consulta el informe completo con indicadores de compromiso y estrategias de mitigación aquí 👉 djar.co/nEUM

🐍 NUEVA VULNERABILIDAD EN MACOS PERMITE ESCALAR PRIVILEGIOS USANDO PYTHON

La vulnerabilidad CVE-2026-28840 detectada en MacOS permite a atacantes con acceso limitado elevar sus privilegios mediante scripts en Python, comprometiendo la integridad del sistema operativo. Este fallo representa un riesgo crítico para usuarios y organizaciones que dependen de entornos Mac, especialmente en sectores sensibles. Actualizar y aplicar parches es urgente para cerrar esta brecha.

Infórmate sobre los detalles técnicos y pasos para proteger tus equipos Mac aquí 👉 djar.co/LMnK

🔍 CÓMO IDENTIFICAR UNA EMPRESA FANTASMA EN 2026: 7 SEÑALES CLAVE

En el entorno empresarial actual, distinguir compañías legítimas de empresas ficticias es vital para evitar fraudes y malas inversiones. Esta guía práctica expone 7 señales basadas en técnicas OSINT y herramientas gratuitas que te ayudarán a verificar la autenticidad de cualquier empresa. Incluye un análisis detallado de un caso real, paso a paso, para que puedas aplicar estos métodos de inmediato.

Aprende a detectar riesgos ocultos y proteger tus decisiones comerciales aquí 👉 djar.co/3pU6

  • 0
  • 0
  • 0
  • 9h ago

Bluesky

Profile picture fallback
Active exploitation of CVE-2026-0257 enables unauthorized access to GlobalProtect portals via authentication bypass, with limited VPN sessions observed and IoCs provided for detection.
  • 0
  • 0
  • 0
  • 13h ago
Profile picture fallback
Palo Alto Networks says CVE-2026-0257 is being actively exploited in PAN-OS GlobalProtect, enabling auth bypass and unauthorized VPN sessions. CISA has added it to KEV. #PANOS #GlobalProtect #CVE20260257
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
Palo Alto Networks has confirmed active exploitation of a critical VPN vulnerability, CVE-2026-0257, allowing unauthorized access. The vulnerability, which affects […]
  • 0
  • 0
  • 0
  • 11h ago
Profile picture fallback
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 #patchmanagement
  • 0
  • 0
  • 0
  • 9h ago

Overview

  • Oracle Corporation
  • PeopleSoft Enterprise PeopleTools

11 Jun 2026
Published
13 Jun 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.72%

Description

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Statistics

  • 6 Posts

Last activity: 2 hours ago

Bluesky

Profile picture fallback
CISAが既知の悪用された脆弱性を1件カタログに追加 CISA Adds One Known Exploited Vulnerability to Catalog #CISA (JUn 12) CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleToolsにおける重要機能の認証欠落の脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
This week in cyber: a PeopleSoft zero-day (CVE-2026-35273) hit 100+ orgs before Oracle's advisory, France's Tchap messenger fell to ONE hijacked account, and Microsoft patched ~200 bugs. Full Top 5 breakdown 👇 commonwealthsentinel.com/cyber-securi...
  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback
References: - Mandiant/GTIG on ShinyHunters/UNC6240 PeopleSoft exploitation: cloud.google.com/blog/topics/... - CISA KEV catalog: www.cisa.gov/sites/defaul... - Oracle CVE-2026-35273 advisory: www.oracle.com/security-ale... - FIRST EPSS CVE-2026-35273: api.first.org/data/v1/epss...
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
CVE-2026-35273 in Oracle PeopleSoft 8.61/8.62 enables unauthenticated remote code execution and is already being exploited against internet-exposed organizations.
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
Weekend CTI signal: not “more CVEs” — prioritization caught up to exploitation. PeopleSoft CVE-2026-35273 and Ivanti Sentry CVE-2026-10520 are KEV now. If exposed, don’t treat as routine patching. Hunt prior access. Lock down edge control planes. #CTI #ThreatIntel #Cybersecurity
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
~Checkpoint~ ShinyHunters breached Univ. of Nottingham via Oracle zero-day (CVE-2026-35273); Microsoft patched 200+ flaws including critical CVE-2026-45657. - IOCs: CVE-2026-35273, CVE-2026-45657, CVE-2026-50751 - ...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Microsoft
  • Microsoft 365 Copilot

04 Jun 2026
Published
15 Jun 2026
Updated

CVSS v3.1
MEDIUM (6.5)
EPSS
0.50%

KEV

Description

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Statistics

  • 3 Posts
  • 6 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

The most interesting thing about the new SearchLeak attack on Microsoft 365 Copilot isn't any single bug. It's that none of the three pieces was dangerous on its own. Varonis combined a prompt injection via a URL parameter, an HTML rendering race condition, and a server-side request forgery in Bing's image search. Each of these is a common bug that security teams usually consider minor. But when you put them together with a Copilot that can access your mailbox, OneDrive, and SharePoint, they create a critical flaw. Microsoft has since patched this issue (CVE-2026-42824).

This is how the attack worked:

* The victim clicks a link. That's the whole interaction. They type nothing.

* The link instructs Copilot to search the mailbox, find sensitive information such as access codes, and place it into an image URL.

* Bing retrieves that image, which sends the stolen data to the attacker's server. Bing serves as the delivery service, allowing the attack to bypass the content security policy intended to stop it.

From the user's perspective, Copilot just pauses for a moment. There is no visible sign that any data has been taken.

In the past, we've spent years rating bugs by their severity on their own. An SSRF here, an HTML injection there—each seemed minor. But when an AI assistant can follow instructions from untrusted input and access your real data, those minor bugs become much more serious. Old types of vulnerabilities become important again in this new context.

If your company uses Copilot or any AI assistant that can access company data, it is important to ask your team how they are rating bugs that affect it. The way we judge what is low risk has changed.

bleepingcomputer.com/news/secu

  • 4
  • 2
  • 0
  • 1h ago

Bluesky

Profile picture fallback
Microsoft fixed CVE-2026-42824, where SearchLeak could turn Microsoft 365 Copilot Enterprise into a 1-click data theft tool, exposing emails, calendars, OneDrive, and SharePoint via a crafted URL. #SearchLeak #CVE202642824 #Microsoft365
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
~Varonis~ SearchLeak (CVE-2026-42824) chains P2P injection, HTML race condition, and SSRF to silently exfiltrate M365 data via Copilot. - IOCs: CVE-2026-42824 - #CVE202642824 #SearchLeak #ThreatIntel
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • ivanti
  • Sentry

09 Jun 2026
Published
12 Jun 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
59.52%

Description

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 8 hours ago

Fediverse

Profile picture fallback

🚨 In this week’s newsletter, we cover CVE-2026-10520, a critical pre-authentication OS command injection vulnerability in Ivanti Sentry now under active exploitation. We break down how attackers can achieve root-level remote code execution without valid credentials and what defenders should do next.

Read the full analysis and protect your systems 👉 crowdsec.net/vulntracking-repo

  • 0
  • 0
  • 0
  • 8h ago

Bluesky

Profile picture fallback
- Ivanti Sentry advisory: hub.ivanti.com/s/article/Se... - FIRST EPSS CVE-2026-10520: api.first.org/data/v1/epss... - VECERT Radar NoName057(16) post: x.com/VECERTRadar/...
  • 0
  • 1
  • 0
  • 8h ago
Profile picture fallback
🚨 In this week’s newsletter, we cover CVE-2026-10520, a critical pre-authentication OS command injection vulnerability in Ivanti Sentry now under active exploitation. Read the full analysis and protect your systems 👉 www.crowdsec.net/vulntracking...
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
Weekend CTI signal: not “more CVEs” — prioritization caught up to exploitation. PeopleSoft CVE-2026-35273 and Ivanti Sentry CVE-2026-10520 are KEV now. If exposed, don’t treat as routine patching. Hunt prior access. Lock down edge control planes. #CTI #ThreatIntel #Cybersecurity
  • 0
  • 0
  • 0
  • 8h ago

Overview

  • checkpoint
  • Quantum Security Gateway

08 Jun 2026
Published
10 Jun 2026
Updated

CVSS
Pending
EPSS
6.22%

Description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Statistics

  • 3 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback

The VPN Authentication Bypass That Let Ransomware Actors Walk Right In: A Deep Dive into CVE-2026-50751

CVE-2026-50751 is a CVSS 9.3 auth bypass in Check Point VPN exploited since May 7, 2026. Full technical breakdown, IOCs, patches and more

thecybersecguru.com/news/cve-2

  • 0
  • 0
  • 0
  • 7h ago

Bluesky

Profile picture fallback
研究者らが、悪用されたCheck Point VPNの脆弱性(CVE-2026-50751)の詳細と概念実証(PoC)を公開 Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751) #HelpNetSecurity (Jun 12) www.helpnetsecurity.com/2026/06/12/c...
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
~Checkpoint~ ShinyHunters breached Univ. of Nottingham via Oracle zero-day (CVE-2026-35273); Microsoft patched 200+ flaws including critical CVE-2026-45657. - IOCs: CVE-2026-35273, CVE-2026-45657, CVE-2026-50751 - ...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Splunk
  • Splunk Enterprise

10 Jun 2026
Published
15 Jun 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
1.68%

KEV

Description

In Splunk Enterprise versions below 10.2.4 and 10.0.7, an unauthenticated user could create or truncate arbitrary files through a PostgreSQL sidecar service endpoint.<br><br>The vulnerability exists because the PostgreSQL sidecar service endpoint lacks authentication controls, allowing any network-reachable user to invoke file operations without credentials.

Statistics

  • 2 Posts
  • 2 Interactions

Last activity: 20 hours ago

Fediverse

Profile picture fallback

🚨 New Critical Vulnerability Analysis: CVE-2026-20253 🚨

Splunk’s June 2026 security advisory revealed a severe 9.8 CVSS flaw affecting Splunk Enterprise and Cloud platforms.

Read the technical deep-dive and remediation guide here:
👉 denizhalil.com/2026/06/15/cve-

#Cybersecurity #ThreatIntel #Splunk #RCE #VulnerabilityAnalysis

  • 0
  • 1
  • 0
  • 22h ago
Profile picture fallback

🚨 ALERT - A critical Splunk Enterprise flaw can go from “no login required” to remote code execution.

Tracked as CVE-2026-20253, the bug carries a 9.8 CVSS score and affects vulnerable Splunk Enterprise servers through exposed PostgreSQL sidecar endpoints.

The exploit chain is now public.

Read the full story: thehackernews.com/2026/06/crit

  • 0
  • 1
  • 0
  • 20h ago

Overview

  • Pending

27 Oct 2021
Published
04 Aug 2024
Updated

CVSS
Pending
EPSS
1.59%

KEV

Description

An SQL Injection vulnerability exists in Sourcecodester Complaint Management System 1.0 via the cid parameter in complaint-details.php.

Statistics

  • 3 Posts

Last activity: 4 hours ago

Bluesky

Profile picture fallback
A look at CVE-2020-24932, the critical SQL injection in Complaint Management System v1.0 that allowed full database disclosure through a single parameter. #sqlinjection
  • 0
  • 0
  • 1
  • 5h ago
Profile picture fallback
CVE-202024932 allowed unauthenticated SQL injection through complaint-details.php cid to enumerate and exfiltrate full database contents, fixed by parameterized queries and input validation.
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Cisco
  • Cisco Catalyst SD-WAN Manager

15 Jun 2026
Published
15 Jun 2026
Updated

CVSS v3.1
MEDIUM (6.5)
EPSS
Pending

Description

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit could allow the attacker to create or overwrite any file on the underlying operating system. This file could later be used to elevate to root. To exploit this vulnerability, the attacker must have valid credentials with at least a lower-privileged, single-task user account.

Statistics

  • 2 Posts

Last activity: Last hour

Bluesky

Profile picture fallback
Cisco patched CVE-2026-20262 in Catalyst SD-WAN Manager after in-the-wild zero-day abuse let authenticated attackers overwrite files and escalate to root. Affects all deployment types. #Cisco #SDWAN #ZeroDay
  • 0
  • 0
  • 0
  • Last hour
Profile picture fallback
~Cisa~ CISA added CVE-2026-20262 (Cisco SD-WAN) and CVE-2026-54420 (LiteSpeed cPanel) to its KEV catalog due to active exploitation. - IOCs: CVE-2026-20262, CVE-2026-54420 - #CISA #CVE202620262 #CVE202654420 #KEV #threatintel
  • 0
  • 0
  • 0
  • Last hour

Overview

  • The Document Foundation
  • LibreOffice

07 May 2026
Published
07 May 2026
Updated

CVSS v4.0
MEDIUM (5.4)
EPSS
0.08%

KEV

Description

Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched encryption salt parameters. This issue affects LibreOffice: from 26.2 before 26.2.3, from 25.8 before 25.8.7.

Statistics

  • 1 Post
  • 6 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

:picklerick: LibreOffice: Schwachstelle ermöglicht nicht spezifizierten Angriff

:cannabis: Ein für LibreOffice herausgegebener Sicherheitshinweis hat vom BSI ein Update erhalten. Welche Betriebssysteme und Produkte von der Sicherheitslücke betroffen sind, lesen Sie hier auf news.de.

news.de/technik/859595854/libr

  • 3
  • 3
  • 0
  • 4h ago

Overview

  • Wertheim GmbH
  • Wertheim SafeController Family 65000 Hardware for VAULT ROOMS (Safe Deposit Locker System - Microcontroller)

15 Jun 2026
Published
15 Jun 2026
Updated

CVSS v4.0
HIGH (7.1)
EPSS
Pending

KEV

Description

The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptographic algorithms with hard-coded cryptographic keys to protect communication. An attacker in an adversary-in-the-middle position can decrypt the data traffic. During reassessment, it was possible to break the encryption/decryption routine and decrypt messages without knowledge of the encryption key. It was also possible to gain knowledge about the encryption key by intercepting enough messages.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Trawling recent CVEs to make my brain stfu, stumbled across these:
sec-consult.com/vulnerability- / sec-consult.com/vulnerability- / db.gcve.eu/search?vendor=Werth

I dont know much about safes & stuff so I won't comment on impact but a few things stood out to me:

  • Disclosure timeline: Man, this is fucked, this shit ran for 3 years?
  • CVE-2026-34022: "The Safecontroller Family 65000 is secured with weak and custom cryptographic algorithms with hard-coded keys." "Cannot be fixed due to missing hardware support." "Proof of concept removed because no patch will be provided" :eyes_squint:
  • RCE on the server: This is actually a quite neat chaining of vulnerabilities/"features" being used in the second advisory to get from Arbitrary File read & Directory Traversal Upload to RCE :blobcatsurprised:
  • 1
  • 1
  • 0
  • 5h ago
Showing 1 to 10 of 52 CVEs