24h | 7d | 30d

Overview

  • DVDFab
  • Virtual Drive

15 Jun 2026
Published
15 Jun 2026
Updated

CVSS v4.0
HIGH (8.5)
EPSS
0.11%

KEV

Description

A security vulnerability has been detected in DVDFab Virtual Drive 2.0.0.5. Impacted is an unknown function in the library dvdfabio.sys of the component Signed Kernel Driver. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Statistics

  • 1 Post

Last activity: 14 hours ago

Fediverse

Profile picture fallback

🔥 HIGH severity: DVDFab Virtual Drive 2.0.0.5 (dvdfabio.sys) suffers from improper privilege management (CVE-2026-12217). Publicly disclosed local exploit, no vendor response. Review exposure & restrict local access. radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 14h ago

Overview

  • koel
  • koel

12 Jun 2026
Published
13 Jun 2026
Updated

CVSS v3.1
HIGH (7.7)
EPSS
0.35%

KEV

Description

Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via the SafeUrl rule (DNS resolution + public IP check), but the individual episode <enclosure url="..."> values extracted from the RSS XML are stored directly into the database without any SSRF validation. When a user plays an episode, the server downloads the full HTTP response from the unvalidated enclosure URL via Http::sink()->get() and streams it back to the user, enabling full-read SSRF against internal services. This issue has been patched in version 9.3.5.

Statistics

  • 1 Post

Last activity: 13 hours ago

Fediverse

Profile picture fallback

CVE-2026-47260 - SSRF in Koel music streaming prior to 9.3.5. Episode enclosure URLs bypass validation, allowing server-side request forgery. CVSS 7.7. Update immediately. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-472

  • 0
  • 0
  • 0
  • 13h ago

Overview

  • Jenkins Project
  • Jenkins

10 Jun 2026
Published
11 Jun 2026
Updated

CVSS
Pending
EPSS
0.37%

KEV

Description

In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.

Statistics

  • 1 Post

Last activity: 6 hours ago

Fediverse

Profile picture fallback

CVE-2026-53435: Inside the Jenkins Deserialization Chain That’s Being Exploited Right Now

CVE-2026-53435 is a high-severity Jenkins deserialization flaw (CVSS 8.8) under active exploitation. Full technical breakdown: gadget chain, PoC

thecybersecguru.com/news/cve-2

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • OpenClaw
  • OpenClaw

12 Jun 2026
Published
12 Jun 2026
Updated

CVSS v4.0
HIGH (7.4)
EPSS
0.11%

KEV

Description

OpenClaw before 2026.5.18 contains an identity header validation vulnerability allowing local same-host callers to forge trusted-proxy identity headers. Attackers with access to the proxy-facing Gateway port can supply forged identity headers to assume operator identity and potentially escalate privileges.

Statistics

  • 1 Post

Last activity: 6 hours ago

Fediverse

Profile picture fallback

CVE-2026-53832 - Privilege escalation in Openclaw. Proxy identity header forgery allows attackers to assume operator identity. CVSS 7.7. Patch unknown but monitor for updates. #CVE #Openclaw #infosec

valtersit.com/cve/CVE-2026-538

  • 0
  • 0
  • 0
  • 6h ago

Overview

  • Apple
  • macOS

11 May 2026
Published
13 May 2026
Updated

CVSS
Pending
EPSS
0.14%

KEV

Description

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.4. An app may be able to gain root privileges.

Statistics

  • 1 Post

Last activity: 8 hours ago

Fediverse

Profile picture fallback

En las últimas 24 horas se han detectado explotaciones críticas en PAN-OS GlobalProtect VPN que permiten accesos no autorizados, un malware NarwhalRAT avanzado de APT37 que usa scripts LNK y PowerShell para infiltrarse, y una vulnerabilidad en MacOS que eleva privilegios vía Python, además de técnicas para identificar empresas fantasma y evitar fraudes. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 15/06/26 📆 |====

🔐 ALERTA POR EXPLOTACIÓN ACTIVA DE VULNERABILIDAD EN PAN-OS GLOBALPROTECT VPN

Palo Alto Networks ha detectado una explotación activa de la vulnerabilidad CVE-2026-0257 en su sistema PAN-OS GlobalProtect VPN. Esta falla permite evadir la autenticación estándar y crear sesiones VPN no autorizadas, poniendo en riesgo la red corporativa. Es fundamental actualizar y reforzar las configuraciones de seguridad para evitar accesos indebidos y posibles brechas de datos.

Descubre cómo proteger tu infraestructura ante esta amenaza crítica aquí 👉 djar.co/m4Ku5

🦈 ANÁLISIS PROFUNDO DEL MALWARE NARWHALRAT DE APT37

El grupo APT37 utiliza un sofisticado malware basado en Python llamado NarwhalRAT que se propaga mediante archivos LNK maliciosos que ejecutan scripts de PowerShell y comandos por lotes. Esta campaña combina técnicas avanzadas de phishing temático, comandos C2 en modo sigiloso y persistencia, afectando a múltiples entornos empresariales. Comprender su modus operandi es clave para implementar defensas efectivas.

Consulta el informe completo con indicadores de compromiso y estrategias de mitigación aquí 👉 djar.co/nEUM

🐍 NUEVA VULNERABILIDAD EN MACOS PERMITE ESCALAR PRIVILEGIOS USANDO PYTHON

La vulnerabilidad CVE-2026-28840 detectada en MacOS permite a atacantes con acceso limitado elevar sus privilegios mediante scripts en Python, comprometiendo la integridad del sistema operativo. Este fallo representa un riesgo crítico para usuarios y organizaciones que dependen de entornos Mac, especialmente en sectores sensibles. Actualizar y aplicar parches es urgente para cerrar esta brecha.

Infórmate sobre los detalles técnicos y pasos para proteger tus equipos Mac aquí 👉 djar.co/LMnK

🔍 CÓMO IDENTIFICAR UNA EMPRESA FANTASMA EN 2026: 7 SEÑALES CLAVE

En el entorno empresarial actual, distinguir compañías legítimas de empresas ficticias es vital para evitar fraudes y malas inversiones. Esta guía práctica expone 7 señales basadas en técnicas OSINT y herramientas gratuitas que te ayudarán a verificar la autenticidad de cualquier empresa. Incluye un análisis detallado de un caso real, paso a paso, para que puedas aplicar estos métodos de inmediato.

Aprende a detectar riesgos ocultos y proteger tus decisiones comerciales aquí 👉 djar.co/3pU6

  • 0
  • 0
  • 0
  • 8h ago

Overview

  • Microsoft
  • Microsoft 365 Apps for Enterprise

13 Jan 2026
Published
01 Apr 2026
Updated

CVSS v3.1
HIGH (8.4)
EPSS
0.50%

KEV

Description

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Statistics

  • 1 Post

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Kabar mengenai security holes di Microsoft yang dipublikasi di awal tahun 2026, mulai dari Microsoft Office remote code execution bugs CVE-2026-20952, CVE-2026-20953 hingga vulnerability secure boot bypass CVE-2026-21265 yang bersifat critical karena sudah menyangkut ancaman bootkit dan rootkit, sedangkan certificate secure boot device lama sudah kadaluarsa pada Juni 2026. Dan masih banyak lagi.

krebsonsecurity.com/2026/01/pa

  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

13 Jan 2026
Published
01 Apr 2026
Updated

CVSS v3.1
MEDIUM (6.4)
EPSS
0.96%

KEV

Description

Windows Secure Boot stores Microsoft certificates in the UEFI KEK and DB. These original certificates are approaching expiration, and devices containing affected certificate versions must update them to maintain Secure Boot functionality and avoid compromising security by losing security fixes related to Windows boot manager or Secure Boot. The operating system’s certificate update protection mechanism relies on firmware components that might contain defects, which can cause certificate trust updates to fail or behave unpredictably. This leads to potential disruption of the Secure Boot trust chain and requires careful validation and deployment to restore intended security guarantees. Certificate Authority (CA) Location Purpose Expiration Date Microsoft Corporation KEK CA 2011 KEK Signs updates to the DB and DBX 06/24/2026 Microsoft Corporation UEFI CA 2011 DB Signs 3rd party boot loaders, Option ROMs, etc. 06/27/2026 Microsoft Windows Production PCA 2011 DB Signs the Windows Boot Manager 10/19/2026 For more information see this CVE and Windows Secure Boot certificate expiration and CA updates.

Statistics

  • 1 Post

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Kabar mengenai security holes di Microsoft yang dipublikasi di awal tahun 2026, mulai dari Microsoft Office remote code execution bugs CVE-2026-20952, CVE-2026-20953 hingga vulnerability secure boot bypass CVE-2026-21265 yang bersifat critical karena sudah menyangkut ancaman bootkit dan rootkit, sedangkan certificate secure boot device lama sudah kadaluarsa pada Juni 2026. Dan masih banyak lagi.

krebsonsecurity.com/2026/01/pa

  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Microsoft
  • Windows 11 version 23H2

09 Jun 2026
Published
10 Jun 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.58%

KEV

Description

Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.

Statistics

  • 1 Post

Last activity: 2 hours ago

Bluesky

Profile picture fallback
~Checkpoint~ ShinyHunters breached Univ. of Nottingham via Oracle zero-day (CVE-2026-35273); Microsoft patched 200+ flaws including critical CVE-2026-45657. - IOCs: CVE-2026-35273, CVE-2026-45657, CVE-2026-50751 - ...
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Microsoft
  • Microsoft 365 Apps for Enterprise

13 Jan 2026
Published
01 Apr 2026
Updated

CVSS v3.1
HIGH (8.4)
EPSS
0.60%

KEV

Description

Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.

Statistics

  • 1 Post

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Kabar mengenai security holes di Microsoft yang dipublikasi di awal tahun 2026, mulai dari Microsoft Office remote code execution bugs CVE-2026-20952, CVE-2026-20953 hingga vulnerability secure boot bypass CVE-2026-21265 yang bersifat critical karena sudah menyangkut ancaman bootkit dan rootkit, sedangkan certificate secure boot device lama sudah kadaluarsa pada Juni 2026. Dan masih banyak lagi.

krebsonsecurity.com/2026/01/pa

  • 0
  • 0
  • 0
  • 5h ago
Showing 41 to 49 of 49 CVEs