home.social

Search

504 results for “CV”

  1. 🚨 SIGINT // Cybersecurity Watch — 2026-09-24
    Critical F5 BIG-IP vulnerability actively exploited as a zero-day. Patch now to prevent network compromise.
    securityweek.com/critical-f5-b

  2. Security Tip: Automate your secret detection! 🛡️ Accidentally committing API keys or hardcoded credentials is a common cause of breaches. By integrating secret scanning tools directly into your CI/CD pipeline, you can block compromised code before it hits your main branch. Actionable step: Audit your pipeline today to ensure no secrets are slipping through. Stay informed on the latest vulnerabilities: cvedatabase.com

  3. Security Tip: Stop patching blindly. Use the CISA Known Exploited Vulnerabilities (KEV) catalog to prioritize. 🛡️ With thousands of new CVEs every year, your team cannot fix everything at once. By focusing on vulnerabilities that attackers are actively using, you significantly reduce your immediate risk profile. Use CVEDatabase to track these critical flaws and understand the technical context. Learn more: cvedatabase.com

  4. 🚨 [CISA-2026:0922] CISA Adds 4 Known Exploited Vulnerabilities to Catalog (secdb.nttzen.cloud/security-ad)

    CISA has added 4 new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.

    ⚠️ CVE-2026-85102 (secdb.nttzen.cloud/cve/detail/)
    - Name: Check Point Multiple Products Improper Certificate Validation Vulnerability
    - Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
    - Known To Be Used in Ransomware Campaigns? Unknown
    - Vendor: Check Point
    - Product: Multiple Products
    - Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

    ⚠️ CVE-2026-93616 (secdb.nttzen.cloud/cve/detail/)
    - Name: Check Point Multiple Products Path Traversal Vulnerability
    - Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
    - Known To Be Used in Ransomware Campaigns? Unknown
    - Vendor: Check Point
    - Product: Multiple Products
    - Notes: support.checkpoint.com/results ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

    ⚠️ CVE-2026-93952 (secdb.nttzen.cloud/cve/detail/)
    - Name: Arista VeloCloud Orchestrator Improper Input Validation Vulnerability
    - Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
    - Known To Be Used in Ransomware Campaigns? Unknown
    - Vendor: Arista
    - Product: VeloCloud Orchestrator
    - Notes: arista.com/en/support/advisori ; ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

    ⚠️ CVE-2026-94127 (secdb.nttzen.cloud/cve/detail/)
    - Name: F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability
    - Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
    - Known To Be Used in Ransomware Campaigns? Unknown
    - Vendor: F5
    - Product: BIG-IP APM
    - Notes: For temporary mitigation to allow for proactive forensic triage, apply the vendor-provided iRule. Once completed, install the final vendor patch as soon as possible. For more information please see: my.f5.com/manage/s/article/K00 ; BOD 26-04: cisa.gov/news-events/directive ; Forensics Triage Requirements: cisa.gov/news-events/directive ; nvd.nist.gov/vuln/detail/CVE-2

    #ZEN #SecDB #InfoSec #CVE #CISA_KEV #cisa_20260922 #cisa20260922 #cve_2026_85102 #cve_2026_93616 #cve_2026_93952 #cve_2026_94127 #cve202685102 #cve202693616 #cve202693952 #cve202694127

  5. CVE-2026-84434 Gravity Forms WordPress plugin, arbitrary file upload to RCE, CVSS 9.8, no patch yet. Unauthenticated attackers can run code. Update immediately or disable. valtersit.com/cve/CVE-2026-844 #CVE #infosec #WordPress

  6. 📢 🪲 Semaine 38 — CVE les plus discutées

    Cette page présente les vulnérabilités les plus discutées sur les sources publiques (Fediverse, Bluesky, GitHub, blogs) sur la période analysée. Période analysée : 2026-09-13 → 2026-09-20. Les données sont collectées via Vulnerability-Lookup (CIRCL) et enrichies automatiquement afin d’aider à la priorisation de la veille et de la remédiation.

    📖 cyberveille : cyberveille.ch/posts/2026-09-2
    #cve #veille #Cyberveille

  7. CVE-2026-19499: glibc 2.38-2.44 strfmon buffer overflow via right-justified padding. CVSS 7.7. Unpatched. Audit risky calls, update now.
    valtersit.com/cve/CVE-2026-194
    #CVE #infosec #glibc

  8. CVE-2026-19499: glibc 2.38-2.44 strfmon buffer overflow via right-justified padding. CVSS 7.7. Unpatched. Audit risky calls, update now.
    valtersit.com/cve/CVE-2026-194
    #CVE #infosec #glibc

  9. CVE-2026-19499: glibc 2.38-2.44 strfmon buffer overflow via right-justified padding. CVSS 7.7. Unpatched. Audit risky calls, update now.
    valtersit.com/cve/CVE-2026-194
    #CVE #infosec #glibc