radar.cysentrix

Security Radar

Page 1 of 10 · 1562 stories from the last 30 days across 19 trusted sources.

Actively exploited 20 actively exploited CVEs in current coverage
View all CVEs →
  • CVE-2026-63030

    WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.

    6storiesEPSS 96%
  • CVE-2026-50522

    Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

    7storiesEPSS 77%
  • CVE-2026-15409

    A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.

    2storiesEPSS 74%
  • CVE-2026-16232

    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

    5storiesEPSS 73%
  • CVE-2026-0770

    Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the exec_globals parameter provided to the validate endpoint. The issue results from the inclusion of a resource from an untrusted control sphere. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-27325.

    1storyEPSS 57%
  • CVE-2026-9198

    IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments

    2storiesEPSS 17%
BleepingComputer · Security Affairs · SecurityWeek3 stories

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

AINew Rust-based macOS infostealer AmnesiaStealer spreads via ClickFix fake GitHub pages, stealing passwords, keychain data, and browser cookies while enabling attackers to remotely control victims' browser sessions.

Open narrative →
malware
Show all coverage
Security Affairs

Sophisticated Cyberattack Exposes Data of 678,000 French Taxpayers

France’s tax agency says hackers stole data on 678,000 taxpayers, including income and tax details, in a sophisticated cyberattack. A threat actor claimed to have breached France’s tax agency in late June. France’s tax administration confirmed that a cyberattack exposed person...

apt
Security Affairs

APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2

Acronis uncovered PATCHCORD, a stealthy backdoor targeting Afghan telecom and South Asian infrastructure via fake VPN tools and Google Sheets C2. Researchers at Acronis just documented an espionage operation that reads like it was built by someone with genuinely good taste in ...

apt
Security Affairs

Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware

Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat ...

malware
Security Affairs · BleepingComputer · SOCRadar · The Hacker News4 stories

SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

AISAP patched CVE-2026-58231, a CVSS 10.0 improper authorization flaw in Commerce Cloud's Data Hub Adapter allowing unauthenticated remote code execution; Defused reports active exploitation within three days of the fix.

Open narrative →
vulnerabilitycloudzero day
Show all coverage
Security Affairs · BleepingComputer2 stories

Hackers exploit macOS Screen Sharing flaw to deploy Monero miner

AIHackers are actively exploiting a macOS Screen Sharing authentication bypass (CVE-2026-65400) to gain root access and deploy Monero miners on Macs with port 5900 exposed, according to the Dutch NCSC.

Open narrative →
vulnerability
Show all coverage
Security Affairs · SecurityWeek2 stories

Hackers Exploiting Unpatched GeoServer Zero-Day

AIHackers are actively exploiting an unpatched GeoServer zero-day, a SQL injection flaw that can lead to remote code execution. No patch is currently available, and exposed systems are already being probed.

Open narrative →
zero dayvulnerability
Show all coverage
Schneier on Security

Friday Squid Blogging: Searching for the Colossal Squid

Fascinating video about searching for life undersea. The video basically makes the point that our bright white searchlights are scaring everything away, and that red light is more neutral. That, plus bait to attract sea creatures, is teaching us a lot about what’s going on dow...

Dark Reading

Mission-Driven Security: Inside a Global Bank's Defense

In this video interview, Standard Chartered's group CISO shares insights on transitioning from technical roles to strategic leadership, the importance of business-savvy security executives, and how AI is reshaping both defensive capabilities and adversarial tactics in banking.

Dark Reading

Amid AI-Driven Bug Tsunami, NIST Looks to…AI

Driven by AI-augmented research and scanning, vulnerability volumes continue to surge, driving the National Institute of Standards and Technology to ask whether AI could be the answer.

vulnerability
Security Affairs · BleepingComputer2 stories

Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks

AIApple issued fresh threat notifications to users possibly targeted by mercenary spyware, urging immediate verification and stronger protections per TechCrunch and BleepingComputer.

Open narrative →
Show all coverage
Schneier on Security

Upcoming Speaking Engagements

This is a current list of where and when I am scheduled to speak: I’m speaking, signing books, and participating in panel discussions at LAcon V in Anaheim, California, USA. My full schedule is here. I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, ...