mitre-t1190
8841 articles with this tag
CRITICAL
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
CRITICAL
HIGH
MEDIUM
MEDIUM
CRITICAL
HIGH
HIGH
CRITICAL
MEDIUM
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
CRITICAL
CRITICAL
MEDIUM
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
MEDIUM
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
MEDIUM
HIGH
MEDIUM
HIGH
CRITICAL
MEDIUM
MEDIUM
HIGH
HIGH
JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
Charity bank pulls online services over third-party software flaw
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability
Coding Agent Horror Stories: The 29 Million Secret Problem
Phishing Dominates as Initial Entry Method for Cyber-Attacks, as Hackers Hone Evasion Techniques
USN-8621-1: Samba vulnerabilities
Chaos in Teams vishing
Exposed BMCs hand out password hashes before login
Agentic Browsers Rewind Web Security by 20 years
[NEU] [hoch] Apache Airflow FAB provider: Schwachstelle ermöglicht Erlangen von Administratorrechten
[NEU] [hoch] JFrog Artifactory: Mehrere Schwachstellen
[NEU] [mittel] Apache Wicket: Mehrere Schwachstellen
[NEU] [mittel] Apple Safari: Mehrere Schwachstellen
JetBrains fixes critical unauthenticated RCE in TeamCity On-Premises (CVE-2026-63077)
Vatican’s Click To Pray app exposed personal data from 700,000 users
[NEU] [hoch] Progress Software LoadMaster und MOVEit WAF: Mehrere Schwachstellen
[NEU] [hoch] Apple macOS (Tahoe, Sonoma und Sequoia): Mehrere Schwachstellen
[NEU] [mittel] Devolutions Server: Mehrere Schwachstellen
[NEU] [mittel] Flowise: Mehrere Schwachstellen
[NEU] [hoch] Apache Axis2: Schwachstelle ermöglicht Codeausführung
[NEU] [hoch] GIMP Plugins: Mehrere Schwachstellen
[NEU] [hoch] OpenCTI: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
[NEU] [mittel] Apple iOS und iPadOS: Mehrere Schwachstellen
Coca-Cola Reveals Subsidiary Fairlife Suffered Data Breach
[NEU] [hoch] Microsoft Azure Portal: Schwachstelle ermöglicht Offenlegung von Informationen
[NEU] [hoch] JetBrains TeamCity: Schwachstelle ermöglicht Codeausführung
[NEU] [hoch] Erlang/OTP: Mehrere Schwachstellen
[NEU] [mittel] Netty: Schwachstelle ermöglicht Denial of Service
[NEU] [mittel] Moodle: Schwachstelle ermöglicht Offenlegung von Informationen
[NEU] [mittel] Apache ActiveMQ: Mehrere Schwachstellen
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock
Coca-Cola confirms hackers stole data in Fairlife ransomware attack
NCSC-2026-0266 [1.00] [M/H] Kwetsbaarheden verholpen in Apple iOS en iPadOS
Mirage Kitten targets Middle East and Africa region with new malware
Hugging Face breach shows why incident response needs a multi-model AI strategy
USN-8620-1: Linux kernel vulnerabilities
USN-8619-1: Linux kernel (HWE) vulnerabilities
USN-8574-3: Linux kernel vulnerabilities
USN-8618-1: Linux kernel vulnerabilities
Unpatched Fastjson Vulnerability Exploited in Attacks
USN-8617-1: Linux kernel (KVM) vulnerabilities
USN-8616-1: Linux kernel (IBM) vulnerabilities
USN-8615-1: Linux kernel vulnerabilities
Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day
Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw
Origin Energy Data Breach Affects 900,000 Australians
Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts
Apple Products Multiple Vulnerabilities
AI Agent Drives Espionage Attack on Thai Ministry of Finance
Hackers target US firms in FastJson RCE zero-day attacks
Did an AI Really Hack Hugging Face?
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
Russian hackers exploited Zimbra zero-day in espionage campaigns
New Certighost PoC exploit lets attackers hijack Windows domains
'Confused Deputy' Flaws Persist in Google Cloud, Microsoft Azure
Steam forums used for ClickFix cryptominer attacks
Malvertising campaign assembles malware in browser
Pope's prayer app leaks 700,000 user emails
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CheckPoint authentication bypass bug exploited, added to CISA list
Aftercall ads are driving Android users crazy
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
27th July – Threat Intelligence Report
BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms
Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw
Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles
USN-8612-1: Roc Toolkit vulnerability
The Sub-10-Minute Cloud Takeover: How Exposed IAM Keys, Misconfiguration and AI Are Rewriting the Rules of Cloud Breaches
⚡ Weekly Recap: Rogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and More
New vBulletin Vulnerability!
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
PTC Windchill Vulnerability Exploited in Ransomware Campaign
MedusaHVNC Malware Uses Hidden Windows Desktops to Evade Detection
PoC exploit released for critical AD CS domain-takeover flaw (CVE-2026-54121)
Certighost haunts Microsoft Active Directory Certificate Services
[NEU] [mittel] Vaultwarden: Mehrere Schwachstellen
[NEU] [kritisch] vBulletin: Schwachstelle ermöglicht Codeausführung
[NEU] [mittel] Linux Kernel: Mehrere Schwachstellen
[NEU] [hoch] ffmpeg: Mehrere Schwachstellen
[NEU] [UNGEPATCHT] [kritisch] Zabbix: Schwachstelle ermöglicht Cross-Site Scripting
[NEU] [mittel] FreeRDP: Mehrere Schwachstellen
[NEU] [mittel] Microsoft Edge: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen und Spoofing-Angriffe
Coca-Cola Confirms Data Breach After Fairlife Ransomware Attack
SourTrade Malvertising Campaign Secretly Builds Malware in the Browser
Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials
Ransomware Groups Increasingly Deploy EDR Kill Techniques
[NEU] [mittel] Red Hat Enterprise Linux (go-billy): Schwachstelle ermöglicht Denial of Service
[NEU] [niedrig] Checkmk: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Manipulation von Dateien
[NEU] [UNGEPATCHT] [mittel] Keycloak: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen
[NEU] [hoch] libssh2: Mehrere Schwachstellen
[NEU] [mittel] OpenCTI: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen und Offenlegung von Informationen
[NEU] [mittel] Webmin: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments
When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk
[NEU] [mittel] ImageMagick: Schwachstelle ermöglicht Offenlegung von Informationen
CVE-2026-16461 Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting
CVE-2026-8450 HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()