mitre-ta0001
13403 articles with this tag
MEDIUM
MEDIUM
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
MEDIUM
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
HIGH
LOW
MEDIUM
CRITICAL
MEDIUM
HIGH
CRITICAL
MEDIUM
MEDIUM
CRITICAL
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
CRITICAL
HIGH
CRITICAL
MEDIUM
MEDIUM
CRITICAL
MEDIUM
HIGH
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
MEDIUM
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
MEDIUM
HIGH
MEDIUM
CRITICAL
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
HIGH
HIGH
CVE-2026-77490 Microsoft Edge (Chromium-based) Spoofing Vulnerability
Chromium CVE-2026-76022: Buffer overflow in Network
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Check Point patches two critical VPN gateway bugs
CISA Adds Three Known Exploited Vulnerabilities to Catalog
GitLab’s critical flaw is already drawing internet-wide probes
Dead drops in public: What the AI agent stashed on Hugging Face
More JFrog Artifactory bugs under attack, and all 3 have patches
Veikleikar hjá Microsoft, Google Chrome, Citrix, Check Point, Cisco, MikroTik, Adobe, Fortinet, SAP, Ivanti, N-able og OSGeo
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
“Eye” spy: Cyclops Blink returns with extended capabilities
Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware
AD Rights Management Service (Part 2): Extraction, Offline Decryption, and the Unrotatable Key
Grand Theft Auto VI hype leads to malware
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
GitLab Vulnerability Exploited One Day After Disclosure
Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
India’s STPI serves TerminalFix-style attack via fake Cloudflare check
Uncontrolled Access Control: Compromising Paxton10
Crypto customers targeted by scammers after email marketing provider breach
Metasploit Wrap Up: This One Goes to Sixteen!
Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Android malware creates a hidden copy of your banking app
ClickFix attacks infecting PCs and Macs are going viral
[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE
[NEU] [hoch] MongoDB: Mehrere Schwachstellen
[NEU] [hoch] Angular: Mehrere Schwachstellen
[NEU] [UNGEPATCHT] [niedrig] GNU libc: Schwachstelle ermöglicht Denial of Service
[NEU] [mittel] OpenClaw: Mehrere Schwachstellen
[NEU] [hoch] GitLab: Mehrere Schwachstellen
[NEU] [mittel] MISP: Mehrere Schwachstellen ermöglichen Manipulation von Dateien
[NEU] [hoch] Flowise: Mehrere Schwachstellen
[NEU] [hoch] Langflow: Schwachstelle ermöglicht Codeausführung
[NEU] [mittel] QT (NFC-Modul): Schwachstelle ermöglicht DoS and die Offenlegung von Informationen
[NEU] [mittel] BigBlueButton: Mehrere Schwachstellen
[NEU] [hoch] IBM DB2: Mehrere Schwachstellen
[NEU] [hoch] IBM MQ Appliance (Axios Node.js): Mehrere Schwachstellen
Check Point Patches Critical VPN Vulnerabilities
AI agents exploited PaperCut flaws to breach 395 organizations
Read the Bits, Not the Integer: msPKI-Certificate-Name-Flag and the ESC4⤍ESC1 Chain
Surfshark Systems Targeted by Hackers
Attackers use passkey-themed scams to hijack Microsoft 365 accounts
Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
Google’s Early Access is creating a blind spot for malicious apps
IDScan confirms breach after 153 million driver’s licenses leak on dark web
PaperCut Flaws Exploited in AI-Powered Attacks
NCSC-2026-0366 [1.00] [M/H] Kwetsbaarheden verholpen in Arista EOS
Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Four groups caught using the same Chrome and Windows exploit kit
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Attackers are weaponizing the gap between Chromium fixes and Chrome patches
Indonesia Hit by Android Banking App-Cloning Campaign
A real Carnival Cruise Line email was serving customers malware
Beltdown: Escaping the Claude Code Sandbox
No Extensions? You Forgot One: Writing Shared Objects to RCE via SQLite's dbpage
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
CISA: WatchGuard Firebox bug exploited in ransomware campaigns
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Detect and disrupt AI-themed attacks with Microsoft Defender
🕵️♂️ SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance
USN-8747-1: Beets vulnerability
USN-8745-1: KissFFT vulnerabilities
AVEVA Pipeline Integrity Monitor
Orthanc DICOM Server
NextGen Healthcare Mirth Connect
Vulnérabilité dans Laravel (10 septembre 2026)
Vulnérabilité dans Apereo CAS (10 septembre 2026)
Multiples vulnérabilités dans MongoDB Server (10 septembre 2026)
Multiples vulnérabilités dans les produits Check Point (10 septembre 2026)
Multiples vulnérabilités dans HPE Aruba Networking ClearPass Policy Manager (10 septembre 2026)
Vulnérabilité dans Microsoft Edge (10 septembre 2026)
Vulnérabilité dans Metabase (10 septembre 2026)
BlueMoon exploit kit turns Chrome and Windows flaws into attacks
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Skullcandy Dime 3 earbuds vulnerable to Bluetooth hijacking
PaperCut MF/NG flaws attacked with hundreds of AI agents
NCSC-2026-0015 [1.01] [M/H] Kwetsbaarheid verholpen in Fortinet FortiOS
Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews
USN-8743-1: PHP vulnerabilities
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
ShinyHunters expose 6.4M in attack on medical supplier McKesson
Attackers call employees’ personal phones to break into Microsoft 365 accounts
[NEU] [hoch] Arista EOS: Mehrere Schwachstellen
[NEU] [kritisch] Budibase: Mehrere Schwachstellen
[NEU] [hoch] Kyverno: Mehrere Schwachstellen
[NEU] [hoch] Drupal Erweiterungen: Mehrere Schwachstellen
[NEU] [niedrig] CUPS: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen
MantaxOtax Android Malware Combines Ransomware With Spyware
[UPDATE] [hoch] Apache Portable Runtime (APR): Mehrere Schwachstellen
[NEU] [hoch] Red Hat Enterprise Linux (postgis, virtuoso-opensource): Mehrere Schwachstellen