mitre-t1190
9025 articles with this tag
HIGH
MEDIUM
LOW
MEDIUM
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
CRITICAL
MEDIUM
CRITICAL
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
CRITICAL
LOW
CRITICAL
MEDIUM
HIGH
MEDIUM
MEDIUM
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
CRITICAL
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
CRITICAL
HIGH
CRITICAL
CRITICAL
CRITICAL
MEDIUM
HIGH
CRITICAL
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
CRITICAL
CRITICAL
MEDIUM
CRITICAL
MEDIUM
CRITICAL
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
Schneider Electric IGSS
Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
Johnson Controls OpenBlue Employee
MikroTik RouterOS
o6 Automation open62541
Mitsubishi Electric CC-Link IE TSN Communication Protocol
MZ Automation lib60870
MZ Automation GmbH libiec61850
NASA Core Flight System (cFS) Health & Safety (HS) Application
Watchfire Controller Software
Toptech Systems RCU II+ and Multiload II+
Read This Before You Buy That TV Streaming Stick
KindaRails2Shell: CVE-2026-66066, Critical Arbitrary File Read and Possible Remote Code Execution in Ruby on Rails
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
VU#790363: foreUP golf management platform's web API contains multiple vulnerabilities
We know how to protect our troops from telecom attacks. We’re just not doing it.
USN-8625-1: OpenSSL vulnerability
Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066)
Vulnérabilité dans Ruby on Rails activestorage (30 juillet 2026)
Vulnérabilité dans CPython (30 juillet 2026)
Vulnérabilité dans Cisco Firewall Management Center (30 juillet 2026)
USN-8624-1: Sinatra vulnerability
Hidden prompt turns Microsoft Copilot into an AI worm
Denying the Worm: Detecting SANDWORM_MODE and the Emerging Class of AI Toolchain Supply Chain Attacks
Hidden prompt can make Microsoft Copilot spread itself through your Word docs
Teams-Themed Phishing Campaign Abused Legitimate Microsoft Login Pages
Microsoft Copilot for Word Can Copy Hidden Prompts Into New Documents
‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale
Critical Ruflo flaw lets attackers hijack AI agents through exposed MCP bridge
[UPDATE] [hoch] KDE "Konsole": Schwachstelle ermöglicht Codeausführung
[NEU] [hoch] Red Hat Enterprise Linux (Pillow): Mehrere Schwachstellen
[NEU] [hoch] FreeBSD Project FreeBSD OS: Mehrere Schwachstellen
OpenAI agent exploited JFrog Artifactory flaw, abused Modal customer sandbox
Russian hackers turn Exchange flaw into ‘half-click’ mailbox takeover
Cisco FMC static credentials exploited by attackers (CVE-2026-20316)
[NEU] [hoch] Flowise: Mehrere Schwachstellen
[NEU] [hoch] GitLab: Mehrere Schwachstellen
[NEU] [mittel] Node.js: Mehrere Schwachstellen
[NEU] [mittel] drawio: Schwachstelle ermöglicht Cross-Site Scripting
[NEU] [mittel] Autodesk AutoCAD: Mehrere Schwachstellen
[NEU] [hoch] SQLite: Mehrere Schwachstellen
Critical VMware vCenter Vulnerabilities Allow Authentication Bypass and Remote Code Execution (CVE-2026-59309, CVE-2026-59310)
Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts
SilverFox Targets Japanese Manufacturer with 3-Driver BYOVD Chain and ValleyRAT
[NEU] [hoch] IBM App Connect Enterprise: Mehrere Schwachstellen
[NEU] [hoch] Google Chrome: Mehrere Schwachstellen
[NEU] [mittel] Red Hat OpenStack (Neutron): Schwachstelle ermöglicht Manipulation von Daten und Umgehen von Sicherheitsvorkehrungen
[NEU] [mittel] Red Hat Quay: Schwachstelle ermöglicht Offenlegung von Informationen
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Russian spies take their half-click email attack from Zimbra to Outlook
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms
1 in 5 Data Center Assets Are Within Easy Reach of Attackers
Coordinated cyberattack hits more than 30 Minnesota water utilities
[UPDATE] [hoch] SCP in mehreren Produkten: Mehrere Schwachstellen
[UPDATE] [mittel] OpenSSH: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
[NEU] [mittel] Cisco Secure Firewall Management Center: Schwachstelle ermöglicht Offenlegung von Informationen
[NEU] [hoch] Ruby on Rails: Schwachstelle ermöglicht Offenlegung von Informationen
Toy Ghouls’ new toy: the GenieLocker ransomware
Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Cisco Secure FMC Zero-Day Exploited in the Wild
Excuses like 'AI did it' don't exist in the eyes of the law
NCSC-2026-0271 [1.00] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Center
Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data
Cisco Secure Firewall Management Center Software Information Disclosure Vulnerability
IBM WebSphere Products Multiple Vulnerabilities
Node.js Multiple Vulnerabilities
Citrix XenServer Multiple Vulnerabilities
GitLab Multiple Vulnerabilities
Xen Multiple Vulnerabilities
Google Chrome Multiple Vulnerabilities
Maximum severity vulnerability in Ruflo AI platform allows memory tampering
Flying Eagle Android RAT source code circulates on Telegram
Health-ISAC warns of ShinyHunters' increasing attacks on healthcare SSO accounts
'Flying Eagle' Full-Service Mobile RAT Builder Wings Across China
FreeBSD-SA-26:55.elf
FreeBSD-SA-26:54.sysvsem
FreeBSD-SA-26:52.if_wg
FreeBSD-SA-26:50.kqueue
A little-known npm package was North Korea’s warm-up act for the axios hack
CISA Adds One Known Exploited Vulnerability to Catalog
Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads
VU#293714: Arbitrary File Overwrite in Develar app-builder (zipx.Unzip) via Symlink Following on macOS (APFS)
CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity
Word worm crawls into Copilot, spreads chaos
WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
Huntress warns about attack spree that hit 30 SonicWall customers in 2 days
New Tengu botnet uses hardware watchdog for advanced persistence
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Patch-Resistant 'RufRoot' Flaw Can Unleash Malicious AI Agent Swarms
CubePilot hit by DNS hijacking attack, warns of potential credential theft
VU#305509: OPeNDAP Hyrax is vulnerable to SSRF and Credential Disclosure
Stack Sports notifies users of payment card data exposure
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline