[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (3 articles)

|

// AI-powered summary generated at 08:00

> OS command injections via GET request parameter
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiADC may allow a remote and authenticated attacker with low privilege to execute unauthorized code via specifically crafted HTTP parameters. Revised on 2025-08-12 00:00:00
> Path traversal in Solution Pack upload
A relative path traversal vulnerability [CWE-23] in FortiSOAR may allow an authenticated attacker to read arbitrary files via uploading a malicious solution pack. Revised on 2025-08-12 00:00:00
> Cyber security for high profile conferences
Managing the cyber security of high profile events in the real and virtual worlds.
> Remote unauthenticated command injection
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiSIEM may allow an unauthenticated attacker to execute unauthorized code or commands via crafted CLI requests.Practical exploit code for this vulnerability was found in the wil...
> Stack buffer overflow in CLI command
A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb CLI may allow a privileged attacker to execute arbitrary code or commands via crafted CLI commands Revised on 2025-08-12 00:00:00
> ZDI-25-830: (0Day) Schneider Electric EcoStruxure Power Monitoring Expert GetPagesAsImages Server-Side Request Forgery Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Schneider Electric EcoStruxure Power Monitoring Expert. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned:...
> Weak authentication - FGFM protocol
An authentication bypass using an alternate path or channel [CWE-288] vulnerability in FortiOS, FortiProxy & FortiPAM may allow an unauthenticated attacker to seize control of a managed device via crafted FGFM requests, if the device is managed by a FortiManager, and if the attacker knows that F...
> XSS in service requests
An Improper neutralization of input during web page generation ('cross-site scripting') vulnerability [CWE-79] in FortiSOAR WEB UI may allow an authenticated remote attacker to perform an XSS attack via stored malicious service requests Revised on 2025-08-12 00:00:00
> ZDI-25-829: (0Day) Schneider Electric EcoStruxure Power Monitoring Expert GetFilteredSinkProvider Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Monitoring Expert. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-549...
> ZDI-25-828: (0Day) Schneider Electric EcoStruxure Power Monitoring Expert HttpPostedFile Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Monitoring Expert. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2025-549...
> Stock in the Channel
Stock in the Channel, une entreprise britannique, a subi une attaque de ransomware qui a entraîné la fermeture de son site web. Les attaquants ont exploité une vulnérabilité zero day dans l'une des applications tierces utilisées par l'entreprise. Selon l'entreprise, il n'y a actuellement aucune preu...
> ZDI-25-827: (0Day) Schneider Electric EcoStruxure Power Monitoring Expert GetTgmlContent Directory Traversal Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Schneider Electric EcoStruxure Power Monitoring Expert. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-...
> ZDI-25-826: (0Day) Schneider Electric EcoStruxure Power Monitoring Expert ExportDataAsXML Server-Side Request Forgery Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Schneider Electric EcoStruxure Power Monitoring Expert. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned:...
> Colt Technology Services
La société de télécommunications britannique Colt Technology Services est victime d'une cyberattaque qui a causé une panne de plusieurs jours de certaines de ses opérations. L'attaque a commencé le 12 août et les services tels que Colt Online et la plateforme Voice API sont toujours hors ligne. Les...
> City of Lubbock
La ville de Lubbock a subi deux attaques informatiques cette année, dont une qui a fermé sa présence en ligne. Une attaque antérieure avait créé une fausse fenêtre contextuelle sur le site de paiement des services publics de la ville. Les autorités de la ville ont travaillé pour restaurer les systèm...
> WinRAR zero-day exploited in espionage attacks against high-value targets
The attacks used spearphishing campaigns to target financial, manufacturing, defense, and logistics companies in Europe and Canada, ESET research finds
> Lycoming County
Le département de la sécurité publique du comté de Lycoming a détecté un logiciel de rançon sur son réseau informatique, ce qui pourrait avoir compromis les données, notamment les numéros de permis de conduire. L'enquête est en cours et les autorités ont sécurisé le réseau. Le comté prend des mesure...
> University of St. Thomas- Houston
A cyberattack was claimed by INC Ransom on September 3, 2025.
> Connex Credit Union Breach Exposes 172,000 Members’ Data
A cyber-attack at Connex Credit Union has compromised data of 172,000 individuals, including sensitive information
> New WinRAR Zero-Day Exploited by RomCom Hackers
A flaw in WinRAR, tracked as CVE-2025-8088, has been exploited by the RomCom group to deploy malware