[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> CVE-2026-50677 Windows Media Elevation of Privilege Vulnerability
Use after free in Windows Media allows an authorized attacker to elevate privileges locally.
> CVE-2026-54115 Windows Message Queuing (MSMQ) Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows Active Directory allows an authorized attacker to elevate privileges locally.
> 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
The flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal. The post 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer appeared first on SecurityWeek.
> CVE-2026-50684 Active Directory Federation Server Spoofing Vulnerability
Improper neutralization of input during web page generation ('cross-site scripting') in Active Directory Federation Services (AD FS) allows an authorized attacker to perform spoofing over a network.
> CVE-2026-50679 Windows Search Service Elevation of Privilege Vulnerability
Heap-based buffer overflow in Microsoft Windows Search Component allows an authorized attacker to elevate privileges locally.
> NATO logistics, Ukrainian troops are top subjects of Russian camera hacks, advisory says
Dutch intelligence officials report that at least one Russian agency is compromising internet-connected cameras across Europe to spy on military logistics and Ukrainian personnel.
> CVE-2026-50688 Windows Win32k Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
> CVE-2026-50680 Windows Hyper-V Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
> RabbitMQ Flaws Could Leak OAuth Secrets and Expose Cross-Tenant Queue Metadata
Cybersecurity researchers have disclosed details of two access control-related flaws impacting the RabbitMQ message broker service that could allow attackers to leak OAuth client secrets, expose enterprise messaging infrastructure to takeover risks, and bypass tenant boundaries. Miggo's security te...
> CVE-2026-50681 Windows Secure Channel Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Cryptographic Services allows an authorized attacker to disclose information locally.
> CVE-2026-54121 Active Directory Certificate Services Elevation of Privilege Vulnerability
Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.
> New macOS malware steals passwords by posing as Apple’s crash-reporting tool
Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple’s crash-reporting tool to steal passwords, Keychain data, and cryptocurrency wallets. The malware was first spotted in May while it was still under development. By early July, Jamf was seeing in-...
> CVE-2026-50682 Active Directory Denial of Service Vulnerability
Out-of-bounds read in Windows Active Directory allows an authorized attacker to deny service over a network.
> CVE-2026-50685 Windows DHCP Server Remote Code Execution Vulnerability
Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
> ESET Full Disk Encryption version 2.4 has been released
A feature update of ESET Full Disk Encryption 2.4 has been released.
> CVE-2026-50683 Windows DHCP Client Elevation of Privilege Vulnerability
Heap-based buffer overflow in Windows DHCP Server allows an authorized attacker to elevate privileges over an adjacent network.
> CVE-2026-50687 Windows Win32k Elevation of Privilege Vulnerability
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
> Ubuntu 26.04 LTS alsa-lib Critical Denial of Service CVE-2026-56109
alsa-lib could be made to crash or run programs as your login if it opened a specially crafted file.
> CVE-2026-50686 Windows OLE Remote Code Execution Vulnerability
Access of resource using incompatible type ('type confusion') in Windows OLE allows an unauthorized attacker to execute code over a network.
> CVE-2026-50689 Windows Clipboard Server Elevation of Privilege Vulnerability
Use after free in Windows Clipboard Server allows an authorized attacker to elevate privileges locally.