Visualização normal

Ontem — 7 de Setembro de 2026Cybersecurity News
  • ✇Cybersecurity News
  • CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild Do Son
    The N-able N-central vulnerability CVE-2026-86218 is a CVSS 10 pre-auth RCE reported exploited in the wild. Apply 2026.3 HF4 immediately. Related Posts: MikroTrick PoC: RouterOS Admin Rights Exploited In Wild AI Agent Coordination: The Unprecedented OpenAI Breakout Roundcube Security Update Fixes 12 Webmail Flaws The post CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild appeared first on Daily CyberSecurity.
     
Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • StyleSmuggler: Magento Zero-Day RCE Exploited in the Wild Do Son
    StyleSmuggler, a Magento zero-day, gives unauthenticated remote code execution and is exploited in the wild. No patch yet. Mitigate now. Related Posts: CVE-2026-86218 (CVSS 10): N-central Pre-Auth RCE Exploited in the Wild MikroTrick PoC: RouterOS Admin Rights Exploited In Wild AI Agent Coordination: The Unprecedented OpenAI Breakout The post StyleSmuggler: Magento Zero-Day RCE Exploited in the Wild appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-85046: Chrome Zero-Day Vulnerability Exploited in the Wild Do Son
    Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046). Related Posts: CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE Apache Allura Security Vulnerabilities Patched in v1.21.0 CVE-2026-52924 PoC Exploit Disclosed: 9.8 CVSS Linux Root Privilege Escalation The post CVE-2026-85046: Chrome Zero-Day Vulnerability Exploited in the Wild appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • NightmareEclipse Releases PoCs for Avast, Kaspersky, and NVIDIA Flaws Do Son
    Discover the details of three new NightmareEclipse vulnerabilities targeting Avast, Kaspersky, and NVIDIA components, lacking official vendor confirmation. Related Posts: CVE-2026-81934: Redis RCE PoC Exploit Now Public CVE-2026-78319: SAUTER Controller RCE Flaw Disclosed CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover The post NightmareEclipse Releases PoCs for Avast, Kaspersky, and NVIDIA Flaws appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-81578 & CVE-2026-82078: PaperCut Zero-Day Exploited, PoC Public Do Son
    PaperCut vulnerability CVE-2026-82078 is exploited in the wild. Attackers run malicious SQL for RCE and a Metasploit PoC is public. Patch now. Related Posts: PoC Published for Linux Kernel Privilege Escalation CVE-2026-52933 Flaw HardBreacher Exploit Targets Kaspersky High-Severity Composer Flaw Enables Command Execution The post CVE-2026-81578 & CVE-2026-82078: PaperCut Zero-Day Exploited, PoC Public appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • HardBreacher Exploit Targets Kaspersky Do Son
    Discover the details of the experimental HardBreacher exploit targeting a potential zero-day vulnerability within Kaspersky Endpoint Security for privilege escalation. Related Posts: PoC Published for Linux Kernel Privilege Escalation CVE-2026-52933 Flaw CVE-2026-81578 & CVE-2026-82078: PaperCut Zero-Day Exploited, PoC Public High-Severity Composer Flaw Enables Command Execution The post HardBreacher Exploit Targets Kaspersky appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • PaperCut NG/MF Vulnerability Exploited in the Wild, Emergency Patch Released Do Son
    PaperCut confirms a NG/MF vulnerability exploited in the wild. Restrict server access now and apply the emergency patch for versions 25 and 26. Related Posts: Critical MongoDB Security Vulnerabilities Require Immediate Patching CVE-2026-73125: Ebyte NA111-M Flaws Let Attackers Fully Compromise the Device D-Link DIR-X1860Z Flaw Lets Attackers Change the Admin Password Without Login The post PaperCut NG/MF Vulnerability Exploited in the Wild, Emergency Patch Released appeared first on Daily Cyb
     
  • ✇Cybersecurity News
  • Public Disclosure: Unpatched Log4j RCE Flaw in FilteredObjectInputStream, No CVE Assigned Do Son
    An unpatched Log4j RCE vulnerability was publicly disclosed on Apache's issue tracker. No CVE is assigned and no fix exists yet. Workaround inside. Related Posts: GitLab Updates Fix Arbitrary Command Execution Vulnerability FreeBSD Patches Eight Kernel Vulnerabilities UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products The post Public Disclosure: Unpatched Log4j RCE Flaw in FilteredObjectInputStream, No CVE Assigned appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Lazarus Exploits Windows Zero-Day in Operation Dream Job Attacks Do Son
    Lazarus exploited a Windows zero-day (CVE-2026-68820) in Operation Dream Job to hit defense firms with fake job offers and a new backdoor. Related Posts: UNC6671 Vishing Extortion Rebrands Across 5 Brands Greatness PhaaS Platform Steals Microsoft 365 Tokens Past MFA SMOKE#SCREEN Campaign Abuses ScreenConnect RMM for Stealthy Remote Access The post Lazarus Exploits Windows Zero-Day in Operation Dream Job Attacks appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Microsoft August 2026 Patch Tuesday Fixes WinSock Zero-Day Exploited in the Wild Do Son
    Microsoft August 2026 Patch Tuesday fixes 421 flaws, including CVE-2026-68820, a WinSock zero-day exploited in the wild by Lazarus Group. Related Posts: Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution MariaDB Low-Privilege Remote Code Execution Chain: Full Details and PoC Exploit Code Publicly Disclosed The post Microsoft August 2026 Patch Tuesday Fixes WinSock Zero-Day Exploited in the Wild appeared first on Daily CyberSecurity
     
  • ✇Cybersecurity News
  • Metabase SQL Injection Zero-Day (CVSS 10) Exploited Do Son
    A critical Metabase SQL injection zero-day (CVSS 10) is exploited in the wild. Unauthenticated attackers gain admin access. Patch now. Related Posts: CVE-2026-27912: PoC Released for SYSTEM Privilege Flaw CVE-2026-58231 (CVSS 10.0) and Code Injection RCE Flaws Top SAP August 2026 Patch Day Windows PnP Attack Chain Turns a USB Plug Into SYSTEM: Details and PoC Now Public The post Metabase SQL Injection Zero-Day (CVSS 10) Exploited appeared first on Daily CyberSecurity.
     
❌
❌