2161 items
Unread (2161) All Dismissed
INFO
Frontier AI and the Future of Defense: Your Top Questions Answered
rss:unit42 threat-actorsmalwarenation-state 44d ago
HIGH
CVE-2026-41205 (CVSS 7.5) — Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vuln...
NVD CVE-2026-41205 44d ago
HIGH
CVE-2026-31532 (CVSS 7.8) — In the Linux kernel, the following vulnerability has been resolved: can: raw: fix ro->uniq use-afte...
NVD CVE-2026-31532 45d ago
CRITICAL
CVE-2026-6887 (CVSS 9.8) — Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a SQL Injection vul...
NVD CVE-2026-6887 45d ago
CRITICAL
CVE-2026-6886 (CVSS 9.8) — Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has a Authentication By...
NVD CVE-2026-6886 45d ago
CRITICAL
CVE-2026-6885 (CVSS 9.8) — Borg SPM 2007 (Sales Ended in 2008) developed by BorG Technology Corporation has an Arbitrary File U...
NVD CVE-2026-6885 45d ago
CRITICAL
CVE-2026-3960 (CVSS 9.8) — A critical remote code execution vulnerability exists in the unauthenticated REST API endpoint /99/I...
NVD CVE-2026-3960 45d ago
INFO
Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System
rss:unit42 threat-actorsmalwarenation-state 45d ago
CRITICAL
CVE-2026-41179 (CVSS 9.8) — Rclone is a command-line program to sync files and directories to and from different cloud storage p...
NVD CVE-2026-41179 45d ago
HIGH
CVE-2026-31527 (CVSS 7.8) — In the Linux kernel, the following vulnerability has been resolved: driver core: platform: use gene...
NVD CVE-2026-31527 45d ago
HIGH
CVE-2026-31500 (CVSS 7.8) — In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btintel: serialize b...
NVD CVE-2026-31500 45d ago
HIGH
CVE-2026-31489 (CVSS 7.8) — In the Linux kernel, the following vulnerability has been resolved: spi: meson-spicc: Fix double-pu...
NVD CVE-2026-31489 45d ago
HIGH
CVE-2026-31455 (CVSS 7.8) — In the Linux kernel, the following vulnerability has been resolved: xfs: stop reclaim before pushin...
NVD CVE-2026-31455 45d ago
HIGH
CVE-2026-6855 (CVSS 7.1) — A flaw was found in InstructLab. A local attacker could exploit a path traversal vulnerability in th...
NVD CVE-2026-6855 45d ago
MEDIUM
CVE-2026-6848 (CVSS 5.4) — A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive ...
NVD CVE-2026-6848 46d ago
INFO
When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks
rss:unit42 threat-actorsmalwarenation-state 46d ago
INFO
CVE-2026-41144 (CVSS 0) — F´ (F Prime) is a framework that enables development and deployment of spaceflight and other embedde...
NVD CVE-2026-41144 46d ago
HIGH
CVE-2026-40938 (CVSS 7.5) — Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting ...
NVD CVE-2026-40938 46d ago
INFO
‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty
Krebs breachesthreat-actors 46d ago
CRITICAL
CVE-2026-5965 (CVSS 9.8) — NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated l...
NVD CVE-2026-5965 47d ago
CRITICAL
CVE-2026-32311 (CVSS 9.8) — Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, tr...
NVD CVE-2026-32311 47d ago
HIGH
CVE-2026-31430 (CVSS 7.1) — In the Linux kernel, the following vulnerability has been resolved: X.509: Fix out-of-bounds access...
NVD CVE-2026-31430 48d ago
INFO
Fracturing Software Security With Frontier AI Models
rss:unit42 threat-actorsmalwarenation-state 48d ago
INFO
Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)
rss:unit42 threat-actorsmalwarenation-state 50d ago
HIGH
CVE-2026-40476 (CVSS 7.5) — graphql-go is a Go implementation of GraphQL. In versions 15.31.4 and below, the OverlappingFieldsCa...
NVD CVE-2026-40476 50d ago
CRITICAL
CVE-2026-29013 (CVSS 9.8) — libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling wher...
NVD CVE-2026-29013 50d ago
HIGH
CVE-2026-40527 (CVSS 7.8) — radare2 prior to commit bc5a890 contains a command injection vulnerability in the afsv/afsvj command...
NVD CVE-2026-40527 50d ago
HIGH
CVE-2026-40518 (CVSS 7.1) — ByteDance DeerFlow before commit 2176b2b contains a path traversal and arbitrary file write vulnerab...
NVD CVE-2026-40518 50d ago
CRITICAL
CVE-2025-15625 (CVSS 9.8) — Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in...
NVD CVE-2025-15625 51d ago
HIGH
CVE-2025-15624 (CVSS 7.5) — Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.  In ...
NVD CVE-2025-15624 51d ago
HIGH
CVE-2025-15623 (CVSS 7.5) — Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System In...
NVD CVE-2025-15623 51d ago
INFO
A Deep Dive Into Attempted Exploitation of CVE-2023-33538
rss:unit42 CVE-2023-33538threat-actorsmalware 51d ago
CRITICAL
CVE-2026-27820 (CVSS 9.8) — zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3...
NVD CVE-2026-27820 51d ago
HIGH
CVE-2026-41035 (CVSS 7.4) — In rsync 3.0.1 through 3.4.1, receive_xattr relies on an untrusted length value during a qsort call,...
NVD CVE-2026-41035 52d ago
HIGH
CVE-2026-6351 (CVSS 7.5) — MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticat...
NVD CVE-2026-6351 52d ago
CRITICAL
CVE-2026-6350 (CVSS 9.8) — MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing ...
NVD CVE-2026-6350 52d ago
CRITICAL
CVE-2026-6349 (CVSS 9.8) — The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticat...
NVD CVE-2026-6349 52d ago
HIGH
CVE-2026-6348 (CVSS 8.8) — WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing...
NVD CVE-2026-6348 52d ago
HIGH
CVE-2026-5363 (CVSS 8.8) — Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allow...
NVD CVE-2026-5363 52d ago
HIGH
CVE-2026-33805 (CVSS 8.6) — @fastify/reply-from v12.6.1 and earlier and @fastify/http-proxy v11.4.3 and earlier process the clie...
NVD CVE-2026-33805 53d ago
CRITICAL
CVE-2026-33808 (CVSS 9.1) — Impact@fastify/express v4.0.4 and earlier fails to normalize URLs before passing them to Express mid...
NVD CVE-2026-33808 53d ago
HIGH
Patch Tuesday, April 2026 Edition
Krebs breachesthreat-actorszero-day 53d ago
HIGH
CVE-2026-27289 (CVSS 7.8) — Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when...
NVD CVE-2026-27289 53d ago
MEDIUM
CVE-2026-40447 (CVSS 5.1) — Integer overflow or wraparound vulnerability in Samsung Open Source Escargot allows undefined behavi...
NVD CVE-2026-40447 55d ago
MEDIUM
CVE-2026-40446 (CVSS 6.9) — Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source E...
NVD CVE-2026-40446 55d ago
MEDIUM
CVE-2026-25204 (CVSS 6.2) — Deserialization of untrusted data vulnerability in Samsung Open Source Escargot Java Script allows d...
NVD CVE-2026-25204 55d ago
HIGH
CVE-2026-32146 (CVSS 7.8) — Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows a...
NVD CVE-2026-32146 56d ago
HIGH
CVE-2026-40180 (CVSS 7.5) — Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs gen...
NVD CVE-2026-40180 57d ago
CRITICAL
CVE-2026-6068 (CVSS 9.6) — NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling ...
NVD CVE-2026-6068 57d ago
HIGH
CVE-2021-47961 (CVSS 8.1) — A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows ...
NVD CVE-2021-47961 58d ago
TL;DR
What are the next steps for security leaders in this new age of frontier AI? We answer the top 10 questions customers are asking. The post Frontier AI and the Future of Defense: Your Top Questions Answered appeared first on Unit 42 .
threat-actorsmalwarenation-state
Read full story ↗