SentinelaTI

Threat Intelligence OSINT · pt-PT

Filtros
126 resultados

Ameaças Recentes

126 itens correspondem aos filtros
CríticoMalwareCVSS 10.0NVD · 1d

CVE-2026-82456 — CVSS 10.0

argocd-mcp 0.8.0 binds its HTTP transport to every network interface and accepts MCP sessions without requiring caller credentials when ARGOCD_API_TOKEN is configured. Attackers who can reach the listener can invoke the full tool surface using the operator's stored token to create applications, request syncs, and modify Argo CD resources.

CVE-2026-82456
CríticoGeralCVSS 10.0NVD · 3d

CVE-2026-81735 — CVSS 10.0

startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was given, so startSseAndStreamableHttpMcpServer bound the Streamable HTTP and SSE MCP transports to every interface, and its authentication middleware was optional: middlewares are applied only when a caller supplies them. The @agent-infra/mcp-server-commands and @agent-infra/mcp-ser

CVE-2026-81735
CríticoMalwareCVSS 9.8NVD · 17h

CVE-2026-15980 — CVSS 9.8

The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. This makes it possible for unauthenticated attackers to generate an activation token for an unconfirmed user account and obtain a valid authentication c

CVE-2026-15980
CríticoMalwareCVSS 9.8NVD · 1d

CVE-2026-82460 — CVSS 9.8

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoints that fails to properly validate path normalization. Attackers can use path traversal sequences to read, write, move, or copy files outside the configured root directory.

CVE-2026-82460
CríticoVulnerabilidadeCVSS 9.8NVD · 1d

CVE-2026-82452 — CVSS 9.8

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly accessing unprotected endpoints without providing valid credentials.

CVE-2026-82452
CríticoMalwareCVSS 9.8NVD · 1d

CVE-2026-82448 — CVSS 9.8

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated attackers to execute arbitrary database queries. Attackers reaching the child node port can present the hardcoded key during WebSocket handshake, then dispatch SQL queries through the onWebSocketDataFromChildNode handler to read and modify user records and camera configuration.

CVE-2026-82448
CríticoVulnerabilidadeCVSS 9.8NVD · 2d

CVE-2026-19286 — CVSS 9.8

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.

CVE-2026-19286
CríticoMalwareCVSS 9.8NVD · 2d

CVE-2026-82277 — CVSS 9.8

Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection. Attackers on the same network can invoke PromoteRollout, AbortRollout, RestartRollout, SetRolloutImage, UndoRollout, and RetryRollout operations across all namespaces accessible to the operator's kubeconfig.

CVE-2026-82277
CríticoMalwareCVSS 9.8NVD · 2d

CVE-2026-82266 — CVSS 9.8

Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers. Attackers can reach port 9644 without credentials to create and delete broker accounts, modify cluster configuration, and disrupt partition replication.

CVE-2026-82266
CríticoGeralCVSS 9.8NVD · 3d

CVE-2026-81707 — CVSS 9.8

openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inject ANSI escape sequences that forge the fingerprint verification line displayed to users. Attackers can deliver a crafted identity bundle through normal contact-exchange flows or keyserver responses to manipulate terminal output and display a fraudulent fingerprint, bypassing th

CVE-2026-81707
CríticoGeralCVSS 9.8NVD · 3d

CVE-2026-81702 — CVSS 9.8

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, allowing attackers to substitute public keys in identity stores. Attackers can replace legitimate public keys with their own while maintaining the claimed fingerprint, enabling silent key substitution where encryption uses attacker keys and signature verification appears valid.

CVE-2026-81702
CríticoMalwareCVSS 9.8NVD · 5d

CVE-2026-79787 — CVSS 9.8

Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauthenticated attackers to spoof user identity. Attackers can extract usernames from unsigned Authorization headers and impersonate any user, including service accounts, to read, write, and delete arbitrary data.

CVE-2026-79787
CríticoVulnerabilidadeCVSS 9.8NVD · 5d

CVE-2026-16286 — CVSS 9.8

Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Software Repository Management allows Upload a Web Shell to a Web Server. This issue affects Software Repository Management: before 2fb4acee.

CVE-2026-16286
CríticoGeralCVSS 9.1NVD · 1d

CVE-2026-82454 — CVSS 9.1

The Omnivore API (packages/api) before the fix in commit abf53d6 contains an authentication bypass in Apple sign-in token verification. The decodeAppleToken function extracted the 'alg' field from the attacker-supplied JWT header and passed it as the sole allowed algorithm to jwt.verify(). Using jsonwebtoken v8 (which does not validate key/algorithm compatibility), an attacker can set alg=HS256 an

CVE-2026-82454
CríticoVulnerabilidadeCVSS 9.1NVD · 2d

CVE-2026-3627 — CVSS 9.1

IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

CVE-2026-3627
InformativoVulnerabilidadeCERT-EU News · 5s

2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway

On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). CERT-EU recommends updating affected devices as soon as possible.

InformativoVulnerabilidadeCERT-EU News · 5s

2026-007: Critical Vulnerability in Windows Netlogon

On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerabi

InformativoMalwareCERT-EU News · 5s

2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC

On 23 March 2026, Citrix published a security advisory addressing multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway. These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations. At the time of writing, there is no public evidence of activ

InformativoIA & CibersegurançaDark Reading · 6s

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

InformativoIA & CibersegurançaDark Reading · 6s

[Virtual Event] Building a Secure AI Strategy for the Enterprise

InformativoGeralThe Register — Security · 14h

Turns out Brits would quite like their private messages to stay private

Polling finds two-thirds don't trust this government, or any future one, with access to their encrypted chats

InformativoGeralSANS ISC Diaries · 15h

YARA-X 1.20.0 Release, (Sun, Aug 30th)

YARA-X&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s 1.20.0 release brings 14 improvements and 13 bugfixes. 

InformativoMalwareSecurityWeek · 1d

Hasbro Data Breach Exposed Employee Personal Information

A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach. The post Hasbro Data Breach Exposed Employee Personal Information appeared first on SecurityWeek .

InformativoGeralMicrosoft Security Blog · 1d

TerminalFix campaign deploys a reverse tunnel through multistage intrusion

Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog .

InformativoMalwareThe Hacker News · 2d

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the

InformativoGeralSchneier on Security · 2d

Friday Squid Blogging: Truckload of Squid Spills in Rhode Island

[object Object]

InformativoGeralThe Register — Security · 2d

Researcher shows how Claude Code can be tricked simply by asking it to summarize a website

More prompt-injection hijinks from wunderwuzzi

InformativoMalwareDark Reading · 2d

Hundreds of OpenAI Agents Invaded Hugging Face Servers

The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.

InformativoIA & CibersegurançaDark Reading · 2d

Offensive Security Investments Surge as AI Threats Increase

Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices.

InformativoVulnerabilidadeThe Hacker News · 2d

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on wh

InformativoGeralThe Hacker News · 2d

19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code

Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and

InformativoGeralThe Register — Security · 2d

US government snitch-finder pleads guilty to leaking state secrets to foreign spies

The IT specialist began contacting a foreign government within days of being assigned to the DIA’s Insider Threat Division

InformativoMalwareDark Reading · 2d

You Need Cyber Deception for OT

The frustrating reality after an OT cyberattack: no data, no trail, and no history.