Bron & ernst

Uw branche
AI Security Medium
28 sep 2026

[The Hacker News] RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

Financieel & VerzekeringenTransport & Logistiek

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
28 sep 2026

Bulletin d'actualité CERTFR-2026-ACT-041 (28 septembre 2026)

Transport & Logistiek

Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
24 sep 2026

Trust and the enticing consultancy offer

Financieel & Verzekeringen

In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem. Hubris might be the real vulnerability that the cyber industry must worry about.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
11 sep 2026

[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

Industrie & Productie

CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCE

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
24 sep 2026

MacSync under the microscope: new delivery methods and a new payload

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Medium
28 sep 2026

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Financieel & VerzekeringenTransport & Logistiek

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p.

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
Mandiant Kritiek
25 sep 2026

ShinyHunters Renewed Mass Exploitation Campaign Targeting Oracle PeopleSoft

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Introduction As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. In June, the threat actor exploited this vulnerability as a zero-day predominan…

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
28 sep 2026

CVE-2026-81355 Virtual Hard Disk (VHD) Miniport Driver Remote Code Execution Vulnerability

Industrie & Productie

Updated an acknowledgement. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Medium
28 sep 2026

NeedyMantis: Unpacking a post-compromise malware family used in targeted operations

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerceIT & Technologie

Microsoft Threat Intelligence identified NeedyMantis, a modular post-compromise malware framework used in targeted intrusions that combines custom loaders, encrypted archives, and extensible components to maintain long-term access and support follow-on operations. The post NeedyMantis: Unpacking a post-compromise malware family used in targeted operations appeared first on Microsoft Security Blog.

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NL Medium
27 sep 2026

NCSC-2026-0394 [1.00] [H/H] Kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Citrix heeft 8 kwetsbaarheden verholpen in NetScaler ADC en NetScaler Gateway.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Kritiek
28 sep 2026

Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
NVD Kritiek
6 sep 2026

CVE-2026-86218 — CVSS 9.8 CRITICAL

Industrie & Productie

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Kritiek
28 sep 2026

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild

Retail & E-commerceIT & Technologie

Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild appeared first on Unit 42.

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
SANS ISC Hoog
28 sep 2026

Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)

Financieel & VerzekeringenIndustrie & Productie

Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today&#;x26;#;39;s update for the current "27" branch does not address security issues, but fixes some functional issues that got caught after…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Kritiek
28 sep 2026

Citrix waarschuwt voor misbruikte kwetsbaarheden: 'Zo snel mogelijk updaten'

IT & Technologie

Citrix waarschuwt voor twee kritieke kwetsbaarheden in Citrix NetScaler ADC en Gateway waar aanvallers actief misbruik van ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Hoog
29 sep 2026

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerce

Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Medium
28 sep 2026

[The Hacker News] ⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
28 sep 2026

Multiples vulnérabilités dans Citrix NetScaler ADC et Gateway (28 septembre 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans Citrix NetScaler ADC et Gateway. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité. Citrix indique que les...

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
22 sep 2026

The Closed Quorum: Inside the first reported autonomous AI C2 implant

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
3 sep 2026

[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)

Industrie & Productie

FreePBX 17.0.2 - Remote Code Execution (RCE)

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
21 sep 2026

Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

Financieel & VerzekeringenIT & Technologie

Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Hoog
16 sep 2026

Data Broker Radaris Loses Domains in Privacy Fight

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement off…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
24 sep 2026

Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure

Financieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Introduction The landscape of software supply chain security has undergone a significant shift. Recent campaigns demonstrate that sophisticated threat actors are systematically targeting the engineering lifecycle by compromising trusted security and programming tools. These intrusions reveal three key tactics: Attackers target trusted security scanners, utility libraries, and AI developer tools to…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

CVE-2026-69522 .NET and Visual Studio Remote Code Execution Vulnerability

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

Security Updates table updated provide links to the KB articles and download center updates. Microsoft recommends installing the updates.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Hoog
25 sep 2026

Storm-3168: Agentic-driven cloud attacks using compromised service principals

Financieel & VerzekeringenRetail & E-commerceIT & Technologie

Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. The post Storm-3168: Agentic-driven cloud attacks using compromised service principals appeared first on Microsoft Security Blog.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
24 sep 2026

NCSC-2026-0389 [1.01] [M/H] Kwetsbaarheid verholpen in WordPress

Financieel & VerzekeringenIndustrie & Productie

De ontwikkelaars van WordPress hebben een kwetsbaarheid verholpen in WordPress. Een kwaadwillende kan de kwetsbaarheid met kenmerk CVE-2026-87902 misbruiken, om zonder authenticatie een lokaal PHP-bestand buiten de actieve themamappen door WordPress te laten inladen.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
15 sep 2026

Iranian cyber targeting of dissidents, activists and journalists

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
5 sep 2026

CVE-2026-67278 — CVSS 9.1 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieIT & Technologie

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue ce…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
25 sep 2026

3 Consulting Myths Debunked by Unit 42 Experts

Financieel & VerzekeringenRetail & E-commerce

Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths Debunked by Unit 42 Experts appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
SANS ISC Hoog
27 sep 2026

Wireshark 4.6.9 Released, (Sun, Sep 27th)

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Wireshark release 4.6.9 fixes 19 vulnerabilities and 16 bugs.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Kritiek
25 sep 2026

NCSC meldt actief misbruik van kritiek WordPress-lek: 'Update nu'

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Aanvallers maken actief misbruik van een kritieke path traversal-kwetsbaarheid in WordPress waardoor websites zijn over te ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Medium
29 sep 2026

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

Overheid & Publieke SectorTransport & LogistiekOnderwijs & OnderzoekIT & Technologie

Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
28 sep 2026

[The Hacker News] Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md persona file," ThreatDown said. "The 39-line prompt directs it to execute tasks received through

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
28 sep 2026

Multiples vulnérabilités dans MongoDB (28 septembre 2026)

Transport & Logistiek

De multiples vulnérabilités ont été découvertes dans MongoDB. Elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
22 sep 2026

Introducing CAIRN: Frontier tracking for AI-integrated malware

Financieel & Verzekeringen

Talos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
3 sep 2026

[webapps] Metabase 0.61.0 - Authenticated Remote Code Execution

Industrie & Productie

Metabase 0.61.0 - Authenticated Remote Code Execution

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
4 sep 2026

Angry Birds: Toy Ghouls’ new toys

Financieel & VerzekeringenIndustrie & Productie

Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Medium
8 sep 2026

Microsoft Plugs Nearly 1,000 Security Holes

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and d…

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
Mandiant Kritiek
8 sep 2026

GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defe…

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
Microsoft MSRC Hoog
25 sep 2026

CVE-2026-78510 Microsoft Outlook and Word Remote Code Execution Vulnerability

Industrie & ProductieIT & Technologie

Updated CVE title and CVSS Score. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Hoog
24 sep 2026

Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Financieel & VerzekeringenRetail & E-commerceIT & Technologie

Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment. The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments appeared first on Microsoft S…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NCSC NL Medium
24 sep 2026

NCSC-2026-0393 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Campaign Classic

Financieel & VerzekeringenIndustrie & Productie

Adobe heeft 18 kritieke kwetsbaarheden verholpen in Adobe Campaign Classic. De kwetsbaarheden betreffen onder meer code- en OS-command-injectie, SQL-injectie, onvoldoende autorisatie, onvoldoende invoervalidatie en Server-Side Request Forgery (SSRF).

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NCSC UK Hoog
15 sep 2026

UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists

Transport & LogistiekRetail & E-commerce

UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
NVD Kritiek
5 sep 2026

CVE-2026-86060 — CVSS 9.8 CRITICAL

Financieel & VerzekeringenTransport & LogistiekIT & Technologie

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
16 sep 2026

Atomic macOS (AMOS) Stealer Activity

Retail & E-commerce

Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
SANS ISC Hoog
25 sep 2026

A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)

Financieel & Verzekeringen

Introduction

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Medium
24 sep 2026

'Android-malware gebruikt vaker vpn voor blokkeren van Google Play Protect'

Industrie & ProductieIT & Technologie

Android-malware gebruikt steeds vaker een vpn-service voor het blokkeren van Google Play Protect om zo detectie door de ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Hoog
28 sep 2026

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

IT & Technologie

The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
AI Security Medium
26 sep 2026

[The Hacker News] Zero Trust for AI Agents Starts With Fixing Zero Visibility

Financieel & VerzekeringenTransport & Logistiek

The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
28 sep 2026

Multiples vulnérabilités dans Citrix NetScaler ADC et Gateway (28 septembre 2026)

Transport & LogistiekIT & Technologie

Le 27 septembre 2026, Citrix a publié un avis de sécurité concernant plusieurs vulnérabilités qui affectent NetScaler ADC et Gateway. Parmi celles-ci, les vulnérabilités CVE-2026-88771 et CVE-2026-88772 permettent une exécution de code arbitraire à distance par un attaquant non authentifié. Ces...

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
17 sep 2026

Should you care about an “AI slowdown?”

Financieel & VerzekeringenIndustrie & Productie

In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
2 sep 2026

[dos] EVerest 2025.9.0 - DoS

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

EVerest 2025.9.0 - DoS

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
1 sep 2026

Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set

Financieel & VerzekeringenIndustrie & Productie

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Krebs on Security Hoog
1 sep 2026

FBI Probes Service Selling 153M+ Drivers Licenses

Financieel & VerzekeringenOverheid & Publieke SectorTransport & Logistiek

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity a…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Mandiant Hoog
1 sep 2026

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceIT & Technologie

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. Thi…

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

CVE-2026-85921 Windows Secure Kernel Mode Elevation of Privilege Vulnerability

IT & Technologie

Updated an acknowledgement. This is an informational change only.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Medium
22 sep 2026

Unmasking EvilTokens: Getting to the root of device code phishing

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations. The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on…

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NL Medium
23 sep 2026

NCSC-2026-0392 [1.00] [M/H] Kwetsbaarheden verholpen in IBM Langflow OSS en IBM MQ Appliance

Industrie & ProductieIT & Technologie

IBM heeft 12 kwetsbaarheden verholpen in IBM MQ, IBM MQ Appliance en Langflow OSS. De kwetsbaarheden kunnen leiden tot het uitvoeren van willekeurige code of commando's. Vier kwetsbaarheden zijn als kritiek aangemerkt en kunnen zonder authenticatie en gebruikersinteractie op afstand worden misbruikt.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Kritiek
4 sep 2026

CVE-2026-85594 — CVSS 9.8 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekIT & Technologie

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
10 sep 2026

The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

Industrie & ProductieRetail & E-commerce

Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
SANS ISC Hoog
24 sep 2026

One URL, Three Different Tricks, (Thu, Sep 24th)

Financieel & Verzekeringen

Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link:

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Medium
24 sep 2026

Verdachte achter ransomware-aanvallen moet 1,2 miljoen dollar betalen

Industrie & ProductieTransport & Logistiek

Een 35-jarige Armeense man is in de Verenigde Staten wegens het uitvoeren van ransomware-aanvallen veroordeeld tot een ...

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
The Hacker News Medium
28 sep 2026

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims

Financieel & VerzekeringenTransport & Logistiek

RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Hoog
24 sep 2026

[Microsoft MSRC] CVE-2026-65675 CoPilot Chat Security Feature Bypass Vulnerability

Financieel & VerzekeringenIndustrie & Productie

Updated the fixed version information and download link. The fix was previously believed to be included in Dynamics 365 Server (on-premises) version 6.2; however, it has been confirmed that the fix is included in Dynamics 365 Server v9.1 (on-premises) Update 1.45 (version 9.1.0045.0011). The download link, release notes, and build number has been updated accordingly in the Security Updates table. …

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
CERT-FR Hoog
25 sep 2026

Multiples vulnérabilités dans les produits IBM (25 septembre 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à la confidentialité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
17 sep 2026

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use

Financieel & Verzekeringen

Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
2 sep 2026

[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting

Financieel & Verzekeringen

Bludit CMS 3.20.0 - Reflected Cross-Site Scripting

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Kaspersky Hoog
31 aug 2026

ValleyRAT masquerading as adware

Financieel & Verzekeringen

Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft MSRC Hoog
25 sep 2026

Chromium CVE-2026-87489: Memory corruption in V8

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

Information published.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Microsoft Security Blog Medium
10 sep 2026

Detect and disrupt AI-themed attacks with Microsoft Defender

Financieel & VerzekeringenRetail & E-commerceIT & Technologie

See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
NCSC NL Medium
23 sep 2026

NCSC-2026-0386 [1.01] [H/H] Kwetsbaarheid verholpen in F5 Networks BIG-IP Access Policy Manager

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

F5 Networks heeft een kwetsbaarheid verholpen in BIG-IP Access Policy Manager (APM). De kwetsbaarheid stelt een ongeauthenticeerde kwaadwillende in staat om malafide code uit te voeren. Hiertoe dient de kwaadwillende malafide netwerkverkeer naar het kwetsbare systeem te versturen.

Aanbevolen actie
Volg de vendor-advisory en plan de update in het reguliere patchvenster. Monitor of er PoC-exploit gepubliceerd wordt — dan herzien.
NVD Kritiek
4 sep 2026

CVE-2026-85595 — CVSS 9.8 CRITICAL

Financieel & VerzekeringenIndustrie & ProductieTransport & Logistiek

Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestAuth-protected route without a valid username or pas…

Aanbevolen actie
CVSS 9.0+: behandel als kritiek. Onderzoek of u kwetsbare versies in gebruik heeft via VM-scan. Patch binnen 7 dagen of mitigeer.
Palo Alto Unit 42 Hoog
9 sep 2026

Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

Financieel & VerzekeringenRetail & E-commerce

An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
SANS ISC Hoog
23 sep 2026

Macfinger ClickFix campaign, (Tue, Sep 22nd)

Financieel & Verzekeringen

Introduction

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Security.NL Kritiek
24 sep 2026

Check Point meldt actief misbruik van kritieke vpn-kwetsbaarheid

IT & Technologie

Cybersecuritybedrijf Check Point waarschuwt voor actief misbruik van een kritieke kwetsbaarheid in de vpn-producten die het ...

Aanbevolen actie
Onderzoek direct of u kwetsbaar bent. Patch binnen 7 dagen of mitigeer. Volg de bron-link voor details.
The Hacker News Medium
28 sep 2026

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems, phishing kits, and strangely easy exploit paths kept doing useful work for attackers. Nothing

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
AI Security Medium
22 sep 2026

[Microsoft Security Blog] Unmasking EvilTokens: Getting to the root of device code phishing

Financieel & VerzekeringenIndustrie & ProductieTransport & LogistiekRetail & E-commerceIT & Technologie

EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations. The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on…

Aanbevolen actie
Lees de bron-pagina voor details en volg de aanbevelingen van de leverancier.
CERT-FR Hoog
25 sep 2026

Multiples vulnérabilités dans le noyau Linux d'Ubuntu (25 septembre 2026)

Transport & LogistiekIT & Technologie

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Cisco Talos Hoog
16 sep 2026

Securing the unpatchable in an age of AI-driven vulnerabilities

Financieel & VerzekeringenTransport & LogistiekRetail & E-commerce

Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensatory layer.

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
Exploit-DB Hoog
2 sep 2026

[webapps] PodcastGenerator 3.2.9 - Stored XSS

Zorg & GezondheidFinancieel & VerzekeringenOverheid & Publieke SectorIndustrie & ProductieTransport & LogistiekEnergie & NutsbedrijvenRetail & E-commerceOnderwijs & OnderzoekIT & Technologie

PodcastGenerator 3.2.9 - Stored XSS

Aanbevolen actie
Plan een update binnen het reguliere patchvenster. Check via VM-scan of asset-inventaris of u kwetsbare versies in gebruik heeft.
🔍 Geen advisories gevonden voor deze combinatie. Probeer een ander filter.
Disclaimer: Deze advisories zijn afkomstig van publieke bronnen waaronder NCSC NL, CISA, CISA KEV, NVD (NIST), MITRE CVE, Exploit-DB, Mandiant, Microsoft MSRC, Cisco Talos, Kaspersky, ENISA en BleepingComputer. De samenvattingen zijn bedoeld als eerste oriëntatie. Raadpleeg altijd de originele bronnen voor volledige technische details. SOC Continu is niet aansprakelijk voor beslissingen genomen op basis van deze samenvatting.