Aggregator
Microsoft Warns of Attackers Using Trusted HPE Operations Agent for Malware-Free Intrusions
A recent intrusion uncovered by security researchers revealed a calculated attack campaign that used a legitimate enterprise management tool as a weapon. The threat actor gained access through a compromised third-party IT services provider, then quietly moved through the victim’s environment using tools that were already approved and running. No obvious malware was dropped, and […]
The post Microsoft Warns of Attackers Using Trusted HPE Operations Agent for Malware-Free Intrusions appeared first on Cyber Security News.
Держите криптовалюту в Transit Finance? Проверьте кошельки после атаки на сеть TRON
成果分享 | [ISSTA 2026]HScope:构建鸿蒙生态安全的“火眼金睛”
CVE-2026-4094 | realmag777 FOX Plugin up to 1.4.5 on WordPress Configuration admin_head woocs_reset authorization (EUVD-2026-30507)
CVE-2026-8654 | Delphix Continuous Data IBM Db2 Connector os command injection (EUVD-2026-30508)
CVE-2026-5229 | m615926 Receive Notifications After Form Submitting Plugin Cookie form_notify_line_email improper authentication (EUVD-2026-30516)
CVE-2026-6646 | Dream-Theme The7 Plugin up to 14.3.2 on WordPress Shortcode dt_default_button cross site scripting (EUVD-2026-30509)
CVE-2026-8398 | AVB Disc Soft DAEMON Tools Lite up to 12.5.0.2434 daemon-tools.cc malicious code (EUVD-2026-30514)
CVE-2026-41970 | Huawei HarmonyOS/EMUI Distributed File System out-of-bounds write (EUVD-2026-30534)
Cyber Pioneers Ponder Past as Prologue
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-42897 Microsoft Exchange Server Cross-Site Scripting Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Thinking carefully before adopting agentic AI
CMD
You must login to view this content