French and Spanish authorities took down an online marketplace selling fake identity documents to migrant smuggling rings operating within the European Union. [...]
A vulnerability marked as critical has been reported in Linux Kernel up to 6.12.74/6.18.15/6.19.5. This vulnerability affects the function mmput of the component procfs. The manipulation leads to buffer overflow.
This vulnerability is listed as CVE-2026-43178. The attack must be carried out from within the local network. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.12.74/6.18.15/6.19.5. The affected element is the function amdgpu_dma_buf_move_notify of the component ticket. Executing a manipulation can lead to memory corruption.
The identification of this vulnerability is CVE-2026-43318. The attack needs to be done within the local network. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability described as critical has been identified in Linux Kernel up to 6.19.5. This issue affects the function __ioam6_fill_trace_data of the file ioam6.c of the component Packet Handler. The manipulation results in buffer overflow.
This vulnerability is cataloged as CVE-2026-43186. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Linux Kernel up to 6.19.5. It has been declared as critical. This vulnerability affects the function con2fb_acquire_newinfo. Such manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2026-43123. The attack needs to be initiated within the local network. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.6.127/6.12.74/6.18.15/6.19.5. This issue affects some unknown processing of the component cifs. Executing a manipulation can lead to privilege escalation.
This vulnerability appears as CVE-2026-31693. The attacker needs to be present on the local network. There is no available exploit.
It is advisable to upgrade the affected component.
A new China-linked cybercrime group known as TA4922 has expanded its targeting focus to target European organizations in the U.K., Germany, Italy, and South Africa.
These efforts have been complemented by a "rapid operational tempo" and a continually evolving malware arsenal comprising known families like ValleyRAT (aka Winos 4.0) and Atlas RAT (aka AtlasCross RAT), as well as previously
A vulnerability classified as critical has been found in Linux Kernel up to 6.19.5. Affected by this issue is the function ixp4xx_get_ts_info. Performing a manipulation results in null pointer dereference.
This vulnerability is known as CVE-2026-43173. Access to the local network is required for this attack. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Linux Kernel up to 6.1.166/6.6.129/6.12.76/6.18.15/6.19.5. This affects the function fw_mbox_index_xlate of the component mailbox. Such manipulation leads to out-of-bounds read.
This vulnerability is referenced as CVE-2026-43281. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in openmcdf up to 3.1.2. It has been declared as problematic. This affects the function Storage.EnumerateEntries of the component CFB File Handler. Executing a manipulation can lead to infinite loop.
This vulnerability is handled as CVE-2026-41511. It is possible to launch the attack on the local host. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in MailEnable Enterprise Premium up to 10.54. This vulnerability affects unknown code of the component Login Endpoint. The manipulation of the argument PersistentLogin results in authorization bypass.
This vulnerability is identified as CVE-2026-44400. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability, which was classified as critical, was found in gitroomhq postiz-app. This affects an unknown function of the file .github/workflows/pr-docker-build.yml. Executing a manipulation can lead to code injection.
This vulnerability is tracked as CVE-2026-42298. The attack can be launched remotely. No exploit exists.
Applying a patch is advised to resolve this issue.
A vulnerability was found in Cribl Edge up to 4.17.0. It has been classified as problematic. This vulnerability affects unknown code. This manipulation causes os command injection.
This vulnerability is registered as CVE-2026-45391. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability, which was classified as critical, has been found in Casdoor up to 2.328.0. The affected element is an unknown function. Performing a manipulation results in path traversal.
This vulnerability was named CVE-2026-6815. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability has been found in Microsoft 365 Copilots Business Chat and classified as critical. This issue affects some unknown processing of the component Downstream Component. Performing a manipulation results in injection.
This vulnerability is cataloged as CVE-2026-26164. It is possible to initiate the attack remotely. There is no exploit available.
This product is a managed service, so users do not have direct control over vulnerability countermeasures.
A vulnerability was found in Microsoft 365 Copilots Business Chat. It has been declared as problematic. The impacted element is an unknown function. The manipulation results in improper neutralization of special elements.
This vulnerability is reported as CVE-2026-26129. The attack can be launched remotely. No exploit exists.
This product is a managed service. This means that users are not able to maintain vulnerability countermeasures themselves.
A vulnerability was found in Microsoft Azure Managed Instance for Apache Cassandra. It has been classified as critical. The affected element is an unknown function. The manipulation leads to improper authorization.
This vulnerability is documented as CVE-2026-33844. The attack can be initiated remotely. There is not any exploit available.
This product is a managed service, therefore users are not responsible for maintaining vulnerability countermeasures.
Threat hunting does not fail because security teams lack tools. It fails because the tools are often used as separate workspaces instead of connected parts of the same investigation. A security information event management (SIEM) or extended detection and response (XDR) solution collects and correlates events. Endpoint...