Situational news & topics
Current cyber situation from curated feeds
Aggregated from BSI Bürger-CERT, BSI WID, SANS NewsBites, Krebs on Security, The Hacker News and the Allianz für Cyber-Sicherheit.
- Newssecurityweek
Surfshark Systems Targeted by Hackers
A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors. The post Surfshark Systems Targeted by Hackers appeared first on SecurityWeek .
2026-09-11 09:41 UTC - Newsbleepingcomputer
Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]
2026-09-11 09:39 UTC - Newssecurityweek
Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model. The post Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion appeared first on SecurityWeek .
2026-09-11 08:47 UTC - Newscsoonline
Google’s Early Access is creating a blind spot for malicious apps
Google’s Early Access program is meant to give developers a place to release unfinished apps, gather feedback and handle bugs before a full launch. But new research from Bitdefender Labs suggests the feature may also be giving potentially deceptive applications an unusual…
2026-09-11 08:36 UTC - Newssecurityweek
PaperCut Flaws Exploited in AI-Powered Attacks
A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide. The post PaperCut Flaws Exploited in AI-Powered Attacks appeared first on SecurityWeek .
2026-09-11 08:18 UTC - Newsbleepingcomputer
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]
2026-09-11 07:55 UTC
Editorial
From the blog
CVSS 10.0, Priority Score 0.00 — and Still This Week's Most Urgent Patch
N-able is patching out of band: CVE-2026-86218 allows code execution on the N-central server with no login at all. CVSS v4 10.0 — alongside an EPSS of 0.4 percent and a priority score of 0.00. Why both figures are correct, why the flaw still needs closing today, and what the case reveals about the limits of any external prioritisation.
schwachstellenmanagementrmmThe First 24 Hours After an AI Agent Incident
An agent holding live credentials does something nobody authorised. What happens in the next 24 hours decides both the damage and your ability to notify — and conventional playbooks miss, because they reach for host isolation instead of revoking an identity. The sequence hour by hour, with the second clock that runs in parallel in Europe: 24 hours to the NIS2 early warning, and the logging duty under Article 12 of the AI Act.
ai-securityincident-responseOT Remote Access: How the VPN Became the Attack Surface
BeyondTrust puts more than half of 2024's ransomware incidents on a remote service as the entry point — a VPN appliance, an RDP server. In OT environments those are the same tunnels and jump hosts that keep production running, and they open the first door for attackers.
otnis2
Latest priority advisories
Ranked by priority score — KEV, EPSS, CVSS, recency and CPE relevance.
CVE-2023-46604
[UPDATE] [KEV] [high] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwachstellen
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.
CVE-2026-21962
[KEV] [critical] Oracle Fusion Middleware: Mehrere Schwachstellen
Vulnerability in the Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in product of Oracle Fusion Middleware (component: Weblogic Server Proxy Plug-in for Apache HTTP Server, Weblogic Server Proxy Plug-in for IIS). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in. While the vulnerability is in Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server, Oracle Weblogic Server Proxy Plug-in accessible data. Note: Affected version for Weblogic Server Proxy Plug-in for IIS is 12.2.1.4.0 only. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).
CVE-2024-38475
[UPDATE] [KEV] [high] Oracle Communications: Mehrere Schwachstellen
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected. Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.
CVE-2026-72898
[UPDATE] [KEV] metabase: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CVE-2026-72898)
Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access to the connected Metabase instance.
CVE-2026-48907
[KEV] [critical] Widget Factory Joomla Content Editor: Schwachstelle ermöglicht Codeausführung
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
CVE-2026-20079
[NEW] [KEV] [critical] Cisco Secure Firewall Management Center: Mehrere Schwachstellen
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device.