Z „Igiho stránky o virech“ se stává agregátor veřejných bezpečnostních zdrojů.

Sleduju 52 zdrojů z 13 zemí — národní CERTy ze střední Evropy, výrobce a threat-intel týmy — a skládám je do jednoho chronologického přehledu v češtině. V databázi je 3 032 položek.

Umím toho spoustu, třeba i generovat týdenní reporty, přičemž AI se snaží o agregaci informací tak, aby to nebyla úplná nuda. Více na stránce o projektu.

Posledních 7 dnů

CZ · EN/orig

185 karet z 190 položek · strana 1 z 4

41

Apple Patches iOS and macOS, (Mon, Aug 17th)

Apple today released updates for iOS/iPadOS (26 and 18) and macOS 26. This update fixes 108 vulnerabilities and comes about two weeks after the much smaller macOS update that addressed the single screen-sharing vulnerability. This vulnerability did not affect iOS/iPadOS. None of the vulnerabilities has been exploited so far. There are a few WebKit vulnerabilities, but no standalone Safari patch for older operating systems. 87 of the vulnerabilities affect only iOS 18, making this more of an iOS…

Apple US

SANS Internet Storm Ctr. ·

Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities

Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts.Key takeawaysStorm-0501 demonstrates that cloud-first ransomware groups have shifted from simple endpoint encryption to the total hijacking of cloud tenants.Storm-0501 systematically…

Tenable Microsoft US

Tenable Research ·

Apple Screen Sharing Security, (Mon, Aug 17th)

About 20 years ago, with macOS 10.5 (Leopard), Apple introduced screen sharing. Apple did not invent a new protocol for screen sharing. Instead, it used the established VNC protocol. VNC is a pretty simple, unencrypted protocol using TCP port 5900. Historically, the protocol used a simple global password for authentication. Apple adapted the protocol for its own use, but overall, left the VNC protocol itself alone. A couple of weeks ago, two severe vulnerabilities exposed issues Apple…

Apple US

SANS Internet Storm Ctr. ·

17th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of its technology infrastructure and disrupted public services related to illicit-drug monitoring and legal processes. Officials confirmed that some files were encrypted but stated that no data theft was detected during the incident. MyDr, Poland’s primary…

KEV ✓ EPSS 0.00 CVSS 9.8 CVE-2026-53413 CVE-2026-65400 CVE-2026-68820 CVE-2026-71362 Microsoft Apple Adobe Zoom veřejná správa zdravotnictví obrana energetika IL

Check Point Research ·

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

Microsoft Defender’s latest patch bypass shows a familiar problem. A newly disclosed Microsoft Defender flaw called ShieldBreak shows that fixing one attack path doesn’t always close every route to the same result. Microsoft has assigned ShieldBreak the identifier CVE-2026-69414 and confirmed it is an elevation of privilege (EoP) vulnerability in the Microsoft Malware Protection Engine. Microsoft says it is still working on a security update. If that sounds somehow familiar, you’re probably…

EPSS 0.00 CVE-2026-69414 Microsoft US 3 zdrojů

Malwarebytes Labs · BleepingComputer · Microsoft Security

CISA Adds One Known Exploited Vulnerability to Catalog 

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive…

KEV ✓ CVE-2025-62593 Ray-Project veřejná správa US 2 zdrojů

CISA Advisories · CISA KEV

Fake TikTok rewards promise cash you’ll never get

TikTok-branded “rewards” pages are promising users cash for checking in every day, completing small tasks, and earning points. Those points supposedly convert into real money, and the balances look enormous. A countdown timer usually warns that your balance is about to expire. But when you try to withdraw it, there’s always something else you need to do first. If you just want the short version TikTok does have a legitimate Creator Rewards Program, but it doesn’t work like the sites we’re…

TikTok US

Malwarebytes Labs ·

Update your Mac: Screen Sharing vulnerability exploited in the wild

The Dutch National Cyber Security Centre (NCSC) issued a warning after being notified of several incidents where a vulnerability in Apple’s Screen Sharing feature was exploited to install Monero cryptominers. The vulnerability, tracked as CVE-2026-65400, was patched by Apple on August 6. It is an authentication-bypass flaw in macOS Screen Sharing that can let an attacker on the network connect without valid credentials. macOS’s built-in Screen Sharing service is a remote-control feature…

EPSS 0.00 CVE-2026-65400 Apple US

Malwarebytes Labs ·

Why Facebook’s war on ad blockers could help scammers

Reports that uBlock Origin is stepping back from the never-ending effort to filter Facebook ads are a reminder that ad blocking is no longer only an argument about inconvenience, publishers, and lost advertising revenue. It is also an issue of security. For years, ad blockers have occupied an uncomfortable place in the web economy. Publishers and platforms rely on advertising to fund their services, while users install blockers to escape intrusive banners, autoplay videos, tracking scripts, and…

Meta uBlock Origin US

Malwarebytes Labs ·

A week in security (August 10 – August 16)

Last week on Malwarebytes Labs: Apple now uses iPhone alerts for targets of mercenary spyware WhatsApp is testing a new warning for scam messages New Android malware lets criminals use your bank card in real time Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits “Zoomsday” flaws could let one Zoom participant attack another Patch Tuesday: Update now to fix 421 flaws, including three zero-days Fake CCleaner installs GhostDesk Chrome spyware Valve warns Steam hardware…

Apple WhatsApp Google Meta US

Malwarebytes Labs ·

GitLab Critical Patch Release: 19.2.4, 19.1.6, 19.0.8, 18.11.11

On August 17, 2026, we released versions 19.2.4, 19.1.6, 19.0.8, 18.11.11 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately. GitLab.com and GitLab Dedicated are already running the patched version. GitLab.com and GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities…

CVSS 9.4 CVE-2026-19478 CVE-2026-19650 GitLab US

GitLab Security ·

3

2

The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure

Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.Key TakeawaysTaiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts,…

CVE-2025-3248 Tenable Palo Alto Networks veřejná správa energetika US

Tenable Research ·

14

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: BroadWorks Crosswork Industrial Ethernet 1000 Series Switches Packaged Contact Center Enterprise and Unified Contact Center Enterprise RoomOS Secure Workload Unified Intelligence Center To fully remediate vulnerabilities to be disclosed on August 19, 2026, Cisco strongly…

Cisco US

Cisco PSIRT ·

Top enterprise DAST tools in 2026

Compare the top enterprise DAST tools of 2026 on authenticated coverage, API discovery, exploit validation, governance, compliance, and AI pentesting Category: DevSec Tools & Comparisons

BE

Aikido Security ·

Upozorňujeme na řetězec kritických zranitelností „wp2shell“ ve WordPress

Upozorňujeme na dvojici zranitelností ve WordPress Core označovaných jako wp2shell (CVE-2026-63030 a CVE-2026-60137), které mohou při kombinovaném zneužití vést ke vzdálenému spuštění kódu (RCE) bez nutnosti přihlášení.

KEV ✓ EPSS 0.96 CVSS 9.0 CVE-2026-60137 CVE-2026-63030 WordPress Cisco Microsoft Progress WORDPRESS CZ US AT FR 5 zdrojů

NÚKIB · Cisco Talos · Elastic Security · CERT.at · CERT-FR – alerty

Apple now uses iPhone alerts for targets of mercenary spyware

Apple has expanded its threat-notification system for targets of mercenary spyware. Apple now shows a warning directly on an iPhone’s Lock Screen and in Settings when it believes the device owner has been targeted by mercenary spyware. The new on-device alert is meant to make a high-risk warning harder to overlook and complements notifications by email and through the user’s Apple Account page. In the explanation, Apple states: “Apple threat notifications are high-confidence alerts that a user…

Apple US

Malwarebytes Labs ·

Nový malware zneužívá Android telefony k NFC platebním podvodům

Nový malware s názvem WindRelay v kombinaci s trojanem SpyNote umožňuje zneužít zařízení s Androidem k bezkontaktním platebním podvodům. Útočníci oběť pomocí phishingu, SMS nebo telefonátu přesvědčí k instalaci škodlivé aplikace a následně k přiložení platební karty k telefonu, například pod záminkou ověření identity či změny PINu. Malware zachycenou NFC komunikaci v reálném čase přenáší do zařízení útočníka, který tak může kartu využít k platbám nebo výběrům hotovosti. Mezi listopadem 2025 a…

finance CZ

CSIRT.CZ (CZ.NIC) ·

WhatsApp is testing a new warning for scam messages

Meta announced it’s rolling out a new feature for WhatsApp users in the fight against scammers. Scam Alert is an optional beta feature that uses an on-device machine-learning model to flag likely scam messages from people who are not in a user’s contacts. The Scam Alert feature arrives as scammers increasingly use WhatsApp for impersonation, fake jobs, fake sales, investment fraud, romance baiting, malicious links, and payment requests. These campaigns often begin on another platform before…

Meta US

Malwarebytes Labs ·

APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit

Introduction CoolClient is a backdoor family attributed to the HoneyMyte APT group (also known as Mustang Panda) that has been used in their cyber-espionage campaigns targeting organizations across Asia and Russia. It supports such capabilities as keylogging, clipboard theft, credential harvesting, file management, system reconnaissance, and plugin-based extensions. Since its first public disclosure by Sophos in 2022 and subsequent analysis by Trend Micro in 2023, CoolClient has continued to…

veřejná správa RU

Securelist (Kaspersky) ·

Varovanie pred rizikami cestných meradiel

Národný bezpečnostný úrad varuje pred významnou kybernetickou hrozbou spojenou s používaním viacerých typov cestných rýchlomerov s kamerou. Bezpečnostná analýza identifikovala viaceré riziká a dotknutým subjektom odporúča predmetné produkty vo svojej infraštruktúre identifikovať. Národný bezpečnostný úrad podľa § 5 ods. 1 písm. q) v spojení s § 27 ods. 1 písm. a) a ods. 2 zákona... The post Varovanie pred rizikami cestných meradiel appeared first on SK-CERT.

doprava veřejná správa SK

SK-CERT (NBÚ SR) ·

ZDI-26-526: (0Day) PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of PAX Technology Q80. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-19910, CVE-2026-19911.

CVSS 7.5 CVE-2026-19910 CVE-2026-19911 PAX Technology US

Zero Day Initiative ·