OSINT & geopolitical
60 alerts in this category.
Open-source intelligence on threats outside the CVE ecosystem — geopolitical events, cyber-physical incidents, sanctions, and infrastructure attacks. Curated for security teams that need situational awareness alongside their patch queue.
USN-8726-2: Linux kernel (Raspberry Pi) vulnerabilities
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observ
AppleCVE-2025-10263USN-8729-2: Linux kernel (Raspberry Pi Real-time) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture
MicrosoftCVE-2025-71289USN-8761-2: Linux kernel (Azure FIPS) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture
VMwareCVE-2025-71289USN-8781-1: Linux kernel (NVIDIA Tegra) vulnerabilities
It was discovered that some Arm processors could complete a broadcast translation lookaside buffer (TLB) invalidation before memory writes made through the invalidated translation were globally observ
MicrosoftCVE-2025-10263Stable Channel Update for Desktop
Google Chrome Releases published an advisory on "Stable Channel Update for Desktop". Topic areas: google, chrome, browser, patch. Published September 17, 2026. See the original source linked under Ref
GoogleCVE-2026-93374Dev Channel Update for ChromeOS / ChromeOS Flex
Google Chrome Releases published an advisory on "Dev Channel Update for ChromeOS / ChromeOS Flex". Topic areas: google, chrome, browser, patch. Published September 17, 2026. See the original source li
GoogleStable Channel Update for ChromeOS / ChromeOS Flex
Google Chrome Releases published an advisory on "Stable Channel Update for ChromeOS / ChromeOS Flex". Topic areas: google, chrome, browser, patch. Published September 17, 2026. See the original source
GoogleUSN-8777-1: GNU Bison vulnerability
It was discovered that GNU Bison incorrectly handled grammar-defined configuration variables when generating HTML reports. An attacker could possibly use this issue to execute arbitrary code.
VU#280377: Dokploy is vulnerable to OS command injection
Overview Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerabi
F5USN-8776-1: python-cryptography vulnerabilities
It was discovered that python-cryptography incorrectly accepted objects with immutable buffers when performing certain cipher operations. This would result in corrupted output, contrary to expectation
UbuntuCVE-2023-23931VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control
Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally appl
VU#212479: Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment
Overview A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution
CVE-2026-90999USN-8514-2: OpenSSH vulnerability
USN-8514-1 fixed a vulnerability in OpenSSH. This update provides the corresponding fix for Ubuntu 14.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. Original advisory details: It was discovered that
UbuntuStable Channel Update for Desktop
Google Chrome Releases published an advisory on "Stable Channel Update for Desktop". Topic areas: google, chrome, browser, patch. Published September 15, 2026. See the original source linked under Ref
GoogleCVE-2026-91726USN-8760-1: Linux kernel (NVIDIA) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - User-space API (UA
AppleCVE-2026-52908USN-8761-1: Linux kernel (Azure) vulnerabilities
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture
VMwareCVE-2025-7128914th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider,
MicrosoftCVE-2026-72898Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive in
CiscoCVE-2026-20353Cisco Secure Email Gateway SQL Injection Vulnerability
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the
CiscoCVE-2026-76461Microsoft’s Patching
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record: Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed
MicrosoftNew Warnings About the Risks of AI to Humanity Revive a Long-Running Debate
Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims. The post New Warnings Abou
Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely. The post Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Executio
The Race to Control AI and Protect What Makes Us Human
As researchers warn that misaligned AI could threaten human survival, even beneficial systems may erode the critical thinking that defines our humanity. The post The Race to Control AI and Protect Wha
Telus Warns Customers of Account Breaches
Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records. The post Telus Warns Customers of Account Breaches appeared first on SecurityWeek. ]]>
Revolut discloses data breach exposing financial info, passports
BleepingComputer published an news on "Revolut discloses data breach exposing financial info, passports". Topic areas: ransomware, malware, data-breach, zero-day. Published September 14, 2026. See the
Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up
Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The post Anthropic CEO Dario Amodei Says AI Industry Needs t
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
BleepingComputer published an news on "Hackers exploit Tencent app flaw to deploy GrayRabbit malware". Topic areas: ransomware, malware, data-breach, zero-day. Published September 13, 2026. See the or
Long Term Support Channel Update for ChromeOS
Google Chrome Releases published an advisory on "Long Term Support Channel Update for ChromeOS". Topic areas: google, chrome, browser, patch. Published September 12, 2026. See the original source link
GoogleCVE-2026-79195BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days
Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityW
ChromeSANS Internet Storm Center Advisory — Sep 11, 2026
I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account far
AWSPhishing Research Challenges Conventional Security Awareness Testing
Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks. The post Phishing Research Challenges Conventional Security Awareness
Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023. The post Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison appear
Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model. The post Anthropic Says Russian Hackers Used Claude AI t
Rapid7 Blog Advisory — Sep 11, 2026
This One Goes to Sixteen!Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all
CiscoCVE-2025-66516Kubernetes v1.37: Native Histograms Graduates to Beta
I'm excited to announce that native histogram support for Kubernetes metrics is graduating to Beta and is enabled by default in Kubernetes v1.37! Native histograms (previously introduced as Alpha in K
GoogleArtifactory flaws chained in attacks deploying backdoor malware
BleepingComputer published an news on "Artifactory flaws chained in attacks deploying backdoor malware". Topic areas: ransomware, malware, data-breach, zero-day. Published September 11, 2026. See the
AWSRussian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
The Hacker News published an news on "Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection". Topic areas: zero-day, malware, ransomware, data-breach. Published September 11, 2
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulner
CVE-2026-42016CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85706 GitLab Community Edition and Enterprise Edition Path
CVE-2026-85706CVE-2026-89090 - Denial of service in the event stream header decoder in AWS SDK for Go v2
Bulletin ID: 2026-110-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 10:00 AM PDT Description: An issue exists in the the EventStream header decoder in AWS SD
AWSCVE-2026-89090CVE-2026-18061 - XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin
Bulletin ID: 2026-109-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 09:30 AM PDT Description: The AWS Advanced JDBC Wrapper is an open-source library that en
AWSCVE-2026-18061CVE-2026-89065 and CVE-2026-89066: Issue with projen - Path traversal and OS command injection
Bulletin ID: 2026-108-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 09:00 AM PDT Description: projen is an open-source tool for defining and synthesizing sof
AWSCVE-2026-89065CVE-2026-89332 - Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration
Bulletin ID: 2026-111-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 12:00 PM PDT Description: Kiro IDE is an agentic development environment that makes it ea
AWSCVE-2026-89332Chromium CVE-2026-76018: Privilege elevation in Import
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-76018Chromium CVE-2026-87491: Out of bounds write in V8
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-87491Chromium CVE-2026-85052: Out of bounds read in CrashReporting
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) f
MicrosoftCVE-2026-85052VU#369611: ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index
Overview An out-of-bounds (OOB) memory access vulnerability involving unchecked array indexing has been identified in the exllamav3_ext compute unified device architecture (CUDA) extension. Successful
CVE-2026-84286Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
The Hacker News published an news on "Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware". Topic areas: zero-day, malware, ransomware, data-breach. Published September 11, 2026
CiscoConti ransomware gang member sentenced to 4 years in prison
BleepingComputer published an news on "Conti ransomware gang member sentenced to 4 years in prison". Topic areas: ransomware, malware, data-breach, zero-day. Published September 11, 2026. See the orig
Long Term Support Channel Update for ChromeOS
Google Chrome Releases published an advisory on "Long Term Support Channel Update for ChromeOS". Topic areas: google, chrome, browser, patch. Published September 11, 2026. See the original source link
GoogleCVE-2026-79010SANS Internet Storm Center Advisory — Sep 10, 2026
[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program] ]]>
LinuxAnthropic Researcher Resigns With Warning About the Dangers of AI Development
Both Anthropic and OpenAI have seen high-profile resignations in recent years that were tied to safety concerns. The post Anthropic Researcher Resigns With Warning About the Dangers of AI Development
Organizations Warned of Cisco Secure FMC Exploitation
Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026. The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek. ]]>
CiscoCVE-2026-20079AIs Compress Exploit Timeline
Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it. What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so c
Kubernetes v1.37: Scheduler Preemption for In-Place Pod Resize (Alpha)
In Kubernetes, resource allocation has historically been a static decision made during a Pod's initial scheduling and placement. With the graduation of the core in-Place Pod resize feature to General
KubernetesCisco FMC flaws exploited by ransomware gang, state-sponsored hackers
BleepingComputer published an news on "Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers". Topic areas: ransomware, malware, data-breach, zero-day. Published September 10, 2026. Se
CiscoTrezor warns users of email provider breach, phishing attacks
BleepingComputer published an news on "Trezor warns users of email provider breach, phishing attacks". Topic areas: ransomware, malware, data-breach, zero-day. Published September 10, 2026. See the or
CISA: WatchGuard RCE flaw now exploited in ransomware attacks
BleepingComputer published an news on "CISA: WatchGuard RCE flaw now exploited in ransomware attacks". Topic areas: ransomware, malware, data-breach, zero-day. Published September 10, 2026. See the or
New Android malware encrypts files, steals data, and harasses victims
BleepingComputer published an news on "New Android malware encrypts files, steals data, and harasses victims". Topic areas: ransomware, malware, data-breach, zero-day. Published September 10, 2026. Se
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Hacker News published an news on "Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks". Topic areas: zero-day, malware, ransomware, data-breach. Published September 10, 2
Get alerts that match YOUR environment
This page shows everything in the category. Vulnios narrows it down to alerts that affect your actual asset inventory — only the CVEs you need to act on.
Start a free scan