vulnerability Gitea Vulnerability Exposes Private Container Images without Authentication A significant vulnerability (CVE-2026-27771) has been identified in Gitea, a popular open-source Git repository hosting platform. The flaw allows unauthorized access to private container images, exposing sensitive data w… The Hacker News · May 27, 2026 High CVE-2026-27771CNUSDEcontainergitvulnerability
vulnerability Microsoft Issues Out-of-Band SharePoint Patch Microsoft has released an out-of-band security patch to address a critical remote code execution vulnerability (CVE-2026-45659) in SharePoint Server. The flaw allows authenticated attackers to execute code without elevat… Dark Reading · May 26, 2026 Critical CVE-2026-45659CHremote code executionsharepointzero-day
vulnerability ABB AbilityTM Zenon Remote Transport Vulnerability This advisory from CISA details a vulnerability in ABB AbilityTM Zenon Remote Transport, specifically versions 7.50 through 14. The flaw allows unauthorized access and remote system reboots without authentication, posing… CISA Advisories · May 26, 2026 High CVE-2025-8754WOauthenticationremote rebootcwe-306
threat-intel Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes Italian authorities disrupted a sophisticated piracy operation centered around the CINEMAGOAL app, which provided unauthorized access to streaming services like Netflix and Disney+. The operation, dubbed "Tutto Chiaro,"… BleepingComputer · May 23, 2026 Medium ITFRDEpiracystreamingauthentication
threat-intel In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking This week’s cybersecurity news highlights several incidents, including Iranian hackers targeting US gas station tank monitor systems, a CISA contractor exposing sensitive credentials, a Huawei router vulnerability causin… SecurityWeek · May 22, 2026 High CVE-2024-9643CVE-2026-45401USLUiotcritical infrastructuresupply-chain
threat-intel Google API Keys Remain Active After Deletion This article details a significant vulnerability in Google Cloud Platform (GCP) API key deletion processes. Researcher Joe Leon of Aikido Security discovered that API keys can remain active for up to 23 minutes after del… Dark Reading · May 21, 2026 High USSGapi keysgcpauthentication
vulnerability Max-severity flaw in ChromaDB for AI apps allows server hijacking A critical vulnerability (CVE-2026-45829) has been identified in the ChromaDB project, allowing unauthenticated attackers to execute arbitrary code on exposed servers. This flaw stems from a misplacement of authenticatio… BleepingComputer · May 19, 2026 Critical CVE-2026-45829apipythonfastapi
threat-intel ScadaBR CISA has issued an advisory regarding critical vulnerabilities in ScadaBR version 1.2.0, a SCADA system. The vulnerabilities include missing authentication, OS command injection, and CSRF, potentially allowing unauthenti… CISA Advisories · May 19, 2026 Critical CVE-2026-8602CVE-2026-8603CVE-2026-8604scadavulnerabilityremote code execution
vulnerability ZKTeco CCTV Cameras A vulnerability has been identified in ZKTeco CCTV cameras, specifically models utilizing the SSC335-GC2063-Face-0b77 Solution firmware, allowing unauthorized access to camera credentials and configuration information. T… CISA Advisories · May 19, 2026 Medium CVE-2026-8598CHcctvcameraauthentication
vulnerability Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities Cisco Talos has identified ongoing exploitation of vulnerabilities within Cisco Catalyst SD-WAN Controller and Manager, specifically CVE-2026-20182 and a set of related vulnerabilities (CVE-2026-20133, CVE-2026-20128, an… Cisco Talos · May 14, 2026 High CVE-2026-20182CVE-2026-20133CVE-2026-20128sd-wanciscoauthentication
vulnerability Siemens SIMATIC A vulnerability (CVE-2026-27662) has been identified in Siemens SIMATIC HMI Unified Comfort Panels. The flaw allows an unauthenticated attacker to gain access to the web browser through the help link, potentially enablin… CISA Advisories · May 14, 2026 High CVE-2026-27662hmiindustrial controlweb browser
vulnerability Siemens SIPROTEC 5 This CISA advisory details a critical vulnerability in Siemens SIPROTEC 5 devices due to the use of insufficiently random session identifiers. An unauthenticated remote attacker could potentially exploit this weakness to… CISA Advisories · May 14, 2026 Critical CVE-2024-54017session_hijackingauthenticationrandomness
vulnerability Universal Robots Polyscope 5 A critical vulnerability has been identified in Universal Robots Polyscope 5 software versions prior to 5.25.1, allowing for unauthenticated code execution via OS command injection. This poses a significant risk to criti… CISA Advisories · May 14, 2026 Critical CVE-2026-8153WOcommand injectionroboticscve-2026-8153
vulnerability Siemens Opcenter RDnL This advisory details a critical vulnerability in Siemens Opcenter RDnL software, specifically related to missing authentication in the ActiveMQ Artemis component. An attacker within an adjacent network could exploit thi… CISA Advisories · May 14, 2026 Critical CVE-2026-27446DEauthenticationcore protocolactivemq artemis
threat-intel Fixing the password problem is as easy as 123456 This article highlights a persistent problem in cybersecurity: the widespread use of easily guessable passwords, particularly ‘123456’ and variations. Despite industry advice and password policies, numerous websites, inc… WeLiveSecurity · May 7, 2026 High password_securityweak_passwordsdata_breach
phishing That data breach alert might be a trap This article highlights the increasing sophistication and prevalence of fake data breach notification scams, driven by factors like record-breaking data breaches and the use of AI tools. Scammers are leveraging these not… WeLiveSecurity · Apr 17, 2026 High USDEphishingsocial engineeringai