threat-intel Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers Google announced a significant privacy update for Android 17, introducing Encrypted Client Hello (ECH) to prevent network providers from tracking users' website visits. This feature is being rolled out alongside Local Network Protection and Certificate Transparency enhancements, aiming to bolster overall connection pri… The Hacker News · 2d ago Medium privacynetworksecurity
vulnerability Multiples vulnérabilités dans Cisco IOS XE (25 août 2026) Cisco has announced multiple vulnerabilities in its IOS XE software, allowing attackers to bypass security policies and potentially cause unspecified security issues. These vulnerabilities affect several versions of the… CERT-FR · 6d ago High CVE-2026-20267CVE-2026-20268CVE-2026-20269ciscoios xevulnerability
vulnerability Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0 Cisco has released security updates to address nine vulnerabilities affecting its Crosswork and Secure Workload platforms. These flaws, discovered during internal testing, range in severity from critical to medium and co… The Hacker News · Aug 21, 2026 High CVE-2026-20030CVE-2026-20357CVE-2026-20358securitypatchvulnerability
vulnerability Multiples vulnérabilités dans HPE Aruba Networking Private 5G Core (10 août 2026) Multiple vulnerabilities have been discovered in HPE Aruba Networking Private 5G Core, allowing attackers to elevate privileges and bypass security policies. These vulnerabilities are present in older versions of the sof… CERT-FR · Aug 10, 2026 Medium CVE-2026-33377CVE-2026-54763vulnerabilitysecurityaruba
vulnerability Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities Cisco has released patches for a significant number of vulnerabilities across its SD-WAN, IOS XE, and FMC products. These include critical flaws that could allow remote code execution and unauthorized access, with some v… SecurityWeek · Aug 6, 2026 High CVE-2026-20303CVE-2026-20304CVE-2026-20310vulnerabilitypatchsecurity
vulnerability Multiples vulnérabilités dans les produits Cisco (06 août 2026) Multiple vulnerabilities have been discovered in Cisco products, including SD-WAN and networking equipment. These vulnerabilities can lead to remote code execution, denial-of-service attacks, and data confidentiality bre… CERT-FR · Aug 6, 2026 High CVE-2026-20124CVE-2026-20200CVE-2026-20263ciscosd-wanvulnerability
vulnerability TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover Researchers at Forescout discovered 15 vulnerabilities in TP-Link’s Omada networking ecosystem’s zero-touch provisioning (ZTP) system, allowing attackers to potentially take over entire networks by chaining together thes… SecurityWeek · Aug 4, 2026 High CVE-2025-7850CVE-2025-7851ztpnetworkvulnerability
threat-intel Mitsubishi Electric CC-Link IE TSN Communication Protocol A critical vulnerability (CVE-2026-13584) exists in the CC-Link IE TSN communication protocol used by Mitsubishi Electric industrial controllers. Attackers with network access can manipulate communication data by sending… CISA Advisories · Jul 30, 2026 Critical CVE-2026-13584cc-linkindustrial control systemsvulnerability
vulnerability Arista patches actively exploited VeloCloud bug as CISA puts admins on the clock Arista Networks has patched a vulnerability in its VeloCloud software that was being actively exploited. The CISA (Cybersecurity and Infrastructure Security Agency) issued an advisory urging administrators to address the… The Register · Jul 28, 2026 High CVE-2026-16812patchvulnerabilitynetwork
threat-intel Captive Portal Detection, (Tue, Jul 21st) This article details how operating systems and browsers detect captive portals – the splash screens that appear when connecting to public Wi-Fi networks. Instead of intercepting old non-TLS homepages, these systems now… SANS Internet Storm Center · Jul 21, 2026 Medium captive portalwifinetwork detection
threat-intel SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough. Traditional SASE security models are failing due to the shift to modern internet protocols and the rise of AI-powered workflows. Employees are now routinely sharing sensitive data with AI tools, bypassing traditional ne… The Hacker News · Jul 15, 2026 High aillmsaas
vulnerability Vulnerability in FIFA’s Network A critical vulnerability in FIFA’s network allowed attackers to potentially gain control of the company’s systems, raising serious concerns about the security of FIFA’s operations and the data it handles. This incident h… Schneier on Security · Jul 14, 2026 High securitynetworkvulnerability
threat-intel China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware A Chinese APT group, UAT-7810, is expanding its Operational Relay Box (ORB) network by utilizing custom malware, including LONGLEASH and LEASHTEST, to establish persistent access for secondary threat actors. The group le… The Hacker News · Jul 8, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717TWaptmalwarec2
threat-intel UAT-7810 continues building ORB networks using new malware Cisco Talos Intelligence has identified UAT-7810, a China-nexus APT group, continuing to develop and deploy malware as part of its Operational Relay Box (ORB) network. The group is actively creating new malware variants,… Cisco Talos · Jul 7, 2026 High CVE-2020-22653CVE-2020-22658CVE-2023-25717CHaptmalwarechina
threat-intel ISC Stormcast For Thursday, June 11th, 2026 https://isc.sans.edu/podcastdetail/9968, (Thu, Jun 11th) The SANS Internet Storm Center's June 11th, 2026 Stormcast reported a heightened level of online threats and unusual network activity. The broadcast highlighted several emerging risks, including increased phishing campai… SANS Internet Storm Center · Jun 11, 2026 Medium phishingvulnerabilitynetwork
vulnerability Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs Microsoft released a significant security update addressing 206 vulnerabilities across its software portfolio, including multiple critical Remote Code Execution (RCE) flaws and several zero-days. The update focuses on pa… The Hacker News · Jun 10, 2026 Critical CVE-2025-10263CVE-2026-8863CVE-2026-45657USzero-dayrcebitlocker
threat-intel Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network A zero-day attack targeting a vulnerability in Huawei’s enterprise router software caused a three-hour nationwide telecoms outage in Luxembourg during July 2025. The attack, which exploited a previously undocumented beha… The Record · May 19, 2026 High CVE-2021-22359CVE-2022-29798LUzero-daydenied-servicenetwork