2026-08-04 19:43 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-074-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 12:30 PM PDT Description: Kiro is an agentic IDE and command-line interface users install on their desktop. We identified CVE-2026-18656 and CVE-2026-18657, an issue where an uncontrolled search path element on Windows might allow an actor to execute arbitrary code via a maliciously crafted project directory containing a planted executable that is resolved before the system PATH when a…
P5
2026-08-04 17:45 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-073-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 10:00 AM PDT Description: We have identified CVE-2026-18830 in the Amazon Bedrock AgentCore harness InvokeHarness API. This issue could allow an authenticated user to execute configured tools while bypassing model invocation and associated security controls. When the most recent message in an InvokeHarness request contained a tool-use content block, the agent event loop could dispatch …
P5
2026-08-04 13:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Xu Zou · indexed 2026-08-15 18:55 UTC
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain. The post The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software appeared first on Unit 42.
P25
2026-08-04 11:11 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-08-15 18:55 UTC
OverviewOn August 2, 2026, N-able published a security advisory for CVE-2026-18577, an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication and obtain administrative control of vulnerable N-central servers in affected deployments.N-able N-central is a widely deployed R…
P65
2026-08-03 21:21 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-08-15 18:55 UTC
Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.
P15
2026-08-03 20:38 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-072-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 13:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the shell tool for executing operating system commands on the agent's host. We identified CVE-2026-18733. The shell tool includes a human consent gate that prompts the operator to approve commands before they ru…
P5
2026-08-03 19:43 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-071-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:30 PM PDT Description: AWS Command Line Interface (AWS CLI) is a unified tool to manage AWS services from the command line. We identified CVE-2026-18654, an issue where the EMR SSH helper commands (aws emr ssh, aws emr socks, aws emr put, aws emr get) disabled SSH host key verification, which might allow man-in-the-middle actors to intercept SSH sessions and file transfers via netwo…
P5
2026-08-03 19:09 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-070-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/03/2026 12:00 PM PDT Description: AWS Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) is a Model Context Protocol server that enables AI assistants to interact with Amazon MQ message brokers. We identified CVE-2026-18655, an improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 that may al…
P5
2026-08-03 17:11 UTC
Vendor Research
Rapid7 · Jonah Burgess · indexed 2026-08-15 18:55 UTC
OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, an arbitrary file read in Active Storage applications that use the Vips image processor with untrusted uploads. The affected Active Storage ranges are < 7.2.3.2, >= 8.0, < 8.0.5.1, and >= 8.1, < 8.1.3.1. Vips is the default Active Storage variant processor for applications that load Rails 7.0 or later defaults. Rails 6 applications are affected only when they explicitly configure Vips.Our Emerg…
P20
2026-08-03 14:48 UTC
Vendor Research
Rapid7 · The Metasploit Team · indexed 2026-08-15 18:55 UTC
Today marks the release of Metasploit Pro 5.1 - building upon the foundation laid in 5.0, adding new evasion primitives for HTTP Meterpreter payloads, support for tracking service hierarchies, a deeper and more interactive Network Topology view, and continuing our commitment to a modern, consistent UI. This release is powered by Metasploit Framework 6.5.Malleable C2 ProfilesOne of the most requested capabilities in modern red-team engagements is the ability to blend Meterpreter's network traffi…
P0
2026-07-31 19:41 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-069-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/31/2026 12:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the http_request tool for making HTTP API requests. We identified CVE-2026-18394, an incorrect authorization issue in the http_request tool. Operators can use the HTTP_REQUEST_TOKEN_CONFIG allowlist to bind a cr…
P5
2026-07-31 18:22 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-068-AWS Publication Date: 07/31/2026 11:00 AM PDT Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
P20
2026-07-31 17:20 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
P5
2026-07-31 16:27 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
P5
2026-07-31 11:53 UTC
Vendor Research
Rapid7 · Emma Burdett · indexed 2026-08-15 18:55 UTC
Black Hat USA returns to Mandalay Bay in Las Vegas this August, bringing together security practitioners, researchers, and leaders from around the world. Rapid7 will be there in the Business Hall, with new capabilities, live demonstrations, expert-led sessions, and two days of activities at the Border Grill.This year, our focus is preemptive security: helping security teams anticipate credible risk, respond at machine speed, and maintain an accurate view of their security and compliance posture…
P0
2026-07-30 17:22 UTC
Vendor Research
AWS Security Blog · Michael Long · indexed 2026-08-15 18:55 UTC
Amazon Inspector is an automated vulnerability management service that continually scans Amazon Web Services (AWS) workloads for software vulnerabilities. The vulnerability management capabilities of Amazon Inspector are powered by an asset inventory engine known as the Amazon Inspector SBOM Generator (inspector-sbomgen), a standalone command-line tool that produces a software bill of materials (SBOM) from container […]
P0
2026-07-30 16:11 UTC
Vendor Research
Rapid7 · Rapid7 Labs · indexed 2026-08-15 18:55 UTC
OverviewOn July 29, 2026, the Ruby on Rails project published a security advisory for CVE-2026-66066, a critical vulnerability affecting Active Storage image processing when used in conjunction with the libvips image processing library. The vulnerability has a CVSSv4 score of 9.5 and is classified as Initialization of a Resource with an Insecure Default (CWE-1188). An unauthenticated attacker may be able to leverage CVE-2026-66066 and read files accessible to the Rails application process, pote…
P50
2026-07-30 16:05 UTC
Vendor Research
Tenable Blog · Ashley Lukeeram · indexed 2026-08-15 18:55 UTC
Canada’s new Critical Cyber Systems Protection Act (Bill C-8) introduces a strict 72-hour cyber incident reporting mandate. Find out how Tenable is helping critical national infrastructure operators bridge the IT/OT divide to ensure full compliance.Key takeaways:Bill C-8 introduces stringent new cyber incident reporting requirements and heavy financial penalties for critical infrastructure operators. Eliminating network blind spots with a hybrid IT/OT discovery approach, including Safe Active Q…
P10
2026-07-30 15:14 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-08-15 18:55 UTC
IDC has named Rapid7 a Leader in the 2026 Worldwide Managed Detection and Response Service for Midmarket 2026 Vendor Assessment (Doc #US52992326, July 2026). We believe this recognition and research highlights where MDR is heading.Many security programs are still built around a reactive sequence of detect, triage, and respond, but the timelines surrounding modern attacks have changed too quickly for that model to hold up on its own. Time-to-exploit has dropped from two years to 22 hours, while …
P0
2026-07-30 14:29 UTC
Vendor Research
Rapid7 · The Metasploit Team · indexed 2026-08-15 18:55 UTC
Today we’re proud to announce that Metasploit Framework version 6.5 has been released. Over the past two years, with the help of countless contributors, we’ve added 422 new modules along with a whole slew of new features.Malleable C2 Profiles for HTTPOne of the latest and most requested features is support for Malleable C2 profiles across all current Meterpreter payloads. This feature enables users to load a standard profile into Meterpreter and change the shape of its HTTP(S) traffic. All Mete…
P0
2026-07-30 10:35 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-08-15 18:55 UTC
OverviewOn July 29, 2026, Broadcom published security advisory VMSA-2026-0006 addressing multiple vulnerabilities in several VMWare products. Included in the advisory are two critical remotely exploitable vulnerabilities affecting VMware vCenter Server: CVE-2026-59309 and CVE-2026-59310. Both vulnerabilities carry CVSSv3.1 base scores of 9.8 and can be exploited by unauthenticated attackers with network access to a vulnerable vCenter Server.CVECVSSv3.1Description SummaryCVE-2026-593099.8 (Criti…
P50
2026-07-29 16:16 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-08-15 18:55 UTC
OverviewOn July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unauthenticated vulnerability affecting all versions of TeamCity On-Premises. The issue is classified as deserialization of untrusted data and has a CVSS score of 9.8. An unauthenticated remote attacker with HTTP(S) access to a TeamCity server can exploit the agent polling protocol to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity ser…
P50
2026-07-29 13:00 UTC
Vendor Research
Rapid7 · Joel Alcon · indexed 2026-08-15 18:55 UTC
The scenario is all too familiar for any cybersecurity professional: It’s late in the day, and a critical zero-day vulnerability is disclosed. When this happens, CISOs from every industry immediately turn to their Security Operations Centers (SOC) with the single most important, and often most difficult, question: "Are we exposed?”Answering questions like these when zero-days drop tends to trigger a frantic, high-stress fire drill. Analysts scramble to cross-reference outdated Configuration Man…
P45
2026-07-28 23:19 UTC
Vendor Research
Tenable Blog · Research Special Operations · indexed 2026-08-15 18:55 UTC
A coordinated cyber attack disrupted water and wastewater systems in at least 12 U.S. states, including more than 30 Minnesota communities. Here is what defenders need to know about the attack so far. This FAQ also details recent cyberactivity targeting internet-exposed PLCs, and how to protect exposed infrastructure.Change logUpdate August 10: Added Columbus Water Works as a second confirmed Georgia victim. Added a table summarizing publicly confirmed affected entities to date.This is an activ…
P45
2026-07-28 18:32 UTC
Vendor Research
Rapid7 · Stephen Fewer · indexed 2026-08-15 18:55 UTC
OverviewOn July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires netwo…
P60
2026-07-28 13:00 UTC
Vendor Research
Rapid7 · Mikayla Wyman · indexed 2026-08-15 18:55 UTC
For years, security operations followed a familiar sequence: detect suspicious activity, investigate what happened, and respond before it caused significant harm. That model developed in a threat landscape where defenders had considerably more time to establish the facts and decide what to do next. In 2019, the average data breach took 206 days to identify and another 73 days to contain, creating a total breach lifecycle of 279 days.As the time between initial access and attacker movement conti…
P0
2026-07-23 20:14 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-065-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 13:00 PM PDT Description: The AWS Bedrock AgentCore Python SDK (bedrock-agentcore) provides tools for building AI agents, including a Code Interpreter client that installs Python packages into a managed sandbox. We identified CVE-2026-16796, an improper neutralization of argument delimiters in the install_packages() method that might allow a remote authenticated user to execute arbitra…
P5
2026-07-23 18:39 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-064-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 11:30 AM PDT Description: Smithy-RS is a Rust code generation and runtime framework that generates HTTP clients and servers from Smithy interface definitions, powering the AWS SDK for Rust and custom service implementations. We identified CVE-2026-16756 where the allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated "Slowloris"…
P5
2026-07-23 15:39 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
Bulletin ID: 2026-063-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/23/2026 08:30 AM PDT Description: The AWS API MCP Server (awslabs.aws-api-mcp-server) is an open-source MCP server that lets AI assistants execute AWS CLI commands against a user's AWS account. It includes an optional, user-configured security policy that can deny or gate specific AWS operations. We identified CVE-2026-16584. On startup, the server loads the data used to enforce this security …
P5
2026-07-23 07:13 UTC
Government
CERT-EU Security Advisories · indexed 2026-08-15 18:50 UTC
[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU…
P45