Skip to content
Threat Feed

Tag

Informational

25 briefs RSS
medium advisory

Detection of Windows Defender Malware and Suspicious Activity Events

This brief outlines the monitoring of Windows Defender Antimalware events that indicate confirmed malware detections or suspicious system behavior.

windows security-monitoring informational
1r
high threat

Cisco Releases Patches for Critical Infrastructure Vulnerabilities

Cisco has issued security advisories for unpatched S/MIME vulnerabilities in Secure Email and critical RCE and authentication bypass flaws across its IOS XR, Nexus, and VoIP phone product lines.

exploited Secure Email +6 vulnerability network-security patch-management informational
2t 5c
high threat

Cisco IOS XR Software Security Hardening Updates

Cisco has released critical security hardening updates for IOS XR Software addressing seven internally discovered vulnerabilities (CVE-2026-20274 through CVE-2026-20280) that have no known workarounds.

exploited IOS XR Software networking security-update informational
7c updated
high advisory

Multiple Vulnerabilities in ServiceNow Now Platform and AI Platform

ServiceNow Now Platform and AI Platform are vulnerable to multiple flaws enabling arbitrary code execution, privilege escalation, and SQL injection, risking full environment compromise.

Now Platform +1 vulnerability service-now cloud-security informational
3t
medium advisory

Arista EOS and WiFi Access Point Denial of Service Vulnerability

A remote, unauthenticated attacker can exploit a vulnerability in Arista EOS and WiFi Access Point firmware to trigger a denial of service condition by crashing affected network devices.

EOS +1 denial-of-service network-security informational
1t
medium advisory

Grafana Improper Access Control Information Disclosure Vulnerability

An authenticated, remote attacker can exploit a flaw in Grafana to perform unauthorized information disclosure due to improper access control.

Grafana informational product-news directory-traversal vulnerability web-application xss security-advisory denial-of-service
3t 1c updated
medium advisory

Vivid Media Driver Race Condition Vulnerability

CVE-2026-68204 is a vulnerability in the Linux vivid media driver where a lack of checks for vb2_is_busy() during capability toggling may result in memory instability or race conditions.

vivid informational product-news
1c
medium threat

Vulnerability in Linux Kernel fscrypt Subsystem

CVE-2026-68147 addresses a memory management vulnerability in the Linux kernel fscrypt subsystem within the fscrypt_get_devices function, where improper dynamic allocation could lead to memory corruption or exhaustion.

exploited fscrypt vulnerability kernel linux informational
1c
medium advisory

Out-of-bounds Vulnerability in NXP i.MX 8 Image Signal Processor Driver

A potential out-of-bounds memory vulnerability in the NXP i.MX 8 Image Signal Processor (ISI) driver could lead to system instability or memory corruption if triggered by an attacker with driver-level access.

i.MX 8 ISI vulnerability kernel hardware informational
1c
low advisory

MediaTek mt76 Wireless Driver Memory Access Vulnerability

CVE-2026-68310 in the MediaTek mt76 wireless driver for mt7915 chipsets allows for potential memory access issues due to inadequate validation during HE capability lookups.

mt7915 vulnerability networking informational
1c
medium advisory

NULL Pointer Dereference Vulnerability in MediaTek mt76 Wi-Fi Driver

A NULL pointer dereference vulnerability exists in the MediaTek mt76 driver within the mt76_connac_mcu_uni_bss_he_tlv function, potentially leading to kernel panic or denial-of-service conditions.

mt76 vulnerability denial-of-service kernel firmware informational product-news linux
1c
low threat

Vulnerability in Linux Kernel RADOS Block Device Module

CVE-2026-68131 identifies a flaw in the Linux kernel rbd module where failure to reset result codes to zero during object map updates may lead to improper status reporting.

exploited rbd informational kernel linux storage
1c
low threat

Kernel Networking Subsystem Vulnerability in dpaa2-eth Driver

CVE-2026-68331 identifies a resource management vulnerability in the dpaa2-eth driver related to improper handling of MAC endpoint devices during disconnection, which may lead to system instability.

exploited dpaa2-eth informational product-news
1c
medium threat

Out-of-Bounds Read in carl9170 Wi-Fi Driver

The carl9170 Wi-Fi driver contains an out-of-bounds read vulnerability due to an off-by-two error in the TX status handler, potentially leading to memory disclosure or system instability.

exploited carl9170 informational product-news
1c
medium advisory

Missing Superblock Check in fscrypt find_or_insert_direct_key

A vulnerability in the Linux kernel fscrypt subsystem exists due to a missing superblock check in the find_or_insert_direct_key function, potentially impacting filesystem integrity.

fscrypt vulnerability linux kernel informational
1c
low threat

Memory Reference Leak in Linux Kernel AMD Display Driver

CVE-2026-68256 describes a memory reference leak in the Linux kernel drm/amd/display driver occurring during specific DP alt mode timeout conditions.

exploited drm/amd/display informational product-news vulnerability
1c
medium advisory

Vulnerability in AMD Display Driver for Linux Kernel

A memory management flaw in the AMD display driver (drm/amd/display) for the Linux kernel allows for improper handling of DisplayPort Multi-Stream Transport (DP MST) configurations.

amdgpu vulnerability linux kernel informational product-news linux-kernel kernel-security kernel-vulnerability +1
1t 1c
low advisory

Memory Leak and List Corruption in Intel Stratix 10 Firmware

Intel has patched memory leaks and list corruption vulnerabilities in the stratix10-svc firmware component that could lead to system instability.

Stratix 10 firmware vulnerability informational product-news
medium advisory

Linux Kernel binfmt_misc Privilege Escalation Vulnerability

CVE-2026-68186 describes a vulnerability in the Linux kernel binfmt_misc module where the have_execfd flag is set prematurely, potentially enabling local privilege escalation.

Linux Kernel +1 linux kernel vulnerability privilege-escalation mac802154 cve linux-kernel networking +2
low advisory

Security Updates for HashiCorp Consul

HashiCorp has released security advisory HCSEC-2026-25 addressing multiple vulnerabilities in Consul Community Edition and Consul Enterprise that require immediate patching.

Consul Community Edition +1 informational product-news
1i
medium advisory

Vulnerability in Linux KVM MMU Page Management

CVE-2026-64561 identifies a flaw in the Linux KVM hypervisor where incorrect validation of MMU pages could lead to memory management inconsistencies.

KVM vulnerability linux virtualization informational privilege-escalation kernel kernel-vulnerability arm64
1t 1c updated
high advisory

Linux Kernel MPLS NULL Pointer Dereference Vulnerability

A NULL pointer dereference vulnerability in the Linux kernel's MPLS subsystem, specifically affecting configurations where CONFIG_INET is disabled, can lead to a denial-of-service condition.

Linux Kernel vulnerability linux kernel informational stability cve filesystem product-news +13
2t 1c updated
medium advisory

Multiple Security Vulnerabilities in Wallix Access Manager and Bastion

Multiple vulnerabilities in Wallix Access Manager and Bastion products allow for unauthorized privilege escalation and security policy bypass.

Access Manager +1 vulnerability privilege-escalation authentication-bypass informational
1t
high advisory

ENDLESSDOORS Vulnerability Affecting Zbtlink Routers

Multiple Zbtlink router models are susceptible to the ENDLESSDOORS root implant, which leverages the rctl remote control tool for unauthorized access and persistent phone-home capabilities.

CPE2801 Firmware +19 firmware-vulnerability implant router network-security informational
1t
low advisory

Information Published for CVE-2026-64191

Information has been published regarding CVE-2026-64191, which addresses an issue in the i2c stub related to rejecting I2C block transfers with invalid lengths.

vulnerability patch-management informational
1c