Tag
Detection of Windows Defender Malware and Suspicious Activity Events
1 ruleThis brief outlines the monitoring of Windows Defender Antimalware events that indicate confirmed malware detections or suspicious system behavior.
Cisco Releases Patches for Critical Infrastructure Vulnerabilities
2 TTPs 5 CVEsCisco has issued security advisories for unpatched S/MIME vulnerabilities in Secure Email and critical RCE and authentication bypass flaws across its IOS XR, Nexus, and VoIP phone product lines.
Cisco IOS XR Software Security Hardening Updates
7 CVEsCisco has released critical security hardening updates for IOS XR Software addressing seven internally discovered vulnerabilities (CVE-2026-20274 through CVE-2026-20280) that have no known workarounds.
Multiple Vulnerabilities in ServiceNow Now Platform and AI Platform
3 TTPsServiceNow Now Platform and AI Platform are vulnerable to multiple flaws enabling arbitrary code execution, privilege escalation, and SQL injection, risking full environment compromise.
Arista EOS and WiFi Access Point Denial of Service Vulnerability
1 TTPA remote, unauthenticated attacker can exploit a vulnerability in Arista EOS and WiFi Access Point firmware to trigger a denial of service condition by crashing affected network devices.
Grafana Improper Access Control Information Disclosure Vulnerability
3 TTPs 1 CVEAn authenticated, remote attacker can exploit a flaw in Grafana to perform unauthorized information disclosure due to improper access control.
Vivid Media Driver Race Condition Vulnerability
1 CVECVE-2026-68204 is a vulnerability in the Linux vivid media driver where a lack of checks for vb2_is_busy() during capability toggling may result in memory instability or race conditions.
Vulnerability in Linux Kernel fscrypt Subsystem
1 CVECVE-2026-68147 addresses a memory management vulnerability in the Linux kernel fscrypt subsystem within the fscrypt_get_devices function, where improper dynamic allocation could lead to memory corruption or exhaustion.
Out-of-bounds Vulnerability in NXP i.MX 8 Image Signal Processor Driver
1 CVEA potential out-of-bounds memory vulnerability in the NXP i.MX 8 Image Signal Processor (ISI) driver could lead to system instability or memory corruption if triggered by an attacker with driver-level access.
MediaTek mt76 Wireless Driver Memory Access Vulnerability
1 CVECVE-2026-68310 in the MediaTek mt76 wireless driver for mt7915 chipsets allows for potential memory access issues due to inadequate validation during HE capability lookups.
NULL Pointer Dereference Vulnerability in MediaTek mt76 Wi-Fi Driver
1 CVEA NULL pointer dereference vulnerability exists in the MediaTek mt76 driver within the mt76_connac_mcu_uni_bss_he_tlv function, potentially leading to kernel panic or denial-of-service conditions.
Vulnerability in Linux Kernel RADOS Block Device Module
1 CVECVE-2026-68131 identifies a flaw in the Linux kernel rbd module where failure to reset result codes to zero during object map updates may lead to improper status reporting.
Kernel Networking Subsystem Vulnerability in dpaa2-eth Driver
1 CVECVE-2026-68331 identifies a resource management vulnerability in the dpaa2-eth driver related to improper handling of MAC endpoint devices during disconnection, which may lead to system instability.
Out-of-Bounds Read in carl9170 Wi-Fi Driver
1 CVEThe carl9170 Wi-Fi driver contains an out-of-bounds read vulnerability due to an off-by-two error in the TX status handler, potentially leading to memory disclosure or system instability.
Missing Superblock Check in fscrypt find_or_insert_direct_key
1 CVEA vulnerability in the Linux kernel fscrypt subsystem exists due to a missing superblock check in the find_or_insert_direct_key function, potentially impacting filesystem integrity.
Memory Reference Leak in Linux Kernel AMD Display Driver
1 CVECVE-2026-68256 describes a memory reference leak in the Linux kernel drm/amd/display driver occurring during specific DP alt mode timeout conditions.
Vulnerability in AMD Display Driver for Linux Kernel
1 TTP 1 CVEA memory management flaw in the AMD display driver (drm/amd/display) for the Linux kernel allows for improper handling of DisplayPort Multi-Stream Transport (DP MST) configurations.
Memory Leak and List Corruption in Intel Stratix 10 Firmware
Intel has patched memory leaks and list corruption vulnerabilities in the stratix10-svc firmware component that could lead to system instability.
Linux Kernel binfmt_misc Privilege Escalation Vulnerability
CVE-2026-68186 describes a vulnerability in the Linux kernel binfmt_misc module where the have_execfd flag is set prematurely, potentially enabling local privilege escalation.
Security Updates for HashiCorp Consul
1 IOCHashiCorp has released security advisory HCSEC-2026-25 addressing multiple vulnerabilities in Consul Community Edition and Consul Enterprise that require immediate patching.
Vulnerability in Linux KVM MMU Page Management
1 TTP 1 CVECVE-2026-64561 identifies a flaw in the Linux KVM hypervisor where incorrect validation of MMU pages could lead to memory management inconsistencies.
Linux Kernel MPLS NULL Pointer Dereference Vulnerability
2 TTPs 1 CVEA NULL pointer dereference vulnerability in the Linux kernel's MPLS subsystem, specifically affecting configurations where CONFIG_INET is disabled, can lead to a denial-of-service condition.
Multiple Security Vulnerabilities in Wallix Access Manager and Bastion
1 TTPMultiple vulnerabilities in Wallix Access Manager and Bastion products allow for unauthorized privilege escalation and security policy bypass.
ENDLESSDOORS Vulnerability Affecting Zbtlink Routers
1 TTPMultiple Zbtlink router models are susceptible to the ENDLESSDOORS root implant, which leverages the rctl remote control tool for unauthorized access and persistent phone-home capabilities.
Information Published for CVE-2026-64191
1 CVEInformation has been published regarding CVE-2026-64191, which addresses an issue in the i2c stub related to rejecting I2C block transfers with invalid lengths.