Doorzoek en filter alle geregistreerde cyberdreigingen voor gemeenten.
381 dreigingen gevonden · pagina 20 van 32
Er is een ernstige kwetsbaarheid, CVE-2026-86218, gevonden in N-central van N-able met een CVSS-score van 10. Deze kwetsbaarheid maakt het voor onbevoegden mogelijk om op afstand, zonder inloggegevens, schadelijke code uit te voeren. Het is belangrijk om de door N-able uitgebrachte updates zo snel mogelijk te installeren, mede omdat er al pogingen tot misbruik zijn waargenomen.
CVE-2026-86218
In this Risky Business sponsored interview, James Wilson chats with Authentik Security CEO Fletcher Heisler about how AI is driving a need for privileged access management to adapt. Fletcher explains Authentik’s approach: each agent has its own identity, begins with no permissions and is tied to a human. They also discuss transferring ownership when employees leave, mitigating risks of agents creating identities for each other, and whether task-based access could eventually be a better fit than clock-controlled access.
Er zijn meerdere kwetsbaarheden gevonden in Google Chrome, specifiek in versie 152.0.7977.82. Deze kwetsbaarheden, waaronder CVE-2026-85042 en CVE-2026-85047, betreffen verschillende onderdelen van de browser. Het advies is om de nieuwste updates van Google Chrome zo snel mogelijk te installeren en zo de risico’s te beperken.
CVE-2026-85042
Overview A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. This previously undocumented framework enabled threat actors to execute remote commands on compromised servers, inject malicious scripts into web traffic, perform credential harvesting, and engage in long-term surveillance. The standout feature of this toolkit is its depth of integration with t
Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
CVE-2026-85046
De politie en het Openbaar Ministerie zien in westerse landen nieuwe hackers opkomen. Ze ontmoeten elkaar online in een los samenhangend netwerk van individuen. Ze zijn niet ideologisch of politiek gemotiveerd, het gaat ze vooral om geld en status. Dat schrijven de politie en het OM in hun Cybercrimebeeld van dit jaar. "Dit zijn personen tussen de 11 en 25 jaar", zegt Stan Duijf, verantwoordelijk voor de aanpak van cybercriminaliteit bij de politie. "Ze komen vooral uit westerse landen, spreken Engels, werken in een soort van online netwerk en plegen vooral data- en cryptodiefstallen." Voorhee
Tom Uren and James Wilson talk about China’s long-term shift to getting private companies to build botnets for cyberespionage. A disruption effort from the US this week is good news, but China has been using these networks for a surprisingly long time and will rebuild. They also discuss a hack at the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). It looks like the Qilin ransomware group might have stolen data from the ATF’s CALEA, or lawful intercept system. That’s a big deal! Finally, they discuss efforts to fix US water sector security. Sprinkling free tools on the problem will h
De cyberdreiging voor Nederland verandert snel. Cybercrime wordt gepleegd door verschillende dadertypes: van statelijke actoren tot jonge cybercriminelen. Tegelijkertijd maakt kunstmatige intelligentie (AI) het mogelijk om cyberaanvallen sneller...
Overview On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances. CVE-2026-83548 is a critical pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. The flaw has a CVSS v3.1 base score of 10.0 and can allow a remote, unauthenticated attacker to access sensitive functionality and p
CVE-2026-83548
Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor first documented targeting gambling sites across Asia. Once inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors, […] The post Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon appeared first on Check Point Research .
SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
CVE-2026-83549
Sangoma Switchvox contains a SQL injection vulnerability which allows an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.
CVE-2026-9586