ScanForge Security Digest 2639-01

200 items
73 critical23 high10 news

This week's security digest includes 0 actively exploited vulnerabilities (CISA KEV), 73 critical CVEs, and 23 high-severity CVEs. Review the details below and prioritize patching for any affected systems.

Critical

73

High Severity

23
8.9 IBM Guardium Data Protection 12.2 could 2 CVEs CVE-2026-84074, CVE-2026-84070
8.8 Vulnerability in the Oracle Hyperion Financial Management pr 6 CVEs CVE-2026-87238, CVE-2026-87227, CVE-2026-87226, CVE-2026-87204 +2
8.8 Sandbox escape due to incorrect boundary conditions in the W 2 CVEs CVE-2026-92065, CVE-2026-92064
8.8 Heap-based buffer overflow in Remote Desktop Client 2 CVEs CVE-2026-80077, CVE-2026-80074

+4 more products affected

Security News

10
Rogue external MFA providers can steal passwords during logins Bleeping Computer

Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider

Sweden fines Miljödata $183,000 over breach affecting 2.2 million Bleeping Computer

Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for

Relays Are Masking Chinese Access to Frontier AI Models in the US Dark Reading

More than 80,000 AI relay servers are helping users in China mask their identities while they access cutting-edge large

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data Bleeping Computer

A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress

Microsoft Disrupts EvilTokens Device Code Phishing Service Dark Reading

Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phi

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach Bleeping Computer

The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gai

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks The Hacker News

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attac

New ClosedQuorum Windows malware uses AI for attack decisions Bleeping Computer

A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously deter

Content aggregated from NIST/NVD, CISA, CERT/CC, and public security news sources. External articles are linked to their original source.