Direct handelen

  1. Handelingsperspectief: Direct handelenGoogle Threat Intelligence / Mandiant · Prioriteit 1

    Defending Against Active Exploitation of Citrix NetScaler ADC and Gateway Appliances

    • CVE-2026-88772KEV
    • CVE-2026-88771KEV
    • CVE-2026-88778
    Handelingsperspectief: Direct handelen(binnen 48 uur)
    1. Stel vast of het product bij jullie of bij een leverancier in gebruik is.
    2. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan.
    3. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

    Gebaseerd op

    • CISA KEV: misbruik bevestigd voor CVE-2026-88772 (Citrix NetScaler), toegevoegd 27 sep 2026, CISA-deadline voor Amerikaanse overheidsinstanties 30 sep 2026.
    • CISA KEV: misbruik bevestigd voor CVE-2026-88771 (Citrix NetScaler), toegevoegd 27 sep 2026, CISA-deadline voor Amerikaanse overheidsinstanties 30 sep 2026.

    Automatisch afgeleid uit brondata volgens vaste regels. Hoe dit werkt

  2. Handelingsperspectief: Direct handelenCISA · Prioriteit 1

    Actief misbruikt: Apple Multiple Products (CVE-2026-86950)

    • CVE-2026-86950KEV
    Handelingsperspectief: Direct handelen(binnen 48 uur)
    1. Stel vast of het product bij jullie of bij een leverancier in gebruik is.
    2. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan.
    3. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

    Gebaseerd op

    • CISA KEV: misbruik bevestigd voor CVE-2026-86950 (Apple Multiple Products), toegevoegd 29 sep 2026, CISA-deadline voor Amerikaanse overheidsinstanties 2 okt 2026.

    Automatisch afgeleid uit brondata volgens vaste regels. Hoe dit werkt

  3. Handelingsperspectief: Direct handelenDark Reading · Prioriteit 2

    Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers

    Handelingsperspectief: Direct handelen(binnen 48 uur)
    1. Stel vast of het product bij jullie of bij een leverancier in gebruik is.
    2. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan.
    3. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

    Gebaseerd op

    • De bron meldt actief misbruik of een zero-day.

    Automatisch afgeleid uit brondata volgens vaste regels. Hoe dit werkt

  4. Handelingsperspectief: Direct handelenBleepingComputer · Prioriteit 2

    Apple patches CoreGraphics zero-day flaw exploited in attacks

    Handelingsperspectief: Direct handelen(binnen 48 uur)
    1. Stel vast of het product bij jullie of bij een leverancier in gebruik is.
    2. Installeer de update binnen 48 uur, of pas de mitigatie van de leverancier toe als dat niet kan.
    3. Controleer op sporen van misbruik en stel bewijs veilig voordat je systemen wijzigt.

    Gebaseerd op

    • De bron meldt actief misbruik of een zero-day.

    Automatisch afgeleid uit brondata volgens vaste regels. Hoe dit werkt

Deze week

Geen kwetsbaarheden voor deze week.

Reguliere patchcyclus

Geen aanwijzing voor misbruik of hoge ernst: meenemen in de reguliere patchcyclus.

  1. Handelingsperspectief: Reguliere patchcyclusGoogle Chrome Releases · Prioriteit 1

    Stable Channel Update for Desktop

  2. Handelingsperspectief: Reguliere patchcyclusCCB (Centre for Cybersecurity Belgium) · Prioriteit 1

    Warning: Two critical vulnerabilities which can lead to Remote Code Execution in WatchGuard, Patch Immediately!

  3. Handelingsperspectief: Reguliere patchcyclusDark Reading · Prioriteit 2

    Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution

  4. Handelingsperspectief: Reguliere patchcyclusHelp Net Security · Prioriteit 2

    Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider

  5. Handelingsperspectief: Reguliere patchcyclusBleepingComputer · Prioriteit 2

    Kiteworks patches critical flaw, brings customer systems online

  6. Handelingsperspectief: Reguliere patchcyclusHelp Net Security · Prioriteit 2

    GitHub’s AI agent found 24 Android app vulnerabilities

Nieuws en analyses

  1. Microsoft Security Blog · Prioriteit 1

    Phishing Abuses RMM Tools for Persistent Access

  2. CCB (Centre for Cybersecurity Belgium) · Prioriteit 1

    Warning: Critical Cross-site Scripting (XSS) in Rancher - Kubernetes management platform, Patch Immediately!

  3. Microsoft Security Blog · Prioriteit 1

    ​​Beyond source code: A path to the keys to the kingdom

  4. Microsoft Security Blog · Prioriteit 1

    Star Blizzard refines phishing and malware delivery with the RedFlick technique

  5. Palo Alto Networks Unit 42 · Prioriteit 1

    OperTraitors: How Kubernetes Operators Betray Your Security Posture

  6. Cisco Talos · Prioriteit 1

    Securing the keys to the kingdom: Announcing Executive Threat Detection

  7. The Record (Recorded Future News) · Prioriteit 2

    US Air Force members given over 6 years in prison for cyber theft of more than $2 million

  8. BleepingComputer · Prioriteit 2

    Custom ChatGPTs push ClickFix attacks to deploy RAT malware

  9. The Record (Recorded Future News) · Prioriteit 2

    Controversial spyware firm Paragon to go public by end of year

  10. SecurityWeek · Prioriteit 2

    OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference

  11. The Record (Recorded Future News) · Prioriteit 2

    OpenAI apologizes for agents breaching Australian government websites without authorization

  12. BleepingComputer · Prioriteit 2

    Former US Air Force members sent to prison over BEC attacks

  13. SecurityWeek · Prioriteit 2

    DARPA Selects Xint to Use AI in Securing Military Messaging Apps

  14. Dark Reading · Prioriteit 2

    Cloudflare Announces Public Certificate Authority for the Post-Quantum Web

  15. SecurityWeek · Prioriteit 2

    New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

  16. BleepingComputer · Prioriteit 2

    Automated AI agent used to breach cybersecurity nonprofit DIVD

  17. Dark Reading · Prioriteit 2

    'NeedyMantis' Provides Long-Term Access to Compromised Networks

  18. SecurityWeek · Prioriteit 2

    RemoteThreat Launches With $7 Million for Offensive Operations Platform

  19. BleepingComputer · Prioriteit 2

    Catch threats before they escalate with real-time Identity Telemetry

  20. Help Net Security · Prioriteit 2

    LastPass warns employees before they share sensitive data with AI tools

  21. Help Net Security · Prioriteit 2

    Postman adds security controls for AI agents, APIs, and MCP servers

  22. SANS Internet Storm Center · Prioriteit 2

    Scans for Wordfence Protected Websites, (Tue, Sep 29th)

  23. SecurityWeek · Prioriteit 2

    Reco Raises $55 Million for Agentic Security

  24. SecurityWeek · Prioriteit 2

    Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

  25. Help Net Security · Prioriteit 2

    Webinar: Closing the accountability gap in AI-assisted delivery

  26. Help Net Security · Prioriteit 2

    Meta gives small businesses an AI agent that knows their work

  27. Help Net Security · Prioriteit 2

    Vega II brings security-trained AI and lasting memory to the SOC

  28. The Record (Recorded Future News) · Prioriteit 2

    Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims

  29. The Record (Recorded Future News) · Prioriteit 2

    Arizona Supreme Court says hackers stole residents’ personal data

  30. SecurityWeek · Prioriteit 2

    Pentagon Personnel Agency Data Breach Impacts 3 Million People

  31. SecurityWeek · Prioriteit 2

    Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks

  32. Help Net Security · Prioriteit 2

    Deepfakes become a board priority once an executive falls for one

  33. Help Net Security · Prioriteit 2

    Malicious Custom GPT on chatgpt.com lures users into installing a RAT

  34. Help Net Security · Prioriteit 2

    OpenAI’s GPT-6 Astra ran supply chain attacks despite being told not to

  35. SecurityWeek · Prioriteit 2

    Four Cyber Threats Harboring Big Plans for the Future

  36. Security.nl · Prioriteit 2

    Onderzoekers melden grootschalig misbruik van kritieke Citrix-lekken

  37. SecurityWeek · Prioriteit 2

    OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training

  38. SecurityWeek · Prioriteit 2

    Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation

  39. Help Net Security · Prioriteit 2

    Cybersecurity hiring practices leave little room for junior talent

  40. Help Net Security · Prioriteit 2

    Palo Alto Networks and NVIDIA want tighter control over AI agents

  41. Security.nl · Prioriteit 2

    CCB heeft in België nog geen aanvallen door AI-agents gezien

  42. SecurityWeek · Prioriteit 2

    Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

  43. Help Net Security · Prioriteit 2

    Cloudflare’s EmDash 1.0 makes sandboxed plugins ask for access first

  44. Help Net Security · Prioriteit 2

    Claude Sonnet 5.5 gets faster without a price hike

  45. Security.nl · Prioriteit 2

    Apple dicht beveiligingslek ingezet bij aanvallen tegen iPhone-gebruikers

  46. Help Net Security · Prioriteit 2

    A four-week plan to tackle vendor concentration risk

  47. Help Net Security · Prioriteit 2

    Hottest cybersecurity open-source tools of the month: September 2026

  48. Help Net Security · Prioriteit 2

    Cybersecurity jobs available right now: September 29, 2026

  49. SANS Internet Storm Center · Prioriteit 2

    ISC Stormcast For Tuesday, September 29th, 2026 https://isc.sans.edu/podcastdetail/10114, (Tue, Sep 29th)

  50. Risky Business News · Prioriteit 2

    Between Two Nerds: The AI crime machine

  51. Dark Reading · Prioriteit 2

    Nvidia Launches AI Agent Safety Platform to Prevent Rogue Activities

  52. NOS · Prioriteit 3

    Jonge hacker nu ook verdacht van moordopdrachten: wie is whizzkid Pepijn van der S.?

  53. NOS · Prioriteit 3

    OpenAI zegt sorry tegen Australië voor hack en ziet af van nieuw AI-model