Martedi 28 Luglio 2026 21:35:04 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContattiLogin
ItalianoEnglish

#vulnerabilità critiche


Dentro l'impennata delle patch di Erlang/OTP: perché un singolo difetto critico può scuotere un intero stack distribuito

Pubblicato: 28 Luglio 2026 18:23Categoria: Vulnerabilità e gestione delle patchArea: Europa / SveziaAutore: DEEPAUDIT

Una nuova ondata di vulnerabilità in Erlang/OTP mette in evidenza i punti di pressione della sicurezza che contano di più nei sistemi ad alta disponibilità: decodifica a runtime, convalida della fiducia ed esposizione di rete.

Le falle di JetBrains spingono i team di patch a controlli urgenti delle versioni

Pubblicato: 24 Luglio 2026 18:24Categoria: Vulnerabilità e gestione delle patchArea: Europa / Repubblica CecaAutore: SECURESPECTER

Gli aggiornamenti di sicurezza correggono ora diverse vulnerabilità JetBrains, tra cui tre classificate critiche e 13 ad alta gravità, ma la domanda pratica è quali installazioni debbano ancora essere aggiornate.

La doppia esposizione di MongoDB: quando sia il database sia lo strumento di amministrazione richiedono un esame urgente

Pubblicato: 24 Luglio 2026 14:16Categoria: Vulnerabilità e gestione delle patchArea: North America / USAAutore: DEEPAUDIT

Un avviso di ACN CSIRT Italia segnala un rischio stratificato in MongoDB Server e MongoDB Compass, dove le patch dipendono ora dalla versione, dal deployment e da quanta fiducia può riporre un workstation di amministrazione.

Le falle di FreePBX mettono nel mirino la sala di controllo vocale

Pubblicato: 24 Luglio 2026 14:11Categoria: Vulnerabilità e gestione delle patchArea: North America / CanadaAutore: DEEPAUDIT

Due problemi critici e una falla ad alta gravità nei moduli FreePBX rafforzano un avvertimento noto: quando il livello amministrativo di uno stack PBX si rompe, l'intero sistema telefonico può diventare la superficie di attacco.

Serv-U sotto pressione: 16 falle chiuse, 15 classificate come critiche

Pubblicato: 23 Luglio 2026 16:23Categoria: Vulnerabilità e gestione delle patchArea: Nord America / USAAutore: NEONPALADIN

ACN CSIRT Italia ha segnalato un intenso ciclo di patch in SolarWinds Serv-U, un promemoria del fatto che le piattaforme di trasferimento file possono diventare da un giorno all'altro confini di sicurezza ad alto valore.

Seven Chrome Flaws, One Narrow Escape Window

Published: 17 July 2026 14:28Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

Google has pushed a Chrome security update that closes seven vulnerabilities, and the mix of critical and high-severity bugs is a reminder that browser patching is now a race against reachability.

Firefox Zero-Days Turn the Browser Into the Weakest Link

Published: 14 July 2026 18:06Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

Mozilla has pushed security updates for two critical Firefox flaws that are reportedly being exploited online, putting patch speed and endpoint visibility at the center of defense.

SAP’s July Patch Wave Exposes How Enterprise Risk Moves on a Clock

Published: 14 July 2026 12:36Category: Vulnerabilities & Patch ManagementGeo: Europe / GermanyAuthor: SECURESPECTER

A monthly maintenance cycle turned into a high-priority security checkpoint as SAP’s July updates touched multiple product layers, from core application runtime to web and cloud components.

When the Login Box Becomes the Blast Radius

Published: 10 July 2026 17:54Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

Two critical Metabase flaws were patched after security updates, and the risk profile is unsettling: an authenticated user could turn ordinary access into arbitrary code execution on affected systems.

Chrome Pushes a Heavy Patch Wave as Browser Risk Stays One Update Behind

Published: 09 July 2026 10:14Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

A new Chrome security release fixes 27 vulnerabilities, including two critical ones, and it highlights how quickly a browser can become the weakest link on a managed endpoint.

Roundcube’s Latest Patch Wave Shows How Mail Can Become a Security Blind Spot

Published: 07 July 2026 18:04Category: Vulnerabilities & Patch ManagementAuthor: NEONPALADIN

Security updates for Roundcube Webmail close off several flaws, including two rated critical, in a reminder that browser-based mail sits on a fragile boundary between untrusted content and authenticated access.

WatchGuard Firebox Flaws Put the Management Layer Under a Microscope

Published: 07 July 2026 12:10Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A set of Fireware OS vulnerabilities, including one critical issue and nine high-severity flaws, turns attention to the patch discipline behind perimeter appliances.

When a Mail Server Patch Becomes NAS Self-Defense

Published: 30 June 2026 15:20Category: Vulnerabilities & Patch ManagementGeo: Asia / TaiwanAuthor: DEEPAUDIT

Synology has pushed fixes for three MailPlus Server vulnerabilities in DSM, including two critical flaws that could permit arbitrary file read/write and disrupt service availability.

Four JetBrains Flaws, Three Critical: The Patch Window Security Teams Cannot Ignore

Published: 26 June 2026 17:14Category: Vulnerabilities & Patch ManagementGeo: Europe / Czech RepublicAuthor: DEEPAUDIT

ACN CSIRT Italia flagged a compact but urgent remediation case: four vulnerabilities in JetBrains products, including three rated critical and one high.

Go’s Crypto Update Exposes a Quiet Dependency Risk Hiding in Plain Sight

Published: 26 June 2026 16:17Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: DEEPAUDIT

Security fixes for golang.org/x/crypto are a reminder that patching a single module can matter far beyond the teams that imported it directly.

Six Flaws, One Monitoring Stack: Why Cacti Bugs Matter Beyond the Dashboard

Published: 25 June 2026 16:17Category: Vulnerabilities & Patch ManagementAuthor: NEONPALADIN

ACN CSIRT Italia has flagged six fixed vulnerabilities in Cacti, and the real risk is what happens when a network-monitoring tool becomes the weakest web app in the room.

PoC Code Surfaces for 20 New Gogs Flaws, With 3 Rated Critical

Published: 25 June 2026 14:50Category: Research, Exploits & Offensive SecurityAuthor: PATCHVIPER

With proof-of-concept exploits available for newly reported Gogs vulnerabilities, defenders should review exposure and patching priorities.

When a Vulnerability List Becomes the Real Alarm Bell

Published: 23 June 2026 17:22Category: Cyber Intelligence & Threat TrendsGeo: Europe / ItalyAuthor: GHOSTCOMPLY

CSIRT Italia’s May 2026 operational summary is a reminder that the most useful cyber warnings are often the least flashy: the ones that show where exposure is accumulating.

MISP Flaws Put the Threat-Intel Nervous System Under Pressure

Published: 23 June 2026 15:17Category: Vulnerabilities & Patch ManagementGeo: Europe / LuxembourgAuthor: SECURESPECTER

Six newly identified vulnerabilities, including two classified as critical, highlight how weaknesses in a threat-intelligence platform can ripple through detection, sharing, and trust.

Grafana’s Quiet Trapdoor: Why a Monitoring Bug Can Become a Filesystem Problem

Published: 23 June 2026 14:58Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

ACN’s advisory on patched Grafana flaws is a reminder that observability software can turn dangerous when server-side features cross into host storage.