< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 4 sources · 7 days · First seen · Last updated

Global cybersecurity vulnerabilities and spyware threats

Overview

A series of critical cybersecurity vulnerabilities and sophisticated digital threats have been identified across major software and hardware platforms.

Initial reports highlighted flaws in the vm2 JavaScript sandbox package, IBM WebSphere Application Server Liberty, and IBM Db2 Mirror for i. Additionally, CISA identified a critical Internet Key Exchange vulnerability in Windows (CVE-2026-33824) with a CVSS score of 9.8, though Microsoft disputed its active exploitation status.

Subsequent findings revealed even higher-severity risks, including CVSS 10.0 vulnerabilities in Microsoft’s Entra ID cloud service and SAP Commerce Cloud, both of which showed signs of exploitation. Other security concerns emerged regarding Cisco platforms and the potential for man-in-the-middle attacks to manipulate NFC exchanges using expired Visa cards. Furthermore, Apple issued notifications regarding the use of sophisticated spyware, such as Pegasus, Predator, and Graphite, targeting high-profile individuals.

Entities

Microsoft · Visa · IBM · Cisco · SAP

Timeline

  1. 19 days ago

    [TECHNOLOGY] 2 sources
    Cybersecurity Alert: Critical vulnerabilities found in Microsoft, SAP, and Visa systems

    Critical cybersecurity threats include CVSS 10.0 vulnerabilities in Microsoft Entra ID and SAP, NFC-based Visa card exploits, and sophisticated spyware campaigns targeting high-profile Apple users.

  2. 26 days ago

    [TECHNOLOGY] 2 sources
    Cybersecurity alerts issued for Windows, IBM, and vm2 software

    Major software vulnerabilities have been reported in Windows IKE, IBM WebSphere and Db2, and the vm2 JavaScript sandbox, posing risks of remote code execution and data manipulation.

Sources

blogspan.net · cert.ssi.gouv.fr · cybersecurity-news.de · ledecodeur.ch