Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 4 sources · 7 days · First seen · Last updated
Global cybersecurity vulnerabilities and spyware threats
Overview
A series of critical cybersecurity vulnerabilities and sophisticated digital threats have been identified across major software and hardware platforms.
Initial reports highlighted flaws in the vm2 JavaScript sandbox package, IBM WebSphere Application Server Liberty, and IBM Db2 Mirror for i. Additionally, CISA identified a critical Internet Key Exchange vulnerability in Windows (CVE-2026-33824) with a CVSS score of 9.8, though Microsoft disputed its active exploitation status.
Subsequent findings revealed even higher-severity risks, including CVSS 10.0 vulnerabilities in Microsoft’s Entra ID cloud service and SAP Commerce Cloud, both of which showed signs of exploitation. Other security concerns emerged regarding Cisco platforms and the potential for man-in-the-middle attacks to manipulate NFC exchanges using expired Visa cards. Furthermore, Apple issued notifications regarding the use of sophisticated spyware, such as Pegasus, Predator, and Graphite, targeting high-profile individuals.
Entities
Timeline
-
19 days ago
[TECHNOLOGY] 2 sourcesCybersecurity Alert: Critical vulnerabilities found in Microsoft, SAP, and Visa systemsCritical cybersecurity threats include CVSS 10.0 vulnerabilities in Microsoft Entra ID and SAP, NFC-based Visa card exploits, and sophisticated spyware campaigns targeting high-profile Apple users.
-
26 days ago
[TECHNOLOGY] 2 sourcesCybersecurity alerts issued for Windows, IBM, and vm2 softwareMajor software vulnerabilities have been reported in Windows IKE, IBM WebSphere and Db2, and the vm2 JavaScript sandbox, posing risks of remote code execution and data manipulation.
Sources
blogspan.net · cert.ssi.gouv.fr · cybersecurity-news.de · ledecodeur.ch