Get a Demo
Under Attack?
Stay ahead of the threat curve.

Get expert help, fast.

If you’re dealing with a potential compromise or active threat, our MDR team can help assess and respond.

Keep an eye on your inbox we will reach out immediately

Keep an eye on your phone we will reach out immediately

Security Feed

See the latest insights and analysis from our MDR team.
RSS for Slack
CVE-2026-18500
By Yogev Levi | 
16 August 2026

Fastify JWT key override allows cross-domain token acceptance

@fastify/jwt `

CVE-2026-74764
By Yogev Levi | 
16 August 2026

Pandora TAR extraction path traversal allows arbitrary file write and potential RCE

Affects `pandora

CVE-2026-72665
By Yogev Levi | 
16 August 2026

Kibana missing authorization allows unprivileged response actions via Elastic Security rules

Missing authorization (CWE-862) in Kibana allows a user who can author/evaluate Elastic Security detection rules to execute Osquery live queries and Elastic Defend response actions on enrolled agents without the required privileges. Affects 8.5.0-8.19.19 and 9.0.0-9.4.4. Patch to 8.19.20 or 9.4.5.

CVE-2026-73263
By Yogev Levi | 
16 August 2026

Prowler Kubernetes provider connection test allows OS command injection via legacy GCP kubeconfig auth-provider

Prowler < 5.36.0 accepts kubeconfig_content with legacy gcp auth-provider config.cmd-path/config.cmd-args during POST /api/v1/providers/{id}/connection. Because kubeconfig_contains_exec_auth checks only exec blocks, config.load_kube_config_from_dict triggers kubernetes-python CommandTokenSource.token to run attacker commands via subprocess.Popen on the shared worker. Upgrade to 5.36.0.

CVE-2026-62878
By Yogev Levi | 
16 August 2026

Windows DNS stack-based buffer overflow enables unauthenticated network RCE

A stack-based buffer overflow (CWE-121) in Windows DNS allows an unauthenticated attacker to execute code over a network (CVSS:3.1 9.8 AV:N/AC:L/PR:N/UI:N). Affects Windows builds before 10.0.14393.9418 (Win10 1607/Server 2016) and 10.0.17763.9115 (Win10 1809/Server 2019). Apply the Microsoft patch per MSRC guidance.

CVE-2026-71398
By Yogev Levi | 
16 August 2026

Adobe Campaign Classic incorrect authorization allows network RCE without user interaction

Adobe Campaign Classic (ACC) has an incorrect authorization (CWE-863) flaw exploitable over the network with no privileges or user interaction, enabling arbitrary code execution as the current user (scope changed). Affects ACC v7 up to 7.4.3 build 9399; fixed in 7.4.4 build 9400. Upgrade to 7.4.4 build 9400 or later.

See More

Secure the new Era of AI & Realtime

Get a Demo
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS