Security Vulnerabilities & CVE Database

Browse the latest CVE vulnerability disclosures, CISA KEV alerts, and OSV advisories. Real-time security vulnerability database curated by 10alert.

U.S. DoJ Charges 12 Chinese Nationals in Massive State-Linked Cyber Espionage Campaign

The U.S. Department of Justice (DoJ) has charged 12 Chinese nationals, including government officers and hackers, for their roles in a global cyber espionage campaign. This coordinated effort involved data theft and suppression of dissent, targeting U.S. critics, Asian governments, and key U.S. agencies. The indictment reveals the intricate web of state-sponsored hacking and the U.S. response to safeguard national security.

#cybersecurity & data protection #chinese hackers #data theft

Read full article →

Webinar Learn How ASPM Transforms Application Security from Reactive to Proactive

Are you tired of dealing with outdated security tools that never seem to give you the full picture? You're not alone. Many organizations struggle with piecing together scattered information, leaving your apps vulnerable to modern threats. That's why we're excited to introduce a smarter, unified approach: Application Security Posture Management (ASPM). ASPM brings together the best of both worlds by combining proactive measures with reactive strategies to enhance your security posture.

#application security #cybersecurity #proactive measures

Read full article →

FBI Alerts: Cybercriminals Impersonate 'BianLian Group' to Extort Corporate Executives

The FBI's Internet Crime Complaint Center (IC3) has issued a critical alert about a data extortion scam targeting corporate executives. Cybercriminals, posing as the 'BianLian Group,' send threatening letters demanding payment to prevent the release of sensitive information. Learn how to protect your organization and report incidents to CISA.

#cybersecurity & data protection #data extortion #corporate executives

Read full article →

Brickcom Camera Vulnerabilities Expose Feeds and Admin Control to Hackers

Brickcom cameras running firmware version 3.2.3.5.6 are vulnerable to two critical flaws—CVE-2026-50245 and CVE-2026-50005—enabling unauthenticated attackers to access live video feeds and seize administrative control. This affects multiple camera models deployed globally in commercial, healthcare, and manufacturing sectors, posing severe privacy and security risks. Users must mitigate risks immediately due to the lack of vendor response.

CVEs: CVE-2026-50245, CVE-2026-50005

#brickcom #cve-2026-50245 #cve-2026-50005 #iot security #unauthorized access

Read full article →

Critical Flaws in Yarbo App Expose Robot Fleets to Cyberattacks

Two critical vulnerabilities (CVE-2026-10557 and CVE-2026-7368) in the Yarbo mobile app and cloud infrastructure allow attackers to extract hard-coded credentials and manipulate robot fleets globally. These flaws expose real-time telemetry data and enable unauthorized command execution, impacting all deployed Yarbo robots worldwide. Users must update to app version 3.17.4 immediately to mitigate risks.

CVEs: CVE-2026-10557, CVE-2026-7368

#yarbo #mqtt #hard-coded-credentials #cve-2026-10557 #cve-2026-7368

Read full article →

Critical Flaws in Naxclow IoT Platform Expose Millions of Devices

Six critical vulnerabilities in the Naxclow IoT Platform (CVE-2026-42947, CVE-2026-50108, CVE-2026-50101, CVE-2026-28742, CVE-2026-42932, CVE-2026-50244, CVE-2026-50099) enable unauthorized device takeover, credential theft, and remote access across millions of smart devices globally, including Naxclow Smart Doorbell X3, X Smart Home, V720, and ix cam. Affected users face immediate risk of exploitation due to the absence of patches and Naxclow’s unresponsiveness to coordination efforts.

CVEs: CVE-2026-42947, CVE-2026-50108, CVE-2026-50101, CVE-2026-28742, CVE-2026-42932

#naxclow #iot-security #cve-2026 #vulnerabilities #cybersecurity

Read full article →

CISA Warns of Actively Exploited Ivanti Sentry Vulnerability

CISA has added CVE-2026-10520, a critical OS command injection vulnerability in Ivanti Sentry, to its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation in the wild. The flaw allows unauthorized command execution on affected systems, posing immediate risks to federal agencies and all organizations using vulnerable Ivanti Sentry versions. Immediate patching is required to prevent potential data breaches or system compromise.

CVEs: CVE-2026-10520

#cve-2026-10520 #ivanti sentry #cisa #known exploited vulnerabilities #os command injection

Read full article →