💥 BREACHES & INCIDENTS
- Hackers accused of €30M bank fraud exploiting service-provider flaw
Hackers allegedly stole about €30 million by exploiting a financial service provider's software flaw.
- Commerzbank customers were affected, but the bank said they suffered no financial losses.
- Attackers made unauthorized direct debits from German online banking accounts.
- A faulty software update introduced a vulnerability in a payment-processing system.
- The funds were routed through Brazil and concealed using pass-through accounts, companies, payment institutions, virtual-asset platforms, and payment cards.
- Four suspects were arrested in Brazil and three others were charged in Europe. 📎 Coverage: bleepingcomputer.com · 👁 via BleepingComputer
🔓 CVEs & KEV
- CVE-2026-73849 — CVSS 9.8 — emlog allows unauthenticated reinstallation via
install.php?action=reinstall... - CVE-2026-19682 — CVSS 9.4 — Command InjectionA command injection vulnerability exists in Security Center ...
- CVE-2026-19681 — CVSS 9.4 — Command InjectionAn authenticated command injection vulnerability exists in S...
- CVE-2026-19679 — CVSS 8.7 — Improper Input ValidationAn input validation vulnerability exists in Security...
- CVE-2026-73850 — CVSS 8.6 — Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase()...
- CVE-2026-19635 — CVSS 8.5 — Local Privilege EscalationA local privilege escalation vulnerability exists i...
- CVE-2026-72970 — CVSS 8.3 — Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityHeap-based...
- CVE-2026-24791 — CVSS 8.1 — Public-only tokens bypass private-resource restrictions on
/api/v1/usersel... - CVE-2026-59765 — CVSS 7.5 — SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal File...
- CVE-2026-19680 — CVSS 7.1 — SQL InjectionA SQL injection vulnerability exists in Security Center that cou...
- CVE-2026-73847 — CVSS 6.8 — Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full dat...
- CVE-2026-24059 — CVSS 6.5 — Gitea runner registration-token GET endpoint performs a write under a read-on...
- CVE-2026-19636 — CVSS 6.0 — Insuffucient Protections Lead to Brute ForceAn issue was identified in which ...