Blog · Radar OCIRIA

On top of every new threat.

Vulnerability alerts, clear guides and what we see on our threat radar — so your company is never the last to know.

Scan my domain free →
All VulnerabilitiesRansomwareComplianceOSINTBy sectorGuides
🛡️
VulnerabilityLatest

CVE-2026-0770: Critical Remote Code Execution Vulnerability in Langflow, Actively Exploited

CVE-2026-0770: critical flaw (CVSS 9.8) in Langflow, listed in CISA KEV as actively exploited. What to do today.

24 Jul 2026Read →
🛡️Vulnerability

CVE-2026-0257: authentication bypass in PAN-OS GlobalProtect, actively exploited

CVE-2026-0257 allows bypassing VPN authentication in PAN-OS GlobalProtect. It is listed in the CISA KEV catalog. What to do today.

22 Jul 2026Read →
🛡️Vulnerability

CVE-2026-42271: remote command execution in LiteLLM, already actively exploited

LiteLLM (CVE-2026-42271) allows commands to be run with low-privilege keys and is listed in the CISA KEV catalog. What to do today.

20 Jul 2026Read →
🛡️Vulnerability

CVE-2026-42208: critical SQL injection in LiteLLM, now on the CISA KEV catalog

Critical vulnerability (CVSS 9.3) of SQL injection in LiteLLM, actively exploited according to CISA KEV. What to do if you use this AI proxy.

17 Jul 2026Read →
🛡️Vulnerability

CVE-2026-45498: denial-of-service vulnerability in Microsoft Defender, on the radar for active exploitation

CVE-2026-45498 affects Microsoft Defender with confirmed active exploitation. What it is, who it affects, and how to protect yourself.

15 Jul 2026Read →
🛡️Vulnerability

CVE-2026-48907: critical vulnerability in Joomla's JCE Editor extension, added to CISA's KEV catalog

CVE-2026-48907: critical flaw (CVSS 10) in JCE Editor for Joomla, listed in CISA's KEV. What to do if your website uses this extension.

15 Jul 2026Read →
🛡️Vulnerability

CVE-2026-34910: critical vulnerability in Ubiquiti UniFi OS actively exploited

CVE-2026-34910 (CVSS 10.0) affects Ubiquiti UniFi OS and is on CISA's KEV catalog. What to do today.

13 Jul 2026Read →
🛡️Vulnerability

CVE-2026-32202: Windows Spoofing Vulnerability Actively Exploited According to CISA KEV

CVE-2026-32202 affects Windows Shell, is listed in CISA KEV (active exploitation) and has a CVSS score of 4.3. What it is and how to protect yourself today.

10 Jul 2026Read →
🛡️Vulnerability

CVE-2026-20182: critical vulnerability in Cisco Catalyst SD-WAN, now in the CISA KEV catalog

Alert: CVE-2026-20182, a critical vulnerability (CVSS 10) in Cisco Catalyst SD-WAN, included in CISA KEV. What to do today.

8 Jul 2026Read →
🛡️Vulnerability

CVE-2026-50751: Check Point VPN authentication bypass, already actively exploited

CVE-2026-50751 allows bypassing Check Point VPN authentication without a valid password. It is on the KEV catalog. What to do today.

6 Jul 2026Read →
🛡️Vulnerability

CVE-2026-35273: critical vulnerability in Oracle PeopleSoft actively exploited

CVE-2026-35273 (CVSS 9.8) affects Oracle PeopleSoft PeopleTools and is on CISA's KEV catalog. What to do today.

3 Jul 2026Read →
📋Compliance

GDPR and NIS2 together: how to avoid duplicating compliance effort

How GDPR and NIS2 overlap, where they diverge, and how to build one programme that satisfies both without doubling the work.

29 Jun 2026Read →
🛡️Vulnerability

CVE-2023-27351: Authentication Bypass in PaperCut NG, Actively Exploited

High-severity vulnerability (CVSS 7.5) in PaperCut NG allows access without credentials. Listed in CISA's KEV catalog. Update now.

29 Jun 2026Read →
🛡️Vulnerability

CVE-2026-9082: Critical SQL Injection in Drupal Core — Update Now

CVE-2026-9082 is a critical vulnerability (CVSS 9.8) of SQL Injection in Drupal Core under active exploitation. Find out how to protect your website.

27 Jun 2026Read →
🛡️Vulnerability

CVE-2026-41940: Critical Authentication Bypass Vulnerability in cPanel and WHM

Critical vulnerability (CVSS 9.3) in cPanel and WHM allows administrative access without credentials. Listed in CISA KEV. Update now.

27 Jun 2026Read →
🛡️Vulnerability

CVE-2026-20253: Critical Authentication Vulnerability in Splunk Enterprise

Splunk Enterprise has a critical function with no authentication that allows the creation or truncation of arbitrary files. Update now if you use Splunk.

27 Jun 2026Read →
🛡️Vulnerability

CVE-2026-31431: Linux Kernel privilege escalation added to CISA's KEV catalog

CVE-2026-31431 affects the Linux kernel and allows privilege escalation to root. Included in KEV. What to do today.

27 Jun 2026Read →
🔎OSINT

OSINT audit: what we deliver and how long it actually takes

A transparent description of an OSINT defensive audit: scope, timeline, deliverables, what we will not include, and the honest limits.

12 Jun 2026Read →
📋Compliance

NIS2 self-assessment: 25 questions to check if your company complies

A 25-question NIS2 self-assessment for European mid-market companies. Operational, no FUD, no sales pitch. Take it in 20 minutes.

8 Jun 2026Read →
📘Guide

Tier-1 vs tier-2 cybersecurity vendors: how to choose by company size

An honest comparison of large cybersecurity vendors and boutique tier-2 firms for mid-market European companies. Criteria, trade-offs, no marketing.

5 Jun 2026Read →
📋Compliance

vCISO vs internal CISO: when each model actually fits

An honest comparison of the virtual CISO and the in-house CISO for mid-market European companies. Decision criteria, not a sales pitch.

29 May 2026Read →
📋Compliance

DMARC explained: why your email is vulnerable and how to fix it in 24h

Why most mid-market companies still have weak DMARC, what a working configuration looks like, and a 24-hour path to p=reject without breaking mail.

22 May 2026Read →
🔎OSINT

OSINT 101: 7 things an attacker finds about your company in 30 minutes

What an external observer learns about your company using only public data, in less than 30 minutes. Honest field report, no scaremongering.

15 May 2026Read →
📋Compliance

AI defensive vs AI offensive: the 2026 paradigm shift, honestly read

What changed in 2026 between offensive and defensive AI in cybersecurity. Concrete capabilities, honest limits, no marketing demos.

8 May 2026Read →

No hay publicaciones en esta categoría todavía.