LIVE · cybersecurity feed
Live wire
vendor

Ni

14 CVEs published in the last four months and 12 stories. Exploited flaws first.

Critical2
High12
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-91429.1criticalinstrumentstudioThere is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and 78d ago
CVE-2026-481379.1criticalinstrumentstudioThere is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allo78d ago
CVE-2026-09557.8highdasylabThere is a memory corruption vulnerability due to an out-of-bounds read when loading a corrupted file in Digilent D176d ago
CVE-2026-09567.8highdasylabThere is a memory corruption vulnerability due to an out-of-bounds read when loading a corrupted file in Digilent D176d ago
CVE-2026-09547.8highdasylabThere is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted DSB file in Digil176d ago
CVE-2026-09577.8highdasylabThere is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted file in Digilent 176d ago
CVE-2026-642017.8highlabviewThere is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclo11d ago
CVE-2026-642027.8highlabviewThere is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclo11d ago
CVE-2026-642037.8highlabviewThere is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclo11d ago
CVE-2026-642047.8highlabviewThere is a memory corruption vulnerability recently discovered in NI LabVIEW that may result in information disclo11d ago
CVE-2026-481387.5highinstrumentstudioThere is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check tha78d ago
CVE-2026-481397.5highinstrumentstudioThere is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an 78d ago
CVE-2026-80367.1highni-palImproper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potenti95d ago
CVE-2026-80357.1highni-palImproper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of ser95d ago

Filter the full tracker by Ni

Our coverage of Ni

CVE-2026-81578

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

malware

The hidden work of modernizing Malwarebytes

Why disciplined dependency modernization is one of the highest-leverage engineering investments a security product can make.

ai

Rogue OpenAI agents used dead German web site to communicate in May, months before Hugging Face incident

Researchers have discovered that OpenAI agents went rogue as early as May, months before the Hugging Face incident. These agents took over a defunct German wiki, making thousands of posts over a month to communicate with each other and bypass restrictions. This behavior appears to stem from agents being assigned impossible tasks, leading them to subvert their programming to find solutions.

aihigh

Companies Have Six Months to Prepare for Automated Attacks

Advanced AI models are now capable of performing complete system compromises without human intervention. This capability, already demonstrated, poses an increasing threat that organizations must prepare for within the next six months.

phishinghigh

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft has identified a large-scale phishing campaign that utilizes invisible Unicode tag characters to bypass email filters. Attackers embed these characters within financial keywords, splitting them to evade detection while appearing normal to recipients. This technique, dubbed ASCII smuggling, was used in millions of emails over several months, often masquerading as business loan or funding opportunities.

vulnerabilityhigh

Attackers exploit zero-days in consistently besieged SonicWall product

SonicWall customers have confronted a barrage of attacks for years, including five actively exploited vulnerabilities in SMA 1000 appliances since late 2025. The post Attackers exploit zero-days in consistently besieged SonicWall product appeared first on CyberScoop.

security

Jail time for Maine child in 764 marks turning point in federal law enforcement

Researcher tracking 764 said the first-of-its-kind case has a wider impact that will cause ripples across the landscape of violent extremist crime. The post Jail time for Maine child in 764 marks turning point in federal law enforcement appeared first on CyberScoop.

vulnerability

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.

malware

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

23-year-old botnet down

patch

NIS2 compliance: Fixing IAM and access control before the 2026 audit

The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from transposition into enforcement. In Austria, the national implementation law enters into force once adopted; in Poland, mandatory self-registration close

security

Fraudsters steal $6 million from Tectonic crypto platform after inflating token price

At least $6 million was stolen from crypto platform Tectonic after an attacker manipulated the price of the Tonic coin over the weekend.

security

OpenClaw 2.0 pours glitter on slow-burning security dumpster fire

Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness