Technology Intelligence

Threats against technology companies, software vendors, cloud services, and tech infrastructure.

1000
Total Reports
192
Critical Threats
288
High Threats
MEDIUMMalwareNEW

The HazyBeacon Protocol – How Malware Weaponizes Amazon Web Services (AWS) Lambda Function URLs

Key Takeaways The Rise of Cloud-Native Command and Control (C2) Command and control (C2) infrastructure traditionally lived outside the victim environment. Malware beaconed to attacker-operated servers hosted on rented VPS infrastructure or compromised websites, and defenders focused on identifying those endpoints through IP reputation, domain intelligence, and network blocking. Cloud computing ha

Qualys Blog
MEDIUMVulnerabilityNEW

Parents Sue Minnesota Hospital to Enforce HIPAA Right of Access for Minor Child’s Medical Records

The parents of a 15-year-old child have filed a lawsuit against a Minnesota hospital for failing to provide them with […] The post Parents Sue Minnesota Hospital to Enforce HIPAA Right of Access for Minor Child’s Medical Records appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMAiNEW

Instagram users locked out after Meta AI abused to steal accounts

Multiple Instagram users had their accounts hijacked after attackers convinced Meta's AI-powered support tools that they were the legitimate owners. [...]

BleepingComputer
MEDIUMVulnerabilityNEW

Infosecurity Europe: NCSC Urges Immediate Action to Boost Resilience as Uncertainty Persists

NCSC director of operations, Paul Chichester, says it’s time to future-proof cybersecurity today

Infosecurity Magazine
MEDIUMVulnerability

XTrasfer and BBVA team i cross-border payments

XTransfer, the world’s leading B2B cross-border trade payment platform, and BBVA, a global financial group, have signed a Memorandum of Understanding (MOU) during Money20/20 Europe 2026 in Amsterdam to deepen cross-border payment infrastructure across Latin America and Europe.

Finextra
MEDIUMAi

ING complete live end-to-end European agentic payment transaction

ING, Worldline and Mastercard have carried out what they claims is Europe's first end-to-end agentic payment transaction.

Finextra
MEDIUMVulnerability

Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk

A simple development setting bypassed protections designed to prevent unauthorized Android apps from accessing Microsoft account tokens, exposing billions of installations. The post Exclusive: How One Line of Code Put Billions of Microsoft Android App Downloads at Risk appeared first on SecurityWeek .

SecurityWeek
LOWVulnerability

Infosecurity Europe: Cybersecurity Teams Which Don’t Leverage AI are "Doomed to Fail"

Humans still need to be part of cyber defense, but refusing to deploy AI is no longer optional against AI-enhanced cyber threats, warns Dataminr’s Joe Slowik

Infosecurity Magazine
MEDIUMVulnerability

Franklin Templeton and MoonPay bid to expand institutional access to tokenised funds

Franklin Templeton and MoonPay today announced a strategic partnership to make tokenized financial products more accessible and usable across the onchain financial ecosystem.

Finextra
MEDIUMVulnerability

Investing app Plynk revamps app

Plynk, the award-winning investing app designed to uncomplicate the investing experience and empower users with confidence-boosting tools, announced its app upgrade and rebrand alongside the launch of the dividend match, a first-of its-kind offer.

Finextra
MEDIUMVulnerability

DNB Bank expands partnership with Infosys for AI-driven financial crime operations

Infosys (NSE, BSE, NYSE: INFY), a global leader in AI-first business consulting and technology services, today announced the expansion of its strategic collaboration with DNB Bank ASA (DNB), Norway’s largest bank, to modernize its Financial Crime (FinCrime) operations using NICE Actimize X-Sight Enterprise platform.

Finextra
CRITICALZero Day

Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities

Google says the Android vulnerability CVE-2025-48595 has been exploited in limited, targeted attacks. The post Android Update Patches Exploited Zero-Day, 123 Other Vulnerabilities appeared first on SecurityWeek .

CVE-2025-48595
SecurityWeek
CRITICALAi

Why the browser is now the front line for AI security

AI-powered attacks and shadow AI adoption are creating new security risks inside the browser. Push Security explains why browser visibility is becoming critical for both threat detection and AI governance. [...]

BleepingComputer
MEDIUMVulnerability

MoneyGram launches stablecoin

MoneyGram has launches a US dollar stabelcoin on the Stellar blockchain and issued by Stripe-owned Bridge.

Finextra
CRITICALAi

Anthropic expanding access to Project Glasswing

Roughly 150 new organizations across critical infrastructure sectors will gain access to Claude Mythos Preview, Anthropic's most capable — and most restricted — AI model. The post Anthropic expanding access to Project Glasswing appeared first on CyberScoop .

CyberScoop
MEDIUMAi

Anthropic Expanding Mythos Access to 150 New Organizations

Only approximately 50 companies have had access to Mythos until now and they have found thousands of vulnerabilities in their products. The post Anthropic Expanding Mythos Access to 150 New Organizations appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Infosecurity Europe: Bayer Reinvents Security Awareness Training to Counter AI Threats

Bayer’s security awareness training now focuses on psychological approaches rather than technical methods for detecting social engineering

Infosecurity Magazine
MEDIUMVulnerability

Red Hat removes tainted packages after software pipeline compromise

According to the company’s preliminary analysis, a compromised GitHub account was used to push the malicious code out to customers, hitting 32 packages downloaded roughly 117,000 times a week.

The Record
MEDIUMApt

LABScon25 Replay | Gamaredon x Turla: Unveiling a 2025 Espionage Alliance Targeting Ukraine

ESET researchers show how Gamaredon facilitated Turla access to Ukrainian targets, revealing rare cooperation between FSB-linked espionage groups.

SentinelLabs
CRITICALVulnerability

CISA flags two-year-old Oracle flaw as actively exploited in attacks

CISA has ordered government agencies to secure their systems against a high-severity Oracle WebLogic Server vulnerability that was patched two years ago and is now actively exploited in attacks. [...]

BleepingComputer
MEDIUMMalware

The Zero-Knowledge Threat Actor and the End of Responsible Disclosure

AI can help attackers generate malware, create malicious payloads, bypass simple security checks, and convert vague malicious intent into functional code. The post The Zero-Knowledge Threat Actor and the End of Responsible Disclosure appeared first on SecurityWeek .

SecurityWeek
CRITICALVulnerability

Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches

A stack-based buffer overflow bug can be exploited for remote code execution on a vulnerable device. The post Critical Vulnerability in HP VoIP Phones Enables Enterprise Network Breaches appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked

Jason Koebler reports: Hackers say that they used Meta’s AI support chatbot to break into a host of high-profile Instagram profiles by asking the support bot to change the email address associated with the target account. The claims coincide with a series of high-profile Instagram account takeovers, including the Barack Obama White House account, the Chief Master... Source

DataBreaches.net
MEDIUMVulnerability

ThinkMarkets launches Ai assistant for CFD trading

ThinkMarkets (www.ThinkMarkets.com) today launches ChelseaAI, a product that connects a live ThinkTrader account directly to an AI assistant.

Finextra
HIGHSupply Chain

Infected Red Hat npm packages expose developer credentials

Developers who pulled packages from Red Hat’s @redhat-cloud-services npm namespace over the weekend got a secret-stealing worm instead. Security researchers from several cybersecurity outlets are warning of a new supply chain attack compromising over 30 Red Hat Cloud Services-related npm packages to steal credentials, authentication tokens, and other secrets from developer environments. The campai

CSO Online
MEDIUMData Breach

Wardriving assessment across Mexico: Preparing for the 2026 World Cup

In the lead-up to the 2026 FIFA World Cup, Kaspersky GReAT experts conducted a wardriving assessment in Mexico City, Monterrey, and Guadalajara to evaluate Wi-Fi hotspot security configurations and potential exposure risks.

Securelist (Kaspersky)
MEDIUMVulnerability

Beyond Assume-Breach: How AI-Native Security Will Reshape Enterprise Defense

Twenty years after Dark Reading launched, we're looking ahead at what's next for enterprise security. Spoiler: It's hyper-segmented, AI-orchestrated, and way more sophisticated than your dad's firewall.

Dark Reading
MEDIUMVulnerability

Eventus names Eric Litz as CTo and Sarah-Jane McColl as chief customer officer

Eventus, a leading provider of comprehensive, at-scale trade surveillance and financial risk solutions, today announced the expansion of its leadership team with the appointment of Eric Litz as Chief Technology Officer (CTO) and Sarah-Jane McColl as Chief Customer Officer (CCO).

Finextra
MEDIUMVulnerability

Klarna adds healthcare to membership programme

Kry Livi, the UK's leading digital healthcare provider, today announces a new partnership with Klarna, the global digital bank and flexible payments provider, bringing on-demand clinical consultations to Klarna's UK members as digital-first healthcare continues to grow.

Finextra
MEDIUMVulnerability

AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.

AI-driven exploitation timelines are rapidly shrinking, and they are not going to stop shrinking. Vulnerabilities are being discovered, reproduced, and weaponized faster than ever in the history of enterprise security. As a result, the window between a vulnerability being disclosed and indiscriminate exploitation observed across the internet is now measured in hours, not days. The industry's

The Hacker News
HIGHVulnerability

Oracle WebLogic Vulnerability Exploited in the Wild

The vulnerability is CVE-2024-21182 and it can be exploited without authentication to hack affected WebLogic servers. The post Oracle WebLogic Vulnerability Exploited in the Wild appeared first on SecurityWeek .

CVE-2024-21182
SecurityWeek
MEDIUMVulnerability

PayWallet expands payout capabilities with TerraPay integration

TerraPay, a global money movement company, has partnered with PalWallet, a fintech infrastructure provider focused on stablecoin settlement, global payments infrastructure and embedded financial services, to help businesses move money across borders faster and more efficiently.

Finextra
CRITICALMalware

Attackers exploit Palo Alto GlobalProtect flaw days after disclosure

A Palo Alto Networks vulnerability that allows attackers to establish unauthorized VPN access into corporate networks is being actively exploited in the wild, weeks after the company disclosed the flaw as a medium-severity issue and said it was unaware of any attacks. However, according to Rapid7, threat actors began exploiting the bug within days of disclosure. “Rapid7 MDR identified successful e

CVE-2026-0257
CSO Online
CRITICALZero Day

Google fixes one actively exploited Android zero-day, 124 flaws

Google has released the June 2026 Android security patches to address 124 vulnerabilities, including one zero-day flaw exploited in targeted attacks. [...]

BleepingComputer
MEDIUMVulnerability

The Intersection of Encryption and AI

As part of their 20th Anniversary celebration, Dark Reading asked five cybersecurity industry leaders who wrote blogs or columns for them over the years to select their favorite piece and share their reflections on the topic today. This is my section. Renowned technologist and author Bruce Schneier contributed a column on June 20, 2010, warning about cryptography’s inability to secure modern

Schneier on Security
HIGHData Breach

Family Medicine Centers Pays $2.15M to Resolve Data Breach Lawsuit

FMC Services, LLC, which does business as Family Medicine Centers in Texas, has agreed to a $2,150,000 settlement to resolve […] The post Family Medicine Centers Pays $2.15M to Resolve Data Breach Lawsuit appeared first on The HIPAA Journal .

HIPAA Journal
HIGHData Breach

Family Medicine Centers Pay $2.15M to Resolve Data Breach Lawsuit

FMC Services, LLC, which does business as Family Medicine Centers in Texas, has agreed to a $2,150,000 settlement to resolve […] The post Family Medicine Centers Pay $2.15M to Resolve Data Breach Lawsuit appeared first on The HIPAA Journal .

HIPAA Journal
CRITICALZero Day

Microsoft Threatening Security Researcher

An anonymous security researcher called “Nightmare Eclipse” has been publishing a series of significant security exploits against Microsoft Windows—including one that breaks BitLocker. Microsoft has threatened legal action against the researcher. Lots of recriminations are being traded back and forth.

Schneier on Security
MEDIUMMalware

Threat Actor Uses AI to Build EDR Evasion Tools

A threat actor used AI coding tools to build and test EDR evasion malware, Sophos finds

Infosecurity Magazine
HIGHData Breach

Patient Data Exposed in Cyberattacks on Dental Practices

Data breaches have been announced by Bridle Trails Family Dentistry, Verber Dental Group, and Bronsky Orthodontics. Across the three incidents, […] The post Patient Data Exposed in Cyberattacks on Dental Practices appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

UK Payments Initiative launches to challenge Visa and Mastercard stranglehold

The UK Payments Initiative, a new company formed with the backing of the UK's biggest banks, has gone live, with the aim of undermining the dominance of US card networks in payments.

Finextra
MEDIUMVulnerability

Meta AI Hands Over High-Profile Instagram Accounts to Hackers

Exploiting a confused deputy weakness, the hackers simply asked the chatbot to link the account to a new email address. The post Meta AI Hands Over High-Profile Instagram Accounts to Hackers appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

transfermate moves on stablecoins

TransferMate, the leading provider of embedded B2B payments, has selected BVNK as its stablecoin infrastructure partner in a new integration that will see TransferMate use BVNK to offer stablecoin capabilities across its global network for the first time.

Finextra
MEDIUMVulnerability

How Leading Organizations Are Turning EDR Into Operational Resilience

Most organizations now recognize that endpoint protection alone is no longer sufficient. That's why adoption of endpoint detection and response (EDR) has accelerated rapidly in recent years. Organizations understand that modern attacks move faster, evade traditional prevention controls, and require continuous visibility into suspicious activity across the environment. But owning EDR

The Hacker News
MEDIUMMalware

Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor

Operation FlutterBridge is a malvertising campaign targeting macOS users. It distributed the new backdoor FlutterShell, built using the Flutter framework. The post Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor appeared first on Unit 42 .

Unit 42 (Palo Alto)
MEDIUMVulnerability

Juspay joins Mastercard Engage network

Juspay, a leading global payments technology company, today announced that it has joined the Mastercard Engage partner network as a certified third-party partner for Mastercard Click to Pay.

Finextra
MEDIUMAi

Infosecurity Europe: UK Firms Prioritize AI Threat Preparedness as Cyber Risks Evolve

UK organizations are prioritizing AI-driven cybersecurity as 43% cite AI-powered attacks as their top risk, prompting significant investment in advanced threat defense

Infosecurity Magazine
MEDIUMSupply Chain

Attackers Hijack Red Hat npm Scope to Steal Cloud Secrets

Attackers backdoored 32 packages in Red Hat's official npm scope to steal cloud and CI secrets

Infosecurity Magazine
HIGHSupply Chain

Attack targeting OpenAI Codex users exposes AI software supply chain risks

A malicious npm package posing as a remote user interface for OpenAI Codex exfiltrated developer authentication tokens, after attackers allegedly published code to npm that was not visible in the project’s public GitHub repository. Researchers at Aikido said the package, called codexui-android, appeared to offer legitimate functionality while collecting authentication tokens and sending them to an

CSO Online
MEDIUMVulnerability

Ripple brings RLUSD stablecoin to Turkey

Ripple, the leading provider of blockchain-based enterprise solutions across traditional and digital finance, today announced that its enterprise-grade, USD-backed stablecoin Ripple USD (RLUSD) is now available to institutions in Türkiye through three new partnerships with BiLira, Bitexen and Bitlo.

Finextra
MEDIUMSupply Chain

Supply Chain Attack Hits 32 Red Hat NPM Packages

Hackers published 96 malicious package versions, injected with a credential-stealing worm similar to Mini Shai-Hulud. The post Supply Chain Attack Hits 32 Red Hat NPM Packages appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

PayAngel taps Currencycloud to strengthen multicurrency accounts and payouts

PayAngel, a cross-border payments platform built by migrants and shaped by a lived understanding of the migrant journey, today announced an expanded collaboration with Visa, a world leader in digital payments.

Finextra
MEDIUMVulnerability

KBank and Ant International turn to JPMorgan's Kinexys for real-time cross-border USD

Kasikornbank has signed an MoU with Ant International to deploy blockchain rails for cross-border US Dollar transactions.

Finextra
MEDIUMMalware

Pakistan-Linked SideCopy Targets Afghanistan Finance Ministry with Xeno RAT

Cybersecurity researchers have disclosed details of a spear-phishing campaign likely undertaken by the Pakistan-aligned SideCopy group targeting Afghanistan's Ministry of Finance with an open-source remote access trojan called Xeno RAT. "The campaign opens with a spear phishing delivery - a ZIP archive containing a malicious LNK file bearing a carefully crafted Pashto-language filename,"

The Hacker News
MEDIUMVulnerability

Infosecurity Europe: Business Leaders Lack Understanding of Threat Intelligence, Study Warns

A new Silobreaker and SANS Institute paper examines the ‘Intelligence-Stakeholder Gap’ and what organizations must do to achieve business buy-in on threat intelligence

Infosecurity Magazine
MEDIUMVulnerability

Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads

Dashlane’s security systems automatically locked accounts to protect them against the hacking attempts. The post Dashlane Brute-Force Attack Leads to Limited Encrypted Vault Downloads appeared first on SecurityWeek .

SecurityWeek
MEDIUMPhishing

New Wave Of Phishing Emails with SVG Files, (Tue, Jun 2nd)

For a few days, my SANS ISC mailbox is flooded with emails that delivers SVG files. An SVG ("Scalable Vector Graphic") is a web-friendly vector file format used for graphics and icons. No URL in the body, just “an image”, that&#x27s the perfect way to deliver some malicious content. This isn&#x27t the first time that we see this technique used by threat actors&#x5

SANS ISC
CRITICALVulnerability

Oracle’s First Monthly Patches Resolve 77 Vulnerabilities

Oracle’s monthly Critical Security Patch Update (CSPU) rollouts are meant to deliver critical fixes faster. The post Oracle’s First Monthly Patches Resolve 77 Vulnerabilities appeared first on SecurityWeek .

SecurityWeek
CRITICALRansomware

7 tabletop exercise mistakes that sabotage incident response

Discussion-based, low-stress simulations during which IT, legal, and other key leadership stakeholders walk through theoretical scenarios to test their preparedness for cyber incidents is a popular and highly useful tool. Yet unless tabletop training is properly handled, the results can be misleading and potentially destructive. When your organization’s incident response training consistently fail

CSO Online
LOWVulnerability

Dashlane Discloses Brute-Force Attack, Encrypted Vaults of Fewer Than 20 Users Downloaded

Password manager Dashlane has disclosed that "fewer than" 20 users on the personal subscription plan had their encrypted vaults downloaded following a brute-force attack launched by an unknown party. On May 31, 2026, the company said an "external" threat actor launched a brute-force attack against certain Dashlane user accounts with the aim of breaking two-factor authentication (2FA)

The Hacker News
MEDIUMVulnerability

Alberto Daniel Hill’s Cybermidnight Coverage of the Latin American Digital Sovereignty Crisis (March–June 2026)

Alberto Daniel Hill’s report is a must-read for anyone who wants to begin to understand what is going on in Argentina, Uruguay, and Mexico with respect to digital security. One of the many limitations of being a solo blogger is that there are entire areas of the world or sectors I basically know nothing about... Source

DataBreaches.net
MEDIUMAi

OpenAI gives UK banks access to cybersecurity model

OpenAI has offered the UK's biggest banks access to its new cybersecurity AI model. The decision contrasts with the approach taken by rival Anthropic, which continues to keep its Mythos model out of the hands of non-US lenders.

Finextra
MEDIUMAi

Gradient Labs raises fresh funds to build specialist AI agents for finance

Gradient Labs, the startup founded by Monzo alumni to create AI agents for the financial services industry, has doubled its Series A round with $13 million in fresh funding.

Finextra
MEDIUMVulnerability

Why Firms Struggle With Vendor Security After They Sign

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/healthcare-firms-struggle-ongoing-vendor-oversight-image_small-9-a-31826.jpg" align=right hspace=4><b>Study: Monitoring Vendor Risk Remains Much Harder Than Onboarding Third Parties</b><br>Healthcare organizations are getting better vetting third-party vendors, including suppliers of medical devices, software and other products. B

Bank Info Security
LOWVulnerability

Rapid7 Names Wael Mohamed CEO Amid Ongoing Growth Struggles

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/rapid7-names-wael-mohamed-ceo-amid-ongoing-growth-struggles-image_small-2-a-31830.jpg" align=right hspace=4><b>Former Forescout CEO, Trend Micro COO Mohamed Succeeds Corey Thomas After 13 Years</b><br>Rapid7 has appointed former Forescout CEO Wael Mohamed as chief executive, betting that a renewed focus on AI-driven security opera

Bank Info Security
MEDIUMVulnerability

Dragos Expands Into Connected Devices With Phosphorus Buy

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/dragos-expands-into-connected-devices-phosphorus-buy-image_small-5-a-31828.jpg" align=right hspace=4><b>OT Firm Looks to Secure IoT, Industrial and Medical Devices</b><br>Dragos, one of the first OT cybersecurity companies, announced Monday it acquired Phosphorus, the IoT security and management player, a move analysts said was de

Bank Info Security
MEDIUMVulnerability

Spain arrests suspected hacker for publishing personal data of police, prosecutors and cyber officials

Police described the incident as a large-scale disclosure of sensitive personal information that posed a threat to both the affected individuals and the institutions they serve. The data was allegedly posted on multiple internet platforms.

The Record
MEDIUMVulnerability

Attackers are exploiting Palo Alto Networks defect that initially flew under the radar

The escalated threat posed by the defect showcases how quickly a seemingly mild vulnerability can turn into an urgent warning. The post Attackers are exploiting Palo Alto Networks defect that initially flew under the radar appeared first on CyberScoop .

CyberScoop
MEDIUMSupply Chain

Red Hat Cloud Services npm Packages Hijacked

<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/red-hat-cloud-services-npm-packages-hijacked" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/blog_miasma_npm_campaign.png" alt="Image with text "Red Hat Hijacked: Malicious Miasma npm campaign"" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0

Sonatype (Maven/npm)
MEDIUMMalware

Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks

A threat actor tracked as DriveSurge has been operating large-scale malware distribution campaigns using ClickFix and FakeUpdates techniques on compromised sites. [...]

BleepingComputer
MEDIUMSupply Chain

Red Hat npm packages compromised to steal developer credentials

More than 30 npm packages under Red Hat's '@redhat-cloud-services' namespace were compromised in a supply-chain attack that distributed a new variant of the Shai-Hulud credential-stealing malware, dubbed "Miasma." [...]

BleepingComputer
MEDIUMVulnerability

Spain arrests doxer leaking sensitive data of govt employees

The Spanish National Police has arrested an individual for leaking sensitive information related to members of various key state organizations, including the National Cybersecurity Institute (INCIBE). [...]

BleepingComputer
MEDIUMAi

Anthropic to Open Mythos AI to EU's ENISA

The European security agency's entry to Project Glasswing is the result of "strong bilateral cooperation" between the European Commission and Anthropic.

Dark Reading
MEDIUMAi

Why Most Enterprise AI Failures Aren't Technical

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/most-enterprise-ai-failures-arent-technical-image_small-7-a-31822.jpg" align=right hspace=4><b>OpenText CIO Shannon Bell on Governance and Operational Maturity</b><br>Enterprise AI often fails not because the models are weak, but because organizations lack operational maturity. OpenText's Shannon Bell explains why governance, data

Bank Info Security
MEDIUMAi

Europe Edges Closer to Claude Mythos Access

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/europe-edges-closer-to-claude-mythos-access-image_small-3-a-31827.jpg" align=right hspace=4><b>Anthropic Offers ENISA a Place in Project Glasswing</b><br>Anthropic offered the European Union’s cybersecurity agency ENISA entry to Project Glasswing, its arrangement for giving organizations controlled early access to its vulnerabilit

Bank Info Security
MEDIUMVulnerability

Inspector general finds NIST mistakes have made vulnerability database ineffective

NIST’s National Vulnerability Database (NVD) backlog mushroomed from 13,000 unprocessed security vulnerabilities in February 2024 to more than 27,000 by the end of 2025, “undermining the NVD’s utility and public trust," according to an inspector general report.

The Record
MEDIUMVulnerability

Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight

The former Colorado election clerk struck an unrepentant pose in her first interview after her prison sentence was commuted by Colorado Governor Jared Polis. The post Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight appeared first on CyberScoop .

CyberScoop
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9311 — IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execu...

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

CVE-2026-9311
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-8644 — IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing...

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

CVE-2026-8644
NIST NVD
CRITICALZero Day

Microsoft's Zero-Day Legal Threats Spark Backlash

After a disgruntled security researcher published several zero-day exploits in recent weeks, Microsoft seemingly indicated criminal charges were in order.

Dark Reading
MEDIUMVulnerability

NSA selects new leads for key cybersecurity posts

David Imbordino, an NSA senior executive who most recently led its cybersecurity directorate in an acting capacity, has been named as its new chief. Bruce Jones, a career NSA technical and operational leader, as the new head of its Cybersecurity Collaboration Center.

The Record
LOWVulnerability

WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites

The security defect (CVE-2026-8732) allows unauthenticated attackers to create administrative accounts on the affected installations. The post WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites appeared first on SecurityWeek .

CVE-2026-8732
SecurityWeek
LOWVulnerability

Dashlane password manager users locked out by brute force attacks

Multiple Dashlane users have been locked out of their accounts following brute-force attacks that attempted logins from distant locations and unknown devices. [...]

BleepingComputer
MEDIUMVulnerability

Mastercard joins Tips cross-currency pilot

Mastercard is working with Denmark's and Sweden's central banks to pilot instant cross-currency payments on the Eurosystem’s Target Instant Payment Settlement (Tips) platform.

Finextra
MEDIUMVulnerability

USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order

A judge said Democrats and civil groups filed the lawsuit too early to demonstrate harm, but that could change after newly proposed postal regulations. The post USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order appeared first on CyberScoop .

CyberScoop
CRITICALSupply ChainPOC

Oracle’s first monthly patch release fixes 35 flaws, including 11 rated ‘critical’

Oracle has released the first security fixes in its new monthly Critical Security Patch Update (CSPU) cycle, designed to address urgent vulnerabilities that can’t wait for the company’s quarterly patching. The initial batch addresses 35 flaws, including several for which exploit code is publicly available. In total, there are 11 flaws rated ‘critical’ , 18 rated ‘high’, and 6 ‘medium’. The most im

CVE-2026-46840CVE-2026-46775
CSO Online
MEDIUMMalware

Dutch Police Dismantle Massive 17-Million-Device Botnet

Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime. The post Dutch Police Dismantle Massive 17-Million-Device Botnet appeared first on SecurityWeek .

SecurityWeek
MEDIUMSupply Chain

Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm

A new Mini Shai-Hulud supply chain attack campaign, codenamed Miasma, has compromised @redhat-cloud-services packages to steal credentials and secrets from developer machines and deliver a self-propagating worm. "This is effectively a Mini Shai-Hulud campaign: it uses the same core tactics of install-time execution, credential harvesting, CI/CD targeting, encrypted exfiltration, and potential

The Hacker News
MEDIUMVulnerability

Hackers Used Meta&#8217;s AI Support Bot to Seize Instagram Accounts

The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how to trick Meta's "AI support assistant" bot into resetting account passwords.

Krebs on Security
MEDIUMMalware

WordPress malware campaign hides payloads in Steam profiles

Nearly 2,000 WordPress websites were infected with malware that relies on Steam Community profile comments to hide command-and-control (C2) data. [...]

BleepingComputer
CRITICALVulnerability

Vulnerability Disclosure in the Age of AI

New article: &#8220; Responsible Disclosure in the Age of AI: A Call for Urgent Action ,&#8221; by Melissa Hathaway. Abstract: Artificial intelligence is fundamentally reshaping the balance between vulnerability discovery and remediation. Frontier AI models are now capable of autonomously identifying exploitable software vulnerabilities at unprecedented speed and scale. This development exposes de

Schneier on Security
MEDIUMVulnerability

Equals Money and Railsr rebrand as Equals

Equals Money and Railsr rebrands as Equals, the next-generation global money movement platform.

Finextra
MEDIUMVulnerability

BIS reports back on open finance Project Aperta

Project Aperta, led by the Bank for International Settlements (BIS), has been designing, developing and testing a prototype for cross-border open finance interconnectivity via application programming interfaces (APIs) – a "network of networks" that connects existing domestic networks through a neutral interoperability layer.

Finextra
MEDIUMVulnerability

OpenPayd inks Spac deal for Nasdaq listing

Financial infrastructure provider OpenPayd is planning to go public on the Nasdaq market at a $1.145 billion valuation via a Spac merger.

Finextra
CRITICALVulnerability

Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs

Organizations are advised to patch CVE-2026-41089 as soon as possible, given its severity, the potential ongoing exploitation. The post Critical Windows Netlogon Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek .

CVE-2026-41089
SecurityWeek
MEDIUMVulnerability

Linux Copy Fail CVE-2026-31431: KEV Privilege Escalation on Shared Build Hosts

[object Object]

CVE-2026-31431
r/cybersecurity
MEDIUMVulnerability

Microsoft investigates Office Apps, Teams file access issues

Microsoft says an ongoing incident is preventing users of its Teams collaboration platform and free Office for the web cloud-based productivity suite from opening files. [...]

BleepingComputer
MEDIUMVulnerability

Patch Now: Another Palo Alto Auth Bypass Bug Under Active Exploit

Exploiting the PAN-OS GlobalProtect VPN vulnerability requires certain conditions, but adversaries have done so in two attack waves that started in mid-May.

Dark Reading
MEDIUMVulnerability

Finastra helps lenders turn more applications into loans with new analytics tool

Finastra today announced the launch of Data Insights 2.0, a powerful analytics solution designed to help mortgage lenders convert more applications into funded loans by turning complex data into decision-ready insights.

Finextra
MEDIUMVulnerability

Race Against Time: Why Faster Vulnerability Alerts Matter

Attackers are exploiting vulnerabilities faster than many organizations can identify and patch them. SecAlerts explains why faster vulnerability alerts can help reduce exposure and improve response times. [...]

BleepingComputer
CRITICALVulnerabilityPOC

Critical Flowise Flaw Gives Attackers Full Server Control

Obsidian publishes PoC for a 1-click Flowise RCE that can fully compromise self-hosted servers

Infosecurity Magazine
HIGHAi

⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More

Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already thought 'curl | sh' had a personality. The vibe is simple: old

The Hacker News
HIGHData Breach

Medical Billing Company Data Breach Affects 7 Medical Groups

The Las Vegas medical billing and coding management company, La Perouse, has announced a data breach that has affected seven [&#8230;] The post Medical Billing Company Data Breach Affects 7 Medical Groups appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

Building societies weigh bids for Atom Bank - FT

Yorkshire Building Society and Leeds Building Society are considering takeover bids for digital challenger Atom Bank, according to the Financial Times.

Finextra
MEDIUMVulnerability

Infosecurity Europe: Tabletop Exercise to Test How CISOs Respond to Major Supermarket Cyber-Attack

Semperis is set to bring ‘Enter the War Room: A Tabletop Experience’ to Infosecurity Europe to help cybersecurity leaders prepare to face real incidents

Infosecurity Magazine
CRITICALAi

CVE-2026-0826: How an Old Bug Can Feed AI-Powered Impersonation

One of the more persistent myths in security is that old bug classes become old problems. They don’t. They just show up in different places, under different conditions, and usually at the exact moment we’ve convinced ourselves not to pay attention to them. That’s part of what makes enterprise voice infrastructure so interesting. Earlier this year, we wrote about a critical vulnerability in Grandst

CVE-2026-0826
Rapid7
CRITICALZero Day

CVE-2026-0826: Critical unauthenticated stack buffer overflow in HP Poly VVX and Trio VoIP Phones (FIXED)

Overview Rapid7 Labs conducted a zero-day research project against an HP Poly VVX 450 Voice over Internet Protocol (VoIP) phone. This research resulted in the discovery of a critical unauthenticated stack-based buffer overflow vulnerability, CVE-2026-0826. A remote attacker can leverage CVE-2026-0826 to achieve unauthenticated remote code execution (RCE) with root privileges on a target device. Th

CVE-2026-0826
Rapid7
LOWVulnerability

Dragos Acquires xIoT Security Firm Phosphorus

Dragos said customers will soon gain expanded asset visibility and integrated device intelligence, with automated remediation workflows and a unified platform experience to follow. The post Dragos Acquires xIoT Security Firm Phosphorus appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Started my first writeup - Sherlock NeuroSync-D (CVE-2025-29927)

[object Object]

CVE-2025-29927
r/cybersecurity
CRITICALVulnerability

Critical Windows Netlogon RCE flaw now exploited in attacks

The Centre for Cybersecurity Belgium (CCB), the country's national authority for cybersecurity, warned on Friday that threat actors are now exploiting a recently patched critical Windows Netlogon vulnerability in attacks. [...]

BleepingComputer
CRITICALZero Day

Microsoft says it will not pursue security researchers after zero-day backlash

Microsoft said it is taking the feedback seriously, adding: “To be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research.”

The Record
HIGHAi

Flowise’s MCP implementation can run ghost commands

Enterprises using the lightweight, open-source Flowise platform to power self-hosted AI workloads have a new near-max severity issue to worry about. Researchers at Obsidian Security have detailed a one-click remote code execution (RCE) vulnerability affecting self-hosted Flowise deployments through its implementation of Model Context Protocol ( MCP ) stdio servers. The problem is essentially a san

CVE-2026-40933
CSO Online
MEDIUMApt

China-Aligned Groups Ramp Up Attacks: Dragon Weave Hits Czech Republic &amp; Taiwan

A new cyber espionage campaign codenamed Operation Dragon Weave has been observed targeting officials and citizens in the Czech Republic and Taiwan to deliver an AdaptixC2 agent. According to Seqrite Labs, targets of the campaign include government, research, academic, technology, and financial services sectors. The activity entails distributing spear-phishing emails containing ZIP attachments

The Hacker News
MEDIUMVulnerability

As the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge Caution

AI’s use in the military is part of the administration’s larger push to grow the capability it sees as a unique American advantage. The post As the Pentagon Pushes for Battlefield AI, Some Military Leaders Urge Caution appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Infosecurity Europe: AI SOCs Will Still Need SOC Analysts, Security Vendors Say

Top cybersecurity vendors said AI won't replace entry-level – only routine ticket-taking and triage

Infosecurity Magazine
MEDIUMVulnerability

Microsoft confirms outage affecting MFA, My Sign-Ins platform

Microsoft is working to address an ongoing incident preventing customers from setting up multi-factor authentication (MFA) or accessing the My Sign-Ins platform. [...]

BleepingComputer
MEDIUMVulnerability

Microsoft fixes outage affecting MFA setup, MySignIn service

Microsoft is working to address an ongoing incident preventing customers from setting up multi-factor authentication (MFA) or accessing the My Sign-Ins platform. [...]

BleepingComputer
MEDIUMVulnerability

Fintech rebounds from reset years as profits and revenues surge

The world’s fintech sector is emerging from a bleak period of retrenchment to a new found maturity, as the giddy excitement from the breakout years is replaced with a more disciplined approach that has prompted a sudden surge in profitability and revenue growth.

Finextra
CRITICALAi

BBVA creates shared infrastructure for AI agent developmentt

The AI Transformation area, which sits at the top level of the organization and will be led by Antonio Bravo combines the current Data area with critical technological capabilities to industrialize the creation, deployment and management of artificial intelligence (AI) agents across the organization.

Finextra
LOWVulnerability

The Security Growth Platform: Why MSPs Are Moving Beyond vCISO Tools

Three years ago, the practical question for an MSP building a cybersecurity practice was which "vCISO platform" to buy. The term was good shorthand for the work at the time: assessments, advisory, reporting, maybe a compliance module bolted on the side. The work has since outgrown the descriptor. A Security Growth Platform is the more precise name for what MSPs and MSSPs need from the software

The Hacker News
LOWVulnerabilityPOC

19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access

proof-of-concept (PoC) exploit code has been released for the CIFSwitch flaw, which allows low-privileged users to escalate to root on vulnerable Linux systems. The post 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

FSB Group Gamaredon Hides Worm in Windows Data Streams

FSB-linked Gamaredon concealed a fileless worm in NTFS data streams to spy on Ukraine targets

Infosecurity Magazine
MEDIUMVulnerability

Microsoft fixes KB5089549 Windows security update install issues

Microsoft has resolved a known issue causing installation failures and 0x800f0922 errors when deploying the May 2026 Windows 11 security update (KB5089549). [...]

BleepingComputer
MEDIUMSupply Chain

Containers on fire: from container escapes to supply chain attacks

We break down the primary attack vectors in containerized environments: exposed secrets, privilege misconfigurations, API compromise, and supply chain attacks.

Securelist (Kaspersky)
MEDIUMVulnerability

Hercle appoints Gabriele Zuliani chief revenue officer

Hercle, the leading institutional cross-border payments infrastructure company, today announced the appointment of Gabriele Zuliani as Chief Revenue Officer. Zuliani joins to drive commercial strategy and revenue growth as Hercle scales its network of 200+ institutional clients, including banks, fintechs, PSPs, and corporate treasuries, across global corridors.

Finextra
MEDIUMVulnerability

Recent Palo Alto Networks Vulnerability Exploited for Weeks

Hackers began exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS, four days after public disclosure. The post Recent Palo Alto Networks Vulnerability Exploited for Weeks appeared first on SecurityWeek .

CVE-2026-0257
SecurityWeek
MEDIUMPhishing

Election threats are focused on campaign systems, not voting machines

Check Point said actors are shifting toward campaign systems and AI-generated content, outpacing the public's ability to understand and respond to the risks. The post Election threats are focused on campaign systems, not voting machines appeared first on CyberScoop .

CyberScoop
MEDIUMVulnerability

Wise shares tumble over AML investigation

Shares in Wise have tumbled after prosecutors in Belgium opened an investigation into the alleged use of the money transfer giant's accounts to launder proceeds of fraud, drug trafficking and corruption.

Finextra
MEDIUMVulnerability

IBM and Red Hat to create clearinghouse for open source software security

IBM and Red Hat have committed $5 billion to build an enterprise clearinghouse for open source software, with a host of top banks lined up as early adopters.

Finextra
MEDIUMSupply Chain

OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-looking remote web UI. The tool, named codexui-android, is advertised on GitHub and npm as a remote web UI for OpenAI Codex, attracting over 29,000 weekly downloads. The package is still available for download from the repository. What

The Hacker News
MEDIUMAi

Attackers Abuse Shared Content for ChatGPT Phishing Campaign

Push Security says threat actors are delivering malware hosted on chatgpt.com/s/ domain

Infosecurity Magazine
MEDIUMVulnerability

AccesPay appoints Johan Jardevall as CEO

AccessPay, the leading bank integration provider, today announced the appointment of Johan Jardevall as Chief Executive Officer. Johan succeeds Anish Kapoor, who will become Chairman.

Finextra
CRITICALVulnerability

NVD CRITICAL: CVE-2026-44825 — Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enab...

Hardcoded credentials in the Basic Authentication setup tool (bin/solr auth enable) in Apache Solr versions 9.4.0 through 9.10.1 and 10.0.0 allows a remote attacker to gain full administrative access to the cluster via publicly known default credentials installed silently alongside the user-specified account. As an immediate workaround without upgrading, delete the template users (superadmin, ad

CVE-2026-44825
NIST NVD
CRITICALVulnerability

Critical WP Maps Pro Flaw Actively Exploited to Create Admin Accounts

Threat actors are attempting to actively exploit a critical security flaw impacting WP Maps Pro, a WordPress plugin that has had over 15,000 sales on the Envato Market, to create malicious administrator accounts on susceptible sites. WP Maps Pro allows site owners to embed customizable Google Maps and OpenStreetMap with markers, listings, and advanced location features on WordPress sites. It is

The Hacker News
CRITICALVulnerability

Palo Alto Warns High-Severity Bug Is Being Actively Exploited

A vulnerability in Palo Alto Networks’ PAN-OS software is being exploited in attacks

Infosecurity Magazine
HIGHData Breach

1,000 Data Breaches Later, the Disclosure Lag is Worse Than Ever

Today, I loaded the 1,000th data breach into Have I Been Pwned . Reflecting on that milestone number, I pondered how to mark the occasion in writing, and what immediately came to mind was a very simple question: why is it still needed? Especially considering the emergence of privacy regulations

Troy Hunt
MEDIUMAi

Rapid7 and Exclusive Networks Expand Partnership Across the Nordics

Building stronger cybersecurity outcomes together The cybersecurity landscape across the Nordics is evolving rapidly. Organizations are facing increasing pressure to modernize security operations, reduce complexity, and respond faster to threats, all while navigating growing regulatory demands and persistent skills shortages. At the same time, partners are being asked to do more than ever before.

Rapid7
MEDIUMAi

Infosecurity Europe: OWASP Forms New Agentic Research Council

OWASP’s new Agentic Research Council will aim to connect academic work to operational realities on agentic AI security

Infosecurity Magazine
CRITICALVulnerability

6 critical security gaps every CISO must address

CISOs acknowledge that no organization is completely safe, but many also admit their security measures aren’t where they’d like them to be. One-third of CISOs surveyed for Proofpoint’s 2025 Voice of the CISO Report said the data within their organization is not adequately protected, and 58% said their organizations were unprepared to respond to a cyberattack. Meanwhile, only 67% believed their org

CSO Online
MEDIUMVulnerability

Weekly Update 506

I&apos;m finding it quite fascinating to watch the current spate of ShinyHunters breaches and dumps. There&apos;s the obvious criminality of it all, but then there&apos;s also the response from organisations (or lack thereof, as it relates to disclosure to victims), the appearance and disappearance

Troy Hunt
LOWAi

Saris raises $28.8m for agentic workflow platform

Saris, an agentic workflow platform for banks and credit unions, has raised $28.8 million in Series A funding.

Finextra
MEDIUMVulnerability

Loqbox and Blackbullion join forces to financially support students build credit

Loqbox and Blackbullion have partnered to help more than 450,000 students build stronger financial futures through accessible credit-building tools and curriculum-linked financial education.

Finextra
HIGHVulnerability

CISA KEV: Oracle WebLogic Server — Oracle WebLogic Server Unspecified Vulnerability

Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data.

CVE-2024-21182Oracle WebLogic Server
CISA KEV
MEDIUMSupply Chain

Miasma supply chain attack: malicious code found in @redhat-cloud-services npm packages

A supply chain worm dubbed Miasma has been found in dozens of @redhat-cloud-services npm releases. The malicious preinstall hook steals credentials, probes cloud identities, and can republish other packages.

Snyk
MEDIUMVulnerability

Unknown hacker group targeted Russian maritime universities, diplomats for nearly two years

More than half of the attacks observed over the past year targeted educational institutions, particularly maritime universities and schools that train personnel for Russia's shipping, inland waterway and fishing industries.

The Record
MEDIUMApt

Afghan finance officials targeted by suspected Pakistani cyberespionage campaign

A suspected Pakistan-linked hacking group has targeted Afghanistan's Ministry of Finance and provincial government officials in a new cyberespionage campaign, researchers have found.

The Record
MEDIUMVulnerability

YARA-X 1.17.0 Release, (Sun, May 31st)

YARA-X&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s 1.17.0 release brings 5 improvements (several performance improvements) and 1 bugfix.&#xd;

SANS ISC
CRITICALVulnerability

NVD CRITICAL: CVE-2026-10187 — A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by...

A vulnerability was detected in Totolink N300RH 6.1c.1353_B20190305. Affected by this issue is the function setWiFiBasicConfig of the file wireless.so of the component Web Management Interface. Performing a manipulation of the argument KeyStr results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.

CVE-2026-10187
NIST NVD
LOWVulnerability

WP Maps Pro bug exploited to create admin accounts on WordPress sites

Hackers are targeting WordPress websites running a vulnerable version of the WP Maps Pro plugin, which allows creating rogue administrator accounts without authentication. [...]

BleepingComputer
HIGHRansomware

Bombay High Court Issues Injunction Prohibiting Hackers From Publishing Allegedly Hacked HDFC Investor Data

The Bombay High Court granted interim relief to HDFC AMC after a ransomware group called “Morpheus” allegedly stole over 680 GB of sensitive company and investor data. The court barred unidentified hackers from publishing or sharing the information, warning that any leak could lead to identity theft, financial fraud and irreparable harm. The case will... Source

DataBreaches.net
HIGHRansomware

Bombay High Court Issues Injunction Prohibiting Hackers From Publishing Allegedly Hacked HDFC Investor Data (1)

The Bombay High Court granted interim relief to HDFC AMC after a ransomware group called “Morpheus” allegedly stole over 680 GB of sensitive company and investor data. The court barred unidentified hackers from publishing or sharing the information, warning that any leak could lead to identity theft, financial fraud and irreparable harm. The case will... Source

DataBreaches.net
MEDIUMMalware

Dutch Authorities Dismantle Botnet Linked to 17 Million Infected Devices

Dutch authorities have announced the takedown of a botnet that enslaved millions of infected devices, including computers, tablets, smartphones, and IoT devices, to carry out malicious attacks. The bot network, per the Dutch Politie and the National Cyber Security Center (NCSC), consisted of at least 17 million infected devices. More than 200 servers located in the Netherlands acted as the

The Hacker News
MEDIUMVulnerability

Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs

[object Object]

CVE-2025-59199
r/blueteamsec
MEDIUMVulnerability

Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)

[object Object]

CVE-2026-0257
r/blueteamsec
MEDIUMVulnerability

CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities - &quot;Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied.&quot;

[object Object]

CVE-2026-0257
r/blueteamsec
MEDIUMVulnerability

Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks

Palo Alto Networks is warning that hackers are now exploiting a PAN-OS GlobalProtect authentication bypass flaw, tracked as CVE-2026-0257, in attacks attempting to breach corporate networks. [...]

CVE-2026-0257
BleepingComputer
CRITICALVulnerability

NVD CRITICAL: CVE-2018-25412 — Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unau...

Delta Sql 1.8.2 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to docs_upload.php with crafted multipart form data. Attackers can upload PHP files with arbitrary content to the upload directory and execute them on the server for remote code execution.

CVE-2018-25412
NIST NVD
MEDIUMApt

Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say

Moscow’s agents are building fake companies, recruiting middlemen and deploying cyber spies and hackers who gather information that could be used to attack key infrastructure. The post Russian Spies Are Aggressively Seeking Western Technology as Sanctions Bite, Officials Say appeared first on SecurityWeek .

SecurityWeek
CRITICALVulnerabilityPOC

Exploit Code Published for Critical Flowise RCE Vulnerability

The one-click vulnerability allows attackers to execute arbitrary code on self-hosted Flowise servers by tricking users into importing a malicious chatflow. The post Exploit Code Published for Critical Flowise RCE Vulnerability appeared first on SecurityWeek .

CVE-2026-40933
SecurityWeek
LOWVulnerability

New CIFSwitch Linux flaw gives root on multiple distributions

A newly discovered local privilege escalation vulnerability dubbed 'CIFSwitch' in the Linux kernel could allow attackers to forge CIFS authentication key descriptions, abuse the kernel's key request mechanism, and gain root privileges. [...]

BleepingComputer
MEDIUMVulnerabilityPOC

Microsoft&#8217;s incident response is getting a failing grade from researchers

Microsoft is ticking off a lot of researchers this week by claiming that those who dump proof-of-concept exploits for vulnerabilities they have not responsibly disclosed are enabling criminal activity, and that Microsoft will track them and bring cases against them. Whoever advised them to issue that statement may want to walk it back. Kevin Beaumont,... Source

DataBreaches.net
MEDIUMVulnerabilityPOC

Microsoft&#8217;s incident response is getting a failing grade from researchers (1)

Microsoft is ticking off a lot of researchers this week by claiming that those who dump proof-of-concept exploits for vulnerabilities they have not responsibly disclosed are enabling criminal activity, and that Microsoft will track them and bring cases against them. Whoever advised them to issue that statement may want to walk it back. (See update... Source

DataBreaches.net
HIGHVulnerability

PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation

Palo Alto Networks has warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections. "Authentication bypass vulnerabilities in the

CVE-2026-0257
The Hacker News
MEDIUMPhishing

Chinese Phishing Service Scams Thousands of FIFA World Cup Fans

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/nist-rebrands-ai-consortium-ditches-safety-from-name-image_small-8-a-31815.jpg" align=right hspace=4><b>Researchers estimate losses ranging from hundreds of millions to billions</b><br>A Chinese-language phishing-as-a-service platform scammed between $470 million to $1 billion from soccer fans ahead of the 2026 FIFA World Cup star

Bank Info Security
MEDIUMVulnerability

23andMe Failed to Stop Months-Long Hack, State Alleges

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/23andme-failed-to-stop-months-long-hack-state-alleges-image_small-2-a-31816.jpg" align=right hspace=4><b>Calif. Lawsuit: Genetics Testing Firm Missed Red Flags Before Massive 2023 Breach</b><br>Hackers in 2023 went undetected for five months in genetics testing firm 23andMe's IT systems, despite multiple unheeded warning signs, al

Bank Info Security
MEDIUMVulnerability

NIST Rebrands AI Consortium, Ditches 'Safety' From Name

<b>Agency Expands Research Beyond Safety Testing to Standards and Evaluation</b><br>The U.S. National Institute of Standards and Technology is expanding one of its largest artificial intelligence initiatives, rebranding the AI Safety Institute Consortium and reopening participation as the Trump administration pushes a more industry-focused approach to AI development and governance.

Bank Info Security
CRITICALAi

Russia-aligned crime group Greyvibe extensively uses AI in attacks

Researchers have uncovered a previously undocumented Russian group that makes extensive use of large language models (LLMs) in its attacks against private, government, and military organizations in Ukraine. It uses a variety of attack vectors along with custom malware, with the goal of intelligence gathering for the ongoing war. Dubbed Greyvibe by researchers from WithSecure, the group has shown s

CSO Online
CRITICALAi

Microsoft and security researcher’s dueling posts about cybersecurity disclosures get nasty

Microsoft and a prominent cybersecurity researcher have gotten into a very public and rather personal exchange of unpleasantries about what responsible cybersecurity disclosures should mean in 2026. A cybersecurity researcher going by the name Nightmare Eclipse, who has disclosed several cybersecurity holes before patches were available, posted that he had tried to contact Microsoft officials and

CVE-2026-45585
CSO Online
HIGHData Breach

Thousands of Oregon prison files accessed by prison worker

Noelle Crombie reports on today&#8217;s reminder of the insider threat: A former Snake River Correctional Institution employee accessed tens of thousands of Oregon Department of Corrections files over a six-month period last year, the agency announced Friday. Officials discovered the data breach in January during an investigation into misconduct allegations involving the unnamed employee, accordin

DataBreaches.net
MEDIUMVulnerability

Friday Squid Blogging: Another Squid

Someone named &#8220;Squid&#8221; seems to be a &#8220; West Country legend .&#8221; As usual, you can also use this squid post to talk about the security stories in the news that I haven&#8217;t covered. Blog moderation policy.

Schneier on Security
MEDIUMApt

Name That Toon: Mark of (Cybersecurity) Progress

As part of Dark Reading's 20th anniversary package, we asked readers for a cybersecurity-related caption that captures their thoughts about the industry's last two decades.

Dark Reading
CRITICALVulnerability

NVD CRITICAL: CVE-2026-45700 — FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0...

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validates the X destination coordinate nXDst against the caller-provided destination stride (nDstStep) even when it is writing into the internal temp buffer p

CVE-2026-45700
NIST NVD
CRITICALVulnerability

CISA Town Halls Set Final Stage for CIRCIA Debate

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cisa-town-halls-set-final-stage-for-circia-debate-image_small-9-a-31812.jpg" align=right hspace=4><b>June Meetings Could Shape Which Entities Must Report Cyber Incidents</b><br>The Cybersecurity and Infrastructure Security Agency's June town halls will give critical infrastructure operators a final opportunity to influence how the

Bank Info Security
MEDIUMVulnerability

AI Is Making Decisions. Who's Owning Them?

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ai-making-decisions-whos-owning-them-image_small-1-a-31810.jpg" align=right hspace=4><b>GSK's Nancy Paul on Why Static Governance, Risk and Compliance Fail in AI Era</b><br>Traditional governance, risk and compliance principles still hold, but periodic, checklist-driven governance is a dangerous mismatch for AI systems that contin

Bank Info Security
MEDIUMVulnerability

BIS and Gleif team on LEIs in cross-border open finance prototype

The Global Legal Entity Identifier Foundation (GLEIF) and the Bank for International Settlements (BIS) have demonstrated how the Legal Entity Identifier (LEI) can bring new Know Your Customer/Business (KYC/B) and Anti-Money Laundering (AML) process efficiencies to small and medium-sized enterprises (SMEs) when using open banking and open finance APIs to initiate payments and open business accounts

Finextra
LOWAi

Metasploit Wrap Up 05/29/2026

More Linux LPEs Hark the age of the Linux LPE has arrived. This week’s release follows up on recent work bringing new Linux LPEs to Metasploit users. Copy Fail seemed to have kicked off a trend of similar bugs and hot on its heels is Dirty Frag. Dirty Frag is actually two vulnerabilities in a trenchcoat, individually identified as CVE-2026-43284 and CVE-2026-43500. Each is exploitable individually

CVE-2026-43284CVE-2026-43500
Rapid7
MEDIUMAi

ISMG Editors: Are We Ready for a Post-Mythos Security World?

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ismg-editors-are-we-ready-for-post-mythos-security-world-image_small-5-a-31814.jpg" align=right hspace=4><b>Also: Why Traditional Patching Can't Keep Up, Closing the AI Visibility Gap</b><br>In this week's panel, four ISMG editors discussed what Anthropic's controversial Mythos AI model signals for the future of cybersecurity, whe

Bank Info Security
MEDIUMVulnerability

AI-Driven Bug Tsunami Prompts Exploitability Questions

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ai-driven-bug-tsunami-prompts-exploitability-questions-image_small-9-a-31813.jpg" align=right hspace=4><b>Severity and Reachability Metrics Also Essential for Mythos-Era Bug Mitigation</b><br>If there's one thing artificial intelligence has done, it's multiply bugs, and the annual CVE Program count of new vulnerabilities is set to

Bank Info Security
MEDIUMAi

ChatGPT share links abused to host fake outage pages to deliver malware

Threat actors are abusing ChatGPT's content-sharing feature to display fake OpenAI outage pages that direct users to download malware disguised as the ChatGPT desktop application. [...]

BleepingComputer
MEDIUMVulnerability

Tennessee man linked to 764 accused of series of crimes against children dating back to 2022

Zachary Sweeney allegedly traveled to New York, Indiana, Missouri and Georgia to meet and harm numerous victims in person. The FBI began investigating him in 2023. The post Tennessee man linked to 764 accused of series of crimes against children dating back to 2022 appeared first on CyberScoop .

CyberScoop
MEDIUMVulnerability

Jack Henry signs Woodforest National

Jack Henry (Nasdaq: JKHY) announced today that Woodforest National, a multi-state bank with more than $9 billion in assets, has selected Jack Henry to support its continued growth, modernization, and long-term digital strategy.

Finextra
MEDIUMVulnerability

California AG sues 23andMe over 2023 breach exposing health data

California Attorney General Rob Bonta filed a lawsuit against 23andMe, now Chrome Holding Co., over the company's failure to protect sensitive customer genetic and personal information. [...]

BleepingComputer
MEDIUMAi

ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface

Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant's implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks. The technique has been codenamed ChatGPhish by Permiso Security. "The chatgpt.com response renderer trusts Markdown links and Markdown

The Hacker News
CRITICALVulnerability

Rapid7 Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)

Overview On May 13, 2026, Palo Alto Networks published a security advisory for CVE-2026-0257, a medium severity authentication bypass affecting PAN-OS and Prisma Access when a specific configuration is present. Successful exploitation of this vulnerability allows a remote unauthenticated attacker to successfully establish a VPN connection through the GlobalProtect gateway of an affected appliance.

CVE-2026-0257
Rapid7
HIGHData Breach

In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks

Noteworthy stories that might have slipped under the radar: Trump Mobile exposes customer data, phishers target the 2026 FIFA World Cup, CISA responds to recent supply chain attacks. The post In Other News: Trump Mobile Data Breach, FIFA World Cup Phishing, CISA Responds to Supply Chain Attacks appeared first on SecurityWeek .

SecurityWeek
MEDIUMAi

DNS-AID will make AI agents easier to discover, says Linux Foundation

As AI agents become more numerous and more communicative, keeping track of where to find them is becoming increasingly important. Numerous proprietary agent registries are on the market, but the Linux Foundation suggests we simply extend the distributed, open Domain Name System (DNS) infrastructure we already have. The foundation is now inviting contributions to the DNS-AID project, a standard way

CSO Online
LOWVulnerability

Federal audit reveals NIST&#8217;s NVD is plagued by poor planning and duplication

A report from the Commerce Inspector General details how mismanagement allowed a backlog of 27,000 unprocessed security flaws to grow unchecked, while the agency duplicated work with a similar CISA program. The post Federal audit reveals NIST&#8217;s NVD is plagued by poor planning and duplication appeared first on CyberScoop .

CyberScoop
LOWVulnerability

Certifiably random: Swiss researchers claim perfect random number source

Researchers in Switzerland claim to have built a perfect random number generator from two quantum superconducting chips, a 30-meter-long pipe, and some software. The resulting device could be used to generate cryptographic keys, or to offer a “public randomness service” for lotteries or blockchain applications, they say. They’re not the first to make the claim . Many sources of randomness are bias

CSO Online
CRITICALVulnerability

NVD CRITICAL: CVE-2026-4290 — The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion ...

The WP Travel Pro plugin for WordPress is vulnerable to arbitrary user deletion via the /wp-json/wp-travel/v1/travel-guide/{user_id} REST API endpoint in all versions up to, and including, 10.6.0. This is due to the check_permission() callback unconditionally returning true and the Database::delete() method passing the user ID directly to wp_delete_user() without any role validation. This makes it

CVE-2026-4290
NIST NVD
MEDIUMVulnerability

As European payments sovereignty debate rages, Visa makes its case for place on continent

With European leaders pushing for greater payments sovereignty, US giant Visa has moved to reassure the bloc that it is a friendly partner, setting out plans for a €500 million investment in the continent, including the building of a new local data processing centre.

Finextra
HIGHData Breach

Charter Communications Data Breach Could Impact Nearly 5 Million

The notorious ShinyHunters extortion group leaked over 42 million records allegedly stolen from Charter in April. The post Charter Communications Data Breach Could Impact Nearly 5 Million appeared first on SecurityWeek .

SecurityWeek
LOWAi

Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit

An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclosed vulnerability. "The attacker compromised an internet-reachable Marimo notebook via CVE-2026-39987, extracted two cloud credentials from the compromised

CVE-2026-39987
The Hacker News
MEDIUMVulnerability

Asia's Cyber Insurance Market Shows Signs of Life

The cyber insurance industry has made relatively weak inroads into Asia due to a a variety of factors, but that could be changing.

Dark Reading
MEDIUMPhishing

MokN Raises $15 Million for Phish-Back Platform

MokN's platform deploys realistic decoy access points to lure attackers into revealing compromised credentials, enabling organizations to respond before abuse occurs. The post MokN Raises $15 Million for Phish-Back Platform appeared first on SecurityWeek .

SecurityWeek
MEDIUMMalware

From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market

DDoS attacks are increasingly being sold like subscription services, complete with pricing tiers, support, and reseller programs. Flare explores how the DDoS-as-a-Service market has evolved from scattered tools into polished attack platforms. [...]

BleepingComputer
MEDIUMMalware

Dutch govt disrupts malware botnet with 17 million infected devices

Dutch authorities have taken offline a massive botnet of 17 million devices and seized more than 200 servers at a local provider that supported the operation. [...]

BleepingComputer
CRITICALVulnerability

NVD CRITICAL: CVE-2026-46376 — FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, una...

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if these were not immediately changed by the Administrator who enabled UCP. Authenticated access to ACP is required for the initial setup of UCP generic templates, but after that, without further steps by

CVE-2026-46376
NIST NVD
MEDIUMVulnerability

Paxos gets green light to settle securities on blockchain

Paxos has become the first blockchain-native firm to be approved by US regulators to provide clearing and settlement services by the SEC.

Finextra
MEDIUMVulnerability

TS Imagine makes sales hires

TS Imagine, a leading platform for integrated electronic front-office multi-asset trading, portfolio management, prime brokerage, and financial risk management, today announced the expansion of its sales team with the appointments of Terrance “Terry” Baum as Director of Sales, US, and Anthony DeRosa as Sales Executive, further strengthening the firm’s North American sales team. Both will report to

Finextra
MEDIUMVulnerability

US Faster Payments Council and ASC X9 form standards steering committee

The U.S. Faster Payments Council (FPC), a membership organization devoted to advancing safe, easy-to-use faster payments in the United States, and the Accredited Standards Committee X9 Inc. (X9), the organization accredited by ANSI to develop financial industry standards for the United States, today announced the formation of the FPC–ASC X9 Joint Standards Steering Committee (JSSC), a collaborativ

Finextra
CRITICALZero DayPOC

Microsoft calls zero-day releases ‘never justifiable’ as researcher threatens to drop more

Each vulnerability was published with working proof-of-concept code to the Microsoft-owned code repository GitHub, making them immediately available to both attackers and security professionals.

The Record
MEDIUMVulnerability

Zilch appoints Florence Quirici chief corporate affairs officer

Zilch, the intelligent payments platform, today announced the appointment of Florence Quirici as Chief Corporate Affairs Officer.

Finextra
CRITICALVulnerability

NVD CRITICAL: CVE-2026-10071 — DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, al...

DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

CVE-2026-10071
NIST NVD
LOWVulnerability

Trump Accounts investment app launches for children, backed by BNY and Robinhood

The US Treasury launched the Trump Accounts app on Thursday, allowing parents to place money in investment accounts for their children.

Finextra
MEDIUMVulnerability

With Complex Cloud Integrations, Small Errors Lead to Major Compromises

Researchers discover an exploit chain combining over-permissioned roles, secrets discovery, and non-human identities that could have compromised a popular automation service.

Dark Reading
MEDIUMVulnerability

Silent Ransom Group Uses In-Person IT Impersonation to Breach Systems

Threat actors from the Silent Ransom Group, aka Luna Moth, are escalating attacks by impersonating IT staff in phone calls and even showing up in person to gain direct access to victim systems

Infosecurity Magazine
CRITICALZero Day

Gogs Zero-Day Exposes Servers to Remote Code Execution

The critical-severity issue, assigned a CVSS score of 9.4, is an argument injection flaw that can be exploited by authenticated attackers via pull requests with malicious branch names. The post Gogs Zero-Day Exposes Servers to Remote Code Execution appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

French Health Payments Breach Exposed ID Data, Fuels Fraud Fears

Michel Gribouille reports: A major French health-care payments middleman says hackers broke into a key authorization portal and may have exposed sensitive personal data, including France’s equivalent of a Social Security number, setting off warnings about identity theft and scam attempts. Almerys, a company that helps process “third-party payment” transactions so patients don’t have to... Source

DataBreaches.net
HIGHData Breach

California AG Bonta Sues Chrome Holding Co., Formerly Known as 23andMe, Over 2023 Data Breach

Jaimie Ding reports: Attorney General Rob Bonta filed the lawsuit against Chrome Holding Co., which 23andMe rebranded under after filing for bankruptcy last March. 23andme is known for its direct-to-consumer DNA test kits that provided customers information on their ancestry and genetic predispositions for certain health conditions. The lawsuit calls for various civil penalties against 23andMe...

DataBreaches.net
CRITICALVulnerability

NVD CRITICAL: CVE-2025-41277 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.

CVE-2025-41277
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2025-41276 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.

CVE-2025-41276
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2025-41275 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.

CVE-2025-41275
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2025-41274 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.

CVE-2025-41274
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2025-41273 — Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Altern...

Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to bypass authentication of the Console web application and perform actions as an authenticated user.

CVE-2025-41273
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2025-41272 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.

CVE-2025-41272
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2025-41270 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.

CVE-2025-41270
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2025-41269 — Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Ele...

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to execute arbitrary operating system commands on the device.

CVE-2025-41269
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2025-41268 — Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Adminis...

Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated attackers to delete arbitrary files on the Host machines.

CVE-2025-41268
NIST NVD
MEDIUMVulnerability

Google Chrome adds session cookie theft protection for all users

Google says the Chrome Device Bound Session Credentials (DBSC) security feature is now generally available and is rolling out to all users to prevent account takeovers. [...]

BleepingComputer
MEDIUMVulnerability

'The Com' Cyberattacks Support Violence &amp; Sexploitation

Your organization's security failures have consequences for everyone else too, since this neo-Nazi-infested criminal gang uses its cyber winnings to support more violent and widespread crimes.

Dark Reading
MEDIUMAi

New Russian-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks

A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025. GREYVIBE, per WithSecure, is assessed to be a Russian-speaking group operating broadly in the Russian time zone, with the activities aligning with Kremlin state interests, specifically when it comes to

The Hacker News
MEDIUMAi

New Russia-Linked GREYVIBE Targets Ukraine with AI-Powered Cyberattacks

A previously undocumented threat actor dubbed GREYVIBE has been attributed to ongoing and persistent attacks targeting Ukraine and Ukraine-related entities since at least August 2025. GREYVIBE, per WithSecure, is assessed to be a Russian-speaking group operating broadly in the Russian time zone, with the activities aligning with Kremlin state interests, specifically when it comes to

The Hacker News
HIGHData Breach

California Sues 23andMe, Alleging It Failed to Protect User Data in 2023 Breach

Attorney General Rob Bonta filed the lawsuit against Chrome Holding Co., which 23andMe rebranded under after filing for bankruptcy last March. The post California Sues 23andMe, Alleging It Failed to Protect User Data in 2023 Breach appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Man sent to prison for selling data of 7 millions elderly Americans

A North Carolina man was sentenced to more than 10 years in prison for selling the personal information of over 7 million elderly Americans to Jamaican scammers. [...]

BleepingComputer
MEDIUMVulnerability

Chilling Effects

Younger Americans have soured on the second Donald Trump presidency , but they are not protesting it. Despite an unpopular Iran war and an even more unpopular Trump administration , college campus protests nationwide have gone silent . And at many schools, student activism is virtually nonexistent . This silence comes in the wake of a relentless Trump administration war on campus speech that has i

Schneier on Security
HIGHData Breach

California AG Files Lawsuit Over 23andMe Data Breach

California Attorney General Rob Bonta has filed a lawsuit against the genetic testing company formerly known as 23andMe over its [&#8230;] The post California AG Files Lawsuit Over 23andMe Data Breach appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMAi

What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks

Shadow AI used to mean employees pasting things they shouldn't into ChatGPT. It now means something bigger: employees building full applications with AI, wiring them into production systems, and publishing them on the open internet. Without Security or IT in the loop. The artifact moved from a prompt to a product. The risk surface moved with it. In The Shadow Builders report (get it here), a

The Hacker News
CRITICALVulnerability

Chrome 148 Update Patches 151 Vulnerabilities

The browser update resolves critical-severity security defects that could potentially lead to remote code execution. The post Chrome 148 Update Patches 151 Vulnerabilities appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

US charges Google security engineer with Polymarket insider trading

A Google security engineer was charged with insider trading after winning $1.2 million using confidential company data to place bets on the cryptocurrency-based Polymarket decentralized prediction market. [...]

BleepingComputer
MEDIUMVulnerability

TrueLayer buys fintech In3, offering users debit and credit at checkout

TrueLayer, Europe's leading Pay by Bank network, today announced the acquisition of In3, a Dutch fintech specialising in consumer credit via bank payments.

Finextra
MEDIUMVulnerability

Project Agora announces findings for tokenised wholesale cross-border payments

The Bank of International Settlements’ (BIS) Project Agora has developed a prototype for programmable wholesale cross-border payments.

Finextra
MEDIUMVulnerability

Infosecurity Europe: CyCOS Project Expands to Support UK SMEs as CIISec Takes Over

From a research-driven pilot, the Cybersecurity Communities of Support (CyCOS) is about to be handed over to CIISec

Infosecurity Magazine
LOWApt

Notepad++ vulnerabilities could enable arbitrary code execution on Windows systems

Two arbitrary code execution vulnerabilities in Notepad++ let local attackers run commands of their choice on Windows machines by tampering with the editor’s XML configuration files, with both flaws rated High at CVSS 7.8. The flaws, tracked as CVE-2026-48778 and CVE-2026-48800, affect every version of the editor up to and including 8.9.6, Notepad++ said in a release note . However, the vulnerabil

CVE-2026-48778CVE-2026-48800
CSO Online
MEDIUMSupply Chain

Malicious Sicoob NuGet Steals Banking Credentials as npm Packages Target Cloud Secrets

Cybersecurity researchers have discovered a malicious NuGet package that masquerades as a C# software development kit for Sicoob, one of Brazil's largest cooperative financial systems, to siphon client IDs and PFX certificates. According to Socket, versions 2.0.0 through 2.0.4 of "Sicoob.Sdk" contain functionality to exfiltrate sensitive information, including PFX certificates that are used to

The Hacker News
HIGHRansomware

The Gentlemen are coming for your files, and then your network

Ransomware operators have spent years refining the art of locking files. Now, some are working harder to get those lockers to every reachable system first. Microsoft’s recent warning of the Gentlemen ransomware revealed its operators using a self-propagating Go-based encryptor capable of moving laterally through compromised environments and deploying itself across additional systems. “Modern ranso

CSO Online
MEDIUMVulnerability

Forbes releases 25th-anniversary Midas List of top VC investors

Forbes has released its Midas List of 2026 in partnership with TrueBridge Capital Partners featuring the top 100 venture capitalist investors.

Finextra
MEDIUMApt

Chinese Hackers Exploit Iran War to Target Maritime and Energy Companies

ESET’s 2026 APT Activity Report suggests China-backed APTs are using instability in the region to target victims, as well as continuing activity against organizations around the globe

Infosecurity Magazine
CRITICALSupply Chain

Cybersecurity trends in SEC filings

In 2023, the Securities and Exchange Commission (SEC) required public companies to include a new section in their 10-K annual filings that is devoted to cybersecurity. This section is meant to address “cybersecurity risk management, strategy, governance and incidents.” I got curious as to what senior cybersecurity executives are conveying about their companies in these reports. I turned this into

CSO Online
HIGHData Breach

Charter Communications data breach affects 4.9 million accounts

The ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking the U.S. telecom giant Charter Communications in early April, according to data breach notification service Have I Been Pwned. [...]

BleepingComputer
CRITICALVulnerability

NVD CRITICAL: CVE-2026-3655 — The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulner...

The OTP Login With Phone Number, OTP Verification plugin for WordPress is vulnerable to authentication bypass in versions 1.8.50 through 1.8.60. This is due to the Firebase verification flow in the `lwp_ajax_register` AJAX handler not binding the Firebase session to the phone number supplied in the request. The `idehweb_lwp_activate_through_firebase()` function validates that a Firebase OTP sessio

CVE-2026-3655
NIST NVD
MEDIUMSupply Chain

AI-Generated npm Malware Leaks Its Own GitHub Token

Sloppy AI-generated npm infostealer leaked its own GitHub token, exposing the operator

Infosecurity Magazine
HIGHData Breach

Police arrest man following hack of Ajax football club

Dutch police have arrested a 35-year-old man suspected of hacking into the computer systems of Amsterdam football giant Ajax, after the personal data of hundreds of thousands of supporters was put at risk. Read more in my article on the Hot for Security blog.

Graham Cluley
CRITICALZero Day

This month in security with Tony Anscombe – May 2026 edition

In this roundup, Tony looks at attacks against Polish water treatment facilities, how AI-directed attacks failed in Mexico, and what Google believes is the first AI-generated zero-day exploit

WeLiveSecurity (ESET)
CRITICALVulnerability

NVD CRITICAL: CVE-2026-8732 — The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via A...

The WP Maps Pro plugin for WordPress is vulnerable to Privilege Escalation via Administrator Account Creation in all versions up to, and including, 6.1.0. This is due to the wpgmp_temp_access_ajax AJAX action being registered with wp_ajax_nopriv_ and protected only by a nonce check using the fc-call-nonce nonce, which is publicly embedded into every frontend page via wp_localize_script as the nonc

CVE-2026-8732
NIST NVD
MEDIUMSupply Chain

What&#8217;s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant

What are the main risks for container environments: vulnerabilities, supply chain attacks, configuration errors; how to improve container security and how Kaspersky Container Security with the KIRA AI assistant can help.

Securelist (Kaspersky)
CRITICALAi

GDPR set the tone for regulatory action — and the AI fine pushback to come

Big tech firms continue to push back against fines levied for alleged violations of European data protection law, in what could be a harbinger for AI regulations to come. While lawyers and experts quizzed by CSO broadly argue that big tech firms contesting data protection rules isn’t a particular cause for concern, the more widespread introduction of AI technologies is a far greater data protectio

CSO Online
MEDIUMApt

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corporate entities through March and April 2026. "Kimsuky employed a range of tailored social engineering tactics, such as spoofing security software installation pages and crafting a fake Webex meeting page that leveraged

The Hacker News
MEDIUMAi

How Relay Network Adopted AI Coding Securely - and Built the Foundation for Agentic Development

See how Relay Network securely adopted AI coding with Snyk and GitHub Copilot, implementing "secure at inception" to reduce vulnerabilities and accelerate development.

Snyk
MEDIUMVulnerability

Fix SCA issues at scale in your terminal with Snyk Remediation Agent in the CLI

Stop security backlogs. Snyk's Remediation Agent in the CLI pairs AI reasoning with Snyk security intelligence to fix SCA issues at scale directly in your terminal.

Snyk
CRITICALSupply Chain

IBM and Red Hat want to become the ‘security clearinghouse’ for open source applications in the enterprise

Open source code is everywhere in the enterprise; it’s estimated that upwards of 90% of Fortune 500 companies have it in their software supply chains. But open source code is notoriously rife with vulnerabilities, and identifying and patching those bugs can be an endless battle for security teams. IBM and Red Hat are betting that a new initiative, Project Lightwell , can help accelerate this proce

CSO Online
CRITICALData Breach

Lack of response to critical vulnerability in Gogs is a reminder of the limits of open source projects

A newly discovered and so far unpatched critical vulnerability in the open source Gogs Git service not only demands immediate action from developers to secure their code, it also puts a spotlight on the potential issues in using self-hosted code platforms from small maintainers. The hole is a critical argument injection vulnerability, discovered by a researcher at Rapid7, that allows any authentic

CSO Online
MEDIUMAi

Anthropic confirms Claude Mythos-class models will roll out to the public

Anthropic has confirmed that it plans to bring Mythos-class models to the general public after delaying the rollout due to security risks to public and private software. [...]

BleepingComputer
MEDIUMAi

Fiserv brings in Cognition&#39;s AI agent software engineer

Fiserv has brought in a new software engineer, an AI agent called Devin created by vendor Cognition, to help speed up the pace at which it ships new capabilities to clients.

Finextra
MEDIUMVulnerability

NatWest taps Cleareye.ai for trade finance ops

NatWest has started working with trade finance tech specialist Cleareye.ai to revamp its its trade operations and strengthen financial crime controls.

Finextra
LOWAi

Snowflake to Buy Startup Natoma Focused on AI Access Control

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/snowflake-to-buy-startup-natoma-focused-on-ai-access-control-image_small-10-a-31808.jpg" align=right hspace=4><b>San Francisco Startup Built MCP Gateway Technology for AI Authorization Workflows</b><br>Snowflake plans to acquire AI governance startup Natoma to help enterprises centrally manage model context protocol access, delega

Bank Info Security
CRITICALZero DayPOC

Microsoft Threatens Legal Action Over Zero-Day Leaks

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/microsoft-threatens-legal-action-over-zero-day-leaks-image_small-3-a-31807.jpg" align=right hspace=4><b>Security Researchers Fear Broader Legal Pressure on Bug Disclosures</b><br>Microsoft is pursuing legal action after a researcher publicly released six Windows zero-days and exploit code following a breakdown in coordinated discl

Bank Info Security
HIGHVulnerability

CISA KEV: Palo Alto Networks PAN-OS — Palo Alto Networks PAN-OS Authentication Bypass Vulnerability

Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.

CVE-2026-0257Palo Alto Networks PAN-OS
CISA KEV
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9874 — Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote...

Use after free in Dawn in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

CVE-2026-9874
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-8809 — The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privi...

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Privilege Escalation via Validation Bypass in all versions up to and including 0.9.2.5. The vulnerability exists due to the after_validate_save_post() function unconditionally trusting the attacker-controlled _acf_post_id POST parameter — with no authentication or integrity verification — to select a cleanup branch that sil

CVE-2026-8809
NIST NVD
MEDIUMSupply Chain

As Global Powers Explore Humanoid Robots, Cyber-Risk Looms

The future of cybersecurity is germinating, as nation states vie for dominance in the embodied AI market and its supply chain.

Dark Reading
MEDIUMVulnerability

Romanian Access Broker Sentenced in Oregon Network Intrusion

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/romanian-access-broker-sentenced-in-oregon-network-intrusion-image_small-4-a-31809.jpg" align=right hspace=4><b>Hacker Amassed $250,000 in Losses Across Multiple US Entities</b><br>The Romanian hacker who in 2021 sold on a hacking forum online credentials to the Oregon disaster management agency received a four year federal prison

Bank Info Security
MEDIUMAi

GreyVibe hackers use ChatGPT, Gemini to power cyberattacks

A likely Russian threat cluster tracked as GreyVibe has been targeting Ukrainian entities with AI-generated lures and a rich set of custom malware tools. [...]

BleepingComputer
CRITICALVulnerability

NVD CRITICAL: CVE-2026-44881 — Portainer Community Edition is a lightweight service delivery platform for conta...

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before 2.33.8, 2.39.2, and 2.41.0, Portainer supports deploying stacks from Git repositories. When a Git-backed stack is created or updated, Portainer clones the repository using go-git v5, which translates G

CVE-2026-44881
NIST NVD
MEDIUMVulnerability

Colorado Rolls Back Landmark AI Governance Law

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/colorado-rolls-back-landmark-ai-governance-law-image_small-3-a-31804.jpg" align=right hspace=4><b>Revised Law Delays Enforcement and Narrows Enterprise AI Obligations</b><br>Colorado lawmakers scaled back what was once considered the nation's most aggressive state artificial intelligence governance law, narrowing its scope and del

Bank Info Security
MEDIUMVulnerability

Connecticut Medicaid Portal Hack Affects Thousands

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/connecticut-medicaid-portal-hack-affects-thousands-image_small-6-a-31805.jpg" align=right hspace=4><b>Attackers Attempted to Reroute Hospital Medicaid Reimbursements</b><br>A hack on a Connecticut Medicaid web portal involving compromised credentials of a healthcare provider has affected the payment account and other information f

Bank Info Security
MEDIUMVulnerability

Breach Roundup: US Troops Tracked With Cell Phone Data

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/roundup-us-troops-tracked-cell-phone-data-image_small-10-a-31806.jpg" align=right hspace=4><b>Also, Kali365 Bypasses MFA, Silent Ransom Group Makes Office Calls</b><br>This week, active duty troops tracked, Kali365 bypassed MFA, Australian lawmakers phished on WhatsApp, Silent Ransom escalated IT scams, Lithuania and German hospit

Bank Info Security
CRITICALVulnerability

CERT-In's AI-Era Cyber Rules Test Enterprise Reality

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cert-ins-ai-era-cyber-rules-test-enterprise-reality-image_small-8-a-31803.jpg" align=right hspace=4><b>Nodal Agency Urges Fix Within 12 Hours for Internet-Facing Flaws</b><br>Hackers move quickly, especially with artificial intelligence there to help them. Cyber defenders should move equally as fast, said the Indian Computer Emerg

Bank Info Security
CRITICALVulnerability

NVD CRITICAL: CVE-2026-46833 — Vulnerability in the Net Service component of Oracle Database Server. Supported...

Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Net Service. While the vulnerability is in Net Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerabi

CVE-2026-46833
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-34311 — Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Ora...

Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.24, 5.6.22, 5.6.25.19, 5.6.27.6 and 5.6.28. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services. Successful attacks of

CVE-2026-34311
NIST NVD
MEDIUMMalware

BTMOB Android malware service generates custom phishing payloads

An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures. [...]

BleepingComputer
MEDIUMVulnerability

Analysis of a Year of Files Uploaded to DShield Sensors, (Wed, May 27th)

Using the data collected over the past year and using Kibana these two ES&#x7c;QL query to summarize the data, this shows the list of the most uploaded threat to two DShield sensors (local and cloud) over the past year. I have sorted the activity by months that shows the evolution of files uploaded to the sensors each month. The activity peaked during the winter months (Dec 2025 - Feb 2026) and st

SANS ISC
MEDIUMVulnerability

FBI warns of fake FIFA websites running World Cup fraud schemes

The FBI is warning of fake websites impersonating FIFA ahead of the 2026 World Cup, to steal personal and financial information, sell fake tickets and hospitality packages, and push other fraud related to the event. [...]

BleepingComputer
MEDIUMVulnerability

Dutch Raid Fails to Dent Russian Bulletproof Host

Dutch law enforcement seized 800 servers and arrested two operators of THE.Hosting but left the hosting provider's core IP address space intact.

Dark Reading
MEDIUMVulnerability

House panel poised to hold hearing centered on AI impact on cyber

It’s part of a series of examinations at the House Homeland Security Committee that now will include a public event. The post House panel poised to hold hearing centered on AI impact on cyber appeared first on CyberScoop .

CyberScoop
MEDIUMAi

Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks

Researchers warn GreyVibe’s extensive use of ChatGPT, Gemini, and other AI tools offers a glimpse into how future cybercriminal and state-aligned groups will operate. The post Russia-Linked ‘GreyVibe’ Attackers Use AI to Supercharge Cyberattacks appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket

Michele Spagnuolo allegedly placed multiple trades on the prediction marketplace, abusing internal access to Google’s nonpublic data on the most searched people in 2025. The post Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket appeared first on CyberScoop .

CyberScoop
MEDIUMVulnerability

Less panic patching, more precision

In this newsletter, Thor breaks down why you should stop relying solely on CVSS and start using EPSS and GCVE to focus your patching efforts on the threats that actually matter.

Cisco Talos
MEDIUMMalware

Hackers exploit FortiClient EMS flaw to push infostealer malware

Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ. [...]

CVE-2026-35616
BleepingComputer
CRITICALVulnerability

Critical Gogs RCE Vulnerability Lets Any Authenticated User Execute Arbitrary Code

A critical security vulnerability has been disclosed in Gogs, a popular open-source self-hosted Git service, that allows an authenticated user to execute arbitrary code under certain conditions. The security flaw, per Rapid7, is rated 9.4 on the CVSS scoring system. It does not have a CVE identifier. "The vulnerability allows any authenticated user to achieve remote code execution (RCE) on

The Hacker News
CRITICALVulnerability

NVD CRITICAL: CVE-2026-24444 — SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 con...

SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interface recovery endpoints (mgmt.php, npcmd.php) that allows unauthenticated attackers to gain root access by submitting the hardcoded credential to the recovery endpoint via HTTP. Attackers can leverage this hardcoded password to enable filtered SSH and T

CVE-2026-24444
NIST NVD
MEDIUMVulnerability

Geordie Raises $30 Million for AI Security and Governance Platform

The funding round was led by Balderton Capital, with additional support from Crosspoint Capital and previous investors General Catalyst and Ten Eleven Ventures. The post Geordie Raises $30 Million for AI Security and Governance Platform appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Extending EOL/EOS Software Intelligence Across Containers, Kubernetes, and Modern Workloads

Key Takeaways Software inventory used to stop at the server. Modern application delivery erased that boundary. In cloud-native environments, software now moves continuously through container images, registries, CI/CD pipelines, and Kubernetes clusters, often reaching production faster than traditional governance models can track it. A single outdated base image or unsupported runtime no longer sta

Qualys Blog
MEDIUMAi

Visa invests in agentic software creation platform Replit

Visa has invested in Replit, the agentic software creation platform already used by more than 1000 of the payment giant's employees. The size of the investment was not disclosed.

Finextra
MEDIUMVulnerability

CISA Announces Rescheduled CIRCIA Virtual Town Hall Meetings

The Cybersecurity and Infrastructure Security Agency (CISA) has announced a revised schedule of virtual town hall meetings for its Cyber [&#8230;] The post CISA Announces Rescheduled CIRCIA Virtual Town Hall Meetings appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMAi

Agentic AI Isn't Risky; the Way Orgs Deploy It Is

AI agents aren't black boxes — they're models interacting with software tools. The risk lies in their overlap.

Dark Reading
MEDIUMVulnerability

Attackers Move Past Typosquatting to Realistic Package Impersonation

Most malicious open source packages now mimic real code rather than rely on typosquatting

Infosecurity Magazine
CRITICALMalware

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware. "The campaign abused trusted endpoint management infrastructure to deliver malware across managed endpoints," Arctic Wolf said. "Threat actors disguised the credential stealer payload as a Fortinet endpoint

The Hacker News
MEDIUMSupply Chain

Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies

<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/inside-a-176-package-npm-campaign-built-to-beat-your-internal-dependencies" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/blog-176-malicious-npm-packages.png" alt="Image with text describing discovery of 176 malicious packages in the npm registry, notably with technique of dependency

Sonatype (Maven/npm)
HIGHData Breach

Carnival Data Breach Exposed 6 Million People

Data breach leaves nearly 6 million Carnival customers navigating identity theft risks. The post Carnival Data Breach Exposed 6 Million People appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

HIPAA Security Rule Training Requirements

The HIPAA Security Rule training requirements mandate HIPAA-Covered Entities and HIPAA Business Associates to provide workforce security awareness training that [&#8230;] The post HIPAA Security Rule Training Requirements appeared first on The HIPAA Journal .

HIPAA Journal
LOWAi

Daloopa raises $47m to power data layer behind AI-driven finance

Daloopa, a startup providing the data infrastructure for AI and agentic workflows in finance, has raised $47 million in Series C funding.

Finextra
CRITICALZero Day

New Gogs zero-day flaw lets hackers get remote code execution

An unpatched zero-day vulnerability in the Gogs self-hosted Git service can allow attackers to gain remote code execution (RCE) on Internet-facing instances. [...]

BleepingComputer
MEDIUMAi

Healthcare Orgs Lack Confidence in Ability to Defend Against an AI-incited Identity Breach

Healthcare organizations have embraced AI and are using AI agents to perform a range of functions, including handling IT support [&#8230;] The post Healthcare Orgs Lack Confidence in Ability to Defend Against an AI-incited Identity Breach appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

How SIEM helps MSPs reduce noise and stop threats faster

MSPs don't lack security data. They struggle to separate real threats from alert noise. Kaseya explains how SIEM helps MSPs improve visibility, reduce fatigue, and respond faster. [...]

BleepingComputer
HIGHData Breach

Cruise giant Carnival confirms data breach affecting nearly 6 million people

The company said the threat actor gained access to a limited portion of its IT environment last month after compromising an employee account. By the end of April, Carnival determined that the attacker had copied personal information from its systems.

The Record
CRITICALZero Day

Microsoft Slams Public Zero-Day Disclosures Amid GitHub Researcher Account Removal

Microsoft has come out strongly in favor of Coordinated Vulnerability Disclosure (CVD), urging the research community to share their findings and give affected vendors an opportunity to better understand the impact and address them before they are publicly disclosed. The development comes after a researcher named Chaotic Eclipse (aka Nightmare-Eclipse) disclosed details of multiple zero-day

The Hacker News
HIGHData Breach

Lakeview Health Systems Settles Class Action Data Breach Lawsuit

A settlement has been negotiated to resolve a class action lawsuit against Lakeview Health Systems LLC. The lawsuit stemmed from [&#8230;] The post Lakeview Health Systems Settles Class Action Data Breach Lawsuit appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

Canadian man gets 33 years for using social media to coerce US children into sending sexual content

Prosecutors said the man spent years using fake online identities to contact children and manipulate them into sending sexually explicit images and videos.

The Record
HIGHRansomware

MyPillow listed on ransomware gang&#8217;s leak site, but denies it has been breached

A notorious ransomware gang claims to have stolen MyPillow's private data, but CEO Mike Lindell calls it a politically motivated "hit job." With the countdown ticking toward a massive dark web leak, who is telling the truth? Read more in my article on the Hot for Security blog.

Graham Cluley
LOWAi

ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

Every time you think the industry has finally stopped doing some reckless, low-effort crap, somebody spins up a fresh box full of sketchy loaders, fake installers, recycled social-engineering bait, and enough exposed infrastructure to make you wonder if prod is just a public beta now - meanwhile some researcher casually drops a technique that turns a "minor" foothold into total account

The Hacker News
MEDIUMVulnerability

Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans

Cybercriminals have registered more than 4,300 fraudulent domains impersonating FIFA's official web presence since August 2025.

The Record
MEDIUMVulnerability

Clearbank launches digital asset rails

ClearBank Europe today announced the launch of its Digital Asset Rails, a new capability enabling programmable liquidity for cross-border settlement with 24/7* fiat payouts in EUR via SEPA Instant.

Finextra
MEDIUMVulnerability

Russia conducting daily attacks on UK 'from seabed to cyberspace,' spy chief warns

Anne Keast-Butler, director of GCHQ, said Russia's actions have prompted the agency to defend subsea cables and energy pipelines in British waters, disrupt Russian networks smuggling sanctioned technology and countering “reckless sabotage and assassination attempts.”

The Record
MEDIUMMalware

New BTMOB Android Malware Enables Full Device Takeover

Delivered via phishing lures, the malware combines financial theft with data exfiltration and remote access. The post New BTMOB Android Malware Enables Full Device Takeover appeared first on SecurityWeek .

SecurityWeek
CRITICALAi

Indian CERT urges firms to contain exploited internet-facing flaws within 12 hours

India’s cybersecurity agency, CERT-In, has urged organizations to patch, mitigate, or isolate known exploited vulnerabilities affecting internet-facing “crown jewel” systems within 12 hours where feasible, warning that AI-assisted attacks are dramatically compressing the time between vulnerability disclosure and exploitation. The recommendation, part of a sweeping new CERT-In blueprint on defendin

CSO Online
LOWVulnerability

Experts on Experts: Why Compliance is becoming Continuous

This week on Experts on Experts, I’m joined by Sergio Alonso – Rapid7’s Director of Trust, Risk, and Compliance – to talk about how compliance is changing and why many security teams are rethinking the way they approach readiness, reporting, and operational risk. One of the biggest themes in the conversation is that compliance is no longer something organizations can treat as a point-in-time exerc

Rapid7
MEDIUMSupply Chain

Zapier fixes bug chain that researchers say risked widespread account takeover

A five-step flaw chain in the popular automation service, now patched, could have let a single attacker act as any signed-in user across thousands of connected apps. The post Zapier fixes bug chain that researchers say risked widespread account takeover appeared first on CyberScoop .

CyberScoop
CRITICALZero Day

Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks

Fortinet rolled out hotfixes for the security defect in April, warning that it had been exploited in the wild as a zero-day and urging immediate patching. The post Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks appeared first on SecurityWeek .

CVE-2026-35616
SecurityWeek
MEDIUMVulnerability

Romanian gets 5 years in prison for hacking Oregon govt network

A Romanian national was sentenced this week to 56 months in federal prison for breaking into an Oregon state government computer network and fr cyberattacks targeting dozens of other U.S. victims. [...]

BleepingComputer
MEDIUMSupply Chain

IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under &#8220;Project Lightwell&#8221;

Project Lightwell is designed to fix vulnerabilities without breaking what is already in production. The post IBM and Red Hat Commit $5 Billion to Secure Open Source Supply Chains Under &#8220;Project Lightwell&#8221; appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security

In this latest installment of the Reporters' Notebook video series, we discuss how cyber insurance is forcing organizations to quantify risk, what's covered (and what's not), and why this could be the best thing to happen to cybersecurity.

Dark Reading
LOWSupply Chain

GlassWorm falls, but the repo problem is far from solved

Taking down a sprawling malware operation once signaled progress in securing the open-source ecosystem. Now, it barely registers. The GlassWorm campaign disruption comes at a moment when attackers can quickly reconstitute, and defenders are increasingly grappling with a new challenge: distinguishing real threats from automated noise. “I think coordinated actions, like GlassWorm, can sever control,

CSO Online
CRITICALPhishing

XCharge C6

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-08.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could allow an attacker to gain administrator rights or execute code on the affected device.</strong></p> <p>The following versions of XCharge C6 are affected:</p> <ul> <li>C6</li> </ul

CVE-2026-9037CVE-2026-9038
CISA Advisories
CRITICALVulnerability

Schnieider Electric EcoStruxure Machine Expert HVAC

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-07.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Schneider Electric is aware of a vulnerability in its EcostruxureTM Machine Expert HVAC product. The [EcostruxureTM Machine Expert HVAC](https://www.se.com/ww/en/download/document/EcoStruxureME_HVAC/) product is a programming software

CVE-2026-6332
CISA Advisories
CRITICALVulnerability

ABB EIBPORT

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. A firmware update is available that resolves these privately reported vulnerabilities in the product versions listed as affected in the adviso

CVE-2021-22291
CISA Advisories
MEDIUMSupply Chain

New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails

France-based startup Edamame says its runtime verification platform uses host telemetry and AI analysis to detect coding-agent “intent drift,” secret theft and supply-chain attacks in real time. The post New Edamame Platform Aims to Catch AI Coding Agents Going Off the Rails appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Microsoft Condemns "Uncoordinated" Zero Day Disclosures

Microsoft warned the disclosure of several unpatched vulnerabilities without notice has put “customers at unnecessary risk”

Infosecurity Magazine
CRITICALData Breach

Authenticated RCE via Argument Injection in Gogs (NOT FIXED)

Overview Rapid7 Labs discovered a critical argument injection ( CWE-88 ) vulnerability in Gogs , a popular open-source self-hosted Git service. Rapid7 Labs scores this vulnerability as CVSSv4 9.4 (Critical). The vulnerability allows any authenticated user to achieve remote code execution (RCE) on the server by creating a pull request with a malicious branch name that injects the --exec flag into g

CVE-2024-39933CVE-2024-39932
Rapid7
CRITICALVulnerability

ABB Busch-Welcome 2 Wire Door Opener Actuator

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-04.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could gain physical, unauthorized access to a Building where the product is installe

CVE-2025-7705
CISA Advisories
CRITICALVulnerability

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could result in an attacker gaining administrator access to the device.</strong></p> <p>The following versions of Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethern

CVE-2026-7786
CISA Advisories
CRITICALPhishing

CP Plus 8 Ch. Network Video Recorder

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-05.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability allows an attacker's malicious script to execute in the browser of any authenticated user or administrator who accesses the affected interface. This could lead to compromise of user sessio

CVE-2026-6824
CISA Advisories
CRITICALVulnerability

MacGregor Voyage Data Recorder (VDR) G4e

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of these vulnerabilities could result in an attacker gaining administrator access to the device.</strong></p> <p>The following versions of MacGregor Voyage Data Recorder (VDR) G4e are affected:</p> <ul> <li>Mac

CVE-2026-42941CVE-2026-42951
CISA Advisories
CRITICALVulnerability

Fourth Frontier Frontier X Mobile Application, Frontier X2

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-148-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to read and write arbitrary handle values and change clinical readings, which could result in taking control of the device and lead to patient harm.</strong></p> <

CVE-2026-5768
CISA Advisories
CRITICALPhishing

KMW CCTV Security Cameras

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-06.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability may grant full unauthorized access to camera feeds and settings.</strong></p> <p>The following versions of KMW CCTV Security Cameras are affected:</p> <ul> <li>KM-IP521 IPCAM_V4.04.91.2303

CVE-2026-5386
CISA Advisories
LOWSupply Chain

Supply Chain Compromises Impact Nx Console and GitHub Repositories

<p>CISA is prioritizing the response to multiple emerging software supply chain intrusion campaigns targeting developer ecosystems Continuous Integration/Continuous Development (CI/CD) pipelines. These recent incidents, including the GitHub compromise via a malicious Nx Console Visual Studio Code (VS Code) extension and the “Megalodon” supply chain intrusion campaign, demonstrate how cyber threat

CVE-2026-48027
CISA Advisories
CRITICALVulnerability

Schneider Electric EcoStruxure Machine Expert HVAC

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-148-07.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Schneider Electric is aware of a vulnerability in its EcostruxureTM Machine Expert HVAC product. The [EcostruxureTM Machine Expert HVAC](https://www.se.com/ww/en/download/document/EcoStruxureME_HVAC/) product is a programming software

CVE-2026-6332
CISA Advisories
MEDIUMMalware

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

New actor Jinx-0164 hit crypto developers with fake recruiter lures and macOS malware

Infosecurity Magazine
MEDIUMVulnerability

New AI Usage Report: Enterprise AI Risk Is Heavily Concentrated Among a Small Group of AI "Power users"

State of AI Usage Report 2026 (full report here) by LayerX Security reveals the extent of the enterprise AI visibility gap and why most organizations still don't understand where their AI exposure is actually coming from. The research shows that enterprise AI risk is not distributed evenly across users or platforms. Instead, it is heavily concentrated among a small group of AI power users and a

The Hacker News
LOWVulnerability

Gitea Vulnerability Exposed 30,000 Deployments to Attacks

The security flaw allowed attackers to pull private container images, exposing source code, credentials, and infrastructure. The post Gitea Vulnerability Exposed 30,000 Deployments to Attacks appeared first on SecurityWeek .

CVE-2026-27771
SecurityWeek
MEDIUMAi

Raising the Cybersecurity Stakes: Ante up for the Agentic Era

CISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale. The post Raising the Cybersecurity Stakes: Ante up for the Agentic Era appeared first on SecurityWeek .

SecurityWeek
HIGHData Breach

Carnival Cruise confirms data breach affecting nearly 6 million people

Carnival Corporation, the world's largest cruise line operator, has confirmed a data breach affecting nearly 6 million people claimed by the ShinyHunters extortion gang in April 2026. [...]

BleepingComputer
MEDIUMVulnerability

Romanian National Sentenced for Selling Access to Networks of Oregon State Government Office

A Department of Justice press release on May 27 reports that a Romanian national who faced seven years in prison for selling access to an Oregon state government office in 2021 and other U.S. entities has been sentenced to 56 months in prison: According to court documents, Catalin Dragomir, 46, formerly of Constanta, Romania, sold... Source

DataBreaches.net
MEDIUMVulnerability

Monzo launches mobile phone plan with discounts for loyal users

UK digital bank Monzo has opened a waitlist for a SIM-only mobile plan over the Virgin Media 02 network.

Finextra
LOWAi

The AI governance imperative you can’t afford to ignore

CIOs rushing to roll out AI agents without real visibility into their decision-making processes are flirting with disaster. According to AI experts, deploying agents without observability processes and tools creates a ticking time bomb with the potential for huge negative consequences . Many companies are deploying AI agents and expecting them to increase productivity with little human interventio

CSO Online
MEDIUMVulnerability

Push by Aave Labs receives FCA crypto approval

Push Labs Limited and Push Virtual Assets Limited (together “Push”), both UK subsidiaries of Aave Labs, today announced that they have received approval from the UK’s Financial Conduct Authority (FCA) for their applications to register as a cryptoasset exchange provider in the UK.

Finextra
MEDIUMVulnerability

Infosecurity Europe: Cybersecurity Staff Prefer CISOs With Real Attack Response Experience, Study Reveals

ISC2 survey of cybersecurity professionals suggests that staff want their information security leaders to have experienced reacting to a significant cyber incident

Infosecurity Magazine
CRITICALRansomware

2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface

The 2026 World Cup presents major cyber risks from ransomware groups, state-aligned actors, and other groups targeting critical infrastructure. Learn more here. The post 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface appeared first on Unit 42 .

Unit 42 (Palo Alto)
LOWVulnerability

DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap

This white paper presents a concrete case study demonstrating the creation of a heap overflow vulnerability through the exploitation of the DICOM file format.

Cisco Talos
MEDIUMAi

Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks

New AI Threat Defense platform combines capabilities from Mandiant, Wiz and Gemini to help customers fight AI with AI. The post Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Cash App opens up for stablecoin transactions

Cash App has made it possible for its 59 million monthly users to send and receive USDC stablecoins, with an immediate conversion to US dollars.

Finextra
MEDIUMVulnerability

Sella is the first bank in Italy to get permission to set up crypto-asset services

Banca Sella has completed the process of notification to the Bank of Italy as set out in the European MiCA (Markets in Crypto-Assets) Regulation and is the first bank in Italy to be authorized to offer crypto-asset services, relating in particular to the custody and transfer of digital assets.

Finextra
LOWVulnerability

Whop issues stablecoin debit card

Whop, the fastest growing internet market where people can create, connect, and transact in one place, today announced the launch of Whop Cards that allow businesses on the platform the ability to spend directly from their Whop balance without withdrawing funds to an external bank.

Finextra
MEDIUMVulnerability

GCHQ Chief Urges Action as AI Reshapes Cyber Threats

GCHQ director urges urgent business cyber action as AI and quantum reshape the threat

Infosecurity Magazine
MEDIUMVulnerability

Sextortionist sentenced to 33 years for targeting 145 children

A Canadian man was sentenced to 33 years in prison after pleading guilty to targeting more than 145 children across the United States, some as young as 6 years old, in an eight-year-long sextortion scheme. [...]

BleepingComputer
CRITICALVulnerability

NVD CRITICAL: CVE-2026-4408 — A flaw was found in Samba. A remote attacker can exploit a misconfiguration in S...

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, the client-controlled username is passed without proper escaping of shell meta-characters. This vulnerability allows an attacker to achieve remote command execu

CVE-2026-4408
NIST NVD
MEDIUMMalware

BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model

An advanced remote access Trojan is propagating online. Notably, it's delivered via an operator licensing model and features a no-code malware-development interface.

Dark Reading
CRITICALAi

What the industrialization of exploitation means for defenders

For decades, cybersecurity was a battle of skill. Elite attackers versus elite defenders. The rules of engagement were understood, even if the playing field wasn’t level. If you hired better analysts and bought better tools, hopefully you hardened your systems well enough and built detection capabilities that wore out the adversary’s patience. That era is over, and most security programs haven’t f

CSO Online
MEDIUMApt

ESET APT Activity Report Q4 2025–Q1 2026

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2025 and Q1 2026

WeLiveSecurity (ESET)
MEDIUMMalware

JINX-0164 Targets Cryptocurrency Firms with Fake Recruiter Lures and macOS Malware

A new campaign orchestrated by a previously undocumented threat actor has targeted cryptocurrency organizations with an aim to facilitate digital asset theft using recruitment-themed social engineering and bespoke macOS malware. "These campaigns leveraged sophisticated social engineering techniques, custom macOS malware, and deep targeting of CI/CD infrastructure," Wiz researchers Shira Ayal,

The Hacker News
MEDIUMVulnerability

Nordic CISOs Handle Rising Cyber Threats Remarkably Well

Artificial intelligence notwithstanding, the vast majority of CISOs in northern Europe say they're facing no more serious cyberattacks than they did two years ago.

Dark Reading
MEDIUMMalware

Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years

Our experts continue to track attacks targeting consumers of pirated content, both books and movies. 2026 saw the discovery of new target sites with tens of millions of visitors, while the miner gained a RAT module.

Securelist (Kaspersky)
MEDIUMVulnerability

AI Is Automating Jobs That Train Security's Next Leaders

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ai-automating-jobs-that-train-securitys-next-leaders-image_small-3-a-31796.jpg" align=right hspace=4><b>SANS Survey Says Industry Risks Future by Cutting Roles That Train Cyber Expertise</b><br>AI is automating the entry-level cybersecurity roles where the next generation of experts have always been trained. As the industry strugg

Bank Info Security
MEDIUMPhishing

Chinese Phishers Use Live MFA Interception for Digital Wallet Fraud

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/chinese-phishers-use-live-mfa-interception-for-digital-wallet-fraud-image_small-8-a-31799.jpg" align=right hspace=4><b>Fraudsters Tokenize Stolen Cards Into Attacker Wallets</b><br>Google Threat Intelligence Group warned that Chinese-language phishing-as-a-service platforms are using AI, encrypted messaging and real-time OTP inter

Bank Info Security
MEDIUMAi

Sonar Acquires Gitar to Eliminate AI Code Review Gaps

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/sonar-acquires-gitar-to-eliminate-ai-code-review-gaps-image_small-7-a-31798.jpg" align=right hspace=4><b>Deal Adds LLM-Based Reasoning to Sonar's Algorithmic Code Verification Platform</b><br>Sonar purchased Silicon Valley-based startup Gitar to add LLM-based code review and verification capabilities as enterprises use AI agents t

Bank Info Security
MEDIUMVulnerability

White House Faces Pressure to Rewrite AI Order

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/white-house-faces-pressure-to-rewrite-ai-order-image_small-6-a-31797.jpg" align=right hspace=4><b>Analysts Say White House Must Quickly Replace Shelved AI Framework</b><br>U.S. President Donald Trump's decision to abruptly shelve an artificial intelligence executive order aimed at creating a federal review process for frontier mod

Bank Info Security
HIGHRansomware

Employees are unknowingly inviting tech support impersonators into firms, says FBI

Online or telephone IT support scams have been tricking employees into downloading or clicking on malware for years. But according to the FBI, one group that targets US-based law firms has recently found success in person, by convincing firms to allow a supposed IT support person into the building, where they insert a storage device into a victim’s computer and install malware or steal data. This

CSO Online
MEDIUMVulnerability

Mastercard secures New York BitLicense

Mastercard Transaction Services has been granted a BitLicense by the New York State Department of Financial Services (NYDFS), cementing its support for digital currencies such as stablecoins and tokenized deposits

Finextra
MEDIUMVulnerability

Tokenisation can improve wholesale cross-border payments - BIS project

A long-running project involving several central banks and a host of private sector players has built a prototype demonstrating that tokenisation can tackle inefficiencies in wholesale cross-border payments.

Finextra
MEDIUMAi

Farsight launches AI agent for client-ready deal materials

Farsight, an institutional AI platform for financial services, has launched an agent designed to produce client-ready deck materials from a single prompt.

Finextra
LOWAi

Another IT governance headache: AI-enabled sanction evasion

Over the next three to five years, both governments and the private sector will need to rapidly adapt identification and mitigation protocols as adversaries move from AI-assisted to AI-enabled sanctions evasion and proliferation financing (PF), a new research paper warns. The report , Algorithms of Evasion: The Rise of AI-Enabled Proliferation Financing, from the Royal United Services Institute (

CSO Online
MEDIUMSupply Chain

Out of the Crypt: The Evolving Cyber Extortion Economy

Unit 42 explores trends in data theft and extortion, outlining key strategies for organizations as frontier AI models advance. The post Out of the Crypt: The Evolving Cyber Extortion Economy appeared first on Unit 42 .

Unit 42 (Palo Alto)
MEDIUMAi

AI models more vulnerable than claimed when faced with iterative attacks

CISOs relying on LLM runtime guardrails and official safety scores when making security decisions about their organizations’ AI usage and model selection are due for a wakeup call. According to a new study from Cisco, frontier models from OpenAI, Anthropic, Google, xAI, and Amazon have significantly worse risk profiles when pressured in multi-turn attacks compared to when their safety is benchmark

CSO Online
MEDIUMMalware

GPU mining malware spreads via SEO poisoning, AI chatbots

Threat actors are targeting systems with high-performance computers in an ongoing cryptojacking campaign spread through a coordinated SEO poisoning operation that also manipulated AI chatbot recommendations. [...]

BleepingComputer
HIGHRansomware

Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th)

Most Akira write-ups focus on the ransom note or the encryption routine. By the time those show up the interesting forensic work is over. The questions that matter to defenders sit earlier. How did they get in. When did they get domain admin. What did they touch before the binary fired. Those answers live in the days before impact. They sit in two log sources that almost never get joined. The peri

SANS ISC
MEDIUMAi

OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms

The announcement builds on work from major tech firms in 2024 to combat AI-infused election chicanery. The post OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms appeared first on CyberScoop .

CyberScoop
HIGHRansomware

Ransomware Actors Show Up In Person to Steal Law Firm Data

The FBI warned that the extortion gang Silent Ransom Group is targeting law firms and socially engineering its way into servers and databases.

Dark Reading
HIGHRansomware

FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person

Silent Ransom Group isn’t prolific, but it's demonstrated a knack for attacking the legal services sector with an extraordinary dual use of social engineering and in-person visits to victims’ workstations. The post FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person appeared first on CyberScoop .

CyberScoop
MEDIUMVulnerability

UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace

Anne Keast-Butler, head of the GCHQ, said her agency was developing an artificial intelligence-powered cyber shield as other nations were deploying AI in warfare. The post UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace appeared first on CyberScoop .

CyberScoop
MEDIUMVulnerability

Fold rolls out bitcoin rewards credit card

Fold Holdings, Inc. (NASDAQ: FLD) (“Fold” or the “Company”), a bitcoin financial services company making it easy for individuals to earn, save and spend bitcoin through everyday financial tools, announced it has begun rolling out the Fold Bitcoin Credit Card to a portion of the waitlist members.

Finextra
MEDIUMVulnerability

Sella becomes first bank in Italy to get permission to set up crypto-asset services

Banca Sella has completed the process of notification to the Bank of Italy as set out in the European MiCA (Markets in Crypto-Assets) Regulation and is the first bank in Italy to be authorized to offer crypto-asset services, relating in particular to the custody and transfer of digital assets.

Finextra
CRITICALVulnerability

Romanian national sentenced to more than 4 years for hacking Oregon government systems

Dragomir was arrested in Romania in November 2024 and brought to the U.S. last year to face charges for hacking into the network belonging to Oregon’s Office of Emergency Management.

The Record
LOWVulnerability

UK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About Russia

The speech is the latest in a string of warnings from intelligence experts that Russia is stepping up hostile activity in a “gray zone” that falls just below the threshold of war. The post UK Cyberspying Chief Calls AI ‘an Unstoppable Force’ and Warns About Russia appeared first on SecurityWeek .

SecurityWeek
CRITICALVulnerability

NVD CRITICAL: CVE-2026-48027 — Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious ver...

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx C

CVE-2026-48027
NIST NVD
MEDIUMVulnerability

Latin American Cybercriminals Hoover Up Government Data

A purported leak exposing 5.8 million records of Uruguayan citizens is the latest incident where cybercriminals targeted government agencies to monetize citizen data.

Dark Reading
MEDIUMVulnerability

AI-Assisted Exploit Development Outpaces Scanner Detection

Attackers are using AI to dramatically reduce the time they need to develop a working exploit for a CVE, according to new research.

Dark Reading
MEDIUMMalware

Grandoreiro Malware and BTMOB RAT Campaigns Target Windows and Android Users

Latin America and Europe become the target of two banking trojan campaigns that are designed to infect Windows and Android devices with Grandoreiro and BTMOB malware, respectively. That's according to new findings from WatchGuard and ESET, which have observed the two malware families being used to single out companies in Spain, Portugal, and Mexico, as well as mobile users in Brazil. The

The Hacker News
LOWSupply Chain

AI Is Making Software Autonomous, and Governance Must Follow

<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/ai-is-making-software-autonomous-and-governance-must-follow" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/blog_ai_software_autonomous.jpg" alt="Image with hexagon shape at center surrounded by software development life cycle icons" class="hs-featured-image" style="width:auto !importa

Sonatype (Maven/npm)
MEDIUMVulnerability

Nium joins Circle Payments network

Nium, the global leader in real-time cross-border payments infrastructure, and Circle Technology Services, LLC, an affiliate of Circle Internet Group, Inc. (NYSE: CRCL) ('Circle') and operator of Circle Payments Network (CPN), today announced a partnership to connect stablecoin settlement with last-mile global payouts.

Finextra
MEDIUMSupply Chain

Malicious npm Package Stole Files From Claude AI User Directory via GitHub

Cybersecurity researchers have discovered a new malicious package on the npm registry that comes with information stealing capabilities. According to OX Security, the package, named "mouse5212-super-formatter," is designed to upload files from "/mnt/user-data," a dedicated directory used by Anthropic's Claude artificial intelligence (AI) tool to handle uploads and outputs in the background. The

The Hacker News
MEDIUMVulnerability

Rudd orders Cyber Command reviews as Pentagon presses reform agenda

Army Gen. Joshua Rudd, who took the twin-leadership reins of Cyber Command and the NSA in March, recently tapped MITRE to conduct a potentially wide-ranging review into the organization, according to three people familiar with the matter.

The Record
MEDIUMApt

Plaid launches income verification tool in the UK and Europe

Lenders across the UK and Europe are facing a growing challenge: traditional credit data alone no longer captures the full picture of a borrower’s financial health.

Finextra
MEDIUMVulnerability

Visa Commercial Solutions Hub expanded to scale virtual cards

Visa Inc. (NYSE: V), a global leader in digital payments, today announced an expansion of the Visa Commercial Solutions Hub (VCS Hub), further strengthening how issuers and suppliers connect to scale virtual card programs.

Finextra
MEDIUMVulnerability

Connecticut Medicaid Portal Breach Affects 22,500 Hartford HealthCare Patients

The personal and protected health information of approximately 22,500 Hartford HealthCare patients has been exposed in a security incident. Data [&#8230;] The post Connecticut Medicaid Portal Breach Affects 22,500 Hartford HealthCare Patients appeared first on The HIPAA Journal .

HIPAA Journal
LOWAi

FastAPI-based AI tools exposed to authentication bypass by flaw in Starlette framework

A single malformed character in a web request can let an unauthenticated attacker slip past the access controls that guard applications built on Starlette, the open-source Python framework that powers FastAPI, researchers said. The flaw, tracked as CVE-2026-48710 could allow attackers to bypass host-validation protections using malformed Host headers, according to an advisory from cybersecurity fi

CVE-2026-48710
CSO Online
MEDIUMVulnerability

SoFi adds USD sablecoin to banking app

SoFi Technologies, Inc. (NASDAQ: SOFI), a member-centric, everything app for digital financial services, announced today that SoFiUSD, a bank-issued U.S. dollar stablecoin, is available for SoFi members to buy, sell, hold, and convert directly within the SoFi app.

Finextra
MEDIUMAi

Coinbase goes live with Base MCP

Base MCP is live. Connect your Base Account to your agent and use simple prompts to swap, transfer, track your portfolio, and tap into the Base Ecosystem from chat. Launching with skills for Morpho, Moonwell, Aerodrome, Bankr, Avantis, Virtuals, and Uniswap, with more on the way.

Finextra
MEDIUMVulnerability

Interac deepens verification capabilities with Incode

Interac Corp. (Interac) today announced a collaboration with Incode Technologies, Inc. – a global leader in identity security and fraud prevention – to add advanced capabilities to Interac Verified solutions.

Finextra
MEDIUMAi

Robinhood customers can now let AI agents make trades and credit card purchases

Robinhood customers can now enable their AI agents to make payments and trade stocks on their behalf.

Finextra
LOWVulnerability

FBI warns extortion hackers are visiting US law firms to steal data

In a public advisory issued Tuesday the FBI said a hacking group has targeted law firms using social engineering schemes to gain remote access to corporate systems and exfiltrate data.

The Record
MEDIUMVulnerability

Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate

Novee researchers discovered an account takeover vulnerability in the open source CFP management tool Pretalx. The post Vulnerability in Popular Conference Software Granted Attackers a 100% Talk Acceptance Rate appeared first on SecurityWeek .

SecurityWeek
CRITICALVulnerability

NVD CRITICAL: CVE-2026-8175 — IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM A...

IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be exploited to cause a denial of service and potentially lead to authentication bypass or remote code execution.

CVE-2026-8175
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-7876 — IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19

IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19

CVE-2026-7876
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-7524 — IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to im...

IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.

CVE-2026-7524
NIST NVD
MEDIUMVulnerability

FBI’s 2025 Internet Crime Report

The 2025 Internet Crime Report was published a few weeks ago, but I only just saw it. Lots of interesting statistics. Press release . News articles .

Schneier on Security
LOWVulnerability

MediaArea heap-based buffer overflow vulnerabilities

Talos researchers find 4 heap-based buffer overflow vulnerabilities in MediaArea's MediaInfoLib.

Cisco Talos
MEDIUMVulnerability

Can you enforce strong Active Directory password rules without frustrating users?

Strong Active Directory passwords don't have to come at the expense of usability. Specops Software explains how passphrases, breached password protection, and self-service resets can improve security without frustrating users. [...]

BleepingComputer
MEDIUMMalware

CrowdStrike, Google Take Down Glassworm Botnet

Operators of the malicious Glassworm botnet have been targeting software developers since at least early 2025

Infosecurity Magazine
MEDIUMData Breach

NL: Schiphol cargo worker arrested over alleged data leaks to drug networks

NL Times reports: The Royal Netherlands Marechaussee detained a 24-year-old Amsterdam-based cargo worker at Schiphol on Tuesday, May 19, on suspicion of unauthorized access to computer systems and the leaking of confidential company information, Luchtvaart Nieuws has reported. According to the ongoing investigation, the suspect allegedly used his access to a cargo handling company’s systems at the

DataBreaches.net
MEDIUMVulnerability

DTC’s tokenization service to connect with Stellar public blockchain

The Depository Trust & Clearing Corporation (DTCC), the premier post-trade market infrastructure for the global financial services industry, and the Stellar Development Foundation (SDF) today announced plans to enable the tokenization of The Depository Trust Company (DTC) custodied assets on the Stellar network, a configurable and public blockchain used across securities, payment, and remittance a

Finextra
MEDIUMSupply Chain

CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain

CrowdStrike has dismantled the Glassworm botnet in an operation aided by Google and Shadowserver, stripping the operators’ access to infrastructure that helped threat actors infect hundreds of pieces of open-source software with malware since early 2025, the company said Tuesday.&#160; The coordinated effort involved the simultaneous takedown of four attacker-controlled servers that were designed

CyberScoop
MEDIUMVulnerability

Infosecurity Europe: Why Burnout in Cybersecurity Demands Risk-Based Response

Cybermindz warns that cybersecurity burnout is a growing risk, urging organizations to move beyond wellness initiatives and adopt a measurable, risk-based approach to workforce stress

Infosecurity Magazine
MEDIUMSupply Chain

Glassworm botnet disrupted after resilient C2 infrastructure takedown

The Glassworm botnet targeting developers in software supply-chain attacks has been disrupted after researchers took down its resilient command-and-control infrastructure relying on Solana blockchain transactions and the BitTorrent DHT network. [...]

BleepingComputer
MEDIUMVulnerability

Dutch police arrest man over cyber breach at Ajax football club

The suspect was detained in the central Dutch town of Buren, where law enforcement officers also searched his home and seized multiple digital storage devices, according to a statement released Tuesday by the Dutch National Police.

The Record
MEDIUMVulnerability

Iranian intelligence service behind hack of LA transit system, researchers say

The hacking group claimed to be a standalone hacktivist crew but actually has ties to the Ministry of Intelligence of the Islamic Republic of Iran (MOIS), researchers at Gambit Security said in a report published Tuesday.

The Record
MEDIUMVulnerability

SBI Group invests in Temple Digital

Japanese financial behemoth SBI Holdings has led an investment round in Temple Digital Group, a New York-based outfit building trading infrastructure on the Canton Network blockchain. The size of the investment was not disclosed.

Finextra
MEDIUMVulnerability

SecurityWeek to Host AI Risk Summit August 11-12 at the Ritz-Carlton, Half Moon Bay

Now in its third year, the AI Risk Summit is the leading conference that brings together CISOs, security leaders, AI researchers, developers, policymakers, and enterprise risk professionals. The post SecurityWeek to Host AI Risk Summit August 11-12 at the Ritz-Carlton, Half Moon Bay appeared first on SecurityWeek .

SecurityWeek
MEDIUMPhishing

Silent Ransom Group Impersonating IT Personnel through Social Engineering

The FBI has issued a Flash Alert about the Silent Ransom Group. Summary The Silent Ransom Group (SRG), also known as Luna Moth, Chatty Spider, and UNC3753, is targeting law firms using social engineering techniques. Through phone calls and phishing emails, SRG actors pose as IT support to establish access to victim computers and exfiltrate... Source

DataBreaches.net
MEDIUMVulnerability

UK Visa Portal spilled thousands of applicants’ passports and selfies online — and hasn’t fixed the leak

Zack Whittaker reports: A website called UK Visa Portal is publicly exposing the passports and selfie photos of applicants who signed up and paid the site to obtain a U.K immigration visa, TechCrunch has learned. An anonymous person notified TechCrunch about the security lapse, saying that the website is exposing at least 100,000 documents from... Source

DataBreaches.net
MEDIUMVulnerability

Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security

The cybersecurity industry of 2006 barely resembled today's billion-dollar behemoth. As part of Dark Reading's 20th anniversary celebration, we trace the industry's evolution through a technology lens.

Dark Reading
MEDIUMMalware

Malware seller known as &#8220;Venom&#8221; extradited to France

There is an update to an arrest made in Greece in November as part of Operation Endgame. Ekathimerini reports: A 39-year-old Albanian national known online as “Venom” was extradited to France in mid-May after his arrest last November at his apartment in the Nikaia district of Athens. The suspect, who described himself as a construction... Source

DataBreaches.net
MEDIUMVulnerability

Lithuania investigates theft of 600,000 state registry records

Daryna Antoniuk reports: The Lithuanian Prosecutor General’s Office said Friday that attackers gained unauthorized access to more than 600,000 records managed by the Centre of Registers, the state agency responsible for handling property and legal entity records. Prosecutors said the breach involved the misuse of login credentials assigned to institutions authorized to access the databases, and li

DataBreaches.net
MEDIUMVulnerability

CISA Adds Three Known Exploited Vulnerabilities to Catalog

<p>CISA has added&nbsp;three&nbsp;new vulnerabilities&nbsp;to its&nbsp;<a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog">Known Exploited Vulnerabilities (KEV) Catalog</a>, based on evidence of active exploitation.</p> <ul type="disc"> <li><a href="https://www.cve.org/CVERecord?id=CVE-2026-8398" target="_blank">CVE-2026-8398</a>&nbsp;Daemon Tools Lite Embedded Malicious Code Vu

CVE-2026-8398CVE-2026-45321
CISA Advisories
MEDIUMAi

Smartcomply brings AML platform to British payment firms serving African markets

Smartcomply, an African compliance and cybersecurity company, has opened operations in the UK and is making its AI-powered anti-money laundering platform, Adhere, available to British payment firms serving African markets.

Finextra
MEDIUMVulnerability

RevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries

Using an AI model called BinNet, RevEng hunts vulnerabilities and backdoors in released software binaries. The post RevEng.AI Raises $15 Million to Hunt for Flaws and Backdoors in Software Binaries appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Extortion Group Conducts Social Engineering Campaign Impersonating Victim&#8217;s IT Department

Silent Ransom Group, a data theft and extortion group that targets law firms, healthcare organizations, and insurance and finance companies, [&#8230;] The post Extortion Group Conducts Social Engineering Campaign Impersonating Victim&#8217;s IT Department appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

Extortion Group Conducts Social Engineering Campaign Impersonating IT Support Staff

Silent Ransom Group, a data theft and extortion group that targets law firms, healthcare organizations, and insurance and finance companies, [&#8230;] The post Extortion Group Conducts Social Engineering Campaign Impersonating IT Support Staff appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

FBI warns of in-person data theft attacks from extortion gang

The FBI warned on Tuesday that the Silent Ransom Group (SRG) extortion gang is now targeting U.S.-based law firms in in-person data theft attacks. [...]

BleepingComputer
MEDIUMSupply Chain

GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure

CrowdStrike, in partnership with Google and the Shadowserver Foundation, has announced the simultaneous disruption of all command-and-control (C2) channels associated with GlassWorm, a persistent software chain campaign targeting software developers through malicious packages and extensions. "Since at least early 2025, GlassWorm operators have systematically targeted software developers, a

The Hacker News
MEDIUMVulnerability

3 SOC Steps that Shut Down Incident Risks Early

Most organizations still picture cyber defense as a fortress problem: build stronger walls, add more guards, buy another detection engine. But modern incidents rarely crash through the front gate. They drift in disguised as routine activity, hide inside legitimate processes, and quietly accumulate risk long before anyone labels them an "incident." That changes the role of the SOC entirely. The

The Hacker News
MEDIUMVulnerability

German media giant Bertelsmann scores banking licence

Riverty, the fintech startup from German media giant Bertelsmann, has gained an EU banking licence and is setting up shop as bank in Luxembourg.

Finextra
MEDIUMVulnerability

Romanian Hacker Sentenced to Prison in US for Selling Access to State Network

Catalin Dragomir previously pleaded guilty to selling access to an Oregon state government office’s network. The post Romanian Hacker Sentenced to Prison in US for Selling Access to State Network appeared first on SecurityWeek .

SecurityWeek
MEDIUMPhishing

Thousands of Fake FIFA Domains Target World Cup Fans

Group-IB uncovered Ghost Stadium phishing and 4300 fake FIFA World Cup domains targeting fans

Infosecurity Magazine
MEDIUMVulnerability

Lastwall Raises $11.5 Million for Quantum-Resilient Identity Platform

The new funding, led by BDC Capital’s StrongNorth Fund, will accelerate Lastwall’s North American expansion. The post Lastwall Raises $11.5 Million for Quantum-Resilient Identity Platform appeared first on SecurityWeek .

SecurityWeek
MEDIUMAi

Highnote and Visa collaborate on agentic commerce

Highnote, the unified platform for modern issuing, acquiring, credit, ledger, and money movement, today announced the launch of its Agentic Commerce capabilities, built with Visa Intelligent Commerce, enabling businesses to securely power AI-initiated payments with programmable controls, tokenized credentials, and dynamic authorization.

Finextra
MEDIUMPhishing

The Credential Crisis: How Stolen Credentials Defeat Modern Security

As AI accelerates phishing, session hijacking, and credential abuse, security teams are racing to close the gap between attacker speed and defensive response. The post The Credential Crisis: How Stolen Credentials Defeat Modern Security appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Westpac fined $26 million for failing customers in financial hardship

Westpac Banking Corporation (Westpac) has been ordered to pay $26 million in civil penalties for failing to respond to customers who were facing financial hardship.

Finextra
MEDIUMSupply Chain

‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems

Malicious repositories and disguised symlinks can trick AI coding agents into silently installing attacker-controlled MCP servers capable of stealing secrets, compromising CI pipelines, and deploying malicious code. The post ‘SymJack’ Attack Turns AI Coding Agents Into Supply Chain Attack Delivery Systems appeared first on SecurityWeek .

SecurityWeek
MEDIUMMalware

GlassWorm Botnet Disrupted

Security firms took down all four command-and-control (C&#038;C) channels used by the GlassWorm malware. The post GlassWorm Botnet Disrupted appeared first on SecurityWeek .

SecurityWeek
LOWVulnerability

Gitea Vulnerability Exposes Private Container Images without Authentication

Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other credentials. The vulnerability, tracked as CVE-2026-27771 (CVSS score: N/A), affects all versions of Gitea prior to 1.26.2

CVE-2026-27771
The Hacker News
CRITICALVulnerability

CISA gives feds 4 days to patch actively exploited cPanel plugin flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has given U.S. federal agencies four days to secure their servers against a critical vulnerability in the LiteSpeed cPanel user-end plugin, which is actively being exploited in attacks. [...]

BleepingComputer
MEDIUMVulnerability

Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake

EvidenceForge generates high-quality, realistic, and consistent datasets across multiple log formats, enabling teams to effectively train personnel and validate detection models without the need for complex manual simulations.

Cisco Talos
MEDIUMVulnerability

PingPong partners with Visa to launch Card to Account Payments for global businesses

PingPong, the embedded financial infrastructure for global businesses, today announced the launch of Card to Account Payment Solution, a new Business Payment Solution Provider (BPSP) offering developed in partnership with Visa.

Finextra
MEDIUMVulnerability

The Oncology Institute Confirms Unauthorized Access to Systems Due to Vendor Breach

The Oncology Institute, a publicly traded provider of cancer care through more than 100 clinics in California, Oregon, Nevada, Arizona, [&#8230;] The post The Oncology Institute Confirms Unauthorized Access to Systems Due to Vendor Breach appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

The Oncology Institute Confirms Vendor Breach Involved Patient Data

The Oncology Institute, a publicly traded provider of cancer care through more than 100 clinics in California, Oregon, Nevada, Arizona, [&#8230;] The post The Oncology Institute Confirms Vendor Breach Involved Patient Data appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

ETS Connect authorised by FCA as consolidated provder for UK bond market

ETS Connect UK today announces that it has been authorised by the Financial Conduct Authority (FCA) as the Consolidated Tape Provider (CTP) for UK bond markets.

Finextra
MEDIUMAi

AppOmni delivers autonomous AI-powered SaaS security

AppOmni, the leader in SaaS security, today launched Marlin AI to fundamentally transform how enterprise organizations defend complex SaaS applications.

Finextra
MEDIUMVulnerability

Alipay+ enables mobile payments for global travellers in Latin America

Alipay+, a leading global payment gateway under Ant International that connects 150 million global merchants and 2 billion consumer accounts, is rolling out cross-border mobile payment services for global travellers in Latin America in collaboration with PVS, a fintech company specialized in developing customized payment solutions in the region.

Finextra
MEDIUMVulnerability

68% of UK Firms Plan to Increase Cyber Spending as AI Risks Rise

UK firms plan higher cyber spending as AI adoption raises security concerns

Infosecurity Magazine
MEDIUMVulnerability

Dutch police arrests suspect linked to Ajax football club hack

The Dutch National Police arrested a 35-year-old man suspected of hacking the professional football club Ajax Amsterdam (AFC Ajax) earlier this year. [...]

BleepingComputer
MEDIUMVulnerability

HSBC emerging technology chief Glasner departs

Ian Glasner, HSBC's group head of emerging technology and innovation is quittng the bank after five years to return to California.

Finextra
CRITICALAi

The NSA, ‘Mythos’ and the quiet emergence of AI cyber doctrine

For most of my career running security operations, the shape of cyber conflict has been defined by who could move faster than the other side. Faster at identifying a vulnerability, faster at patching, faster at detecting, faster at responding. The last few months have made me reevaluate that framing. Speed still matters. It just no longer carries the picture on its own. Scale and autonomy have mov

CVE-2026-4747
CSO Online
MEDIUMVulnerability

What to consider before asking an AI chatbot for health advice

Using chatbots for medical advice could elicit hallucinations and even expose you to security and privacy risks. Here’s what’s at stake and how to stay safe.

WeLiveSecurity (ESET)
MEDIUMVulnerability

Windows 11 KB5089573 update released with performance improvements

Microsoft has released the KB5089573 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 30 changes, including performance and reliability improvements. [...]

BleepingComputer
HIGHRansomware

FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data

The FBI has issued an alert warning of Silent Ransom Group attacks targeting law firms. The post FBI: Hackers Sending Operatives in Person to Insert USB Drives and Steal Data appeared first on SecurityWeek .

SecurityWeek
HIGHVulnerability

NVD HIGH: CVE-2026-40819 — An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the sync_data24 task due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

CVE-2026-40819
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-40818 — An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24confi_getDevice function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

CVE-2026-40818
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-40817 — An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getAlarmProfiles function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

CVE-2026-40817
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-40816 — An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the mb24alarm.php files _mb24confi_getTagAlarm function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

CVE-2026-40816
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-40815 — An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the _mb24api_getUserAccount function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

CVE-2026-40815
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-40814 — An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the dataapi.php files _mb24confi_getTagAlarm function due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

CVE-2026-40814
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-40813 — An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues functions tagid parameter due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

CVE-2026-40813
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-40812 — An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getLiveValues functions sn parameter due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

CVE-2026-40812
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-40811 — An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the ssoabstractservice due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

CVE-2026-40811
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-40810 — An unauthenticated remote attacker can exploit an unauthenticated SQL Injection ...

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the userinfo endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

CVE-2026-40810
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-3375 — The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scri...

The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the /wp-json/litespeed/v1/notify_ccss and /wp-json/litespeed/v1/notify_ucss REST API endpoints in all versions up to, and including, 7.7. These endpoints accept CSS content from QUIC.cloud callback notifications and store it to disk without sanitization. The stored content is later rendered inline frontend pa

CVE-2026-3375
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2025-41670 — A local user with low privileges may be able to influence the behavior of a priv...

A local user with low privileges may be able to influence the behavior of a privileged system service by manipulating configuration or application-related files located in user-writable areas of the filesystem. The affected service processes data from locations that are not sufficiently protected against modification by low-privileged users. As the service runs with elevated privileges, successful

CVE-2025-41670
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2025-41669 — The Web-based Management allows a remote low privileged Engineer user to install...

The Web-based Management allows a remote low privileged Engineer user to install additional APPs on the device downloaded from the PLCnext Store without implementing any data verification mechanism, leading to the capability for an Engineer user to reach arbitrary code execution with root privileges on the PLC device. A successful exploitation may allow to install a manipulated APP package, potent

CVE-2025-41669
NIST NVD
LOWVulnerability

PureLogs Variant Steals Data via Purchase Order Lures

FortiGuard Labs detailed a PureLogs campaign using JavaScript, PowerShell and process hollowing

Infosecurity Magazine
MEDIUMMalware

AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites

Microsoft has warned of an active cryptojacking campaign that makes use of artificial intelligence (AI) chatbot interactions as a mechanism for surfacing malicious download sites. "This emerging delivery technique extends social engineering beyond conventional search results and increases the visibility of malicious software recommendations," Microsoft Defender Experts and the Microsoft

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-9200 — The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion i...

The Query Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 0.2.1 via the shortcode function. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls

CVE-2026-9200
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8994 — The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass ...

The Login with NEAR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 0.3.3. The `ajaxLoginWithNear()` function — registered as a `wp_ajax_nopriv` action and therefore reachable by unauthenticated users — accepts an attacker-supplied `account` POST parameter and issues a valid WordPress authentication cookie based solely on a substring check for `.ne

CVE-2026-8994
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8787 — The Firebase Support & Chat Management plugin for WordPress is vulnerable to pri...

The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This is due to the `firebase_auth()` function authenticating the request as the WordPress user whose email is supplied in the `user_email` POST parameter without verifying ownership of that email (no Firebase ID token signature/issuer/audience verification)

CVE-2026-8787
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-8760 — The Login with OTP plugin for WordPress is vulnerable to authentication bypass i...

The Login with OTP plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.6. This is due to an incomplete fix for CVE-2024-11178: the rate-limit/lockout check added to `otpl_login_action()` was placed only inside the OTP-generation branch and is never evaluated on the OTP-validation branch, and the generated 6-digit OTP additionally has no expiration. T

CVE-2026-8760
NIST NVD
LOWVulnerability

Zscaler Struggles to Win New Customers Despite AI Fears

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/zscaler-struggles-to-win-new-customers-despite-ai-fears-image_small-2-a-31788.jpg" align=right hspace=4><b>Zscaler CEO Jay Chaudhry Says New AI Frontier Models Have Yet to Boost Revenue</b><br>Zscaler reported strong renewal growth and rising demand for zero trust security amid AI-driven threats, but slowing new customer acquisiti

Bank Info Security
LOWVulnerability

GitHub Tells Self-Hosted Admins to Rotate Keys

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/github-tells-self-hosted-admins-to-rotate-keys-image_small-1-a-31787.jpg" align=right hspace=4><b>Company Pushes Key Rotation After 3,800 Repositories Compromised</b><br>Hacked code repository GitHub warned administrators of self-hosted git servers to rotate public encryption keys following a May 18 incident involving a poisoned V

Bank Info Security
MEDIUMSupply Chain

Socket Raises $60M for Wider Software Supply-Chain Defense

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/socket-raises-60m-for-wider-software-supply-chain-defense-image_small-10-a-31785.jpg" align=right hspace=4><b>Funding at $1B Valuation Will Expand Controls Across Developer and AI Ecosystems</b><br>Socket raised $60 million in a Thrive Capital-led Series C at a $1 billion valuation to expand its supply-chain security platform beyo

Bank Info Security
MEDIUMVulnerability

OMB Scraps Biden-Era Cyber Logging Rules

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/omb-scraps-biden-era-cyber-logging-rules-image_small-2-a-31784.jpg" align=right hspace=4><b>New Memo Replaces SolarWinds-Era Rules With Risk-Based Model</b><br>The White House issued a new memo replacing SolarWinds-era logging mandates with a narrower framework focused on risk, threat hunting and forensic readiness as agencies con

Bank Info Security
CRITICALData Breach

DSPM buyer’s guide: Top 10 data security posture management tools

Data security posture management (DSPM) explained Data security posture management (DSPM) tools help security teams examine their entire data environment to find shadow data, reducing the risk of data loss. Tracking down sensitive data across both cloud and on-premises systems can be vexing. Each environment presents its own challenges. Given the dynamic and ephemeral nature of cloud computing, cl

CSO Online
CRITICALZero Day

CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day

Resolved last week, the vulnerability was exploited in the wild as a zero-day to execute scripts with root privileges. The post CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day appeared first on SecurityWeek .

SecurityWeek
MEDIUMAi

Anthropic Releases New Claude Sandbox, Security Guidance Plugin

The AI giant says the new plugin, which helps developers find vulnerabilities as they write code, has been used extensively internally. The post Anthropic Releases New Claude Sandbox, Security Guidance Plugin appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Continuous Offensive Security: The Line We've Been Walking

Snyk's Continuous Offensive Security unifies DAST, AI pentesting, and agent red teaming to find exploitable flaws — not just bugs — before attackers do. Here's why lineage matters.

Snyk
HIGHVulnerability

NVD HIGH: CVE-2026-9632 — A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by...

A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the component Web Management Interface. Executing a manipulation of the argument Profile can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been published and may be used.

CVE-2026-9632
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9631 — A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affe...

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectionW of the component Web Management Interface. Performing a manipulation of the argument Profile results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used.

CVE-2026-9631
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9627 — A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This...

A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management Interface. The manipulation of the argument sysAdmUser/sysAdmPass results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

CVE-2026-9627
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9156 — Tanium addressed a denial of service vulnerability in Tanium Server.

Tanium addressed a denial of service vulnerability in Tanium Server.

CVE-2026-9156
NIST NVD
CRITICALRansomware

Microsoft previews automatic device isolation in Defender for Endpoint

Microsoft is previewing a new automatic device isolation capability in Defender for Endpoint’s auto attack disruption tool to help security pros contain cyber attacks in progress on their IT networks. The company announced the capability earlier this month in a column about new features in Defender. There’s no word on when automatic device isolation will be in full production. However, a new SANS

CSO Online
HIGHVulnerability

NVD HIGH: CVE-2026-9606 — A vulnerability has been found in itsourcecode Courier Management System 1.0. Im...

A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVE-2026-9606
NIST NVD
MEDIUMVulnerability

Indian travel-fintech Scapia raises $63m

Scapia, an Indian outfit that combines co-branded credit cards with travel booking, has raised $63 million in a funding round led by General Catalyst.

Finextra
MEDIUMVulnerability

CommBank tests AI companion in banking app

CommBank is testing a new conversational AI interface within its banking app, designed to slice and dice spending and savings data to help customers to better manage their money

Finextra
MEDIUMVulnerability

As rivals pull down the shutters, Nationwide to become UK&#39;s biggest branch network

With its rivals closing branches, Nationwide Building Society says its pledge to keep the doors open at all of its site means that it will have the UK's biggest network by June.

Finextra
HIGHVulnerability

CISA KEV: Nx Nx Console — Nx Console Embedded Malicious Code Vulnerability

Nx Console contains an embedded malicious code vulnerability that allowed a malicious version of Nx Console to be published. The compromised extension fetched an obfuscated payload that could harvested credentials from multiple sources on disk and in memory.

CVE-2026-48027Nx Nx Console
CISA KEV
HIGHVulnerability

CISA KEV: TanStack TanStack — TanStack Unspecified Vulnerability

TanStack contains an unspecified vulnerability that allowed malicious versions of the product to be published to the npm registry to publish credential-stealing malware under a trusted identity.

CVE-2026-45321TanStack TanStack
CISA KEV
HIGHVulnerability

CISA KEV: Daemon Daemon Tools Lite — Daemon Tools Lite Embedded Malicious Code Vulnerability

Daemon Tools contains an unspecified vulnerability that has a high impact on confidentiality, integrity, and availability.

CVE-2026-8398Daemon Daemon Tools Lite
CISA KEV
HIGHVulnerability

NVD HIGH: CVE-2026-9584 — A security vulnerability has been detected in code-projects Project Management S...

A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The manipulation leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

CVE-2026-9584
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-45298 — Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a def...

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is reachable without authentication and forwards an attacker-controlled URL into a WebhookDispatcher that sends an HTTP POST to the supplied URL with attacker-controlled request headers, and returns the res

CVE-2026-45298
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-44985 — Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSo...

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepting upgrade requests from any origin. Combined with the JWT cookie using SameSite: Lax, this enables Cross-Site WebSocket Hijacking (CSWSH). An attacker hosting a page on a same-site origin (e.g., a sib

CVE-2026-44985
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9580 — A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is...

A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation causes improper access controls. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.9.2 is sufficient to fix this issue. It is suggested to upgrade

CVE-2026-9580
NIST NVD
MEDIUMVulnerability

US Takeover of Dutch Cloud ID Provider Blocked by Government

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/us-takeover-dutch-cloud-id-provider-blocked-by-government-image_small-2-a-31780.jpg" align=right hspace=4><b>New York-Based Kyndryl Can't Buy Amsterdam-Based Solvinity Group</b><br>The growing push for European technological sovereignty from the United States claimed a significant scalp in the Netherlands, where authorities blocke

Bank Info Security
MEDIUMAi

Anthropic Expands Public Access to Claude Mythos AI Model

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/anthropic-expands-public-access-to-claude-mythos-ai-model-image_small-1-a-31778.jpg" align=right hspace=4><b>Expect to See Widespread Availability of Mythos-Level Models Within 6-12 Months</b><br>Anthropic is expanding public access to its frontier artificial intelligence model Claude Mythos "to qualifying customers' security team

Bank Info Security
MEDIUMAi

Why AI Agents Are Creating a New Security Blind Spot

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ai-agents-are-creating-new-security-blind-spot-image_small-6-a-31776.jpg" align=right hspace=4><b>Okta's Charlotte Wylie on Identity, Governance and Rogue AI Access</b><br>AI agents are becoming a new identity type inside enterprises, creating visibility gaps and security risks most organizations aren't prepared to manage. Okta's

Bank Info Security
MEDIUMAi

Microsoft Code Editor Flaw Lets Attackers Hijack Developer PCs

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/microsoft-code-editor-flaw-let-attackers-hijack-developer-pcs-image_small-6-a-31775.jpg" align=right hspace=4><b>Hidden Install Settings Let Malicious MCP Links Execute Code</b><br>Microsoft patched a high-severity flaw in Visual Studio Code after researchers found attackers could hide malicious settings inside MCP server install

Bank Info Security
HIGHVulnerability

NVD HIGH: CVE-2026-9575 — A vulnerability has been found in itsourcecode Student Transcript Processing Sys...

A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.php?view=view. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2026-9575
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9574 — A flaw has been found in itsourcecode Student Transcript Processing System 1.0. ...

A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Executing a manipulation of the argument studentId/cid can lead to sql injection. The attack can be launched remotely. The exploit has been published and may be used.

CVE-2026-9574
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-44833 — Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redir...

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header stored in session variable. This vulnerability is fixed in 8.4.1.

CVE-2026-44833
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-44832 — Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authentic...

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api/v1/users/{id} with permissions[admin]=1. The API controller only strips the superuser key from the permissions array, allowing admin and all other permission keys to be set by any user who can update

CVE-2026-44832
NIST NVD
CRITICALZero Day

KnowledgeDeliver flaw exploited as a zero-day to install web shells

Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell. [...]

BleepingComputer
MEDIUMMalware

Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos

In just six hours, the campaign quietly pushed thousands of malicious commits to more than 5,500 GitHub repositories, stealing credentials, developer secrets, and more.

Dark Reading
HIGHData Breach

Charter confirms data breach after ShinyHunters extortion threat

U.S. telecommunications giant Charter Communications has confirmed it suffered a data breach after the ShinyHunters extortion group threatened to leak stolen data unless a ransom is paid. [...]

BleepingComputer
MEDIUMVulnerability

Apple open-sources quantum-resistant encryption code

The release includes implementations of two quantum-secure algorithms and demonstrates how formal verification caught bugs that traditional testing would have missed. The post Apple open-sources quantum-resistant encryption code appeared first on CyberScoop .

CyberScoop
CRITICALVulnerability

State Cyber Leaders Beg Congress for More Funding, Support

A recent congressional hearing highlighted how states are reeling from federal cutbacks to important cyber grants and information sharing initiatives amid damaging attacks to critical infrastructure.

Dark Reading
CRITICALVulnerability

State Cyber Leaders Push Congress for More Funding, Support

A recent congressional hearing highlighted how states are reeling from federal cutbacks to important cybergrants and information-sharing initiatives amid damaging attacks to critical infrastructure.

Dark Reading
MEDIUMVulnerability

The Hackers Behind Shai-Hulud: Lucky or Skilled?

TeamPCP, the hackers behind the Shai-Hulud worm, has done significant damage to the open source ecosystem. But it's not necessarily due to skill alone.

Dark Reading
MEDIUMVulnerability

Shai-Hulud Hackers TeamPCP: Lucky or Skilled?

TeamPCP, the cybercrime group behind later waves of the Shai-Hulud worm, has done significant damage to the open source ecosystem. But it's not necessarily due to skill alone.

Dark Reading
CRITICALVulnerability

NVD CRITICAL: CVE-2026-48689 — FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buf...

FastNetMon Community Edition through 1.2.9 contains an off-by-one heap-based buffer overflow in the dynamic_binary_buffer_t class (src/dynamic_binary_buffer.hpp). Five methods (append_dynamic_buffer, append_data_as_pointer, append_data_as_object_ptr, memcpy_from_ptr, memcpy_from_object_ptr) use an incorrect bounds check of the form 'if (offset + length > maximum_internal_storage_size + 1)' instead

CVE-2026-48689
NIST NVD
LOWAi

For Enterprises, Security Remains Agentic AI's Biggest Challenge

Every company needs an agentic AI strategy, but the tools to allow agentic AI frameworks be safely and securely adopted are just starting to appear.

Dark Reading
MEDIUMVulnerability

White House charts new course for federal agencies and cybersecurity logging

A Trump administration memo published last week replaces one from its predecessor, with at least one analyst fearful of potential harmful results. The post White House charts new course for federal agencies and cybersecurity logging appeared first on CyberScoop .

CyberScoop
MEDIUMAi

BNP Paribas partners Mistral to strengthen AI defences

BNP Paribas is working with French startup Mistral AI as it seeks to strengthen its cyber defences against weaknesses exposed by new models such as Anthropic's Mythos.

Finextra
MEDIUMVulnerability

Microsoft Issues Out-of-Band SharePoint Patch

SharePoint access often means access to the keys of the kingdom, something attackers and defenders understand all too well.

Dark Reading
HIGHVulnerability

NVD HIGH: CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8...

Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel

CVE-2026-9560
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-8856 — IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configuration...

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service in configurations where an attacker has write access to parts of the server configuration.

CVE-2026-8856
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-8855 — IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial o...

IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code execution and denial of service in configurations with TLS mutual authentication (client authentication).

CVE-2026-8855
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8854 — IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional...

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache.

CVE-2026-8854
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8835 — IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A pri...

IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to expose sensitive information or cause a denial of service.

CVE-2026-8835
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8834 — IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privile...

IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administration Server, could exploit this vulnerability to execute remote code or cause a denial of service.

CVE-2026-8834
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-8633 — IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8...

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code execution in the Web Server Plug-ins, through a specially crafted request.

CVE-2026-8633
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8620 — IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8...

IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggling in the Web Server Plug-ins through a specially crafted request.

CVE-2026-8620
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-7454 — A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force ...

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

CVE-2026-7454
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-7452 — A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force ...

A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

CVE-2026-7452
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-7451 — A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force ...

A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

CVE-2026-7451
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48695 — FastNetMon Community Edition through 1.2.9 contains an OS command injection vuln...

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integration plugin. The _log() function in src/mikrotik_plugin/fastnetmon_mikrotik.php (lines 107-108) constructs shell commands by concatenating the $msg parameter directly into exec() calls: exec("echo `date` \"- {FASTNETMON] - " . $msg . " \" >> " . $FILE_LOG_TMP). This is identical

CVE-2026-48695
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48694 — FastNetMon Community Edition through 1.2.9 contains a configuration injection vu...

FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In src/juniper_plugin/fastnetmon_juniper.php, the $IP_ATTACK variable (received from argv[1]) is directly interpolated into Juniper NETCONF set-configuration commands at lines 69 and 90 without any validation or sanitization. Line 69: $conn->load_set_configuration("

CVE-2026-48694
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-44728 — Babel is a compiler for writing next generation JavaScript. From 7.12.0 to befor...

Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel to generate output code that executes arbitrary code. This vulnerability is fixed in 7.29.4 and 8.0.0-alpha.13.

CVE-2026-44728
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8852 — IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional...

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.

CVE-2026-8852
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8850 — IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional...

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.

CVE-2026-8850
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-48904 — An improper access check allows privelege escalation through the com_users group...

An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

CVE-2026-48904
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-48899 — An improper access check allows privilege escalation through the com_users batch...

An improper access check allows privilege escalation through the com_users batch task.

CVE-2026-48899
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-48898 — An improper access check allows privilege escalation through the com_users batch...

An improper access check allows privilege escalation through the com_users batch task.

CVE-2026-48898
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48897 — Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

CVE-2026-48897
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48896 — Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

CVE-2026-48896
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48697 — FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on o...

FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_web_request_secure() function in src/fast_library.cpp creates a boost::asio::ssl::context with tls_client mode and calls set_default_verify_paths() to load CA certificates, but never calls set_verify_mode(boost::asio::ssl::verify_peer). Without this call, OpenSSL performs the TLS

CVE-2026-48697
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-48691 — FastNetMon Community Edition through 1.2.9 contains an integer overflow in the B...

FastNetMon Community Edition through 1.2.9 contains an integer overflow in the BGP AS_PATH attribute encoder. In src/bgp_protocol.hpp, the IPv4UnicastAnnounce::get_attributes() function computes attribute_length as 'sizeof(bgp_as_path_segment_element_t) + this->as_path_asns.size() * sizeof(uint32_t)' and stores it in a uint8_t field (line 600-605). Since uint8_t can only hold values 0-255, an AS_P

CVE-2026-48691
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48690 — FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerab...

FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer allocation. In src/packet_storage.hpp, the allocate_buffer() function computes memory_size_in_bytes as 'buffer_size_in_packets * (max_captured_packet_size + sizeof(fastnetmon_pcap_pkthdr_t)) + sizeof(fastnetmon_pcap_file_header_t)' using unsigned int (32-bit) arithmetic. With max_capt

CVE-2026-48690
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-44723 — Vowpal Wabbit is a machine learning system. The workflow .github/workflows/pytho...

Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate steps across four jobs, each passing it as a CLI argument to the Python test script run_tests_model_gen_and_load.py. The shell interprets the expanded string before invoking Python, allowing an attacke

CVE-2026-44723
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-40384 — An improper validation of the search parameter of the com_media files API endpoi...

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

CVE-2026-40384
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-40383 — An improper validation of user-supplied input leads to a local file inclusion vu...

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

CVE-2026-40383
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-35223 — An improper access check allows unauthorized access to com_config webservice end...

An improper access check allows unauthorized access to com_config webservice endpoints.

CVE-2026-35223
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-35222 — Improperly validated order clauses lead to a SQL injection vulnerability in com_...

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

CVE-2026-35222
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-35221 — Improperly built filter clauses lead to a SQL injection vulnerability in the sea...

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

CVE-2026-35221
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-24212 — NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive infor...

NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

CVE-2026-24212
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2025-36221 — IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cl...

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the installation process, which could allow an attacker to bypass authentication.

CVE-2025-36221
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2025-36220 — IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cl...

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

CVE-2025-36220
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2025-36126 — IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 1...

IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

CVE-2025-36126
NIST NVD
MEDIUMVulnerability

Your Outdated Repository Still Works, But It May Not Be Safe

<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/your-outdated-repository-still-works-but-it-may-not-be-safe" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/blog_legacy_repo.png" alt="Image with hexagon shape at center containing an exclamation point, signifying a technology notification. Icons surrounding the hexagon comprise a soft

Sonatype (Maven/npm)
MEDIUMPhishing

FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts &#8211; no password required

So, you've enabled multi-factor authentication. You've taught your staff never to type their passwords into dodgy-looking login pages. Surely your Microsoft 365 accounts are safe now? Well, think again. Read more in my article on the Hot for Security blog.

Graham Cluley
HIGHVulnerability

NVD HIGH: CVE-2026-48692 — FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 500...

FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The server is initialized with grpc::InsecureServerCredentials() (src/fastnetmon.cpp line 477) and a source code comment explicitly acknowledges 'Listen on the given address without any authentication mechanism.' None of the RPC methods in src/api.cpp (ExecuteBan, ExecuteUnBan, GetB

CVE-2026-48692
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48688 — FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads...

FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute decoder. The function decode_mp_reach_ipv6() in src/bgp_protocol.cpp contains a TODO comment at line 156 explicitly acknowledging 'we should add sanity checks to avoid reads after attribute memory block.' The function casts raw pointers to structure types without verifying suffi

CVE-2026-48688
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-48687 — FastNetMon Community Edition through 1.2.9 contains an OS command injection vuln...

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (lines 117-118) constructs shell commands by concatenating the $msg parameter directly into exec() calls: exec("echo `date` \"- {FASTNETMON] - " . $msg . " \" >> " . $FILE_LOG_TMP). The $msg variable con

CVE-2026-48687
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-48686 — FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflo...

FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_encoding_ipv4_raw() in src/bgp_protocol.cpp reads prefix_bit_length directly from the BGP packet (line 99) without validating it is <= 32 for IPv4 prefixes. This value is passed to how_much_bytes_we_need_for_storing_certa

CVE-2026-48686
NIST NVD
MEDIUMVulnerability

Garanti BBVA launches Request to Pay API

Garanti BBVA has gone live with its BKM-integrated Request to Pay API, enabling businesses to manage collections directly from their own systems while offering customers a fast, easy, and seamless bill-payment experience. The solution was piloted in partnership with energy company Uludağ Elektrik.

Finextra
MEDIUMApt

MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries

The Iranian hacking group known as MuddyWater has been linked to a new campaign affecting at least nine organizations across nine countries on four continents in the first quarter of 2026. The activity targeted industrial and electronics manufacturing, education and public-sector bodies, financial services, and professional services, per the Threat Hunter Team from Symantec and Carbon Black.

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-9552 — A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2...

A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The manipulation of the argument Value results in sql injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure b

CVE-2026-9552
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9551 — A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. T...

A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRecords of the component API Endpoint. The manipulation of the argument Value leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this

CVE-2026-9551
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9550 — A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operati...

A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionality of the file /SubstationWEBV2/app/..;/main/upfile. Executing a manipulation of the argument path can lead to path traversal. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

CVE-2026-9550
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-4480 — A flaw was found in the Samba printing subsystem. Samba passes the client-contro...

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could

CVE-2026-4480
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-46368 — luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on f...

luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the luci.https-dns-proxy ACL permission can inject shell metacharacters through the 'name' parame

CVE-2026-46368
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-45247 — Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a ...

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its de

CVE-2026-45247
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-42785 — OpenKM 6.3.12 contains a remote code execution vulnerability that allows authent...

OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can submit malicious script content with an action=Evaluate parameter to execute operating system commands in the context of the OpenKM application server.

CVE-2026-42785
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-42425 — OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows a...

OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements against the application database via the DatabaseQuery interface. Attackers can submit malicious SQL queries through the qs parameter to the /admin/DatabaseQuery endpoint to extract sensitive data including usernames and password hashes from the OKM_

CVE-2026-42425
NIST NVD
MEDIUMAi

Anthropic: Mythos finds more than 10,000 software flaws in first month

Early results show a tenfold jump in bug discovery at some partners, and a widening gap between finding flaws and fixing them. The post Anthropic: Mythos finds more than 10,000 software flaws in first month appeared first on CyberScoop .

CyberScoop
MEDIUMVulnerability

Identifying People Using Wi-Fi Routers

Not identifying people based on their use of Wi-Fi routers, but identifying people using Wi-Fi signals . This is accomplished through what is known as WiFi sensing , or the use of WiFi signals to infer information about a physical environment. When radio signals like WiFi travel through a space, they interact with the objects and people around them. Those signals can be reflected, scattered, or ab

Schneier on Security
MEDIUMPhishing

Chinese Threat Actors Ditch Static Phishing Pages for Live Credential Interception

Almost all organizations impersonated by Chinese phishing platforms are non-Chinese entities, suggesting operators deliberately avoid domestic targets

Infosecurity Magazine
HIGHVulnerability

NVD HIGH: CVE-2026-9544 — A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Busine...

A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functionality of the file /api/Dinner/PayConfig. Performing a manipulation of the argument tableno results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contact

CVE-2026-9544
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-7374 — A flaw was found in KubeVirt's virt-handler component. This vulnerability allows...

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket with a symlink to the host's container runtime (CRI-O) socket, an attacker can hijack virt-handler's privileged connecti

CVE-2026-7374
NIST NVD
MEDIUMVulnerability

Lithuania investigates theft of 600,000 state registry records by foreign actor

The Lithuanian Prosecutor General’s Office said Friday that attackers gained unauthorized access to more than 600,000 records managed by the Centre of Registers, the state agency responsible for handling property and legal entity records.

The Record
HIGHData Breach

OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2024

The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has submitted its annual reports to Congress [&#8230;] The post OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2024 appeared first on The HIPAA Journal .

HIPAA Journal
LOWMalware

GitHub Actions abused by Megalodon attack to slip malicious commits into 5,500 repos

A large-scale automated GitHub backdooring campaign was caught pushing thousands of malicious commits into public repositories while posing as routine CI/CD upkeep. Researchers at SafeDep observed the campaign, Megalodon, touching more than five thousand repositories over a six-hour window on May 18. The attack was in the form of a malicious commit, “acac5a9,” targeting GitHub Actions workflows. U

CSO Online
MEDIUMAi

How Varonis Atlas integrates Claude Compliance API for AI governance

AI governance requires visibility into how AI tools interact with enterprise data. Varonis explains how its Atlas platform uses Claude Compliance API data to help monitor usage, investigate risk, and support compliance. [...]

BleepingComputer
MEDIUMPhishing

BTMOB Android RAT Spreads Through No-Code Builder Tooling

BTMOB Android RAT sold as a service with a no-code builder for fast, regional phishing lures

Infosecurity Magazine
MEDIUMVulnerability

AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security

Marlin AI automatically analyzes SaaS misconfigurations, investigates related activity across enterprise environments, and recommends remediation steps — while stopping short of fully autonomous corrective action. The post AppOmni’s Marlin AI Brings Autonomous Investigation to SaaS Security appeared first on SecurityWeek .

SecurityWeek
MEDIUMAi

Circle co-founder raises $30m for agentic finance startup Catena

Agentic finance startup Catena Labs has raised $30 million in Series A financing and applied for a national trust bank charter.

Finextra
MEDIUMApt

Iranian APT Targets Aviation, Software Companies With Updated Tools

Nimbus Manticore has continued its operations during and after the US military campaign against Iran. The post Iranian APT Targets Aviation, Software Companies With Updated Tools appeared first on SecurityWeek .

SecurityWeek
LOWVulnerability

How Security Leaders Cut Through Complexity to Drive Better Outcomes

Security leaders are operating in an environment that is only getting more complex. Expanding attack surfaces, rapid AI adoption, growing toolsets, and increasing pressure to respond faster have made it harder to maintain a clear view of risk and priorities. At the Rapid7 Global Cybersecurity Summit, the customer panel How Clarity Beats Complexity explores how leaders are navigating that reality i

Rapid7
MEDIUMVulnerability

Tether to build national stablecoin for Georgian Government

Tether has been commissioned by the Government of Georgia to develop GEL₮, a stablecoin representing the Georgian Lari.

Finextra
MEDIUMVulnerability

Microsoft Defender can now automatically isolate hacked endpoints

Microsoft is testing a new Defender for Endpoint capability that will automatically isolate compromised endpoints to thwart attackers' attempts to move laterally across the network. [...]

BleepingComputer
MEDIUMVulnerability

Enfuce names M&#229;rten Mickos as chairman

Enfuce, Europe’s card issuing and processing powerhouse, today announces the appointment of M&#229;rten Mickos as Board Chairman of Enfuce Financial Services.

Finextra
CRITICALVulnerability

ABB AbilityTM Zenon Remote Transport Vulnerability

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-146-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. The vulnerability enables unauthorized access to the Reboot OS function within the Remote Transport Service, allowing an attacker to trigger a

CVE-2025-8754
CISA Advisories
CRITICALVulnerability

ABB AC500 V2

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-146-02.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>ABB became aware of vulnerabilities in AC500 V2 listed as affected in the advisory. An attacker who successfully exploited this vulnerability could access fragments of Modbus telegrams that have been sent earlier by that PLC</strong><

CVE-2025-7745
CISA Advisories
CRITICALVulnerability

ABB Terra AC

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-146-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. An attacker who successfully exploited this vulnerability could cause the pollution of heap memory which potentially takes remote control of t

CVE-2025-5517
CISA Advisories
CRITICALVulnerability

ABB LVS MConfig

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-146-06.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>ABB became aware of an internally discovered vulnerability in the MConfig product versions listed as affected in the advisory. An attacker with access to local networks who successfully exploits vulnerability could have access to appl

CVE-2025-9970
CISA Advisories
CRITICALPhishing

Eppendorf BioFlo 320

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsma-26-146-01.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>Successful exploitation of this vulnerability could allow an attacker to gain full access to functionality and data with the bioreactor.</strong></p> <p>The following versions of Eppendorf BioFlo 320 are affected:</p> <ul> <li>BioFlo

CVE-2026-7251
CISA Advisories
MEDIUMVulnerability

Remembering Tim Wilson, Whose Legacy Lives on at Dark Reading

The co-founder and former editor-in-chief passed away five years ago in November. As Dark Reading enters is third decade, we pause to celebrate and honor Wilson's instrumental role in building and elevating the media site.

Dark Reading
CRITICALSupply Chain

ABB Ability Camera Connect

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-146-05.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>ABB is aware of public reports of vulnerabilities in a 3rd party component VLC media player Version 2.2.4 which was delivered together with the installation package of Camera Connect Version 1.5.0.14 and below. An update is available

CVE-2024-46461CVE-2023-47360
CISA Advisories
CRITICALVulnerability

ABB B&amp;R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-146-04.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>An update is available that resolves a vulnerability identified by B&amp;Rs internal security analysis in the product versions listed as affected in this advisory. An attacker who successfully exploited this vulnerability could cause

CVE-2025-3450
CISA Advisories
CRITICALVulnerability

ABB Ability Zenon Remote Transport Vulnerability (Update A)

<p><a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-146-03.json"><strong>View CSAF</strong></a></p> <h2>Summary</h2> <p><strong>ABB is aware of vulnerabilities in the product versions listed as affected in the advisory. The vulnerability enables unauthorized access to the Reboot OS function within the Remote Transport Service, allowing an attacker to trigger a

CVE-2025-8754
CISA Advisories
HIGHData Breach

185,000 Likely Impacted by 7-Eleven Data Breach

The allegedly stolen information leaked by ShinyHunters contains email addresses, names, addresses, and dates of birth. The post 185,000 Likely Impacted by 7-Eleven Data Breach appeared first on SecurityWeek .

SecurityWeek
LOWVulnerability

Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions

Microsoft has rolled out updates to fix a remote code execution vulnerability impacting SharePoint that could be exploited by bad actors in attacks without requiring any specialized conditions to be met. The vulnerability, tracked as CVE-2026-45659, carries a CVSS score of 8.8. It has been assigned an important severity. "Deserialization of untrusted data in Microsoft Office SharePoint allows

CVE-2026-45659
The Hacker News
MEDIUMAi

Anthropic Expands Claude&#8217;s Enterprise Security Governance With 28 New Integrations

Notable integrations include CrowdStrike, Palo Alto Networks, Microsoft, Okta, Zscaler, Netskope, Cloudflare, Fortinet, and Wiz. The post Anthropic Expands Claude&#8217;s Enterprise Security Governance With 28 New Integrations appeared first on SecurityWeek .

SecurityWeek
LOWSupply Chain

TrapDoor malware campaign puts developer workstations in CISO spotlight

A malicious package campaign across npm, PyPI, and Crates.io has put developer workstations back under scrutiny, after researchers said it targeted developer workflows and AI coding assistant files. Researchers at Socket said the campaign, which they are tracking as TrapDoor, “spans more than 34 malicious packages and 384+ related versions and artifacts” across the three open-source ecosystems. Th

CSO Online
CRITICALZero Day

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment

Hardcoded machineKey values in a configuration file enabled ViewState deserialization attacks leading to remote code execution. The post Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment appeared first on SecurityWeek .

SecurityWeek
MEDIUMMalware

Watch on Demand: Threat Detection &#038; Incident Response Summit &#8211; All Sessions Available

Register to enjoy free access and explore the tools, strategies, and frameworks needed to build a resilient security program for a world where every minute counts. The post Watch on Demand: Threat Detection & Incident Response Summit &#8211; All Sessions Available appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images

DockSec, an OWASP incubator project, correlates findings from multiple container security scanners and uses AI to generate plain-English remediation guidance and exact Dockerfile fixes. The post Open Source DockSec Uses AI to Cut Through Vulnerability Noise in Docker Images appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

India's CERT-In Sets 12-Hour Patch Deadline for Exposed Flaws

CERT-In urges 12-hour patching of exposed flaws as AI compresses exploitation timelines

Infosecurity Magazine
CRITICALVulnerability

MFA Prompt Bombing: Why Your Second Factor Isn't Saving You

Multi-factor authentication (MFA) was supposed to close a critical gap in identity security. It meant that, even if an attacker possessed the account credentials, they couldn't log in without the second factor. While that logic was sound, attackers have now figured out that they don't need to steal the second factor: they just need the user to hand it over. If your workforce authenticates with

The Hacker News
HIGHData Breach

Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register Entries

Lithuanian authorities are on high alert after a massive data leak involving more than 600,000 entries from national data registers. The post Lithuania Suspects Foreign Involvement in Data Leak of Over 600,000 National Register Entries appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands

The two own Dutch companies that allegedly provided bulletproof hosting services to Russia-aligned threat actors. The post Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands appeared first on SecurityWeek .

SecurityWeek
HIGHData Breach

Mission Community Hospital Pays $1.55M to Settle Data Breach Lawsuit

Deanco Healthcare, LLC, the operator of Mission Community Hospital, an acute care hospital serving patients in the San Fernando Valley [&#8230;] The post Mission Community Hospital Pays $1.55M to Settle Data Breach Lawsuit appeared first on The HIPAA Journal .

HIPAA Journal
LOWVulnerability

7-Zip CVE-2026-48095: NTFS Heap Overflow Can Trigger Through Renamed Files

[object Object]

CVE-2026-48095
r/cybersecurity
MEDIUMVulnerability

UK Government commissions review into bank branch closures

The UK Government has commissioned an independent review to examine the impact of bank branch closures and consider whether further intervention is needed to protect access to services.

Finextra
CRITICALAi

CERT-In Mandates 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks

The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged where "feasible" to safeguard against potential threats stemming from threat actors' abuse of artificial intelligence (AI) tools and large language models (LLMs) to automate vulnerability

The Hacker News
CRITICALAi

CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks

The Indian Computer Emergency Response Team (CERT-In) has issued new guidelines requiring organizations to patch critical security vulnerabilities in internet-exposed systems within 12 hours of being flagged where "feasible" to safeguard against potential threats stemming from threat actors' abuse of artificial intelligence (AI) tools and large language models (LLMs) to automate vulnerability

The Hacker News
MEDIUMAi

Alipay delivers full-stack Ai payments infrastructure

Alipay today introduced its full-stack AI payment solution to partners across industries, ranging from AI companies to traditional retailers, and debuted two new services — the world’s first AI Wallet and Token Pay — to support the agentic economy’s rapid growth.

Finextra
MEDIUMPhishing

Iran-Linked Hackers Target US Aviation with Phishing and SEO Poisoning Campaign

Iran's Nimbus Manticore pushes AI-built MiniFast backdoor via phishing and SEO poisoning

Infosecurity Magazine
MEDIUMVulnerability

Finova strengthens Manchester hub with senior appointments

Finova, the UK's largest provider of cloud-based mortgage, savings and lending software, has appointed three directors who will be based in its new Manchester hub, with recruitment for the site now 80% complete.

Finextra
CRITICALRansomware

Stop treating AI governance as a review layer. Make it release infrastructure

I’ve spent years building compliance into security products. FedRAMP and Department of War Impact Level authorizations, vulnerability management pipelines: They all follow the same pattern. Build the product, then prove it meets requirements. The compliance layer sits outside the engineering workflow. It reviews what already exists. That model worked when the product stayed static between audits.

CSO Online
LOWMalware

BTMOB: A stealthy RAT burrowing deep into Android devices

The malware pairs remote access capabilities with ready-made campaign tools, lowering the barrier for full device compromise

WeLiveSecurity (ESET)
CRITICALVulnerability

CISA orders feds to patch actively exploited Drupal vulnerability

CISA has given U.S. government agencies until Wednesday evening to secure their servers against an SQL injection vulnerability in the Drupal content management system (CMS) that it flagged as actively exploited. [...]

BleepingComputer
HIGHVulnerability

NVD HIGH: CVE-2026-8047 — The affected products perform improper length checking when parsing incoming HTT...

The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this flaw to cause a denial of service via a system crash on the affected device.

CVE-2026-8047
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8046 — The affected products insufficiently verify authorization when deleting user acc...

The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those with higher privileges.

CVE-2026-8046
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-44469 — The affected product extracts installation files to a temporary directory with i...

The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting in local privilege escalation.

CVE-2026-44469
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-44468 — The affected product creates a directory with insecure default permissions durin...

The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.

CVE-2026-44468
NIST NVD
MEDIUMVulnerability

Microsoft: Domain Controller lookup may fail on Windows Server 2016

Microsoft has confirmed a new known issue affecting Windows Server 2016 systems that causes domain controller lookups to fail after installing the KB5087537 May 2026 security update. [...]

BleepingComputer
LOWApt

Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning

The Iranian state-sponsored threat actor known as Nimbus Manticore (aka Screening Serpens and UNC1549) has been attributed to a fresh campaign using lures impersonating organizations in the aviation and software sectors across the U.S., Europe, and the Middle East following the joint U.S.-Israeli military campaign against the country in late February 2026. The activity, besides embracing

The Hacker News
HIGHData Breach

7-Eleven data breach exposes personal information of 185,000 people

The ShinyHunters extortion gang stole the personal information of over 183,000 people after hacking the systems of convenience store chain giant 7-Eleven in April, according to data breach notification service Have I Been Pwned. [...]

BleepingComputer
CRITICALRansomware

Vulnerabilities have become cyber attackers’ No. 1 door to the enterprise

Patching practices are coming under intense pressure of late, as time-to-exploit windows accelerate — a new reality likely to worsen as AI assistance in attack chains rises. Now cyber defenders have another cause for flaw alarm: Vulnerability exploitation has significantly pulled away from stolen credentials as the most common entry point in security breaches, according to the latest edition of Ve

CSO Online
CRITICALZero Day

KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon. The vulnerability, tracked as CVE-2026-5426 (CVSS score: 7.5), stems from the use of hard-coded ASP.NET machine keys, leading to

CVE-2026-5426
The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-9528 — A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Im...

A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /admin/delete_judge.php. Such manipulation of the argument judge_id leads to sql injection. The attack can be executed remotely. The exploit is publicly available and might be used.

CVE-2026-9528
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9526 — A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vu...

A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the file /admin/edit_team.php. The manipulation of the argument num_id results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used.

CVE-2026-9526
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9525 — A vulnerability has been found in itsourcecode Electronic Judging System 1.0. Th...

A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /admin/edit_judge.php. The manipulation of the argument judge_id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

CVE-2026-9525
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9523 — A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation...

A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV2. Affected by this vulnerability is an unknown functionality of the file /SubstationWEBV2/app/..;/calc/getCalcmeterDetailDayListTree. Performing a manipulation of the argument sort results in sql injection. The attack can be initiated remotely. The exploit is now public and may

CVE-2026-9523
NIST NVD
LOWSupply Chain

Automated 'Megalodon' Campaign Spreads GitHub Repo Backdoors

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/automated-megalodon-campaign-spreads-github-repo-backdoors-image_small-9-a-31772.jpg" align=right hspace=4><b>Supply-Chain Attack Uses Malicious GitHub Actions Workflow File to Steal Secrets</b><br>More than 5,000 GitHub repositories fell victim to an automated campaign, codenamed "Megalodon," in which an attacker injected malicio

Bank Info Security
MEDIUMVulnerability

Responding to Breaches With AI? Beware Cross-Contamination

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/responding-to-breaches-ai-beware-cross-contamination-image_small-8-a-31771.jpg" align=right hspace=4><b>Separate Breach Details Can Bleed Into Each Other, Incident Responders Find</b><br>Cybersecurity investigators who use artificial intelligence tools to draft incident response reports, beware: Information tied to one security in

Bank Info Security
CRITICALApt

Security experts caution MFA alone can no longer stop threat actors

Cybersecurity experts are warning enterprise admins about an increasing number of phishing campaigns aimed at stealing Microsoft 365 (M365) access tokens to bypass multifactor authentication login protection. Phishing kits aimed at capturing M365 tokens aren’t new; some reports say these kits have been around since 2021. One of the latest is EvilTokens , which researchers at Sekoia say has been ci

CSO Online
HIGHVulnerability

NVD HIGH: CVE-2026-9538 — Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker ...

Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value. A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of th

CVE-2026-9538
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9521 — A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affec...

A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation leads to improper validation of specified type of input. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 5.2.5 is able to address this

CVE-2026-9521
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-42497 — Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker control...

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode. A subsequent write through the extracted name modifies the victim file, and the post-extract

CVE-2026-42497
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-42496 — Archive::Tar versions before 3.08 for Perl extract symlinks with attacker contro...

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target. A subsequent open through the extracted na

CVE-2026-42496
NIST NVD
CRITICALAi

Project Glasswing has uncovered 10,000 vulnerabilities: Anthropic

Anthropic says it and upwards of 50 partners involved in Project Glasswing have uncovered an estimated 10,000 critical or high-severity vulnerabilities in their software offerings. The company launched the cybersecurity initiative, which is built around Claude Mythos Preview , in April, stating that its launch partners would use it as part of their defensive security work. Anthropic said it create

CSO Online
HIGHVulnerability

NVD HIGH: CVE-2026-9517 — A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem...

A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student Management Handler. Executing a manipulation can lead to improper access controls. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product implemen

CVE-2026-9517
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-8376 — Perl versions through 5.43.10 have a heap buffer overflow when compiling regular...

Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGR

CVE-2026-8376
NIST NVD
MEDIUMVulnerability

SME banking platform Relay raises $50m

Relay, a business banking and money management service for SMEs, has secured $50 million in growth investment from General Catalyst.

Finextra
MEDIUMAi

SmartComply bids to help UK firms reopen African payment corridors

Lagos-based compliance and cybersecurity company SmartComply has launched in the UK, making its AI-powered anti-money laundering platform available to British payment firms serving African markets.

Finextra
HIGHVulnerability

CISA KEV: LiteSpeed cPanel Plugin — LiteSpeed cPanel Plugin Privilege Escalation Vulnerability

LiteSpeed cPanel Plugin contains privilege escalation vulnerability that is exposed via the user-end cPanel plugin, which can be abused by any cPanel user account to execute arbitrary scripts with root privileges.

CVE-2026-48172LiteSpeed cPanel Plugin
CISA KEV
MEDIUMVulnerability

Kremlin appoints cyber executive with alleged GRU ties to Security Council role

Andrei Kozlov, the former head of a cybersecurity center within Russia’s state-owned defense conglomerate Rostec, was named an aide to Security Council Secretary Sergei Shoigu on Friday.

The Record
MEDIUMVulnerability

Dutch authorities arrest men suspected of providing infrastructure for Russian cyber operations

Investigators seized more than 800 servers as they arrested two men suspected of violating European sanctions and assisting pro-Russian cyberattacks and disinformation campaigns.

The Record
MEDIUMData Breach

Welcoming the Bhutanese Government to Have I Been Pwned

Today, we welcome the 45th government onboarded to Have I Been Pwned&#x2019;s free gov service: Bhutan. The Bhutan Computer Incident Response Team, BtCIRT, now has access to monitor Bhutanese government domains against the data in HIBP. As Bhutan&#x2019;s national CIRT, BtCIRT is responsible for consuming threat

Troy Hunt
MEDIUMVulnerability

CVE-2026-20700: A controlled exploration of dyld's page-in linking and chained fixup machinery as a PAC signing oracle, in the context of CVE-2026-20700.

[object Object]

CVE-2026-20700
r/blueteamsec
HIGHVulnerability

NVD HIGH: CVE-2026-9481 — A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formS...

A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /goform/formStats. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-9481
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9480 — A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is ...

A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-9480
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9479 — A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affect...

A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of the file /goform/formLogout. The manipulation of the argument submit-url leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did no

CVE-2026-9479
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9478 — A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted...

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.

CVE-2026-9478
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9477 — A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Thi...

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for at

CVE-2026-9477
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9476 — A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vul...

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument admpass leads to os command injection. The attack can be executed remotely. The exploit is publicly available and might be used.

CVE-2026-9476
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9475 — A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This aff...

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument Comment causes os command injection. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized.

CVE-2026-9475
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9474 — A vulnerability was found in yashpokharna2555 StudentManagementSystem up to cb2f...

A vulnerability was found in yashpokharna2555 StudentManagementSystem up to cb2f558ddf8d19396de0f92abf2d224d46a0a203. Affected by this issue is the function confirm_logged_in of the file /studentdel.php. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. This product operates on a rolling release ba

CVE-2026-9474
NIST NVD
MEDIUMAi

Anthropic’s restricted Claude Mythos model may be coming to Claude Code

Anthropic appears to be preparing for the public rollout of the Mythos model, which was announced in April as a restricted model that poses major security risks to private and public software. [...]

BleepingComputer
HIGHVulnerability

NVD HIGH: CVE-2026-9470 — A security vulnerability has been detected in yashpokharna2555 StudentManagement...

A security vulnerability has been detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This affects the function confirm_logged_in of the file student_trans.php. Such manipulation of the argument FIRST_NAME/Last_Name/EMAIL leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. This pro

CVE-2026-9470
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9469 — A weakness has been identified in yashpokharna2555 StudentManagementSystem cb2f5...

A weakness has been identified in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. The impacted element is an unknown function of the file /success.php. This manipulation of the argument User causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. This product is using a

CVE-2026-9469
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-42782 — Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An ...

Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution path via the class static initializer. This issue affects Apache Syncope: 3.0 through 3.0.16, 4.0 through 4.0.5, 4.1.0. Users are recommended to upgrade to ve

CVE-2026-42782
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9465 — A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0....

A vulnerability was found in Tiandy Easy7 Integrated Management Platform 7.17.0. This vulnerability affects unknown code of the file /Easy7/apps/WebService/GetDBDataEx.jsp. Performing a manipulation of the argument strTBName results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. The vendor was contacted early about this disclosu

CVE-2026-9465
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9463 — A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the f...

A flaw has been found in Edimax EW-7438RPn 1.31. Affected by this issue is the function formLicence of the file /goform/formLicence. This manipulation of the argument submit-url causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-9463
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9462 — A vulnerability was detected in Edimax EW-7438RPn 1.31. Affected by this vulnera...

A vulnerability was detected in Edimax EW-7438RPn 1.31. Affected by this vulnerability is the function formWpsProxyEnable of the file /goform/formWpsProxyEnable. The manipulation of the argument submit-url results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond i

CVE-2026-9462
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-47077 — Allocation of Resources Without Limits or Throttling vulnerability in benoitc ha...

Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. hackney_h3:await_response_loop/6 accumulates the HTTP/3 response body in memory without any size cap. The after Timeout clause is a per-message inactivity timer that resets on every received chunk, housekeeping message, or settings frame — it is not a wall-clock deadline. A malicious HTTP/3 serve

CVE-2026-47077
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-47075 — Improper Neutralization of CRLF Sequences vulnerability in benoitc hackney allow...

Improper Neutralization of CRLF Sequences vulnerability in benoitc hackney allows HTTP Request Splitting. hackney does not percent-encode carriage return (\r) or line feed (\n) characters in the URL query component before constructing the HTTP/1.1 request target. Characters outside the grammar defined in RFC 3986 Section 3.4 must be percent-encoded, but hackney_url:make_url/3 passes the query bina

CVE-2026-47075
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-47073 — Allocation of Resources Without Limits or Throttling vulnerability in benoitc ha...

Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The WebSocket client in src/hackney_ws.erl imposes no upper bound on memory consumption in three code paths. First, read_handshake_response/3 accumulates received bytes into a growing buffer with no size cap; the per-receive timeout resets on every chunk, so a server that streams bytes without ev

CVE-2026-47073
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-47072 — Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in be...

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Request/Response Splitting. The WebSocket upgrade code in src/hackney_ws.erl copies the host, path, headers (ExtraHeaders), and protocols options from the caller-supplied opts map into the internal #ws_data{} record in init/1 and then splices them verbatim into the raw HTTP/1.1 upgrade request

CVE-2026-47072
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-47071 — Uncontrolled Resource Consumption vulnerability in benoitc hackney allows Floodi...

Uncontrolled Resource Consumption vulnerability in benoitc hackney allows Flooding. The SOCKS5 transport in src/hackney_socks5.erl correctly applies the caller-supplied timeout to the SOCKS5 negotiation phase, but then upgrades the connection to TLS using the two-argument form ssl:connect/2, which defaults to an infinite timeout. The Timeout value is in scope at the call site but is not forwarded.

CVE-2026-47071
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-47067 — Allocation of Resources Without Limits or Throttling vulnerability in benoitc ha...

Allocation of Resources Without Limits or Throttling vulnerability in benoitc hackney allows Flooding. The URL parser in src/hackney_url.erl converts every unrecognized URL scheme to a permanent BEAM atom via binary_to_atom/2. BEAM atoms are never garbage-collected and the atom table defaults to a hard limit of 1,048,576 entries. An attacker who can supply URLs with attacker-chosen scheme prefixes

CVE-2026-47067
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-47066 — Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in benoitc ...

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in benoitc hackney allows Excessive Allocation. The Alt-Svc response header parser in src/hackney_altsvc.erl does not guarantee forward progress. When parse_token/2 receives a non-token, non-whitespace, non-comma byte (e.g. !, @, =, ;), it returns the input unchanged. skip_comma/1 also returns the buffer unchanged when the first

CVE-2026-47066
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25381 — Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that a...

Joomla Responsive Portfolio 1.6.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through multiple filter parameters. Attackers can inject malicious SQL code via the filter_type_id, filter_pid_id, and filter_search parameters in POST requests to extract sensitive database information including credentials and server details.

CVE-2018-25381
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25380 — Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that a...

Joomla Component eXtroForms 2.1.5 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL commands through the filter_type_id, filter_pid_id, and filter_search parameters. Attackers can submit POST requests to the extroformfield view with malicious SQL payloads to extract sensitive database information and server data.

CVE-2018-25380
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25379 — Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in...

Collectric CMU 1.0 contains a boolean-based blind SQL injection vulnerability in the lang parameter that allows unauthenticated attackers to manipulate database queries during authentication. Attackers can inject SQL code through the lang parameter in login requests to extract sensitive information from the database using time-based blind techniques.

CVE-2018-25379
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25377 — Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability...

Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload and paste it into the Name and Code fields of the Help > Register dialog to trigger a reverse shell with system privileges.

CVE-2018-25377
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25376 — Socusoft 3GP Photo Slideshow 8.05 contains a buffer overflow vulnerability in th...

Socusoft 3GP Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft malicious input in the Registration Name and Registration Key fields to overwrite the SEH chain and execute shellcode for reverse shell access.

CVE-2018-25376
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25375 — SocuSoft iPod Photo Slideshow 8.05 contains a buffer overflow vulnerability in t...

SocuSoft iPod Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft malicious input in the Registration Name and Registration Key fields to trigger a stack-based buffer overflow and execute a reverse shell payload.

CVE-2018-25375
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25374 — Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vul...

Softneta MedDream PACS Server Premium 6.7.1.1 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the path parameter. Attackers can send requests to nocache.php with encoded backslash sequences to traverse directories and access sensitive files including system configuration and password files.

CVE-2018-25374
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25373 — SocuSoft DVD Photo Slideshow Professional 8.07 contains a stack-based buffer ove...

SocuSoft DVD Photo Slideshow Professional 8.07 contains a stack-based buffer overflow vulnerability in the registration name field that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious text file with carefully constructed payload containing junk bytes, SEH chain overwrite, and shellcode, then paste the contents into the R

CVE-2018-25373
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25372 — MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability tha...

MedDream PACS Server Premium 6.7.1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the email parameter. Attackers can submit crafted POST requests to the userSignup.php endpoint with SQL payloads in the email field to extract sensitive database information from the backend MySQL database.

CVE-2018-25372
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25371 — mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that all...

mooSocial Store Plugin 2.6 contains a blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries through the product parameter in URL rewrite functionality. Attackers can inject SQL code using boolean-based blind, time-based blind, or stacked query techniques in the product URI parameter to extract sensitive database information.

CVE-2018-25371
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25368 — Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthen...

Nord VPN 6.14.31 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting an excessively long string in the password field. Attackers can paste a buffer of repeated characters into the password input field to trigger an application crash when attempting to authenticate.

CVE-2018-25368
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25366 — CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attack...

CuteFTP 5.0 XP contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by injecting malicious payload into the Site Manager label field. Attackers can craft a payload exceeding 520 bytes that overwrites the return address and executes shellcode when a shortcut is created and launched.

CVE-2018-25366
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25364 — Twitter-Clone 1 contains a SQL injection vulnerability that allows unauthenticat...

Twitter-Clone 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the name parameter. Attackers can submit crafted payloads to the search.php endpoint to extract database information including usernames, credentials, and system data using error-based and union-based SQL injection techniques.

CVE-2018-25364
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25362 — Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows...

Twitter-Clone 1 contains a SQL injection vulnerability in follow.php that allows attackers to manipulate database queries by injecting SQL code through the userid parameter. Attackers can submit union-based or time-based blind SQL injection payloads to extract sensitive database information including usernames, passwords, and database credentials.

CVE-2018-25362
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25360 — AgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerabili...

AgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability in the Trace Route host name field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious ping.txt file with shellcode and jump instructions that overwrite the SEH handler pointer to achieve code execution when the file contents are pasted i

CVE-2018-25360
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25359 — Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vul...

Splinterware System Scheduler Pro 5.12 contains an insecure file permissions vulnerability that allows low-privilege users to escalate privileges by modifying service executable files. Attackers can rename the WService.exe file in the installation directory and replace it with a malicious executable that executes with LocalSystem privileges when the service is triggered.

CVE-2018-25359
NIST NVD
MEDIUMVulnerability

&#39;The clock is ticking&#39; - ECB calls in banks over Mythos risks

The European Central Bank has called in banks for a meeting this week to urge them to speed up their efforts to fix IT issues exposed by new AI models.

Finextra
MEDIUMVulnerability

CVE-2021-21735: ZTE H168N wizard whitelist exposed PPPoE and WLAN secrets pre-auth

[object Object]

CVE-2021-21735
r/netsec
MEDIUMVulnerability

Italian state lender to raise stake in Nexi

Italy’s state lender Cassa Depositi e Presti is set to increase its stake Nexi, strengthening its hold on the strategically important payments giant, which has attracted takeover interest from US private equity group CVC.

Finextra
HIGHVulnerability

NVD HIGH: CVE-2026-9461 — A security vulnerability has been detected in Edimax EW-7438RPn 1.31. Affected i...

A security vulnerability has been detected in Edimax EW-7438RPn 1.31. Affected is the function formRadius of the file /goform/formRadius. The manipulation of the argument submit-url leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-9461
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9460 — A weakness has been identified in Edimax EW-7438RPn 1.31. This impacts the funct...

A weakness has been identified in Edimax EW-7438RPn 1.31. This impacts the function formAccept of the file /goform/formAccept. Executing a manipulation of the argument submit-url can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure

CVE-2026-9460
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9459 — A security flaw has been discovered in Edimax EW-7438RPn 1.31. This affects the ...

A security flaw has been discovered in Edimax EW-7438RPn 1.31. This affects the function formConnectionSetting of the file /goform/formConnectionSetting. Performing a manipulation of the argument max_Conn/timeOut results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted e

CVE-2026-9459
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9458 — A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impa...

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWanCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument enabled leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used.

CVE-2026-9458
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9457 — A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affe...

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument FileName causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2026-9457
NIST NVD
MEDIUMVulnerability

Microsoft Access VBA, (Mon, May 25th)

Microsoft Access files (Microsoft Office&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s Database) can contain VBA code.&#xd;

SANS ISC
MEDIUMZero Day

⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos

Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should've patched years ago. Good times. Phishing crews are getting smarter too - less obvious scam junk, more targeted stuff that actually

The Hacker News
CRITICALAi

2 PhaaS 2 Furious: The Evolution of Chinese-language Phishing Services

<div class="block-paragraph_advanced"><p>Written by: Jamie Collier</p> <hr/></div> <div class="block-paragraph_advanced"><p><span style="vertical-align: baseline;">While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed

Mandiant
CRITICALZero Day

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

<div class="block-paragraph_advanced"><p>Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek</p> <hr/></div> <div class="block-paragraph_advanced"><h3><span style="vertical-align: baseline;">Introduction</span></h3> <p><span style="vertical-align: baseline;">In late 2025, Mandiant responded to a security incident involving a compromised web server running </span><a href="https://www.dig

CVE-2026-5426
Mandiant
MEDIUMVulnerability

Mastercard asks Brazilian payment processors to split Will losses

Mastercard is asking Brazilian payment processors to absorb some of nearly $1 billion in losses connected to the failure of Banco Masters.

Finextra
MEDIUMVulnerability

Ghost CMS Vulnerability Exploited to Hack Over 700 Websites

Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack. The post Ghost CMS Vulnerability Exploited to Hack Over 700 Websites appeared first on SecurityWeek .

SecurityWeek
MEDIUMSupply Chain

TeamPCP Supply Chain Campaign: Activity Through 2026-05-24, (Mon, May 25th)

TeamPCP now operates across three package ecosystems in parallel, it reached GitHub&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s own internal codebase, it trojanized an officially Microsoft-published Python SDK, and it appears to have open-sourced its own framework on GitHub.&#xd;

SANS ISC
MEDIUMVulnerability

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the European Union. The two men were the focus of a 2025 KrebsOnSecurity story about how their hosting companies had assumed control over the technical infrastructure o

Krebs on Security
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9456 — A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is t...

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument enabled results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

CVE-2026-9456
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9455 — A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This iss...

A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function UploadOpenVpnCert of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument FileName leads to os command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

CVE-2026-9455
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9454 — A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerabilit...

A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setOpenVpnCertGenerationCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument servername can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used.

CVE-2026-9454
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9453 — A vulnerability was detected in FoundDream miniclawd up to 2d65665046e2222eeea76...

A vulnerability was detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. This affects the function which of the file /src/application/skills-loader.ts of the component SkillsLoader. Performing a manipulation of the argument requires.bins results in command injection. The attack may be initiated remotely. The exploit is now public and may be used. This product uses a rol

CVE-2026-9453
NIST NVD
MEDIUMVulnerability

PowerSchool’s $17.25 Million Settlement Exposes Years of Student Data Tracking

If you ask most people what breach PowerSchool experienced, their first response might be the 2024 hacking incident that affected tens of millions of students. But even before that breach, there was another significant breach involving PowerSchool that began in 2021. Colin Lee and Koji Edmunds report: In early April, many students across the world... Source

DataBreaches.net
MEDIUMPhishing

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA). [...]

BleepingComputer
LOWAi

AI security needs a shift from models to systems, researchers argue

Enterprises cannot secure AI agents by making the underlying models more robust and must instead enforce security controls at the system level around them, researchers behind a paper published this month argued, warning that traditional AI-security approaches are increasingly misaligned with how autonomous agents actually operate inside enterprise environments. The paper argues that enterprises sh

CSO Online
HIGHData Breach

Oncology Institute Discloses Data Breach

The affected third-party vendor has not been named, but one possible candidate is TriZetto. The post Oncology Institute Discloses Data Breach appeared first on SecurityWeek .

SecurityWeek
CRITICALVulnerability

Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks

Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), an SQL injection vulnerability in Ghost's Content API that could allow an unauthenticated attacker to read arbitrary data from the

CVE-2026-26980
The Hacker News
LOWSupply Chain

As AI speeds coding, CVE Lite CLI keeps security deliberately AI-free

As AI coding assistants accelerate software development, one OWASP-backed open-source project is arguing that dependency security tooling still arrives too late to be truly useful. CVE Lite CLI , a JavaScript and TypeScript dependency vulnerability scanner focused on local lockfile analysis, is positioning itself around a simple idea. Developers should see dependency risks while they are still wri

CSO Online
MEDIUMAi

The Alert Firehose Finally Meets Its Match

Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear "Noisy," "Too much data." But ask the teams running NDR that includes agentic AI capabilities and you'll hear they're actually using it to catch threats earlier, triage faster, and chase fewer false positives. The old complaint lingers in part because reputations are sticky, and because NDR has evolved

The Hacker News
HIGHData Breach

266,000 Affected by Data Breach at Radiology Associates of Richmond

Threat actors stole files containing names and protected health information from the healthcare organization’s systems. The post 266,000 Affected by Data Breach at Radiology Associates of Richmond appeared first on SecurityWeek .

SecurityWeek
HIGHVulnerability

NVD HIGH: CVE-2026-9452 — A security vulnerability has been detected in FoundDream miniclawd up to 2d65665...

A security vulnerability has been detected in FoundDream miniclawd up to 2d65665046e2222eeea76cafc8570ed546a8c125. Affected by this issue is the function ExecTool.execute of the file /src/tools/exec.ts. Such manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why info

CVE-2026-9452
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9447 — A vulnerability was found in SourceCodester Simple POS and Inventory System 1.0....

A vulnerability was found in SourceCodester Simple POS and Inventory System 1.0. The impacted element is an unknown function of the file /user/search.php. Performing a manipulation of the argument Name results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

CVE-2026-9447
NIST NVD
CRITICALAi

Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects

Many findings have been confirmed to be critical or high-severity vulnerabilities and the number will continue to increase. The post Anthropic: Mythos Detected 23,000 Potential Vulnerabilities Across 1,000 OSS Projects appeared first on SecurityWeek .

SecurityWeek
MEDIUMSupply Chain

Laravel-Lang Packages Poisoned for Malware Delivery

Published within a 15-minute window, the malicious tags introduced backdoors to exfiltrate CI secrets. The post Laravel-Lang Packages Poisoned for Malware Delivery appeared first on SecurityWeek .

SecurityWeek
HIGHVulnerability

NVD HIGH: CVE-2026-9443 — A security vulnerability has been detected in Edimax BR-6478AC 1.23. This vulner...

A security vulnerability has been detected in Edimax BR-6478AC 1.23. This vulnerability affects the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. The manipulation of the argument L2TPUserName leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about

CVE-2026-9443
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9442 — A weakness has been identified in Edimax BR-6478AC 1.23. This affects the functi...

A weakness has been identified in Edimax BR-6478AC 1.23. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. Executing a manipulation of the argument selSSID can lead to buffer overflow. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted

CVE-2026-9442
NIST NVD
HIGHData Breach

DocketWise Data Breach Impacts 143,000

Hackers accessed names, addresses, Social Security numbers, financial information, and medical data from third-party partner repositories. The post DocketWise Data Breach Impacts 143,000 appeared first on SecurityWeek .

SecurityWeek
MEDIUMMalware

Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations. RemotePE, per NCC Group subsidiary Fox-IT, is part of a multi-stage attack chain that involves two loaders tracked as DPAPILoader and RemotePELoader. "DPAPILoader decrypts and

The Hacker News
LOWPhishing

FBI Warns 'Kali365' Phishing Kit Hijacks Microsoft 365 OAuth Tokens

The Kali365 phishing-as-a-service platform lowers the barrier of entry for cybercriminals, said the FBI

Infosecurity Magazine
MEDIUMVulnerability

Fake Streams, Counterfeit Merch and Other Scams: How Fraudsters Target F1 Fans

From fake F1 streams to counterfeit merch, fraudsters are exploiting fans online and the Bitdefender Cybersecurity Grand Prix Fan Threat Index details how

Infosecurity Magazine
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9436 — A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted elem...

A flaw has been found in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setL2tpServerCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used.

CVE-2026-9436
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9435 — A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affect...

A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setQosCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument enable results in os command injection. Remote exploitation of the attack is possible. The exploit is now public and may be used.

CVE-2026-9435
NIST NVD
MEDIUMVulnerability

Fix: CVE-2025-33073 NTLM reflection not exploitable on pre-NT10.0 systems by azoxlpf · Pull Request #1245 · Pennyw0rth/NetExec

[object Object]

CVE-2025-33073
r/blueteamsec
LOWSupply Chain

Over 5,500 GitHub Repositories Infected in &#8216;Megalodon&#8217; Supply Chain Attack

Fake automated commits injected GitHub Actions workflows containing payloads to steal credentials, CI secrets, keys, and tokens. The post Over 5,500 GitHub Repositories Infected in &#8216;Megalodon&#8217; Supply Chain Attack appeared first on SecurityWeek .

SecurityWeek
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9434 — A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b202005...

A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setWiFiWpsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument wscDisabled leads to os command injection. The attack may be launched remotely. The exploit has been disclosed publicly and may be used.

CVE-2026-9434
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9433 — A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This iss...

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setMacFilterRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument enable causes os command injection. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.

CVE-2026-9433
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9432 — A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Thi...

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setWiFiAdvancedCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument bgProtection results in os command injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.

CVE-2026-9432
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9431 — A vulnerability was identified in Tenda F1202 1.2.0.20(408). This affects the fu...

A vulnerability was identified in Tenda F1202 1.2.0.20(408). This affects the function fromPptpUserAdd of the file /goform/PptpUserAdd. The manipulation of the argument opttype leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit is publicly available and might be used.

CVE-2026-9431
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9430 — A vulnerability was determined in Tenda F1202 1.2.0.20(408). Affected by this is...

A vulnerability was determined in Tenda F1202 1.2.0.20(408). Affected by this issue is the function formGstDhcpSetSer of the file /goform/GstDhcpSetSerof. Executing a manipulation of the argument dips can lead to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2026-9430
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9429 — A vulnerability was found in Tenda F1202 1.2.0.20(408). Affected by this vulnera...

A vulnerability was found in Tenda F1202 1.2.0.20(408). Affected by this vulnerability is the function formWrlExtraSet of the file /goform/WrlExtraSet. Performing a manipulation of the argument delno results in stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been made public and could be used.

CVE-2026-9429
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9428 — A vulnerability has been found in Tenda F1202 1.2.0.20(408). Affected is the fun...

A vulnerability has been found in Tenda F1202 1.2.0.20(408). Affected is the function fromPPTPUserSetting of the file /goform/PPTPUserSetting. Such manipulation of the argument delno leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVE-2026-9428
NIST NVD
HIGHRansomware

To pay, or not to pay: 58% of CISOs say they would pay the ransom for their data

If you were hit by ransomware tomorrow, would you pay to get your data back? That’s what more than half of CISOs in a recent survey said their organization would do. It’s a situation more companies are going to face in future. “Attacks are increasing and continuing to increase,” said Christy Wyatt , CEO of security vendor Absolute Software, which commissioned the survey. “Companies are better prep

CSO Online
MEDIUMSupply Chain

TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO

A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The campaign, codenamed TrapDoor, spans more than 34 malicious packages across over 384 versions. The earliest activity was recorded on May 22, 2026, at 8:20 p.m. UTC, with new packages published to the ecosystems in waves from a cluster of

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-9427 — A flaw has been found in Edimax EW-7438RPn 1.31. This impacts the function formW...

A flaw has been found in Edimax EW-7438RPn 1.31. This impacts the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component webs. This manipulation of the argument selSSID/submit-url causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did

CVE-2026-9427
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9426 — A vulnerability was detected in Edimax EW-7438RPn 1.31. This affects the functio...

A vulnerability was detected in Edimax EW-7438RPn 1.31. This affects the function formHwSet of the file /goform/formHwSet. The manipulation of the argument Anntena/Mcs/regDomain/nic0Addr/nic1Addr/wlanAddr/wanAddr/wlanSSID/wlanChan/initgain/txcck/txofdm/submit-url results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used. The vendor was c

CVE-2026-9426
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9425 — A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The impact...

A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The impacted element is the function formWlanMP of the file /goform/formWlanMP. The manipulation of the argument ateFunc/ateGain/ateTxCount/ateChan/ateRate/ateMacID/e2pTxPower1/e2pTxPower2/e2pTxPower3/e2pTxPower4/e2pTxPower5/e2pTxPower6/e2pTxPower7/e2pTx2Power1/e2pTx2Power2/e2pTx2Power3/e2pTx2Power4/e2pTx2Power5/e2pTx2Power6/e2p

CVE-2026-9425
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9421 — A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerabilit...

A vulnerability was determined in KLiK SocialMediaWebsite 1.0. This vulnerability affects the function uniqid of the file upload.inc.php of the component File Handler. This manipulation causes unrestricted upload. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2026-9421
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9408 — A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected b...

A vulnerability was detected in Totolink A8000RU 7.1cu.643_b20200521. Affected by this issue is the function setStaticDhcpRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument enable results in os command injection. The attack may be performed from remote. The exploit is now public and may be used.

CVE-2026-9408
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9407 — A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b202005...

A security vulnerability has been detected in Totolink A8000RU 7.1cu.643_b20200521. Affected by this vulnerability is the function setFirewallType of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument firewallType leads to os command injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may b

CVE-2026-9407
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9406 — A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected...

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Affected is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument enable can lead to os command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks.

CVE-2026-9406
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9405 — A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. Thi...

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument enable results in os command injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

CVE-2026-9405
NIST NVD
MEDIUMAi

TD builds AI model to speed up mortgage applications

Canada's TD Bank has launched an agentic AI model that automates and streamlines the application process for mortgages and home equity lines of credit.

Finextra
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9404 — A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This aff...

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument provider leads to os command injection. The attack may be launched remotely. The exploit is publicly available and might be used.

CVE-2026-9404
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9403 — A vulnerability was determined in Edimax BR-6675nD 1.12. The impacted element is...

A vulnerability was determined in Edimax BR-6675nD 1.12. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. This manipulation of the argument selSSID causes buffer overflow. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclo

CVE-2026-9403
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9401 — A vulnerability has been found in Edimax BR-6675nD 1.12. Impacted is the functio...

A vulnerability has been found in Edimax BR-6675nD 1.12. Impacted is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. The manipulation of the argument pppUserName leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure

CVE-2026-9401
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9399 — A vulnerability was detected in Edimax BR-6675nD 1.12. This vulnerability affect...

A vulnerability was detected in Edimax BR-6675nD 1.12. This vulnerability affects the function formsetPPPoE of the file /goform/formsetPPPoE of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in buffer overflow. It is possible to initiate the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this discl

CVE-2026-9399
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9397 — A weakness has been identified in Besen BS20 EV Charging Station up to 20260426....

A weakness has been identified in Besen BS20 EV Charging Station up to 20260426. Affected by this issue is some unknown functionality of the component OTA Update Installation Handler. This manipulation causes improper authorization. The attack is possible to be carried out remotely. A high degree of complexity is needed for the attack. The exploitation is known to be difficult. The original disclo

CVE-2026-9397
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9393 — A vulnerability was found in H3C Magic B0 up to 100R002. This affects the functi...

A vulnerability was found in H3C Magic B0 up to 100R002. This affects the function Edit_BasicSSID_5G of the file /goform/aspForm. Performing a manipulation of the argument param results in buffer overflow. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-9393
NIST NVD
MEDIUMVulnerability

Wireshark 4.6.6 Released, (Sun, May 24th)

Wireshark release 4.6.6 fixes 1 vulnerability and 11 bugs.&#xd;

SANS ISC
HIGHVulnerability

NVD HIGH: CVE-2026-9389 — A security vulnerability has been detected in Tenda F456 1.0.0.5. This affects t...

A security vulnerability has been detected in Tenda F456 1.0.0.5. This affects the function frmL7ImForm of the file /goform/L7Im. The manipulation of the argument page leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.

CVE-2026-9389
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9388 — A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impa...

A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing a manipulation of the argument mode can lead to os command injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for at

CVE-2026-9388
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9387 — A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The...

A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument resetFlags results in os command injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for

CVE-2026-9387
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9386 — A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted...

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such manipulation of the argument lang leads to os command injection. The attack may be performed from remote. The exploit is publicly available and might be used.

CVE-2026-9386
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9385 — A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This iss...

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setTracerouteCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation of the argument command causes os command injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

CVE-2026-9385
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-9384 — A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerab...

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setDiagnosisCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. The manipulation of the argument ip results in os command injection. The attack can be executed remotely. The exploit has been made public and could be used.

CVE-2026-9384
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9383 — A vulnerability has been found in itsourcecode Electronic Judging System 1.0. Th...

A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/admin/login.php. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

CVE-2026-9383
NIST NVD
CRITICALVulnerability

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. [...]

CVE-2026-26980
BleepingComputer
HIGHVulnerability

NVD HIGH: CVE-2026-9382 — A flaw has been found in Edimax BR-6675nD 1.12. Affected by this issue is the fu...

A flaw has been found in Edimax BR-6675nD 1.12. Affected by this issue is the function formPPTPSetup of the file /goform/formPPTPSetup of the component POST Request Handler. Executing a manipulation of the argument pptpUserName can lead to buffer overflow. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but d

CVE-2026-9382
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9381 — A vulnerability was detected in Edimax BR-6675nD 1.12. Affected by this vulnerab...

A vulnerability was detected in Edimax BR-6675nD 1.12. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. Performing a manipulation of the argument pppUserName results in buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disc

CVE-2026-9381
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9380 — A security vulnerability has been detected in Edimax BR-6675nD 1.12. Affected is...

A security vulnerability has been detected in Edimax BR-6675nD 1.12. Affected is the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such manipulation of the argument L2TPUserName leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure

CVE-2026-9380
NIST NVD
MEDIUMVulnerability

France Sees More Violent Attacks on Crypto Holders Than Any Other Country

Julian Lim reports: The hardest part of crypto security used to be keeping private keys away from hackers. In France, the problem has moved much closer to home. A new report says roughly 70% of documented wrench attacks against crypto holders and their families are happening there, turning a niche security term into a very... Source

DataBreaches.net
HIGHVulnerability

NVD HIGH: CVE-2026-9372 — A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affec...

A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affects unknown code of the file src/app/api/providers/route.ts of the component Model Provider API. This manipulation of the argument baseURL causes server-side request forgery. Remote exploitation of the attack is possible. The exploit has been published and may be used. The project was informed of the problem early throu

CVE-2026-9372
NIST NVD
MEDIUMVulnerability

CVE-2026-48029: Two grid-decode bugs in libheif

[object Object]

CVE-2026-48029
r/blueteamsec
HIGHVulnerability

NVD HIGH: CVE-2026-9368 — A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. Thi...

A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Handler. Such manipulation leads to sandbox issue. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure bu

CVE-2026-9368
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9367 — A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f1948...

A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dangerous_command of the file tools/approval.py of the component terminal_tool. This manipulation causes os command injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacte

CVE-2026-9367
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9366 — A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted e...

A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.py. The manipulation results in injection. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2026-9366
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9364 — A flaw has been found in projectworlds Online Art Gallery Shop 1.0. Impacted is ...

A flaw has been found in projectworlds Online Art Gallery Shop 1.0. Impacted is an unknown function of the file /admin/adminHome.php. Executing a manipulation of the argument social_linked can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

CVE-2026-9364
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9360 — A security flaw has been discovered in Edimax EW-7438RPn 1.28a. Affected by this...

A security flaw has been discovered in Edimax EW-7438RPn 1.28a. Affected by this issue is the function formwlencrypt24g of the file /goform/formwlencrypt24g of the component POST Request Handler. The manipulation of the argument key1 results in buffer overflow. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted ear

CVE-2026-9360
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9356 — A vulnerability has been found in SourceCodester Hospitals Patient Records Manag...

A vulnerability has been found in SourceCodester Hospitals Patient Records Management System 1.0. This affects an unknown function of the file /admin/patients/manage_history.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.

CVE-2026-9356
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9355 — A flaw has been found in SourceCodester Hospitals Patient Records Management Sys...

A flaw has been found in SourceCodester Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_patient_history. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.

CVE-2026-9355
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9353 — A security vulnerability has been detected in NousResearch hermes-agent up to 20...

A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.23. Impacted is an unknown function of the file agent/skills_guard.py of the component Skills Guard Multi-Word Prompt Handler. The manipulation of the argument THREAT_PATTERNS leads to injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was

CVE-2026-9353
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9350 — A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. Thi...

A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This affects the function check_all_command_guards of the file tools/approval.py of the component Batch Runner. Such manipulation leads to missing authorization. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respon

CVE-2026-9350
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9348 — A vulnerability was found in Edimax EW-7438RPn up to 1.31. Affected by this vuln...

A vulnerability was found in Edimax EW-7438RPn up to 1.31. Affected by this vulnerability is an unknown functionality of the file /goform/mp of the component webs. The manipulation of the argument webs results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did

CVE-2026-9348
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9346 — A flaw has been found in Edimax EW-7438RPn up to 1.31. This impacts the function...

A flaw has been found in Edimax EW-7438RPn up to 1.31. This impacts the function formWirelessTbl of the file /goform/formWirelessTbl of the component webs. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attack may be performed from remote. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond i

CVE-2026-9346
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9345 — A vulnerability was detected in Edimax EW-7438RPn up to 1.31. This affects the f...

A vulnerability was detected in Edimax EW-7438RPn up to 1.31. This affects the function formWizSurvey of the file /goform/formWizSurvey of the component webs. Performing a manipulation of the argument ssid/manualssid/ip/mask/gateway results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this dis

CVE-2026-9345
NIST NVD
MEDIUMVulnerability

Weekly Update 505

Well, that didn&apos;t last long! Recording this on Saturday morning my time, I observed ShinyHunters having gone quiet since the massive haul that would have been the Instructure ransom. It was two weeks almost to the hour since I&apos;d first heard rumour of payment being made,

Troy Hunt
HIGHVulnerability

NVD HIGH: CVE-2026-9344 — A security vulnerability has been detected in Edimax EW-7438RPn up to 1.31. The ...

A security vulnerability has been detected in Edimax EW-7438RPn up to 1.31. The impacted element is an unknown function of the file /goform/formWpsStart of the component webs. Such manipulation of the argument pinCode/wlan-url leads to stack-based buffer overflow. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this

CVE-2026-9344
NIST NVD
LOWVulnerability

UK: £355,880.10 confiscation order secured following proceeds of crime hearing

There&#8217;s a follow-up to the case of a motor insurance worker who received a suspended prison sentence for unlawfully accessing personal information. On May 21, the Information Commissioner&#8217;s Office (ICO) announced that it had secured a £355,880.10 confiscation order against the former Manchester motor insurance worker, Rizwan Manjra. A statement by the ICO indicates that... Source

DataBreaches.net
MEDIUMSupply Chain

Laravel Lang packages hijacked to deploy credential-stealing malware

A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after attackers abused GitHub version tags to distribute malicious code through Composer packages. [...]

BleepingComputer
CRITICALVulnerability

NVD CRITICAL: CVE-2018-25357 — Dolibarr ERP CRM 7.0.3 contains a remote code evaluation vulnerability that allo...

Dolibarr ERP CRM 7.0.3 contains a remote code evaluation vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.

CVE-2018-25357
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25356 — SIPp 3.6 and earlier contains a local buffer overflow vulnerability in command-l...

SIPp 3.6 and earlier contains a local buffer overflow vulnerability in command-line argument handling that allows local attackers to crash the application or execute arbitrary code. Attackers can trigger the vulnerability by supplying oversized input to the -3pcc, -i, or -log_file parameters, causing strcpy to write beyond buffer boundaries in sipp.cpp.

CVE-2018-25356
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25355 — Audiograbber 1.83 contains a local buffer overflow vulnerability that allows att...

Audiograbber 1.83 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling mechanisms. Attackers can craft malicious input in the Interpret or Album fields that triggers a buffer overflow, overwriting SEH pointers and executing injected shellcode with application privileges.

CVE-2018-25355
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25353 — Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vul...

Redaxo CMS Mediapool Addon 5.5.1 and older contains an arbitrary file upload vulnerability that allows authenticated users to bypass file extension blacklist restrictions. Attackers with editor accounts can upload executable files by using obfuscated extensions like php71 or php53 to evade the blacklist filter and execute arbitrary code.

CVE-2018-25353
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25352 — WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an ...

WordPress Ultimate Form Builder Lite plugin version 1.3.7 and below contains an SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the entry_id POST parameter. Attackers can send POST requests to the admin-ajax.php endpoint with the ufbl_get_entry_detail_action action to extract, modify, or escalate privileges within the Wor

CVE-2018-25352
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2018-25350 — userSpice 4.3.24 contains a username enumeration vulnerability that allows unaut...

userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. Attackers can submit usernames and analyze response text for the 'taken' string to identify existing accounts in the system.

CVE-2018-25350
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25348 — Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that al...

Joomla! Component Ek Rishta 2.10 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cid parameter. Attackers can send GET requests to the user_detail view with malicious cid values containing SQL commands to extract sensitive database information.

CVE-2018-25348
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25347 — WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabiliti...

WordPress Contact Form Maker Plugin 1.12.20 contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through the FormMakerSQLMapping and generete_csv_fmc AJAX actions. Attackers can inject malicious SQL code via the 'name' and 'search_labels' parameters to extract sensitive database information or escalate privileges.

CVE-2018-25347
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25346 — WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabili...

WordPress Form Maker Plugin 1.12.24 and below contains SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through the FormMakerSQLMapping and generete_csv actions. Attackers can submit POST requests with malicious SQL payloads in the name and search_labels parameters to extract, modify, or escalate privileges within the WordPress d

CVE-2018-25346
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25345 — 10-Strike Network Scanner 3.0 contains a local buffer overflow vulnerability in ...

10-Strike Network Scanner 3.0 contains a local buffer overflow vulnerability in the host name field that allows attackers to bypass SafeSEH protections and execute arbitrary code. Attackers can craft a malicious payload in the host name or address field and trigger the vulnerability through the Trace route or System information functions to achieve code execution.

CVE-2018-25345
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25344 — 10-Strike Network Inventory Explorer 8.54 contains a stack-based buffer overflow...

10-Strike Network Inventory Explorer 8.54 contains a stack-based buffer overflow vulnerability in the registration key input field that allows local attackers to execute arbitrary code by triggering a structured exception handler overwrite. Attackers can craft a malicious registration key string with 4188 bytes of padding followed by SEH chain values and shellcode, then paste it into the registrat

CVE-2018-25344
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25342 — Smartshop 1 contains a time-based blind SQL injection vulnerability that allows ...

Smartshop 1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'searched' parameter in search.php. Attackers can send GET requests with malicious SQL payloads like SLEEP commands to extract sensitive database information including product details and system data.

CVE-2018-25342
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25341 — Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated a...

Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to product.php with union-based SQL injection payloads in the id parameter to extract sensitive database information including usernames and database names.

CVE-2018-25341
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2018-25340 — Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated a...

Smartshop 1 contains a SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to category.php with UNION-based SQL injection payloads in the id parameter to extract sensitive database information including usernames and other data.

CVE-2018-25340
NIST NVD
HIGHData Breach

Rhode Island&#8217;s workers&#8217; compensation notifies those affected by January data breach

Rhode Island residents may understandably wonder about the state&#8217;s vendor security monitoring. First, it was the Deloitte and the RIBridges data breach that affected more than 730,000 residents. Now the vendor that administers the state&#8217;s workers&#8217; compensation insurance has disclosed a breach affecting 131,000 residents, including 4,500 former and current state employees. Alexand

DataBreaches.net
MEDIUMSupply Chain

npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation. Called staged publishing, the feature is now generally available on npm. It mandates that a human maintainer pass a two-factor authentication (2FA) challenge to approve

The Hacker News
MEDIUMSupply Chain

Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware

A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases URL. "Although the affected packages were all Composer packages, the malicious code was not added to composer.json," Socket said. "Instead, it was inserted into package.json, targeting projects that ship JavaScript

The Hacker News
LOWSupply Chain

Laravel Lang Supply Chain Advisory

Hundreds of historical Laravel Lang Packagist releases were republished with malicious code, putting Composer installs at risk of credential theft and secret exfiltration.

Snyk
HIGHData Breach

UK: Victims feel &#8216;violated&#8217; after water firm&#8217;s data breach

Oprah Flash reports: &#8220;Violated&#8221; and being &#8220;unable to trust&#8221; have been the feelings plaguing victims of a cyber attack on a Midlands-based water company. The personal data of 633,887 people was stolen and published on the dark web, after South Staffs Water was hacked in 2020. Customers said they faced a deluge of scam emails... Source

DataBreaches.net
MEDIUMVulnerability

Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes

Italian authorities have dismantled a piracy ecosystem centered around the CINEMAGOAL app that provided access to various streaming platforms, including Netflix, Disney+, and Spotify. [...]

BleepingComputer
HIGHVulnerability

NVD HIGH: CVE-2026-46300 — In the Linux kernel, the following vulnerability has been resolved: net: skbuff...

In the Linux kernel, the following vulnerability has been resolved: net: skbuff: preserve shared-frag marker during coalescing skb_try_coalesce() can attach paged frags from @from to @to. If @from has SKBFL_SHARED_FRAG set, the resulting @to skb can contain the same externally-owned or page-cache-backed frags, but the shared-frag marker is currently lost. That breaks the invariant relied on by

CVE-2026-46300
NIST NVD
CRITICALAi

Claude Mythos AI Finds 10,000 High-Severity Flaws in Widely Used Software

Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cybersecurity initiative went live last month. Project Glasswing is an effort led by the artificial intelligence (AI) company, as part of which a small set of about 50 partners

The Hacker News
MEDIUMVulnerability

‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains

The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic. The post ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains appeared first on SecurityWeek .

SecurityWeek
MEDIUMSupply Chain

Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer

Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive credential-stealing framework. The affected packages include - laravel-lang/lang laravel-lang/http-statuses laravel-lang/attributes laravel-lang/actions "The timing and pattern of the newly published tags

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-9295 — A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the f...

A security flaw has been discovered in Edimax BR-6428NS 1.10. This affects the function formWirelessTbl of the file /goform/formWirelessTbl of the component POST Request Handler. Performing a manipulation of the argument vapurl results in buffer overflow. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early ab

CVE-2026-9295
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-9294 — A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is...

A vulnerability was identified in Edimax BR-6428NS 1.10. The impacted element is the function formWanTcpipSetup of the file /goform/formWanTcpipSetup of the component POST Request Handler. Such manipulation of the argument pppUserName leads to buffer overflow. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about thi

CVE-2026-9294
NIST NVD
HIGHVulnerability

LiteSpeed cPanel Plugin CVE-2026-48172 Exploited to Run Scripts as Root

A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary scripts with elevated permissions. "Any cPanel user (including an attacker or a compromised account) may

CVE-2026-48172
The Hacker News
CRITICALVulnerability

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability in question is CVE-2026-9082 (CVSS score: 6.5), an SQL injection vulnerability affecting all supported versions of Drupal Core. "Drupal Core

CVE-2026-9082
The Hacker News
MEDIUMMalware

An Example of Stack String in High Level Language, (Sat, May 23rd)

This week, I&#x27m attending the SEC670&#x5b;1&#x5d; training (&#xe2;&#x80;&#x9c;Red Teaming Tools - Developing Windows Implants, Shellcode, Command and Control&#xe2;&#x80;&#x9d;). From my point of view, this training fits perfectly with FOR610 or FOR710 (malware analysis) because it addresses malware from the opposite: Instead of performing reverse engineering, you write malicious code&#x21; Alwa

SANS ISC
HIGHVulnerability

NVD HIGH: CVE-2026-9284 — The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthoriz...

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to unauthorized order manipulation and information disclosure due to missing authorization checks on the `ppc-create-order` and `ppc-get-order` WC-AJAX endpoints in all versions up to, and including, 4.0.1. The `ppc-create-order` endpoint accepts an arbitrary WooCommerce order ID in the `pay-now` context without validating order ow

CVE-2026-9284
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-6898 — The Wishlist Member plugin for WordPress is vulnerable to unauthorized modificat...

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the REST API Secret Key, which can be used to create a new membershi

CVE-2026-6898
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-6897 — The Wishlist Member plugin for WordPress is vulnerable to unauthorized modificat...

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary plugin options, includes the REST API Secret

CVE-2026-6897
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-6895 — The WishList Member plugin for WordPress is vulnerable to Missing Authorization ...

The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_settings' function. This function returns the REST API Secret Key to the attacker in the AJAX JSON response. An attacker who obtains this key can authe

CVE-2026-6895
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-6419 — The WishList Member plugin for WordPress is vulnerable to Privilege Escalation v...

The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the ajax_get_screen() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to supply an arbitrary admin screen identifier via the data[url] parameter

CVE-2026-6419
NIST NVD
LOWMalware

RondoDox Botnet Exploits 2018 Flaw in Asus Routers

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/rondodox-botnet-exploits-2018-flaw-in-asus-routers-image_small-3-a-31768.jpg" align=right hspace=4><b>Botnet Operators Execute First Known Exploit of Nearly Decade-Old Flaw</b><br>Operators behind a botnet picked up on a nearly decade-old flaw in Asus routers allowing an unauthenticated attacker to achieve remote code execution as

Bank Info Security
MEDIUMMalware

FBI Director’s Former Apparel Brand Hit by Malware

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/fbi-directors-former-apparel-brand-hit-by-malware-image_small-9-a-31767.jpg" align=right hspace=4><b>Malware Targeted macOS Users Visiting Patel Foundation Merchandise Page</b><br>Two months after Iran-linked hackers exfiltrated FBI Director Kash Patel's personal email, the government official's name is tangled up in another cyber

Bank Info Security
LOWVulnerability

CISA to allow researchers to report vulnerabilities to exploited bugs catalog

The Cybersecurity and Infrastructure Security Agency (CISA) announced the creation of a nomination form on Thursday that they said enables “researchers, vendors, and industry partners” to report bugs that need to be added to the Known Exploited Vulnerabilities catalog.

The Record
LOWVulnerability

Google leaks details for Chromium bug that can turn browsers into bots

Chromium — the open-source browser that underpins Google Chrome, Microsoft Edge, and Opera, among others — contains an unpatched vulnerability that attackers can exploit to execute JavaScript code persistently across browser restarts. As a result, the flaw can be used to hijack users’ browsers for distributed denial-of-service attacks, run crypto miners, and more. The vulnerability was reported ov

CSO Online
CRITICALVulnerability

NVD CRITICAL: CVE-2026-47280 — Improper authentication in Azure Resource Manager (ARM) allows an unauthorized a...

Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-47280
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-45659 — Deserialization of untrusted data in Microsoft Office SharePoint allows an autho...

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

CVE-2026-45659
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-42901 — Origin validation error in Microsoft Entra ID allows an unauthorized attacker to...

Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-42901
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-42827 — Improper neutralization of special elements used in a command ('command injectio...

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

CVE-2026-42827
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-41104 — Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an ...

Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.

CVE-2026-41104
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-41090 — Improper neutralization of special elements used in a command ('command injectio...

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.

CVE-2026-41090
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-40412 — Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows a...

Unrestricted upload of file with dangerous type in Azure Orbital Spatio allows an unauthorized attacker to execute code over a network.

CVE-2026-40412
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-40411 — Improper input validation in Azure Virtual Network Gateway allows an authorized ...

Improper input validation in Azure Virtual Network Gateway allows an authorized attacker to execute code over a network.

CVE-2026-40411
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-35430 — Authorization bypass through user-controlled key in Azure Privileged Identity Ma...

Authorization bypass through user-controlled key in Azure Privileged Identity Management (PIM) allows an authorized attacker to elevate privileges over a network.

CVE-2026-35430
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-33843 — Authentication bypass using an alternate path or channel in Microsoft Azure Acti...

Authentication bypass using an alternate path or channel in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-33843
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-26147 — Improper input validation in Azure Compute Gallery allows an authorized attacker...

Improper input validation in Azure Compute Gallery allows an authorized attacker to disclose information over a network.

CVE-2026-26147
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-23663 — Improper privilege management in Azure Entra ID allows an unauthorized attacker ...

Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-23663
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-23652 — Improper neutralization of special elements used in a command ('command injectio...

Improper neutralization of special elements used in a command ('command injection') in Microsoft Power Pages allows an unauthorized attacker to execute code over a network.

CVE-2026-23652
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-41071 — libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 a...

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAuxInfoReader constructor. The SampleAuxInfoReader constructor iterates over saiz->get_num_samples() samples but doesn't validate

CVE-2026-41071
NIST NVD
MEDIUMApt

New Telecom Espionage Campaign Tied to China

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/new-telecom-espionage-campaign-tied-to-china-image_small-5-a-31763.jpg" align=right hspace=4><b>Researchers Trace Linux and Windows Toolsets to Suspected PRC Espionage Activity</b><br>Newly discovered malware tied to China-linked actors breached telecom providers across Asia and the Middle East, highlighting growing efforts to gai

Bank Info Security
MEDIUMMalware

Iranian Hackers Using Fake Job Sites to Breach Defense Firms

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/iranian-hackers-using-fake-job-sites-to-breach-defense-firms-image_small-4-a-31762.jpg" align=right hspace=4><b>Unit 42 Says Iranian Operators Target Aerospace and Government Staff</b><br>Palo Alto Networks' Unit 42 said Iran-linked operators tied to Screening Serpens are using fake recruiting campaigns, cloned aerospace hiring po

Bank Info Security
MEDIUMAi

Zscaler Targets AI Identity Risk With Symmetry Acquisition

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/zscaler-targets-ai-identity-risk-symmetry-acquisition-image_small-3-a-31766.jpg" align=right hspace=4><b>Startup Symmetry Systems Maps Relationships Across AI, SaaS and Cloud Assets</b><br>Zscaler plans to acquire San Francisco-based Symmetry Systems to unify visibility across AI models, identities, applications and datasets, help

Bank Info Security
MEDIUMVulnerability

Friday Squid Blogging: Regulating Squid Fishing in the South Pacific

The South Pacific Regional Fisheries Management Organization (SPRFMO) needs to regulate squid fishing in the South Pacific. As usual, you can also use this squid post to talk about the security stories in the news that I haven&#8217;t covered. Blog moderation policy.

Schneier on Security
MEDIUMVulnerability

Europe Again Delays Digital Sovereignty Push

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/europe-again-delays-digital-sovereignty-bill-image_small-1-a-31760.jpg" align=right hspace=4><b>The Package Is Either Not Yet Ready or Bumping Up Against American Objections</b><br>Europe for the third time delayed presenting its long-awaited Tech Sovereignty Package, legislation aimed at weaning the continent off American technol

Bank Info Security
MEDIUMAi

ISMG Editors: The Governance Questions Haunting OpenAI

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/ismg-editors-governance-questions-haunting-openai-image_small-7-a-31765.jpg" align=right hspace=4><b>Also: Rethinking SASE and AI's Impact on the Cyber Workforce</b><br>In this week's panel, four ISMG editors discussed what the Musk vs. Altman trial exposed about OpenAI's governance program, how AI is reshaping the way enterprises

Bank Info Security
MEDIUMPhishing

FBI warns about fast-growing phishing kit targeting Microsoft 365 users

Kali365, which was first observed in April, abuses legitimate Microsoft device authorization pages to grant persistent access to cybercriminal-controlled applications. The post FBI warns about fast-growing phishing kit targeting Microsoft 365 users appeared first on CyberScoop .

CyberScoop
LOWApt

FBI warns of Kali365 phishing-as-a-service after April Microsoft 365 attacks

The law enforcement agency published an advisory on Thursday about Kali365 — a Telegram-based service for cybercriminals that allows them to capture legitimate "OAuth" tokens enabling widespread access to Microsoft 365 environments.

The Record
MEDIUMVulnerability

Meta settles school district lawsuit claiming addictive design harmed students' mental health

The bellwether lawsuit was the first of at least 1,200 to be brought by a school district against Meta, Snap, YouTube and TikTok for similar alleged harms. The other cases have not yet been tried.

The Record
MEDIUMVulnerability

CVE-2026-9256 - &quot;nginx-poolslip&quot;, another new vulnerability in the rewrite module

[object Object]

CVE-2026-9256
r/netsec
LOWVulnerability

Metasploit Wrap Up 05/22/2026

Another week, another authentication bypass Our humble Metasploit weekly(ish) blog has been blessed with a new network component vulnerability. The dynamic duo of @sfewer-r7 and @jburgess-r7 have discovered and authored the admin/networking/cisco_sdwan_vhub_auth_bypass module for CVE-2026-20182, a vulnerability gracing the Cisco Catalyst SD-WAN Controller. The devices, whose purpose is to control

CVE-2026-20182CVE-2026-24479
Rapid7
MEDIUMMalware

23-Year-Old Canadian Charged in KimWolf Botnet Operation

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/23-year-old-canadian-charged-in-kimwolf-botnet-operation-image_small-7-a-31757.jpg" align=right hspace=4><b>DOJ Says KimWolf Powered Massive DDoS-for-Hire Operations</b><br>U.S. prosecutors charged a Canadian man accused of operating the KimWolf botnet, alleging the DDoS-for-hire platform compromised nearly two million IoT devices

Bank Info Security
MEDIUMVulnerability

Mastercard renews partnership with Egypt&#39;s CIB

Mastercard and CIB, Egypt’s leading and largest private-sector bank, have renewed their partnership to support digital payments innovation and expand access to financial solutions in Egypt.

Finextra
LOWApt

FBI warns of Kali Oauth stealers

The FBI has warned of the danger from a new wave of phishing attack s generated by a tool called Kali365. It enables cyber criminals to obtain Microsoft 365 access tokens and bypass multi-factor authentication (MFA) protocols without intercepting the user’s credentials by capturing Oauth tokens linked to the victim’s Microsoft 365 account. The scam works in a similar way to most phishing attacks .

CSO Online
HIGHRansomware

First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups

Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks. The disruption of First VPN Service was led by France and the Netherlands, with several other nations supporting the investigation since December

The Hacker News
MEDIUMVulnerability

HIPAA Certification for Business Associates

HIPAA certification for Business Associates is documented evidence that employees have completed training on HIPAA Privacy Rule, HIPAA Security Rule, [&#8230;] The post HIPAA Certification for Business Associates appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

Netherlands seizes 800 servers of hosting firm enabling cyberattacks

Financial crime investigators in the Netherlands (FIOD) arrested two men and seized 800 servers linked to a web hosting company that enabled cyberattacks, interference operations, and disinformation campaigns. [...]

BleepingComputer
MEDIUMVulnerability

Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure

Drupal is warning users that it has already seen attempts to exploit CVE-2026-9082 and security firms are seeing attacks against thousands of websites. The post Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure appeared first on SecurityWeek .

CVE-2026-9082
SecurityWeek
HIGHRansomware

Police take down VPN service (this time with a good reason)

European authorities have cracked down on a VPN that has been used for various criminal activities. The operation, led by investigators in France and the Netherlands with help from Europol and Eurojust, has dismantled First VPN, a service that has been heavily promoted within Russia as a way of evading law enforcement. Criminals used it to conceal their identities and infrastructure while carrying

CSO Online
CRITICALVulnerability

Water, the Soft Underbelly of Critical Infrastructure

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/water-soft-underbelly-critical-infrastructure-image_small-5-a-31758.jpg" align=right hspace=4><b>Fragmented Governance and Scarce Resources Make America's Water Sector Vulnerable</b><br>America's water utilities are the nation's most cyber-vulnerable critical service sector, but their cybersecurity is overseen and supported by an

Bank Info Security
MEDIUMAi

Everyone Suddenly Wants Claude's Audit Logs

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/everyone-suddenly-wants-claudes-audit-logs-image_small-6-a-31753.jpg" align=right hspace=4><b>27 Enterprises Integrate Claude's Compliance API</b><br>More than two dozen enterprise security vendors, including Microsoft, CrowdStrike and Palo Alto Networks, have built integrations with Anthropic's Claude Compliance API, an interface

Bank Info Security
HIGHData Breach

Radiology Associates of Richmond discloses second data breach; 266k people affected

On July 1, 2025, Radiology Associates of Richmond (&#8220;RAR&#8221;) reported a breach to HHS that had occurred in April 2024 and affected more than 1.4 million patients. By the end of July 2025, the well-known radiology practice had experienced a second breach. The second breach, recently reported to the Maine Attorney General&#8217;s Office on May... Source

DataBreaches.net
HIGHData Breach

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity &#038; Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The inquiry comes as CISA is still struggling to contain the breach and invalidate the leaked

Krebs on Security
MEDIUMVulnerability

Home Healthcare Agency Owner Facing Decades in Jail for $1.6M Medicare Fraud Scheme

The owner and operator of a Michigan home health care company has been convicted of five counts of healthcare fraud [&#8230;] The post Home Healthcare Agency Owner Facing Decades in Jail for $1.6M Medicare Fraud Scheme appeared first on The HIPAA Journal .

HIPAA Journal
CRITICALMalware

Ghostwriter Targets Ukraine Government Entities with Prometheus Phishing Malware

The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine's National Security and Defense Council) has been observed using lures related to Prometheus, a Ukrainian online learning platform, to target government organizations in the country. The activity, per the Computer Emergency Response Team of Ukraine (CERT-UA), involves sending phishing emails to government

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2022-34363 — Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authoriz...

Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the  Unisphere for VMAX application running in vApp

CVE-2022-34363
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2022-31231 — Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identi...

Dell ECS, versions 3.5 and 3.6, contain an Improper Access Control in the Identity and Access Management (IAM) module. A remote unauthenticated attacker may potentially exploit this vulnerability, leading to gaining read access to unauthorized data.

CVE-2022-31231
NIST NVD
MEDIUMVulnerability

Wealthtech Farther raises $150m

Wealth management platform Farther has hit unicorn status after raising $150 million in Series D funding led by General Atlantic.

Finextra
LOWAi

Microsoft says it’s making AI ‘safe for work’ in your browser

Microsoft is testing the addition of agentic AI to its corporate browser, Edge for Business . A new version, currently available in a limited preview, will help perform routine tasks more efficiently, according to Microsoft’s partner product manager for Edge, Lindsay Kubasik. Agentic AI will help with completing multi-step tasks such as filling in forms, navigating sites, or gathering information

CSO Online
MEDIUMVulnerability

Akamai Joins Growing Chorus of Vendors Betting Big on Secure Enterprise Browsers

When Akamai announced its LayerX acquisition, the company joined a growing list of vendors adding secure enterprise browsers to their product portfolios.

Dark Reading
HIGHData Breach

Datavant Group to Pay $900,000 to Settle Class Action Data Breach Lawsuit

A settlement has been agreed to resolve a class action lawsuit against Ciox Health, which does business as Datavant Group, [&#8230;] The post Datavant Group to Pay $900,000 to Settle Class Action Data Breach Lawsuit appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

Former US execs plead guilty to aiding tech support scammers

Two former executives of a call-tracking and analytics company pleaded guilty to concealing a years-long tech support fraud scheme that victimized individuals worldwide. [...]

BleepingComputer
MEDIUMVulnerability

Why the Supreme Court's Chatrie case could change the meaning of privacy in America

Lawyer Adam Unikowsky spoke with Recorded Future News about why he believes geofence searches are problematic and why the way the court rules could have a dramatic impact on Americans’ right to privacy.

The Record
MEDIUMMalware

Canadian man arrested, charged for running KimWolf DDos botnet

In court documents unsealed on Thursday, the Justice Department said Jacob Butler ran KimWolf as a DDoS-for-hire service that infected over a million devices worldwide.

The Record
MEDIUMVulnerability

Trump Mobile confirms it exposed customers’ personal data, unclear whether it will notify those affected

Lorenzo Franceschi-Bicchierai reports: Phone provider Trump Mobile has confirmed that it was exposing customers’ names, email addresses, mailing addresses, cell numbers, and order identifiers to the open internet. Chris Walker, a spokesperson for the Trump-branded phone maker, told TechCrunch that the company is investigating the exposure and has not found evidence that content or financial... Sou

DataBreaches.net
MEDIUMVulnerability

NAB refreshes app

NAB has unveiled a refreshed NAB app and Internet Banking experience, focused on helping customers to better manage and protect their money at a time when every dollar matters.

Finextra
HIGHVulnerability

NVD HIGH: CVE-2025-32749 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Informatio...

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

CVE-2025-32749
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2025-32747 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege As...

Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

CVE-2025-32747
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2025-26483 — Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vuln...

Dell PowerFlex Manager, versions 4.6.2 and prior, contains an Open Redirect Vulnerability. An unauthenticated attacker could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge sensitive information.

CVE-2025-26483
NIST NVD
MEDIUMMalware

In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking

Other noteworthy stories that might have slipped under the radar: CISA contractor exposes credentials, Mythos testing and new features, Huawei router flaw triggered telecom blackout. The post In Other News: Industrial Router Exploitation, CISA KEV Nomination Form, Gas Station Hacking appeared first on SecurityWeek .

SecurityWeek
HIGHData Breach

CISA Security Leak

Crazy story : Until this past weekend, a contractor for the Cybersecurity &#038; Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. Security experts said the public archive included files detailing how CISA builds, tests and deploys software internally,

Schneier on Security
LOWVulnerability

Proposed State Laws For Breach Notification Could Reshape Incident Response Plans

Joseph Lazzarotti of JacksonLewis writes: State breach-notification laws continue to evolve, and legislatures are using 2026 sessions to tighten consumer protections and shift the civil liability landscape that often follows a cyber event. For businesses, the practical takeaway is that incident response planning increasingly needs to account not only for “whether notice is required,” but... Source

DataBreaches.net
MEDIUMVulnerability

How a consultant and a concert pianist from the Netherlands were arrested on suspicion of aiding NoName057(16)

Officials allege that WorkTitans and MIRhosting were used to facilitate pro-Russian hackers and evade EU sanctions. Huib Modderkolk and Henrik Moltke write: Youssef Z. may have seen trouble coming. The 57-year-old entrepreneur and organizational consultant from Amsterdam, arrested at his home in the early hours of Monday 18 May by agents of the Dutch fiscal investigation... Source

DataBreaches.net
HIGHRansomware

Verus Hacker Returns $8.5M After Bridge Exploit Deal

Do those who say never to pay ransomware or hack-and-leak criminals because it encourages more crime also say never to pay those who hack crypto? If you negotiate with hackers to let them keep a percent of what they stole as a non-prosecutable &#8220;bounty,&#8221; aren&#8217;t you just creating more incentive for other criminals? Kenrodgers Fabian... Source

DataBreaches.net
MEDIUMSupply Chain

Hugging Face Hiding Second-Stage Malware for npm Supply Chain Attack

Tushar Subhra Dutta reports: Hackers have found a new and alarming way to weaponize one of the most trusted platforms in the AI world. A threat actor linked to North Korea has embedded second-stage malware inside Hugging Face, the widely used AI and machine learning hub, effectively turning it into a malware delivery channel and... Source

DataBreaches.net
HIGHData Breach

Hackers breach two Vietnamese ministerial systems in major cyberattack

Vietnamnet Global reports: Speaking at the Vietnam Security Summit 2026 on May 22, Lieutenant Colonel Tran Trung Hieu, Deputy Director of the National Cybersecurity Center and Director of VNCERT under the Ministry of Public Security’s Department of Cybersecurity and High-Tech Crime Prevention, said the agency is currently responding to two highly serious data breach incidents... Source

DataBreaches.net
MEDIUMVulnerability

SoFi buys lending tech platform Peach

US fintech SoFi has made its second acquisition in a matter of weeks, snapping up lending technology platform Peach. Financial terms were not disclosed.

Finextra
MEDIUMMalware

U.S. officials seeking extradition of Ottawa man accused of record cyberattack

Jordan Ercit reports: Jacob Butler, 23, who was arrested Wednesday by OPP, also facing aiding and abetting computer intrusion charge in Alaska A 23-year-old Ottawa man is facing extradition to the United States after being accused of involvement in massive cyberattacks that affected more than a million devices worldwide. Ontario Provincial Police said their cybercrime... Source

DataBreaches.net
MEDIUMVulnerability

Murphy measure to protect Illinois consumers’ sensitive data advances in Senate

From the Illinois Senate Democrats: State Senator Laura Murphy is leading a comprehensive measure to protect consumers’ data and shield them from targeted advertisements. “By placing guardrails around consumers’ personal information, we eliminate companies’ ability to collect and sell the most sensitive data of Illinoisans,” said Murphy (D-Des Plaines). “We then put the power in... Source

DataBreaches.net
CRITICALZero Day

Trend Micro warns of Apex One zero-day exploited in the wild

Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. [...]

BleepingComputer
HIGHData Breach

May 2026 Data Breach Round Up: Data Breaches Affect 9 HIPAA-regulated Entities

A round-up of data breaches recently announced by 9 HIPAA-regulated entities: University of Nebraska Medical Center, Singing River Health System, [&#8230;] The post May 2026 Data Breach Round Up: Data Breaches Affect 9 HIPAA-regulated Entities appeared first on The HIPAA Journal .

HIPAA Journal
MEDIUMVulnerability

Raqami Islamic Digital Bank granted commercial license by State Bank of Pakistan

Raqami Islamic Digital Bank Limited (RIDBL) has been granted a Digital Retail Banking License by the State Bank of Pakistan for commencement of Commercial Operations, marking a significant milestone as Raqami becomes the first fully digital Shariah-compliant retail bank in Pakistan.

Finextra
MEDIUMVulnerability

TBC Georgia adds crypto trading to banking app

TBC Georgia, a leading financial services provider in the South Caucasus country and part of London-listed TBC Bank Group, announces the launch of a new cryptocurrency trading feature in its digital banking app.

Finextra
HIGHData Breach

Radiology Associates of Richmond Data Breach Affects 266K Individuals

Radiology Associates of Richmond in Virginia, one of the oldest, continuously operating private radiology practices in the United States, has [&#8230;] The post Radiology Associates of Richmond Data Breach Affects 266K Individuals appeared first on The HIPAA Journal .

HIPAA Journal
HIGHRansomware

Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks

Ransomware and vendor breaches persist, but the 2026 Data Breach Investigations Report (DBIR) highlights how evolving social engineering tactics make the sector more vulnerable.

Dark Reading
CRITICALVulnerability

NVD CRITICAL: CVE-2026-44930 — An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS s...

An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.  Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

CVE-2026-44930
NIST NVD
CRITICALVulnerability

Drupal: Critical SQL injection flaw now targeted in attacks

Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week. [...]

BleepingComputer
MEDIUMVulnerability

Why Chargebacks are Just One Piece of the Fraud Puzzle

Fraud losses don't stop at chargebacks. False declines, account takeovers, and abuse also damage revenue and trust. IPQS breaks down why fraud teams need broader visibility into risk and customer impact. [...]

BleepingComputer
MEDIUMApt

Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns

Unit 42 details Screening Serpens' use of AppDomainManager hijacking and new RAT variants to target tech and defense sectors in recent campaigns. The post Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns appeared first on Unit 42 .

Unit 42 (Palo Alto)
MEDIUMMalware

Canadian Man Arrested for Operating Kimwolf Botnet

Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges. The post Canadian Man Arrested for Operating Kimwolf Botnet appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Boerse Stuttgart and SocGen partner for digital securities settlement platform

Seturion, Boerse Stuttgart Group's European settlement platform for tokenized securities, today announced a strategic partnership with flatexDEGIRO, Societe Generale, and SG-FORGE, on a clear path to expand its network of leading financial institutions across Europe and to advance digital blockchain-based securities settlement.

Finextra
MEDIUMVulnerability

Ubiquiti patches three max severity UniFi OS vulnerabilities

Ubiquiti has released security updates to patch three maximum severity vulnerabilities in Unify OS that can be exploited by remote attackers without privileges. [...]

BleepingComputer
MEDIUMVulnerability

UK parliament receives Financial Services bill

The UK government has taken the first step in its plan to overhaul and update financial regulation after introducing the Financial Services and Markets bill before Parliament.

Finextra
LOWVulnerability

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window. "Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded bash payloads that exfiltrate CI

The Hacker News
MEDIUMVulnerability

Making Vulnerable Drivers Exploitable Without Hardware - The BYOVD Perspective

1 Introduction This article provides a technical analysis of how many Windows kernel mode drivers can be interacted with from user mode without the hardware they were developed for. This work was motivated by driver-oriented vulnerability research and the need to evaluate the exploitability of individual findings, which frequently affect code whose reachability is hardware-gated. The

The Hacker News
MEDIUMAi

Fake Gemini and Claude Code Sites Spread Infostealers Through SEO Poisoning

The infostealer payload in this campaign collect a vast amount of data, from collaboration authentication keys to cryptocurrency wallets

Infosecurity Magazine
HIGHVulnerability

NVD HIGH: CVE-2026-5308 — Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11....

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP endpoints which allows an attacker to cause a denial of service via crafted oversized HTTP requests.. Mattermost Advisory ID: MMSA-2026-00646

CVE-2026-5308
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-3473 — Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11....

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or teams via crafted Boards API requests using valid file IDs.. Mattermost Advisory ID: MMSA-2026-00620

CVE-2026-3473
NIST NVD
HIGHSupply Chain

We hardened zizmor's GitHub Actions static analyzer

<p>In March 2026, attackers exploited a <code>pull_request_target</code> misconfiguration in the <a href="https://github.com/aquasecurity/trivy-action"><code>aquasecurity/trivy-action</code></a> GitHub Action to exfiltrate organization and repository secrets, then used those credentials to backdoor <a href="https://github.com/BerriAI/litellm">LiteLLM</a> on PyPI (see <a href="https://github.com/aq

Trail of Bits
LOWVulnerability

Standard Chartered backtracks on &#39;lower value human capital&#39; comments

The boss of British bank Standard Chartered has been forced to clarify comments he made when announcing the loss of 7,800 jobs which are set to be replaced by AI.

Finextra
MEDIUMVulnerability

William Blair recruits fintech banker for London team

William Blair announced today the addition of Rishi Sethi as a London-based managing director in the firm’s global Technology team.

Finextra
MEDIUMVulnerability

Mizuho launches global fintech ops centre in Pune

Mizuho Global Services India Pvt. Ltd., the Global Capabilities Center arm (Mizuho GCC) of Mizuho Financial Group, one of the world’s leading financial institutions, today announced the launch of its new Global Capabilities Center in Pune, India (Pune GCC).

Finextra
MEDIUMVulnerability

Apple Blocked $2.2bn in App Store Fraud in the Last Year

Total figure for fraudulent transactions Apple has blocked since 2020 now stands at over $11bn

Infosecurity Magazine
MEDIUMVulnerability

Paved With Intent: ROADtools and Nation-State Tactics in the Cloud

Open-source framework ROADtools is being misused by threat actors for cloud intrusions. Learn how to identify its malicious use. The post Paved With Intent: ROADtools and Nation-State Tactics in the Cloud appeared first on Unit 42 .

Unit 42 (Palo Alto)
CRITICALRansomware

Why your AI strategy stops where the PLC starts: Hard lessons from the OT frontlines

I spent two days at a substation connecting a major offshore wind farm to the grid. The control room featured three new AI-ready dashboards and a board mandate to “leverage machine learning for resilience.” It also had a maintenance laptop running Windows 7, literally taped to the inside of a cabinet because the Velcro had failed. That laptop was the only device in the building that could still ta

CSO Online
MEDIUMVulnerability

Centenary Group and Huawei partner for banking inclusion project in Uganda

Uganda-based financial institution Centenary Group has teamed up with Huawei Uganda for an initiative designed to use AI and other technologies to extend banking services to the country's rural population.

Finextra
HIGHRansomware

&#8216;First VPN&#8217; Cybercrime Service Disrupted, Administrator Arrested

The FBI says First VPN has been used by dozens of ransomware groups for network reconnaissance and intrusions. The post &#8216;First VPN&#8217; Cybercrime Service Disrupted, Administrator Arrested appeared first on SecurityWeek .

SecurityWeek
MEDIUMVulnerability

Future Processing upgrades claims management platform

Future Processing, a leading software development and technology consulting company, has today announced plans to scale futureClaims™, a claims modernisation platform built specifically for insurance organisations seeking to modernise without migration.

Finextra
HIGHVulnerability

NVD HIGH: CVE-2026-9011 — The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is ...

The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.1.65. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to retrieve the full item content of non-public Dittys — including drafts, pending, sched

CVE-2026-9011
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8679 — The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Re...

The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 2.0.2. This is due to the handle_playlist_endpoint() function (hooked to template_redirect) accepting a user-controlled playlist ID via the audioigniter_playlist_id query var or the /audioigniter/playlist/{id}/ rewrite rule and returning playlist track data without performing a

CVE-2026-8679
NIST NVD
MEDIUMApt

Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload

The experienced Cloud Atlas group remains active, continuing to target government sectors and diplomatic entities in Russia and Belarus, employing both new and established techniques to maintain persistence in compromised systems.

Securelist (Kaspersky)
MEDIUMMalware

US and Canada arrest and charge suspected Kimwolf botnet admin

U.S. and Canadian authorities arrested and charged a Canadian man with operating the KimWolf distributed denial-of-service (DDoS) botnet, which infected nearly two million devices worldwide. [...]

BleepingComputer
CRITICALRansomware

Identity as the primary attack surface: What modern breaches are really exploiting

The “retro” way “The thing about the old days is… they are the old days” – Slim Charles , The Wire Protecting a specified network perimeter was the main focus of enterprise security strategy for several decades. Businesses made significant investments in firewalls, intrusion detection systems, endpoint security and segmentation controls, all of which were built on the premise that an organization

CSO Online
MEDIUMVulnerability

EBAday 2026 Fintech Zone unveils 16 finalists set to pitch in Copenhagen

After reviewing a strong field of entries from across the fintech landscape, 16 innovative companies have been selected to pitch their solutions live to a panel of judges and senior banking executives at EBAday in Copenhagen, Denmark on 16 and 17 June 2026. Here’s all you need to know about Europe’s most innovative fintech startups and the organisations most likely to shape the future of payments.

Finextra
MEDIUMMalware

Kimwolf DDoS Botnet Operator Arrested in Canada Over DDoS-for-Hire Attacks

The U.S. Department of Justice (DoJ) on Thursday announced the arrest of a Canadian man in connection with allegedly operating a distributed denial-of-service (DDoS) botnet known as Kimwolf. In tandem, Jacob Butler (aka Dort), 23, Ottawa, Canada, has been charged with offenses related to the development and operation of the botnet. Kimwolf is assessed to be a variant of AISURU. "Kimwolf

The Hacker News
LOWVulnerability

Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise

Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to steal money and personal data

WeLiveSecurity (ESET)
CRITICALZero Day

TrendAI Patches Apex One Zero-Day Exploited in the Wild

CVE-2026-34926 is a directory traversal flaw that can be exploited against the on-premise version of Apex One. The post TrendAI Patches Apex One Zero-Day Exploited in the Wild appeared first on SecurityWeek .

CVE-2026-34926
SecurityWeek
HIGHData Breach

Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack

Hackers accessed Grafana’s GitHub repositories after a token compromised in the TanStack attack was not rotated. The post Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack appeared first on SecurityWeek .

SecurityWeek
LOWAi

Google folds CodeMender into agent ecosystem amid push for AI-led AppSec

Google is expanding the role of its CodeMender security agent from autonomous vulnerability remediation toward a larger agentic development ecosystem, signalling a broader push toward AI-driven AppSec. Months after introducing CodeMender, an AI-powered agent designed to autonomously identify and patch software vulnerabilities, Google is now integrating the technology into its expanding Agent Platf

CSO Online
MEDIUMVulnerability

China's Webworm Uses Discord, Microsoft Graphs to Hack EU Governments

The advanced persistent threat group also relied on SOCKS proxies like SoftEther VPN, tunneling tools that act as a middleman between victim and attacker.

Dark Reading
MEDIUMVulnerability

China's Webworm Uses Discord, Microsoft Graphs to Hack EU Govts.

The advanced persistent threat group also relied on SOCKS proxies like SoftEther VPN, tunneling tools that act as a middleman between victim and attacker.

Dark Reading
MEDIUMSupply Chain

Cross-Platform NPM Stealer, (Fri, May 22nd)

I found a Node.js stealer that looked pretty well obfuscated. The file was not running out-of-the-box because it was uploaded on VT as &#xe2;&#x80;&#x9c;extracted-decoded.js&#xe2;&#x80;&#x9d; (and reformated). The SHA256 is 049300aa5dd774d6c984779a0570f59610399c71864b5d5c2605906db46ddeb9&#x5b;1&#x5d;. It did not run properly in a sandbox so only a static analysis was performed.&#xd;

SANS ISC
LOWVulnerability

CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are listed below - CVE-2025-34291 (CVSS score: 9.4) - An origin validation error vulnerability in Langflow that could

CVE-2025-34291
The Hacker News
LOWVulnerability

Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access

Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CVSS score: 10.0), the vulnerability arises from insufficient validation and authentication when accessing REST API endpoints. "An attacker could exploit this vulnerability if they are able to send

CVE-2026-20223
The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2026-9018 — The Easy Elements for Elementor – Addons & Website Templates plugin for WordPres...

The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.5 via the `easyel_handle_register()` function. This is due to the `wp_ajax_nopriv_eel_register` AJAX handler iterating the attacker-controlled `custom_meta` POST array and writing every supplied key-value pair to the newly created user's

CVE-2026-9018
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-4834 — The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'sear...

The WP ERP Pro plugin for WordPress is vulnerable to SQL Injection via the 'search_key' parameter in all versions up to, and including, 1.5.1. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be

CVE-2026-4834
NIST NVD
HIGHVulnerability

CISA KEV: Drupal Core — Drupal Core SQL Injection Vulnerability

Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API.

CVE-2026-9082Drupal Core
CISA KEV
MEDIUMMalware

Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada

Jacob Butler, a 23-year-old from Ottawa, awaits extradition to the United States and faces up to 10 years in prison. The post Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada appeared first on CyberScoop .

CyberScoop
MEDIUMAi

Mythos-Level AI Is Creating a Tech Debt Crisis

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/mythos-level-ai-creating-tech-debt-crisis-image_small-10-a-31750.jpg" align=right hspace=4><b>Advanced AI Models Find More Holes Than Enterprise Security Teams Can Plug</b><br>Artificial intelligence models such as Anthropic's Mythos are rapidly exposing decades of hidden software security debt, forcing CIOs and CISOs to rethink v

Bank Info Security
MEDIUMVulnerability

New Jamf CEO Sees AI Advances as Apple Security Driver

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/new-jamf-ceo-sees-ai-advances-as-apple-security-driver-image_small-3-a-31749.jpg" align=right hspace=4><b>CEO Beth Tschida: AI Developers' Apple Preference Could Strengthen Jamf's Position</b><br>Chief Technology Officer Beth Tschida takes over as CEO of Minneapolis-based Jamf with a mandate to define how the Apple management and

Bank Info Security
MEDIUMVulnerability

State Officials Urge Congress to Renew Cyber Grant Program

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/state-officials-urge-congress-to-renew-cyber-grant-program-image_small-6-a-31748.jpg" align=right hspace=4><b>Officials Warn Local Governments Lack Resources to Counter Advanced Threats</b><br>State cybersecurity officials warned Congress that Chinese-linked intrusions and rapidly advancing artificial intelligence systems are over

Bank Info Security
HIGHData Breach

Breach Roundup: Shai-Hulud Copycat Hits npm

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/breach-roundup-shai-hulud-copycat-hits-npm-image_small-1-a-31747.jpg" align=right hspace=4><b>Also, YellowKey Gets CVE, 7-Eleven Breach, Linux Maintainers Warn on AI Bug Spam</b><br>This week, more incidents that we can here list. Among them: cloned Shai-Hulud malware, a new maximum CVSS Cisco flaw. Edge to stop loading passwords

Bank Info Security
HIGHData Breach

Hackers steal patient and billing data from German hospitals via third-party provider

The large-scale data breach reportedly hit Unimed, a company that handles billing services for privately insured and self-paying patients on behalf of numerous German hospitals.

The Record
MEDIUMApt

Belarus-linked hackers use fake training certificates to target Ukrainian officials

A Belarus-linked hacking group known as GhostWriter has launched a new espionage campaign against Ukrainian government officials using fake emails disguised as messages from a popular online learning platform to deliver malware.

The Record
CRITICALVulnerability

Critical vulnerability in Cisco Secure Workload rated at maximum severity

A critical vulnerability in the on-premises version of the Cisco Secure Workload security platform could allow a threat actor to obtain the privileges of a site admin, enabling them to compromise endpoints and read or modify configuration data. “CSOs need to drop what they are doing and patch this immediately,” warned consultant Robert Enderle , who heads the Enderle Group. “Cisco Secure Workload

CVE-2026-20223
CSO Online
HIGHVulnerability

NVD HIGH: CVE-2026-8434 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescanMultiple(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.

CVE-2026-8434
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8433 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file rescan(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.

CVE-2026-8433
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8432 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file star(). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.

CVE-2026-8432
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8427 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file removeFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.

CVE-2026-8427
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8416 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/backend/file addFavoriteFolder($id). The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.

CVE-2026-8416
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8415 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/express/association/reorder. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.

CVE-2026-8415
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8414 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/event/duplicate. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.

CVE-2026-8414
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8413 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.

CVE-2026-8413
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8412 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/cache. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.

CVE-2026-8412
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8411 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/delete. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.

CVE-2026-8411
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8410 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/bulk/delete.  The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.

CVE-2026-8410
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8409 — Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) a...

Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/logs/delete.  The The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 2.3 with vector CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N. Thanks Yonatan Drori (Tenzai) for reporting.

CVE-2026-8409
NIST NVD
CRITICALVulnerability

NVD CRITICAL: CVE-2026-6960 — The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file upload...

The BookingPress Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'bookingpress_validate_submitted_booking_form_func' function in all versions up to, and including, 5.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulne

CVE-2026-6960
NIST NVD
CRITICALZero Day

Microsoft patches two zero-day flaws in Defender

Microsoft released emergency fixes for two zero-day vulnerabilities in the malware protection components of Microsoft Defender. The flaws allow local attackers to gain system-level privileges or cause the anti-malware service to stop working correctly. Both conditions are valuable in a malware attack, first to prevent detection if the system relies only on Microsoft endpoint protection and second

CVE-2026-41091CVE-2026-45498
CSO Online
MEDIUMMalware

Alleged Kimwolf Botmaster &#8216;Dort&#8217; Arrested, Charged in U.S. and Canada

Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity publicly named the suspect in February 2026 after the accused launched a volley of DDoS,

Krebs on Security
CRITICALAi

Unpatched ChromaDB flaw leaves servers open to remote code execution

Researchers have published details about a critical vulnerability in ChromaDB that could allow unauthenticated attackers to execute arbitrary code and access sensitive data on machines running the open-source vector database. The issue, tracked as CVE-2026-45829, is located in ChromaDB’s API server and was published by researchers at HiddenLayer after reportedly failing to get in contact with the

CVE-2026-45829
CSO Online
HIGHVulnerability

NVD HIGH: CVE-2026-8428 — Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.ph...

Concrete CMS 9.5.0 and below emits a CSRF token in the local_available_update.php view ($token->output('do_update')) but the corresponding do_update() method in concrete/controllers/single_page/dashboard/system/update/update.php never calls $this->token->validate('do_update'). The form is rendered as a POST form, meaning the token reaches the browser, but because the controller discards it without

CVE-2026-8428
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8426 — Concrete CMS 9.5.0 and below does not validate a CSRF token before processing re...

Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/prepare_remote_upgrade/<remoteMPID>. An attacker who controls the remote package returned for a known marketplace item ID can overwrite the package PHP on disk and force its upgrade() method to execute in a single browser navigation. This results in remote code execution as the web se

CVE-2026-8426
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8421 — Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_packag...

Concrete CMS 9.5.0 and below contains a CSRF vulnerability in the install_package() method of concrete/controllers/single_page/dashboard/extend/install.php.  An attacker who can cause an authenticated administrator to visit a crafted page,  and who has placed or caused a package to be present under DIR_PACKAGES/<handle>/, can force the installation of that package without any CSRF protection. Pack

CVE-2026-8421
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8417 — Concrete CMS 9.5.0 and below does not validate a CSRF token before processing re...

Concrete CMS 9.5.0 and below does not validate a CSRF token before processing requests to /dashboard/extend/update/do_update/<pkgHandle>. The do_update() method in concrete/controllers/single_page/dashboard/extend/update.php checks only canInstallPackages() before executing upgradeCoreData() and upgrade() on the named package's controller. Because the endpoint is a state-changing GET route with no

CVE-2026-8417
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8350 — Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_...

Concrete CMS 9.5.0 and below is vulnerable to missing authorization in the bulk_user_assignment.php which can lead to privilege escalation to Administrative Group. Any authenticated user with access to the bulk user assignment dashboard page can add any user email to any group and can remove legitimate admins. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 score of 7.5 with ve

CVE-2026-8350
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8135 — Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to inse...

Concrete CMS 9.5.0 and below is vulnerable to Remote Code Execution due to insecure deserialization occurring in the ExpressEntryList block controller. An rogue administrator with privileges to add blocks to an area can bypass the intended protection mechanism (_fromCIF === true), which normally restricts malicious inputs over form POST requests, by leveraging the REST API functionality. Because

CVE-2026-8135
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-8134 — Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the p...

Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue administrator with composer form editing rights can exploit this to include arbitrary readable files on the server. Combined with the file uploader's extension-only validation (which permits PHP code in

CVE-2026-8134
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-47102 — LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /us...

LiteLLM prior to 1.83.10 allows a user to modify their own user_role via the /user/update endpoint. While the endpoint correctly restricts users to updating only their own account, it does not restrict which fields may be changed. A user who can reach this endpoint can set their role to proxy_admin, gaining full administrative access to LiteLLM including all users, teams, keys, models, and prompt

CVE-2026-47102
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-47101 — LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API key...

LiteLLM prior to 1.83.14 allows an authenticated internal_user to create API keys with access to routes that their role does not permit. When generating a key, the allowed_routes field is stored without verifying that the specified routes fall within the user's own permissions. A key created with access to admin-only routes can then be used to reach those routes successfully, bypassing the role-ba

CVE-2026-47101
NIST NVD
MEDIUMAi

How CISOs Should Prep for Agentic-Ready AI BOMs

Finding ways to document both component and execution attributes for AI bill of materials (AI BOM).

Dark Reading
MEDIUMSupply Chain

Hijacked npm Package Attempts to Deliver PolinRider-Linked RAT

<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/hijacked-npm-package-attempts-to-deliver-polinrider-linked-rat" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/blog_npm_hijack2.jpg" alt="Image with large text at center "npm package hijack" and the Sonatype company name above it." class="hs-featured-image" style="width:auto !important

Sonatype (Maven/npm)
HIGHVulnerability

NVD HIGH: CVE-2026-47114 — IINA before 1.4.3 contains a user-assisted command execution vulnerability that ...

IINA before 1.4.3 contains a user-assisted command execution vulnerability that allows remote attackers to execute arbitrary commands by supplying malicious mpv_-prefixed query parameters through the iina://open custom URL scheme handler. Attackers can deliver a crafted URL via a browser that passes unvalidated mpv_options/input-commands parameters into the mpv runtime, causing arbitrary command e

CVE-2026-47114
NIST NVD
MEDIUMVulnerability

Google API Keys Remain Active After Deletion

A security researcher discovered the API keys can still be used for 23 minutes after deletion, even though the cloud provider claims deletion is immediate.

Dark Reading
CRITICALVulnerability

Lawmakers from both parties say CISA cuts have gone too far

Reps. Don Bacon, R-Neb., and James Walkinshaw, D-Va., found rare bipartisan agreement that the agency tasked with defending civilian networks has been diminished at a moment when threats from China and others are growing. The post Lawmakers from both parties say CISA cuts have gone too far appeared first on CyberScoop .

CyberScoop
MEDIUMVulnerability

Tech giants promise British regulator they will tweak platforms to protect kids online

The regulator, Ofcom, had required Roblox, Snapchat, Instagram, Facebook, YouTube and TikTok to answer questions about their efforts to remove harmful algorithms, check kids’ ages and protect them from sexual predators by the end of April.

The Record
MEDIUMVulnerability

OnDemand | What we got wrong about AI in the public sector

<b>A fireside chat with Elastic and IDC</b><br>Join IDC and Elastic for a fireside chat about the assumptions, missteps, and surprises that have shaped AI adoption in government and public sector organizations.

Bank Info Security
MEDIUMZero Day

Trump postpones executive order focused on AI security

Under a draft executive order, the NSA, Treasury Department and other federal agencies would get 90-days to test new models for cybersecurity and national security concerns. The post Trump postpones executive order focused on AI security appeared first on CyberScoop .

CyberScoop
HIGHVulnerability

NVD HIGH: CVE-2026-48242 — Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection cre...

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host, username, password, database name) in import_mdb.php. The credentials are embedded in source code committed to the public repository, allowing any reader of the source to obtain valid configuration values that may match deployed installations.

CVE-2026-48242
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48241 — Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in...

Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a public-facing database utility) that are committed to the source repository. Any actor with access to the public source tree (or an unauthenticated attacker with read access to the file on a deployed installation) can read the username, password, and database name and use them to connect to the database

CVE-2026-48241
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48240 — Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/s...

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/statistics.php where the tick_id and f_tick_id POST parameters are concatenated into WHERE clauses of SELECT statements in the statistics rollup queries without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

CVE-2026-48240
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48239 — Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/r...

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/reports.php where the tick_id POST parameter is concatenated into the WHERE clause of SELECT statements in the incidents summary report without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

CVE-2026-48239
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48238 — Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/m...

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/mobile_main.php where the id GET parameter is concatenated into the WHERE clause of a SELECT statement used as a ticket-existence sanity check without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

CVE-2026-48238
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48237 — Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in messag...

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in message.php where the frm_ticket_id and frm_resp_id POST parameters are concatenated into WHERE clauses of SELECT/UPDATE statements without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

CVE-2026-48237
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48236 — Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in db_loa...

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in db_loader.php where the multiple POST parameters (ticketsdb, ticketshost, ticketsuser, ticketspassword) are concatenated into mysqli connection arguments and dynamic SQL operating against an attacker-controlled database without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modif

CVE-2026-48236
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48235 — Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in incs/r...

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in incs/remotes.inc.php where latitude, longitude, callsign, mph, altitude, and timestamp values parsed from external GPS tracking service XML/JSON responses (InstaMapper and Google Latitude integration) are concatenated into UPDATE and INSERT statements without sanitization. An attacker able to compromise or impersonate the re

CVE-2026-48235
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48234 — Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in portal...

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in portal/ajax/list_requests.php where the sort and dir GET parameters are concatenated into the ORDER BY clause of a SELECT statement without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

CVE-2026-48234
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48233 — Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/s...

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/sit_incidents.php where the offset GET parameter is concatenated into the LIMIT clause of a SELECT statement without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

CVE-2026-48233
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48232 — Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/f...

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in ajax/fullsit_incidents.php where the offset GET parameter is concatenated into the LIMIT clause of a SELECT statement without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

CVE-2026-48232
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2026-48231 — Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in tables...

Open ISES Tickets before 3.44.2 contains a SQL injection vulnerability in tables.php where the multiple POST parameters (tablename, indexname, sortby) are concatenated into table/column identifiers in dynamically constructed SELECT/UPDATE/DELETE statements without sanitization. Authenticated attackers can craft requests that alter query semantics to read, modify, or destroy database contents.

CVE-2026-48231
NIST NVD
LOWVulnerability

Google accidentally exposed details of unfixed Chromium flaw

Google has accidentally leaked details about an unfixed issue in Chromium that keeps JavaScript running in the background even when the browser is closed, allowing remote code execution on the device. [...]

BleepingComputer
MEDIUMVulnerability

Two Americans plead guilty to assisting India-based tech support scam centers

Adam Young, 42, and Harrison Gevirtz, 33, pleaded guilty to misprision of a felony after they were accused of offering phone numbers, call routing services, call tracking tools and call forwarding services to India-based telemarketing fraudsters.

The Record
MEDIUMVulnerability

One Inc appoints Kishore Konakanchi chief product officer

One Inc, the leading digital payments network for the insurance industry, today announced the appointment of Fintech veteran Kishore Konakanchi as the company’s new Chief Product Officer (CPO).

Finextra
MEDIUMVulnerability

The art of being ungovernable

In this edition of the Threat Source newsletter, William explores the value of being "ungovernable" in a professional setting, sharing how challenging the status quo and seeking out the smartest people in the room can lead to a more fulfilling and successful career.

Cisco Talos
MEDIUMVulnerability

Cryptohack Roundup: US Extradition of Accused in $340M Scam

<img src="https://ismg-cdn.nyc3.cdn.digitaloceanspaces.com/articles/cryptohack-roundup-us-extradition-accused-in-340m-scam-image_small-5-a-31741.jpg" align=right hspace=4><b>Also: Hackers Stole From Verus Bridge, ThorChain and Echo Protocol</b><br>This week, Forsage's co-founder was extradited to the U.S. over a $340M scam, hackers stole from Verus Bridge, ThorChain and Echo Protocol, ZachXBT alle

Bank Info Security
HIGHRansomware

Operation Saffron: Bitdefender Joins “First VPN” Takedown

Bitdefender reports: An international law enforcement operation led by France and the Netherlands dismantled First VPN, a cybercriminal anonymization service used by ransomware actors, fraudsters, and data thieves across every major cybercrime investigation Europol has supported in recent years. Bitdefender supported the investigation through Europol, helping generate intelligence that exposed hun

DataBreaches.net
MEDIUMVulnerability

Kaspersky, Group-IB Detail Role in INTERPOL Cyber Operation Involving Morocco

Adil Faouzi reports: Global cybersecurity firms Kaspersky and Group-IB have disclosed their contributions to Operation Ramz, the first large-scale cybercrime crackdown coordinated by INTERPOL across the Middle East and North Africa region. The operation, which ran from October 2025 to February 2026, brought together 13 countries and resulted in 201 arrests, with 382 additional suspects... Source

DataBreaches.net
HIGHRansomware

Defenders fall behind, as AI rewrites the rules of a data breach

For almost 20 years, stolen credentials have been the most common route for attackers into organizations, according to the Verizon Data Breach Investigations Report (DBIR). But that's no longer the case. Read more in my article on the Fortra blog.

Graham Cluley
MEDIUMMalware

CISA chief frets about open-source vulnerabilities, delayed security improvements

Acting director Nick Andersen’s comments came as a wave of malware attacks hit tech that’s publicly available for collaboration. The post CISA chief frets about open-source vulnerabilities, delayed security improvements appeared first on CyberScoop .

CyberScoop
MEDIUMAi

Snyk announces Anthropic updates: Evo integrates with Claude Enterprise, and Snyk Desk comes to Claude Desktop

Snyk announces two new integrations with Anthropic that cover both sides of AI-assisted development. Evo by Snyk now integrates with Anthropic's Claude Enterprise, and the Snyk Security Desktop Extension is now available in Claude for macOS and Windows.

Snyk
MEDIUMVulnerability

Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks

[object Object]

CVE-2026-26980
r/blueteamsec
HIGHRansomware

European authorities take down prolific cybercrime VPN service

Officials arrested the alleged administrator of First VPN, seized its servers and domains. Europol said the service appeared in almost every major recent cybercrime investigation. The post European authorities take down prolific cybercrime VPN service appeared first on CyberScoop .

CyberScoop
MEDIUMAi

macOS Kernel Memory Corruption Exploit

A group used Anthropic&#8217;s Mythos AI model to help find a kernel memory corruption vulnerability and exploit on Apple&#8217;s M5. News article .

Schneier on Security
MEDIUMVulnerability

CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox

[object Object]

CVE-2026-40369
r/cybersecurity
MEDIUMVulnerability

CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat

[object Object]

CVE-2026-34474
r/netsec
MEDIUMAi

AI Agents Are Shifting Identity Security Budget Dynamics

AI agent projects are proliferating throughout the enterprise, and those AI agent identities require management, security, and governance. New Omdia research shows the AI agent identity budget dynamics are very different than traditional IAM projects.

Dark Reading
MEDIUMSupply Chain

The npm Threat Landscape: Attack Surface and Mitigations (Updated May 21)

Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more. The post The npm Threat Landscape: Attack Surface and Mitigations (Updated May 21) appeared first on Unit 42 .

Unit 42 (Palo Alto)
HIGHRansomware

Cybercriminal VPN Dismantled in Europol Crackdown

First VPN, a service used by ransomware actors and fraudsters, was dismantled by Europol

Infosecurity Magazine
MEDIUMVulnerability

Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)

[object Object]

CVE-2026-9082
r/netsec
MEDIUMVulnerability

Apple blocked over $11 billion in App Store fraud in 6 years

Apple revealed that it blocked over $11 billion in fraudulent App Store transactions over the last six years, more than $2.2 billion in potentially fraudulent App Store transactions in 2025 alone. [...]

BleepingComputer
MEDIUMVulnerability

UK plans for cybercrime law reform would protect almost no one, experts warn

The proposals would require researchers to cease activity the moment a vulnerability is identified, meaning they could not confirm it was real, assess its severity or determine its exploitability.

The Record
MEDIUMVulnerability

GitHub Breach Traced to Malicious 'Nx Console' VS Code Extension

A threat actor compromised an Nx developer and posed as a legitimate maintainer to publish a malicious extension on Visual Studio Marketplace

Infosecurity Magazine
MEDIUMMalware

Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor

Cybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use in a campaign targeting a telecommunications provider in the Middle East since at least mid-2022. "Showboat is a modular post-exploitation framework designed for Linux systems, capable of spawning a remote shell, transferring files, and functioning as a SOCKS5 proxy," Lumen

The Hacker News
HIGHVulnerability

NVD HIGH: CVE-2025-13479 — Authorization bypass through User-Controlled key vulnerability in PosCube Hardwa...

Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu allows Exploitation of Trusted Identifiers. This issue affects QR Menu: through 21052026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-13479
NIST NVD
HIGHVulnerability

NVD HIGH: CVE-2025-13477 — Exposure of private personal information to an unauthorized actor, Insufficientl...

Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass. This issue affects WifiBurada: through 21052026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2025-13477
NIST NVD
MEDIUMPhishing

Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet

Modern crypto drainers don't hack wallets. They trick users into approving malicious transactions. Flare explores how the Lucifer DaaS platform scales wallet theft through phishing and automation. [...]

BleepingComputer
MEDIUMApt

Chinese hackers target telcos with new Linux, Windows malware

A Chinese cyber-espionage campaign has been targeting telecommunications providers with newly discovered Linux and Windows malware dubbed Showboat and JFMBackdoor, respectively. [...]

BleepingComputer