Aggregator
CVE-2026-31979: The Symlink Trap — Root Privilege Escalation in Himmelblau
Interlock Ransomware Targets Cisco Enterprise Firewalls
Your Endpoint Management Platform Is the New Battleground
A New Class of Attack: No Malware, No Zero-Days, No Warning In early 2026, a pattern of attacks emerged that […]
The post Your Endpoint Management Platform Is the New Battleground appeared first on HawkEye.
CVE-2026-4500 | bagofwords1 bagofwords up to 0.0.297 code_execution.py generate_df injection (Issue 60)
Submit #773890: https://bagofwords.com/ bagofwords <=0.0.297 Remote command execution [Accepted]
Google slows Android sideloading to trip up scammers
Google’s advanced flow for Android changes how apps from unverified developers are installed, adding steps to reduce scam-driven sideloading. The feature is aimed at experienced users and allows sideloading through a controlled, one-time setup. It addresses scam scenarios where attackers pressure individuals to install malicious software. In these cases, scammers often stay on the phone and guide victims step by step, pushing them to bypass security warnings and disable protections before they can pause or … More →
The post Google slows Android sideloading to trip up scammers appeared first on Help Net Security.
Ушёл из жизни Сергей Минеев — легендарный охотник за APT-группировками
CVE-2026-33135 | LabRedesCefetRJ WeGIA up to 3.6.6 novo_memorandoo.php msg cross site scripting (GHSA-w5rv-5884-w94v)
CVE-2026-33134 | LabRedesCefetRJ WeGIA up to 3.6.5 GET Parameter restaurar_produto.php id_produto sql injection (GHSA-qg95-x997-66wq)
CVE-2026-33132 | Zitadel up to 3.4.8/4.12.2 API V2 Endpoint authorization (GHSA-g2pf-ww5m-2r9m)
CVE-2026-33136 | LabRedesCefetRJ WeGIA up to 3.6.6 Memorando listar_memorandos_ativos.php msg cross site scripting (GHSA-xjqp-5q3h-2cxh)
CVE-2026-32595 | Traefik up to 2.11.40/3.6.10 timing discrepancy (GHSA-g3hg-j4jv-cwfr)
CVE-2026-33131 | h3js h3 up to 2.0.0-0/2.0.1-rc.14/2.0.1-rc.15 Host event.url/event.url.hostname/event.url._url authentication spoofing (GHSA-3vj8-jmxq-cgj5)
CVE-2026-25792 | Greenshot up to 1.3.312 untrusted search path (GHSA-f8v9-7fph-fr2j)
CVE-2026-32305 | Traefik up to 2.11.40/3.6.10 TLS Configuration improper authentication (GHSA-wvvq-wgcr-9q48)
CVE-2026-33133 | LabRedesCefetRJ WeGIA up to 3.6.6 SQL File Parser loadBackupDB sql injection (GHSA-qqff-p8fc-hg5f)
CVE-2026-4499 | D-Link DIR-820LW 2.03 SSDP ssdpcgi_main os command injection
DragonForce
You must login to view this content
Terminated contract led to $2.5 million cyber extortion scheme
A federal jury convicted Cameron Curry, 27, a Charlotte resident, of carrying out an extensive cyber extortion scheme targeting a Washington, D.C.-based international technology company. He faces up to two years in prison on each of the six charges. Curry, who worked as a data analyst for about six months with the victim company and had access to its data files and internal personnel and corporate information, began the scheme after learning his contract would … More →
The post Terminated contract led to $2.5 million cyber extortion scheme appeared first on Help Net Security.