Aggregator
CVE-2026-31825 | Sylius up to 2.2.2 orderBy sql injection (GHSA-xcwx-r2gw-w93m)
ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More
4chan shrugs off UK regulator, refuses to pay £520,000 in fines over online safety violations
The U.K.’s media regulator Ofcom fined 4chan £450,000 under the Online Safety Act for failing to introduce age checks to stop children from accessing pornographic content on its platform. 4chan is an online forum notorious for its extreme right-wing content, gory videos, and non-consensual pornography. The regulator ordered the company to introduce age assurance measures by 2 April 2026 and said additional daily penalties of £500 could apply if the issue is not resolved, with … More →
The post 4chan shrugs off UK regulator, refuses to pay £520,000 in fines over online safety violations appeared first on Help Net Security.
Versa Secure Enterprise Browser delivers browser-native security for enterprise apps
Versa has revealed early access to Versa Secure Enterprise Browser, a new browser-native security capability within the VersaONE Universal SASE Platform that protects employees, contractors, and partner users as they access web, SaaS, and enterprise AI applications by enforcing security, access, and data protection policies directly within the browser session. The browser has become the dominant execution environment for enterprise work, yet it often remains outside the reach of consistent security, access, and data protection … More →
The post Versa Secure Enterprise Browser delivers browser-native security for enterprise apps appeared first on Help Net Security.
CVE-2026-3419 | fastify up to 5.8.0 Header Content-Type incorrect regex (GHSA-573f-x89g-hqp9)
CVE-2026-29791 | Agentgateway up to 0.11.x input validation
CVE-2026-30942 | FlintSH Flare up to 1.7.2 Path Validation path.join path traversal (GHSA-h639-p7m9-mpgp)
CVE-2026-30934 | gtsteffaniak filebrowser up to 1.2.1-stable/1.3.0-beta /public/share/ cross site scripting
CVE-2026-25960 | vLLM up to 0.16.x Incomplete Fix CVE-2026-24779 urllib3.util.parse_url server-side request forgery (GHSA-qh4c-xf7m-gxfc)
CVE-2026-30937 | ImageMagick up to 6.9.13-40/7.1.2-15 XWD Encoder heap-based overflow (EUVD-2026-10402)
CVE-2026-31802 | isaacs node-tar up to 7.5.10 path traversal
CVE-2026-30909 | TIMLEGGE Crypt::NaCl::Sodium up to 2.002 on Perl Message bin2hex/aes256gcm_encrypt_afternm/seal integer overflow (EUVD-2026-10199 / CNNVD-202603-1448)
CVE-2026-29795 | stellar rs--xdr up to 25.0.0 StringM::from_str allocation of resources
CVE-2025-69651 | GNU Binutils up to 2.46 readelf process_got_section_contents denial of service (Nessus ID 301408)
CVE-2025-69650 | GNU Binutils up to 2.46 readelf process_got_section_contents denial of service (Nessus ID 301402)
Nagomi Security expands into agent-driven exposure elimination with Agentic Exposure Ops
Nagomi Security has announced the next evolution of its platform with Agentic Exposure Ops, expanding Nagomi from exposure visibility to agent-driven exposure elimination. Most exposure management programs generate findings faster than teams can validate what’s real, route fixes to the right owners, and re-check outcomes as environments change. Agentic Exposure Ops closes that execution loop so high-impact conditions get eliminated and stay closed over time. That loop breaks in enterprises for a simple reason: the … More →
The post Nagomi Security expands into agent-driven exposure elimination with Agentic Exposure Ops appeared first on Help Net Security.
Безопасное небо по цене Луны: Пентагон вытряс еще 10 миллиардов на спутники, которые увидят гиперзвуковую ракету ещё до старта
CVE-2026-20805 | Microsoft Windows up to Server 2025 Desktop Window Manager information disclosure (WID-SEC-2026-0083)
CISO Whisperer Names 11 Vendors Leading the Shift from Tools to Outcomes at RSA Conference 2026
Austin, United States, March 19th, 2026, CyberNewswire Cybersecurity has entered a new phase, one defined less by reactive controls and more by continuous, intelligence-driven operations. As attack surfaces expand and adversaries increasingly leverage AI, the modern CISO is tasked with orchestrating resilience at scale. Amid this shift, CISO Whisperer has released its list of “Cybersecurity […]
The post CISO Whisperer Names 11 Vendors Leading the Shift from Tools to Outcomes at RSA Conference 2026 appeared first on Cyber Security News.