Aggregator
CVE-2025-52475 | Chamilo LMS up to 1.11.29 admin/user_list.php keyword_inactive cross site scripting
CVE-2025-52470 | Chamilo LMS up to 1.11.29 session_category_add.php Category Name cross site scripting
CVE-2025-52998 | Chamilo LMS up to 1.11.29 deserialization
You’re Optimizing for the Wrong AI Engine. And It’s Costing You Enterprise Deals.
Two cybersecurity companies told me they're optimizing for Perplexity. Their buyer? Enterprise CISOs. The data shows ChatGPT leads at 67% enterprise adoption and 87.4% of AI referral traffic. Only 11% of domains get cited by both ChatGPT and Perplexity. Most B2B companies are optimizing wrong.
The post You’re Optimizing for the Wrong AI Engine. And It’s Costing You Enterprise Deals. appeared first on Security Boulevard.
CVE-2025-52564 | Chamilo LMS up to 1.11.29 help.php Open cross site scripting
CVE-2025-50199 | Chamilo LMS up to 1.11.29 /index.php openid_url server-side request forgery
ИИ сыграл сам с собой в тысячу партий, чтобы объяснить археологам, зачем древним людям был нужен этот камень
CVE-2025-50198 | Chamilo LMS up to 1.11.29 Configuration import.php configuration_file/course_path/home_path deserialization
Dell security advisory (AV26-181)
DuckDuckGo Browser UXSS Flaw in Auto Consent JS Bridge Enables Cross-Origin Code Execution
A critical Universal Cross-Site Scripting (UXSS) vulnerability was recently discovered in the DuckDuckGo Android browser. This flaw allowed untrusted, cross-origin iframes to execute arbitrary JavaScript in the top-level origin, tracked with a high-severity CVSS score of 8.6. The vulnerability was originally detailed in a Medium post by security researcher Dhiraj Mishra. The vulnerability stems from […]
The post DuckDuckGo Browser UXSS Flaw in Auto Consent JS Bridge Enables Cross-Origin Code Execution appeared first on Cyber Security News.
Chrome Unveils Plan For Quantum-Safe HTTPS Certificates
CVE-2026-3380 | Tenda F453 1.0.0.3 /goform/L7Im frmL7ImForm page buffer overflow (EUVD-2026-9116 / CNNVD-202603-017)
CVE-2026-3379 | Tenda F453 1.0.0.3 /goform/SetIpBind fromSetIpBind page buffer overflow (EUVD-2026-9115 / CNNVD-202603-018)
CVE-2026-3377 | Tenda F453 1.0.0.3 /goform/SafeUrlFilter fromSafeUrlFilter page buffer overflow (EUVD-2026-9113 / CNNVD-202603-020)
CVE-2026-3378 | Tenda F453 1.0.0.3 /goform/qossetting fromqossetting qos buffer overflow (EUVD-2026-9114 / CNNVD-202603-019)
MSHTML Framework 0-Day Exploited by APT28 Hackers Before Feb 2026’s Patch Tuesday Update
A zero-day vulnerability in the Microsoft HTML (MSHTML) framework was actively exploited in the wild. The vulnerability, tracked as CVE-2026-21513, allows attackers to bypass security features and execute arbitrary files. With a CVSS score of 8.8, it impacts all Windows versions. Security researchers at Akamai discovered that the Russian state-sponsored threat group APT28 was targeting […]
The post MSHTML Framework 0-Day Exploited by APT28 Hackers Before Feb 2026’s Patch Tuesday Update appeared first on Cyber Security News.
IBM security advisory (AV26-180)
Western Cybersecurity Experts Brace for Iranian Reprisal
Organizations across the West and allied nations should prepare for Iranian cyberattacks in the wake of Israeli and U.S. ongoing strikes, threat intelligence firms warned as the first signs of the Iranian cyber counteroffensive became clear on Sunday