Aggregator
CVE-2026-26979 | Discourse up to 2025.12.1/2026.1.0 Private Category authorization
CVE-2026-26973 | Discourse up to 2025.12.1/2026.1.0 enable_category_group_moderation authorization
CVE-2026-27509 | UnitreeRobotics Unitree Go2 up to 1.1.9 Message actuator_manager.py missing authentication
CVE-2026-27510 | UnitreeRobotics Unitree Go2 up to 1.1.9/1.1.11 com.unitree.doggo2 unitree_go2.db pyCode data authenticity
CVE-2026-1241 | Pelco Sarix Professional IWP 3 up to 02.52 Web Management Interface authentication bypass (icsa-26-057-02)
Phishing‑Led Agent Tesla Campaign Uses Process Hollowing and Anti‑Analysis to Evade Detection
A newly uncovered phishing campaign is delivering Agent Tesla, one of the most widely used credential-stealing malware families, through a multi-stage attack chain that leaves almost no trace on a victim’s machine. The campaign uses business-themed phishing emails, obfuscated scripts, and in-memory execution to silently harvest sensitive data from Windows users. With its ability to […]
The post Phishing‑Led Agent Tesla Campaign Uses Process Hollowing and Anti‑Analysis to Evade Detection appeared first on Cyber Security News.
CVE-2026-22715 | VMware Workstation/Fusion 9.0.1 Network Packet denial of service
New Aeternum C2 Botnet Evades Takedowns via Polygon Blockchain
CVE-2026-23760 | SmarterTools SmarterMail up to 100.0.9510 Password Reset API authentication bypass (EUVD-2026-4143 / Nessus ID 297224)
Why Perimeter Firewall is Not Enough: Lessons from the GoAnywhere MFT Zero-Day
In September 2025, the cybercriminal group Storm-1175 exploited a zero-day vulnerability in GoAnywhere Managed File Transfer to deploy Medusa ransomware across multiple organizations. The attack succeeded despite perimeter defenses because no signature existed to detect it, and by the time one did, attackers had already established persistence and were moving freely through victim networks. This … Continued
The post Why Perimeter Firewall is Not Enough: Lessons from the GoAnywhere MFT Zero-Day appeared first on VMware Security Blog.