Aggregator
DevChallenges Database Leaked With 20,000 User Records Published for Free Download
CVE-2023-48204 | sanluan PublicCMS 4.0.202302.e api/method/getHtml appToken information disclosure (Issue 77 / EUVD-2023-52284)
CVE-2023-48199 | Grocy 4.0.3 QR Code information disclosure (EUVD-2023-52279)
CVE-2023-48200 | Grocy 4.0.3 Equipment Description /equipment/ cross site scripting (EUVD-2023-52280)
Zoom Update Scam Infected 1,437 Users to Deploy Surveillance Tools in 12 Days
A cleverly crafted fake Zoom website has silently pushed surveillance software onto Windows machines, infecting 1,437 users globally in just 12 days. The campaign, first detected on February 11, 2026, on the Microsoft Defender for Endpoint (MDE) platform, used a rogue version of Teramind — a legitimate commercial workforce monitoring tool — to spy on […]
The post Zoom Update Scam Infected 1,437 Users to Deploy Surveillance Tools in 12 Days appeared first on Cyber Security News.
European DYI chain ManoMano data breach impacts 38 million customers
MSP Strategic Defense: Building Compliance on Dynamic Attack Surface Reduction
Compliance expectations across SMB markets are rising as supply chain regulations and cyber insurance requirements raise the baseline for security maturity. Regulatory standards such as CIS Controls v8, the NIS2 Directive, ISO 27001, SOC 2, PCI DSS, HIPAA, Cyber Essentials, CMMC 2.0, DORA, and the Essential Eight now shape what that baseline looks like.
The post MSP Strategic Defense: Building Compliance on Dynamic Attack Surface Reduction appeared first on Security Boulevard.
Облака — главные враги климатических прогнозов. Физика капитулирует… зато теперь ИИ готов взять реванш
CVE-2025-15520 | RegistrationMagic Plugin up to 6.0.2.1 on WordPress information disclosure (CNNVD-202602-2300)
CVE-2023-48192 | TOTOLINK A3700R 9.1.2u.6134_B20201202 setTracerouteCfg code injection (EUVD-2023-52272)
CVE-2023-48193 | JumpServer 3.8.0 permission (EUVD-2023-52273)
CVE-2023-48198 | Grocy 4.0.3 Product Description api/stock/products cross site scripting (EUVD-2023-52278)
CVE-2023-48188 | opartdevis Module up to 4.5.18/4.6.12 on PrestaShop getModuleTranslation sql injection (EUVD-2023-52268)
Fake Avast Website Targets Users With €499 Phishing Refund Scam
CVE-2020-26262 | Coturn up to 4.5.1 Loopback Interface confused deputy (Nessus ID 299987)
CVE-2026-3146 | libvips up to 8.18.0 matrixload.c vips_foreign_load_matrix_header null pointer dereference (Issue 4875 / Nessus ID 299986)
CVE-2026-27624 | Coturn up to 4.8.x ns_turn_ioaddr.c access control (GHSA-6g6j-r9rf-cm7p / EUVD-2026-8620)
1Campaign Platform Helps Attackers Bypass Google Ads Screening to Show Malicious Ads
A newly uncovered cloaking platform called 1Campaign is giving cybercriminals a powerful tool to push malicious advertisements through Google’s ad review system, putting everyday users at serious risk of phishing scams and cryptocurrency theft. Google Ads is one of the most trusted advertising networks online. Millions of users click on sponsored search results daily, trusting those links […]
The post 1Campaign Platform Helps Attackers Bypass Google Ads Screening to Show Malicious Ads appeared first on Cyber Security News.