Aggregator
CVE-2026-40611 | go-acme lego up to 4.33.x path traversal (GHSA-qqx8-2xmm-jrv8)
CVE-2026-40608 | DayuanJiang next-ai-draw-io up to 0.4.14 POST allocation of resources (GHSA-9q7h-wgfw-p378 / EUVD-2026-24217)
CVE-2026-40613 | Coturn up to 4.9.x type conversion
From Panic to Playbook: Modernizing Zero‑Day Response in AppSec
Learn how AppSec teams build a repeatable zero-day response workflow.
The post From Panic to Playbook: Modernizing Zero‑Day Response in AppSec appeared first on Security Boulevard.
CVE-2026-40587 | blueprintue blueprintue-self-hosted-edition up to 4.1.x Password Change session expiration (GHSA-gqpq-x62g-p4mg)
CVE-2026-40606 | mitmproxy up to 12.2.1 ldap injection (GHSA-527g-3w9m-29hv)
CVE-2026-40604 | craigjbass clearancekit up to 5.0.5 AUTH Endpoint protection mechanism (GHSA-5r9w-9fg6-266q / EUVD-2026-24213)
CVE-2026-40602 | home-assistant-ecosystem home-assistant-cli up to 0.x code injection (GHSA-33qf-q99x-wpm8)
CVE-2026-40594 | pyLoad up to 0.5.0b3.dev97 __init__.py set_session_cookie_secure origin validation (GHSA-mp82-fmj6-f22v)
CVE-2026-40599 | craigjbass clearancekit up to 5.0.4 authorization (GHSA-w253-42qp-5f2x / EUVD-2026-24209)
Зарубежные SIM-карты против блокировок: миф или рабочий способ
Scottish man pleads guilty to attack spree that created Scattered Spider’s notoriety
Tyler Robert Buchanan “was the glue that held this gang together,” a cybercrime researcher said. He faces up to 22 years in federal prison.
The post Scottish man pleads guilty to attack spree that created Scattered Spider’s notoriety appeared first on CyberScoop.
Lawmakers ponder terrorism designations, homicide charges over hospital ransomware attacks
The ideas came up at a House Homeland Security Committee hearing, as health care ransomware attacks are on the rise.
The post Lawmakers ponder terrorism designations, homicide charges over hospital ransomware attacks appeared first on CyberScoop.
New Lotus data wiper used against Venezuelan energy, utility firms
CVE-2026-6310 | Google Chrome up to 147.0.7727.55 Dawn use after free (ID 497969 / Nessus ID 307658)
CVE-2026-6311 | Google Chrome up to 147.0.7727.55 on Windows Accessibility uninitialized variable (ID 498201 / Nessus ID 307658)
CVE-2026-6360 | Google Chrome up to 147.0.7727.55 Fileystem use after free (ID 497880 / Nessus ID 307658)
North Korea’s Lazarus APT stole $290M from Kelp DAO
Iran Alleges US Networking Gear Was Deliberately Disabled
Reports from Iranian state media claim that U.S.-manufactured networking gear ceased functioning at critical moments during military strikes. The allegations, which cannot be independently verified, claim there were simultaneous failures across routers and switches produced by Cisco, Fortinet, Juniper Networks, and MikroTik during attacks on Iranian infrastructure. According to accounts published by the Iranian Fars..
The post Iran Alleges US Networking Gear Was Deliberately Disabled appeared first on Security Boulevard.