Aggregator
CVE-2025-54157 | MedDream PACS Premium 7.3.6.870 encapsulatedDoc cross site scripting
CVE-2025-15223 | Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958 /login.php Username cross site scripting (IDBUOY)
Matanbuchus Malware Downloader Evading AV Detections by Changing Components
Matanbuchus is once again drawing attention in the cybersecurity community as it quietly returns to the threat landscape with refined tactics and better tools to avoid detection. This malware, known for its role as a stealthy downloader, is actively being used to deliver more dangerous payloads, including ransomware, onto targeted systems. Recent activity shows that […]
The post Matanbuchus Malware Downloader Evading AV Detections by Changing Components appeared first on Cyber Security News.
CVE-2025-14610 | TableMaster for Elementor Plugin up to 1.3.6 on WordPress Data Table Widget wp-config.php csv_url server-side request forgery (EUVD-2025-206417)
CVE-2026-1298 | Easy Replace Image Plugin up to 3.5.2 on WordPress image_replacement_from_url authorization (EUVD-2026-4865)
CVE-2026-1083 | Appointment Hour Booking Plugin up to 1.5.60 on WordPress Form Builder Interface cross site scripting (EUVD-2026-4866)
CVE-2026-1466 | Jirafeau up to 4.7.0 Image cross site scripting (EUVD-2026-4867)
CVE-2025-8072 | Target Video Easy Publish Plugin up to 3.8.8 on WordPress placeholder_img cross site scripting (EUVD-2025-206416)
CVE-2026-24837 | dnnsoftware Dnn.Platform up to 9.13.9/10.1.x Persona Bar cross site scripting (GHSA-vm5q-8qww-h238 / EUVD-2026-4864)
CVE-2025-68013 | Payment Gateway Authorize.Net CIM for WooCommerce Plugin authorization (EUVD-2026-4048)
Google Disrupts Extensive Residential Proxy Networks
Второй раз — это уже традиция. Антивирус eScan снова поймали на «сотрудничестве» с хакерами
CVE-2026-1638 | Tenda AC21 1.1.1.1/1.dmzip/16.03.08.16 /goform/mDMZSetCfg dmzIp command injection
CVE-2026-1637 | Tenda AC21 16.03.08.16 /goform/AdvSetMacMtuWan fromAdvSetMacMtuWan stack-based overflow
The Security Debt We Pretend Isn’t There
Season 5, EP 01: Unpacking RTO fallout, endpoint sprawl, tooling fatigue, junior workforce erosion
The post The Security Debt We Pretend Isn’t There appeared first on Security Boulevard.
Moltbot Personal Assistant Goes Viral—And So Do Your Secrets
Early 2026, Moltbot a new AI personal assistant went viral. GitGuardian detected 200+ leaked secrets related to it, including from healthcare and fintech companies. Our contribution to Moltbot: a skill that turns secret scanning into a conversational prompt, letting users ask "is this safe?"
The post Moltbot Personal Assistant Goes Viral—And So Do Your Secrets appeared first on Security Boulevard.