Aggregator
CVE-2020-36999 | Elaniin CMS 1.0 login.php email/password sql injection (Exploit 48705)
CVE-2020-37005 | TimeClock 1.01 add_entry.php notes sql injection (Exploit 48874)
CVE-2020-37006 | crm-now berliCRM 1.0.24 HTTP POST Request index.php src_record sql injection (Exploit 48872)
Aisuru botnet sets new record with 31.4 Tbps DDoS attack
CVE-2026-1625 | D-Link DWR-M961 1.1.47 SMS Message /boafrm/formSmsManage sub_4250E0 action_value command injection (EUVD-2026-4938)
Virtue AI AgentSuite enables enterprises to test and secure AI agents
Virtue AI announced AgentSuite, a multi-layer security and compliance platform for enterprise AI agents. Organizations worldwide are deploying agents that modify databases, trigger payments, and access systems containing sensitive information. AgentSuite is the AI-native platform built specifically for this new reality, enabling enterprises to test and secure AI agents as complete systems, enforce security policies for agents and tool calls, and prevent insecure or out-of-policy actions in real time. According to IBM, 79% of enterprises … More →
The post Virtue AI AgentSuite enables enterprises to test and secure AI agents appeared first on Help Net Security.
New Microsoft Teams feature will let you report suspicious calls
Submit #740792: D-Link DW V1.1.47 Command Injection [Accepted]
中国批准进口英伟达 H200 芯片
CISA Warns of FortiCloud SSO Authentication Bypass Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical authentication bypass vulnerability in multiple Fortinet products, actively exploited in the wild. Tracked as CVE-2026-24858, the flaw allows attackers with a FortiCloud account to hijack sessions on devices registered to other accounts when FortiCloud Single Sign-On (SSO) is enabled. First […]
The post CISA Warns of FortiCloud SSO Authentication Bypass Vulnerability Exploited in Attacks appeared first on Cyber Security News.
CVE-2026-1624 | D-Link DWR-M961 1.1.47 formLtefotaUpgradeFibocom fota_url command injection (EUVD-2026-4939)
Смерть за «алло». Китай казнил 11 членов клана, державших в рабстве тысячи «телефонных мошенников»
CVE-2026-1623 | Totolink A7000R 4.1cu.4154 /cgi-bin/cstecgi.cgi setUpgradeFW FileName command injection (EUVD-2026-4962)
Submit #740770: D-Link DWR-M961 V1.1.47 Command Injection [Accepted]
Submit #740767: TOTOLINK A7000R V4.1cu.4154 Command Injection [Accepted]
eScan AV users targeted with malicious updates
The update infrastructure for eScan antivirus, a product of Indian cybersecurity company MicroWorld Technologies, has been compromised by unknown attackers to deliver a persistent downloader to enterprise and consumer endpoints. The compromise also resulted in the eScan antivirus on those endpoints to stop working as intended, since the trojanized eScan update tampered with the solution’s registry, files and update configuration to block remote updates, Morphisec researchers said on Thursday. MicroWorld’s incident response It’s unknown when … More →
The post eScan AV users targeted with malicious updates appeared first on Help Net Security.