Aggregator
Devman
2 months 1 week ago
You must login to view this content
cohenido
Supreme Court to hear Facebook pixel tracking case
2 months 1 week ago
The Supreme Court said Monday that it will hear a case stemming from the use of a Facebook tracking pixel to monitor the streaming habits of the user of a sports website.
CVE-2026-21509: Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally
2 months 1 week ago
CVE-2026-21509: Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally
Dark Web Informer
Эйнштейн называл это «жутким действием». Теперь оно поможет создать самые точные часы в истории
2 months 1 week ago
Физики научились использовать квантовую запутанность для идеальных измерений.
Microsoft patches actively exploited Office zero-day vulnerability
2 months 1 week ago
Microsoft has released emergency security updates to patch a high-severity Office zero-day vulnerability exploited in attacks. [...]
Sergiu Gatlan
Fake Microsoft Teams Billing Phishing Alerts Reach 6,135 Users via 12,866 Emails
2 months 1 week ago
Scammers are abusing Microsoft Teams invitations to send fake billing notices, with 12,866 emails reaching around 6,135 users in a phone-based phishing campaign.
Deeba Ahmed
Play
2 months 1 week ago
You must login to view this content
cohenido
Play
2 months 1 week ago
You must login to view this content
cohenido
Play
2 months 1 week ago
You must login to view this content
cohenido
Play
2 months 1 week ago
You must login to view this content
cohenido
INC
2 months 1 week ago
You must login to view this content
cohenido
Хакер думал, что украл пароль, а на самом деле – позвонил в полицию. На GitHub учат, как развести взломщика на эмоции (и логи)
2 months 1 week ago
Обновился каталог Awesome Deception с инструментами для киберобмана.
The key of AI: How Agentic Tuning can make your detection strategy sing
2 months 1 week ago
Remove unwanted alerts from your environment using plain language
Sam Straka
Randall Munroe’s XKCD ‘High Altitude Cooking Instructions’
2 months 1 week ago
via the comic artistry and dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘High Altitude Cooking Instructions’ appeared first on Security Boulevard.
Marc Handelman
CVE-2026-1446 | Esri ArcGIS Pro up to 3.6.0 cross site scripting
2 months 1 week ago
A vulnerability was found in Esri ArcGIS Pro up to 3.6.0. It has been rated as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2026-1446. The attack needs to be performed locally. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
Cloudflare misconfiguration behind recent BGP route leak
2 months 1 week ago
Cloudflare has shared more details about a recent 25-minute Border Gateway Protocol (BGP) route leak affecting IPv6 traffic, which caused measurable congestion, packet loss, and approximately 12 Gbps of dropped traffic. [...]
Bill Toulas
CVE-2026-1449 | Hisense TransTech Smart Bus Management System up to 20260113 TireMng.aspx Page_Load key sql injection
2 months 1 week ago
A vulnerability was found in Hisense TransTech Smart Bus Management System up to 20260113. It has been declared as critical. Affected is the function Page_Load of the file YZSoft/Forms/XForm/BM/BusComManagement/TireMng.aspx. Executing a manipulation of the argument key can lead to sql injection.
This vulnerability is registered as CVE-2026-1449. It is possible to launch the attack remotely. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #737032: Hisense TransTech Hisense Smart Bus Management System 1.0 SQL Injection [Accepted]
2 months 1 week ago
Submit #737032 / VDB-342881
jiefengliang
CVE-2026-1448 | D-Link DIR-615 up to 4.10 Web Management Interface wiz_policy_3_machine.php ipaddr os command injection
2 months 1 week ago
A vulnerability was found in D-Link DIR-615 up to 4.10. It has been classified as critical. This impacts an unknown function of the file /wiz_policy_3_machine.php of the component Web Management Interface. Performing a manipulation of the argument ipaddr results in os command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is cataloged as CVE-2026-1448. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com