Aggregator
CVE-2026-26220 | ModelTC LightLLM up to 1.1.0 WebSocket Endpoint pickle.loads deserialization
CVE-2026-1216 | RSS Aggregator Plugin up to 5.0.10 on WordPress template cross site scripting
CVE-2026-2247 | Clickedu SaaS Platform Day-to-day Section id_alu sql injection
CVE-2025-8303 | EKA Real Estate Script V5 up to 17022026 cross site scripting
CVE-2026-2439 | BVA Concierge::Sessions up to 0.8.4 on Perl rand generation of predictable numbers or identifiers
CVE-2025-15578 | TEEJAY Maypole up to 2.13 on Perl rand weak prng
CVE-2026-2592 | Zarinpal Gateway for WooCommerce Plugin up to 5.0.16 on WordPress Payment Call Return_from_ZarinPal_Gateway access control
CVE-2026-2002 | Forminator Forms Plugin up to 1.50.2 on WordPress form_name cross site scripting
CVE-2026-1657 | EventPrime Plugin up to 4.2.8.4 on WordPress AJAX Endpoint ep_upload_file_media authorization
Apache Tomcat Vulnerabilities Let Attackers Bypass Security Constraints via HTTP/0.9 Requests
Apache Tomcat has disclosed CVE-2026-24733, a Low-severity security constraint bypass that can be triggered via HTTP/0.9 requests when certain access-control rules are configured in a specific way. The Apache Tomcat security team identified the issue, and the original advisory was published on 2026-02-17. At a high level, the vulnerability stems from Tomcat not restricting HTTP/0.9 […]
The post Apache Tomcat Vulnerabilities Let Attackers Bypass Security Constraints via HTTP/0.9 Requests appeared first on Cyber Security News.
针对疑似某红队大佬的样本分析
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2025-49113 RoundCube Webmail Deserialization of Untrusted Data Vulnerability
- CVE-2025-68461 RoundCube Webmail Cross-site Scripting Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Hackers breach contractor linked to Ukraine’s central bank collectible coin store
ClickFix Campaign Abuses Compromised Sites to Deploy MIMICRAT Malware
Critical Vulnerabilities in VS Code Extensions Threaten 128 Million Developer Environments
Three critical vulnerabilities have been found in four popular Visual Studio Code extensions. These extensions have been downloaded over 128 million times. The vulnerabilities are identified as CVE-2025-65715, CVE-2025-65716, and CVE-2025-65717. The findings from the OX Security Research team, later confirmed on Cursor and Windsurf IDEs, expose a systemic blind spot in modern software supply […]
The post Critical Vulnerabilities in VS Code Extensions Threaten 128 Million Developer Environments appeared first on Cyber Security News.
Mississippi medical center closes all clinics after ransomware attack
FBI 线人协助运营了暗网毒品市场 Incognito
Илон Маск снова рискует. За «шутки» чат-бота Grok соцсеть X могут просто заблокировать
LLM-Generated Passwords Expose Major Security Flaws with Predictability, Repetition, and Weakness
Large language models, commonly known as LLMs, are increasingly being asked to generate passwords — and new research has shown that the passwords they produce are far weaker than they appear. A password like G7$kL9#mQ2&xP4!w may look convincingly random, but it carries a fundamental flaw that standard password-strength tools consistently miss. The core problem lies in how […]
The post LLM-Generated Passwords Expose Major Security Flaws with Predictability, Repetition, and Weakness appeared first on Cyber Security News.