Aggregator
CVE-2026-2027 | AMP Enhancer Plugin up to 1.0.49 on WordPress Setting cross site scripting
CVE-2026-0692 | BlueSnap Payment Gateway for WooCommerce Plugin up to 3.3.0 on WordPress X-Forwarded-For get_ip_address authorization
CVE-2025-1790 | Genetec Sipelia Plugin up to 2.14.270 unnecessary privileges
CVE-2026-26268 | Cursor up to 2.4 authorization (GHSA-8pcm-8jpx-hv8r)
Malicious Chrome AI Extensions Attacking 260,000 Users via Injected IFrames
A coordinated campaign is using malicious Chrome extensions that impersonate popular AI tools like ChatGPT, Claude, Gemini, and Grok. These fake “AI assistants” spy on users through injected, remote-controlled iframes, turning helpful browser add-ons into surveillance tools. More than 260,000 users have installed these extensions. Security researchers identified at least 30 Chrome extensions promoted as […]
The post Malicious Chrome AI Extensions Attacking 260,000 Users via Injected IFrames appeared first on Cyber Security News.
Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs
CVE-2026-26226 | lukilabs beautiful-mermaid up to 0.1.2 SVG Attribute cross site scripting
CVE-2025-70095 | Open Source Point of Sale 3.4.1 cross site scripting
CVE-2025-70093 | OpenSourcePOS 3.4.1 AJAX command injection
CVE-2025-70091 | OpenSourcePOS 3.4.1 Phone Number cross site scripting
CVE-2026-2026 | Tenable Agent up to 11.0.3/11.1.1 on Windows default permission (Nessus ID 298991)
CVE-2025-70094 | OpenSourcePOS 3.4.1 Generate Item Barcode Category cross site scripting
CVE-2025-70123 | Free5GC 4.0.1/29.244 PFCP Session Establishment Request denial of service
CVE-2025-70122 | Free5GC 4.0.1 UPF sdf-filter.go SDFFilterFields.UnmarshalBinary heap-based overflow
CVE-2025-70121 | Free5GC 4.0.1 AMF NAS_MobileIdentity5GS.go GetSUCI denial of service
CVE-2026-26221 | Hyland OnBase Workflow Timer Service up to 17.0.x Hyland.Core.Workflow.NTService.exe deserialization
Check Point Unveils a New Security Strategy for Enterprises in the AI Age
Check Point is rolling out a new four-pillar cybersecurity strategy to give security teams an edge in the ongoing AI arms race with threat actors and is making three acquisitions that will play a critical role in getting it going.
The post Check Point Unveils a New Security Strategy for Enterprises in the AI Age appeared first on Security Boulevard.