Aggregator
CVE-2023-45874 | Couchbase Server up to 7.2.2 denial of service (EUVD-2023-50140)
CVE-2023-45856 | qdPM 9.2 /uploads unrestricted upload (EUVD-2023-50125)
CVE-2023-45864 | Samsung Exynos up to 9820 race condition (EUVD-2023-50130)
CVE-2026-25530 | Kanboard up to 1.2.49 getSwimlane API authorization (GHSA-6rxw-vvvj-r93q / Nessus ID 298597)
CVE-2026-0965 | libssh Configuration File ssh_config_parse_file/ssh_bind_config_parse_file denial of service (Nessus ID 298598)
CVE-2026-0967 | libssh Client Configuration match_pattern redos (Nessus ID 298588)
CVE-2026-1703 | Python Packaging Authority pip up to 25.x Wheel Archive path traversal (EUVD-2026-5106 / Nessus ID 298602)
First Malicious Outlook Add-In Found Stealing 4,000+ Microsoft Credentials
Massive Spike in Attacks Exploiting Ivanti EPMM Systems 0-day Vulnerability
An unprecedented surge in exploitation attempts targeting CVE-2026-1281, a critical vulnerability in Ivanti Endpoint Manager Mobile (EPMM). On February 9, 2026, Shadowserver scans revealed over 28,300 unique source IP addresses attempting to exploit the flaw, marking one of the largest coordinated attack campaigns observed against enterprise mobile management infrastructure this year. CVE-2026-1281 is a pre-authentication […]
The post Massive Spike in Attacks Exploiting Ivanti EPMM Systems 0-day Vulnerability appeared first on Cyber Security News.
Proactive strategies for cyber resilience with Wazuh
Приготовьтесь кликать чаще: Windows вводит «мобильную» систему разрешений для ПК
Major US Debt Collection Agency Radius Global Solutions Allegedly Breached, Employee HR Data and Client Information Exposed
Не отвечайте этому «эйчару»: как фальшивая вакансия может привести к утечке гостайны
CVE-2026-21531 | Microsoft Azure AI Language Authoring deserialization
CVE-2026-21533 | Microsoft Windows up to Server 2025 Remote Desktop Services privileges management
LummaStealer infections surge after CastleLoader malware campaigns
LangGraph SQLite Store $ne 操作符访问控制绕过漏洞分析
Prometei Botnet Attacking Windows Server to Gain Remote Access and Deploy Malware
A sophisticated attack is targeting Windows Server systems using Prometei, a Russian-linked botnet that has been active since 2016. This multi-functional malware combines cryptocurrency mining, credential theft, and remote-control capabilities to maintain long-term access to compromised systems. The Prometei botnet infiltrates systems by exploiting weak or default credentials via Remote Desktop Protocol (RDP). Once attackers […]
The post Prometei Botnet Attacking Windows Server to Gain Remote Access and Deploy Malware appeared first on Cyber Security News.
Critical SandboxJS Vulnerability Allows Remote Host Takeover – PoC Released
A severe sandbox escape vulnerability has been discovered in the JavaScript library, enabling attackers to execute arbitrary code on host systems. The flaw, tracked as CVE-2026-25881 with a critical CVSS score of 8.3/10, affects all versions up to 0.8.30 and has been patched in version 0.8.31. The vulnerability exploits a weakness in SandboxJS’s protection mechanism. […]
The post Critical SandboxJS Vulnerability Allows Remote Host Takeover – PoC Released appeared first on Cyber Security News.