Aggregator
CISA flags critical Microsoft SCCM flaw as exploited in attacks
Unity游戏逆向进阶 - IL2CPP逆向技术详解
Munich Security Conference: Cyber Threats Lead G7 Risk Index, Disinformation Ranks Third
CVE-2026-1841 | PixelYourSite Plugin up to 11.2.0 on WordPress pys_landing_page pysTrafficSource cross site scripting
CVE-2026-1844 | PixelYourSite Pro Plugin up to 12.4.0.2 on WordPress pys_landing_page pysTrafficSource cross site scripting
Nederlandse instructeurs geven spoedcursus StratCom in Korea
CVE-2025-15157 | Starfish Review Generation & Marketing Plugin up to 3.1.19 on WordPress srm_restore_options_defaults improper authorization
CVE-2026-2443 | GNOME libsoup out-of-bounds (Nessus ID 299000)
Zimbra Security Update – Patch for XSS, XXE & LDAP Injection Vulnerabilities
In a critical move for email server security, Zimbra released version 10.1.16 on February 4, 2026, tackling high-severity vulnerabilities including cross-site scripting (XSS), XML external entity (XXE), and LDAP injection. Labelled as high-patch severity and deployment risk, this update urges admins to upgrade immediately to shield deployments from exploits. Robust fixes for web-based threats. Zimbra […]
The post Zimbra Security Update – Patch for XSS, XXE & LDAP Injection Vulnerabilities appeared first on Cyber Security News.
CVE-2026-22892 | Mattermost up to 10.11.9/11.1.2/11.2.1 Jira Plugin /create-issue authorization
CVE-2026-20796 | Mattermost up to 10.11.9/11.2.x Channel Membership /common_teams toctou
Как захватить 900000 сайтов, не зная ни одного пароля. Пособие для тех, кто забывает обновлять WordPress
Zr.Ms. Groningen thuis na patrouilles in Caribisch gebied
『跨年SRC联合狩猎翻倍盛典』活动圆满收官!
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-1731 BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Uitkomsten bekend naar extra onderzoeken Nederlandse wapeninzet Hawija in 2015
New XWorm RAT Campaign Uses Themed Phishing Lures and CVE‑2018‑0802 Excel Exploit to Evade Detection
A new phishing campaign has been observed delivering an updated variant of XWorm, a Remote Access Trojan (RAT) that can give attackers full remote control of infected Microsoft Windows systems. First tracked in 2022, XWorm is still actively distributed and is often traded through Telegram-based marketplaces, keeping it within easy reach of many threat actors. […]
The post New XWorm RAT Campaign Uses Themed Phishing Lures and CVE‑2018‑0802 Excel Exploit to Evade Detection appeared first on Cyber Security News.