Week in review: 74k Fortinet firewall credentials stolen, Splunk Enterprise RCE under active attack Help Net Security
Cybercriminals abused GitHub, YouTube and VirusTotal to push crypto-stealing malware Help Net Security
CVE-2026-56382 | Craft CMS up to 5.9.13 POST Parameter actionRenderCardPreview fieldLayoutConfig code injection (GHSA-86vw-x4ww-x467 / EUVD-2026-38176) Vuldb Updates
CVE-2026-56378 | ImageMagick up to 7.1.2-14 PCD File out-of-bounds (GHSA-wgxp-q8xq-wpp9 / EUVD-2026-38174) Vuldb Updates
CVE-2026-56381 | Craft CMS up to 5.8.21 User Permissions Page cross site scripting (GHSA-g3hp-vvqf-8vw6 / EUVD-2026-38175) Vuldb Updates
CVE-2026-12814 | Comfast CF-WR631AX V3 up to 2.7.0.8 API Endpoint mbox-config?section=ping_config system destination os command injection VulDB Recent Entries
CVE-2026-12813 | activepieces up to 0.83.0 File URL file.ts handleUrlFile server-side request forgery VulDB Recent Entries
Microsoft Discovers Crypto Clipper Utilizing Tor for Control Penetration Testing Tools - Metepreter.org