Aggregator
Submit #803751: OWASP DefectDojo < 2.56.0 Authorization Bypass [Accepted]
Popular Python Package lightning Hacked in Supply Chain Attack
The widely used PyTorch Lightning framework, which automatically executes credential-stealing malware on import, has also compromised GitHub maintainer accounts. The popular PyPI package lightning — the deep learning framework used to train, deploy, and ship AI products has been compromised in an active supply chain attack. Socket’s Research Team flagged versions 2.6.2 and 2.6.3 as […]
The post Popular Python Package lightning Hacked in Supply Chain Attack appeared first on Cyber Security News.
国际刑警DDoS蜜罐意外曝光:安全研究员意外逼停执法行动
CVE-2026-7508 | Bootstrap CMS 0.9.0-alpha Page Creation show.blade.php body code injection
UserGate предупреждает: ProFTPD с открытым модулем SQL можно взломать за секунды
Email threat landscape: Q1 2026 trends and insights
In early 2026, email threats increased with a rise in credential phishing, QR code phishing, and CAPTCHA-gated campaigns, highlighted by Microsoft’s disruption of the Tycoon2FA phishing platform which led to a 15% volume decrease and shifts in threat actor tactics.
The post Email threat landscape: Q1 2026 trends and insights appeared first on Microsoft Security Blog.
Two new extortion crews are speedrunning the Scattered Spider playbook
CrowdStrike says The Com-affiliated threat groups are using voice phishing and fake SSO pages to break into SaaS environments and steal data fast for extortion.
The post Two new extortion crews are speedrunning the Scattered Spider playbook appeared first on CyberScoop.
Email threat landscape: Q1 2026 trends and insights
In early 2026, email threats increased with a rise in credential phishing, QR code phishing, and CAPTCHA-gated campaigns, highlighted by Microsoft’s disruption of the Tycoon2FA phishing platform which led to a 15% volume decrease and shifts in threat actor tactics.
The post Email threat landscape: Q1 2026 trends and insights appeared first on Microsoft Security Blog.
Deep#Door Python Backdoor Evades Detection On Windows
Submit #803531: Bootstrap CMS v0.9.0-alpha Bootstrap CMS [Accepted]
CVE-2026-7506 | SourceCodester Hotel Management System 1.0 check room_type sql injection
CVE-2026-7505 | nextlevelbuilder GoClaw/GoClaw Lite up to 3.8.5 RPC improper authorization (Issue 866)
Submit #803492: SourceCodester Hotel Management System in PHP using CodeIgniter Framework Free Source Code V1.0 SQL Injection [Accepted]
GNU security advisory (AV26-407)
Submit #803458: Goclaw V0.4.0 Command execution [Accepted]
CVE-2026-7503 | code-projects for Plugin 4.1.2cu.5137 /cgi-bin/cstecgi.cgi setWiFiMultipleConfig wepkey2 buffer overflow
Managed vs Self-Managed Cloud Hosting: Choosing the Best Option for Your Business
Submit #803120: TOTOLINK A800R V4.1.2cu.5137_B20200730 Stack-based Buffer Overflow [Accepted]
Aur0ra New Threat Actor
You must login to view this content