Aggregator
CVE-2026-9575 | itsourcecode Student Transcript Processing System 1.0 index.php?view=view ID sql injection
CVE-2026-9574 | itsourcecode Student Transcript Processing System 1.0 trans.php studentId/cid sql injection
CVE-2026-9573 | itsourcecode Student Transcript Processing System 1.0 index.php?view=view studentId sql injection
Submit #817751: Bitwarden Bitwarden/Server <2026.4.0 Missing Authorization / Broken Object Level Authorization (BOLA) [Duplicate]
Submit #817580: itsourcecode Student Transcript Processing System V1.0 SQL Injection [Accepted]
Submit #817578: itsourcecode tudent Transcript Processing System V1.0 SQL Injection [Accepted]
Submit #817552: itsourcecode Student Transcript Processing System V1.0 SQL Injection [Accepted]
CVE-2026-9572 | GPAC up to 2.4.0 MP4Box src/isomedia/media.c Media_GetSample cat memory leak (Issue 3557)
«Несколько раз перезагрузите систему». Microsoft внесет изменения в Windows на следующей неделе
Submit #817137: GPAC MP4Box <= 2.4.0 (master commit 525bf1a and earlier) Memory leak (Denial of Service) [Accepted]
NightSpire Ransomware Uses RDP Access and Remote Admin Tools for Stealthy Persistence
A new ransomware threat is making waves across dozens of industries and countries, using a surprisingly simple but effective approach to break into systems and lock victims out of their own data. NightSpire, first identified in early 2025, has already shown it is willing to cast a wide net, hitting hospitals, schools, government offices, and […]
The post NightSpire Ransomware Uses RDP Access and Remote Admin Tools for Stealthy Persistence appeared first on Cyber Security News.
GitHub Down – Authentication Issues Denying Access to Actions
GitHub experienced a widespread service disruption on May 26, 2026, after authentication failures prevented developers from accessing critical automation services, including GitHub Actions and GitHub Pages. The outage significantly impacted CI/CD pipelines, blocking workflow execution and halting software delivery for many organizations worldwide. According to GitHub’s official status page, the incident began around 10:57 UTC, […]
The post GitHub Down – Authentication Issues Denying Access to Actions appeared first on Cyber Security News.
Hackers Exploit Ghost CMS CVE-2026-26980 to Poison 700 Websites With ClickFix Malware
A critical SQL injection flaw in Ghost CMS has been weaponized by at least two threat actor groups to silently poison over 700 websites with ClickFix malware, putting unsuspecting visitors at serious risk. The vulnerability, tracked as CVE-2026-26980, was publicly disclosed as early as February 19, 2026. Despite this, many Ghost CMS administrators failed to […]
The post Hackers Exploit Ghost CMS CVE-2026-26980 to Poison 700 Websites With ClickFix Malware appeared first on Cyber Security News.
Microsoft Defender can now automatically isolate hacked endpoints
Webinar: Too many tools are slowing network incident response
基于ptrace与/proc/mem的Linux无文件进程注入:攻击实现与内存取证检测
Старое оборудование, новая архитектура и обход Apple. Huawei готовит чип Kirin 9050, который может превзойти топовый процессор Apple
Remembering Tim Wilson, Whose Legacy Lives on at Dark Reading
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.