Aggregator
Submit #785836: DbGate DbGate Premium 7.1.4 Server-Side Request Forgery [Accepted]
13th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The Los Angeles Police Department has reported a data breach involving a digital storage system used by the L.A. City Attorney’s Office. The exposure included 7.7 terabytes and more than 337,000 files, […]
The post 13th April – Threat Intelligence Report appeared first on Check Point Research.
Agents have their own computers with Sandboxes GA
Durable Objects in Dynamic Workers: Give each AI-generated app its own database
Hackers hijacked CPUID downloads, served STX RAT to victims
If you tried to download software from CPUID’s website late last week, you might have downloaded malware instead. “Investigations are still ongoing, but it appears that a secondary feature (basically a side API) was compromised for approximately six hours between April 9 and April 10, causing the main website to randomly display malicious links (our signed original files were not compromised),” Samuel Demeulemeester, a contributor to CPUID, stated on Friday, and apologized to affected users. … More →
The post Hackers hijacked CPUID downloads, served STX RAT to victims appeared first on Help Net Security.
CVE-2026-34476 | Apache SkyWalking MCP up to 0.1.0 Header SW-URL server-side request forgery (EUVD-2026-21918)
CVE-2026-34884 | Apache SkyWalking MCP up to 0.1.0 set_skywalking_url injection
CVE-2026-36919 | SourceCodester Basic Library System 1.0 exam-update.php sql injection (EUVD-2026-21916)
CVE-2026-36874 | SourceCodester Basic Library System 1.0 /load_student.php sql injection (EUVD-2026-21914)
CVE-2026-36873 | SourceCodester Basic Library System 1.0 /load_admin.php sql injection (EUVD-2026-21912)
CVE-2026-36872 | SourceCodester Basic Library System 1.0 /load_book.php sql injection (EUVD-2026-21910)
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
Подводные лодки станут невидимыми: ядерные часы на тории‑229 позволят им месяцами не всплывать
Dynamic, identity-aware, and secure Sandbox auth
CVE-2026-1731 | BeyondTrust Remote Support & Privileged Remote Access up to PRA 24.3.4/RS 25.3.1 os command injection (KB0023293 / EUVD-2026-5559)
Переезд рабочих чатов: зачем бизнесу корпоративный мессенджер
OpenSSF Flags Malware Campaign on Slack Posing as Linux Foundation Figures
$12 million frozen, 20,000 victims identified in crypto scam crackdown
More than $12 million has been frozen, and over 20,000 victims have been identified in an international law enforcement operation targeting cryptocurrency and investment scammers. Authorities also uncovered more than $45 million in suspected cryptocurrency fraud losses worldwide. One UK victim identified during the operation is thought to have lost more than £52,000 to the fraud. According to the FBI’s report, cryptocurrency remained a central element in fraud-related activity, with losses totaling $11.3 billion. Investment … More →
The post $12 million frozen, 20,000 victims identified in crypto scam crackdown appeared first on Help Net Security.