Aggregator
CVE-2026-2683 | Tsinghua Unigroup Electronic Archives System 3.2.210802(62532) downLoad.html path path traversal
CVE-2026-2684 | Tsinghua Unigroup Electronic Archives System up to 3.2.210802(62532) uploadFile.html File unrestricted upload
CVE-2026-1999 | GitHub Enterprise Server up to 3.17.10/3.18.4/3.19.1 Pull Request enable_auto_merge authorization (WID-SEC-2026-0460)
CVE-2025-15559 | NesterSoft WorkTime up to 11.8.8 API Endpoint os command injection
CVE-2026-26030 | Microsoft semantic-kernel up to 1.39.3 code injection
CVE-2026-26336 | Hyland Alfresco Enterprise/Alfresco Community prior 7.4.2.6/23.6.1/25.3.0 Configuration File /share/page/resource/ authorization
Сделано в Аризоне, придумано в Тегеране. США ударили по Ирану копиями его же «Шахедов»
Qilin
You must login to view this content
KI CTF 2026
Date: March 3, 2026, 3:30 a.m. — 03 March 2026, 11:30 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Kumaraguru College of Technology, Coimbatore
Offical URL: https://cyberconclave.yugam.in/
Rating weight: 0.00
Event organizers: YUGAM KUMARAGURU
LexisNexis Data Breach — Threat Actor Allegedly Claims 2.04 GB Stolen
A threat actor operating under the alias FulcrumSec has publicly claimed responsibility for a fresh breach of LexisNexis Legal & Professional, the legal information division of RELX Group, alleging the exfiltration of 2.04 GB of structured data from the company’s AWS cloud infrastructure. According to FulcrumSec’s post published on March 3, 2026, initial access was […]
The post LexisNexis Data Breach — Threat Actor Allegedly Claims 2.04 GB Stolen appeared first on Cyber Security News.
CVE-2026-2770 | Mozilla Firefox up to 147 WebIDL use after free (Nessus ID 299964 / WID-SEC-2026-0497)
CVE-2026-2771 | Mozilla Firefox up to 147 HTML Remote Code Execution (Nessus ID 299906 / WID-SEC-2026-0497)
CVE-2026-2772 | Mozilla Firefox up to 147 Playback use after free (Nessus ID 299964 / WID-SEC-2026-0497)
CVE-2026-2768 | Mozilla Firefox up to 147 IndexedDB sandbox (Nessus ID 299964 / WID-SEC-2026-0497)
CVE-2026-2769 | Mozilla Firefox up to 147 IndexedDB use after free (EUVD-2026-8469 / Nessus ID 299892)
Ransomware Groups
Microsoft Warns of New Phishing Attack Exploiting OAuth in Entra ID to Evade Detection
A new active phishing attack that exploits OAuth’s legitimate redirection behavior, allowing it to bypass traditional email and browser defenses without stealing any tokens. According to Microsoft Defender researchers, the campaigns primarily target government and public-sector organizations, using trusted identity provider domains to mask malicious redirects. Unlike traditional phishing that relies on credential theft or […]
The post Microsoft Warns of New Phishing Attack Exploiting OAuth in Entra ID to Evade Detection appeared first on Cyber Security News.