Aggregator
CVE-2026-25739 | Indico up to 3.3.9 Content Security Policy cross site scripting (GHSA-jxc4-54g3-j7vp)
CVE-2025-69674 | CData FD614GS3-R850 3.2.7_P161006 mesh_node_config/domiainblk_config domainblk buffer overflow
CVE-2026-25940 | parallax jsPDF up to 4.1.x Acroform escape output (GHSA-p5xg-68wr-hm3m)
OpenClaw’s Top Skill is a Malware that Stole SSH Keys and Opened Reverse Shells in 1,184 Packages
The most downloaded AI agent skill on OpenClaw’s ClawHub marketplace was functional malware, not a productivity tool. OpenClaw, an open-source AI agent platform, operates a public skill marketplace called ClawHub, where third-party developers can publish plugins, or “skills,” that extend an agent’s capabilities. Security researcher @chiefofautism has identified 1,184 malicious skills on OpenClaw’s ClawHub marketplace, […]
The post OpenClaw’s Top Skill is a Malware that Stole SSH Keys and Opened Reverse Shells in 1,184 Packages appeared first on Cyber Security News.
News alert: Link11’s ‘AI Management Dashboard’ makes AI traffic, AI access policies enforceable
FRANKFURT, Feb. 19, 2026, CyberNewswire — Link11 launches its new “AI Management Dashboard”, closing a critical gap in how companies manage AI traffic. Artificial intelligence is fundamentally changing internet traffic. But while many companies are already feeling the … (more…)
The post News alert: Link11’s ‘AI Management Dashboard’ makes AI traffic, AI access policies enforceable first appeared on The Last Watchdog.
The post News alert: Link11’s ‘AI Management Dashboard’ makes AI traffic, AI access policies enforceable appeared first on Security Boulevard.
CVE-2026-26016 | Pterodactyl Panel up to 1.12.0 Configuration Data config.yml authorization
The Chicken Littles of Silicon Valley: Why AI Doomsayers Are Repeating History’s Greatest Mistake
The sky has never been falling. Yet here we are again, watching a new generation of prognosticators prophecy civilizational collapse while evidence of human adaptability and economic dynamism surrounds them. Salon’s recent piece about “swarms of AI bots threatening democracy” epitomizes this tiresome pattern—a sensational claim dressed up in legitimate-sounding language that dissolves upon even..
The post The Chicken Littles of Silicon Valley: Why AI Doomsayers Are Repeating History’s Greatest Mistake appeared first on Security Boulevard.
CVE-2026-25998 | strongswan strongMan up to 0.1.x nonce re-use
CVE-2025-69725 | go-chi 5.2.2 redirect
CVE-2026-2274 | AppSheet Web prior 2025-11-23 server-side request forgery
ChatGPT — всем сотрудникам, Codex — всем разработчикам. Tata Group запускает крупнейшее внедрение корпоративного ИИ в истории
CVE-2026-26336 | Hyland Alfresco Enterprise/Alfresco Community prior 7.4.2.6/23.6.1/25.3.0 Configuration File /share/page/resource/ authorization
CVE-2026-24834 | kata-containers Kata Containers up to 3.26.x permission assignment
CVE-2026-26030 | Microsoft semantic-kernel up to 1.39.3 code injection
Remcos RAT Expands Real-Time Surveillance Capabilities
Microsoft reveals critical Windows Admin Center vulnerability (CVE-2026-26119)
Microsoft has disclosed a privilege-escalation vulnerability in Windows Admin Center (WAC), a browser-based platform widely used by IT administrators and infrastructure teams to manage Windows clients, servers, clusters, Hyper-V hosts and virtual machines, as well as Active Directory-joined systems. Although the issue was patched in early December 2025 with the release of Windows Admin Center version 2511, it has only just been publicly acknowledged. The delay in disclosure likely reflects both the nature of the … More →
The post Microsoft reveals critical Windows Admin Center vulnerability (CVE-2026-26119) appeared first on Help Net Security.
IceWarp security advisory (AV26-148)
Beyond CVE China’s Dual Vulnerability Databases Reveal a Different Disclosure Timeline
The emergence of a distinct vulnerability disclosure ecosystem within China has introduced a complex layer to the global threat landscape. Unlike the centralized CVE system used internationally, China maintains two separate databases—the CNVD and CNNVD—which operate with different disclosure timelines and priorities. This dual structure has allowed for the quiet emergence of vulnerabilities that remain […]
The post Beyond CVE China’s Dual Vulnerability Databases Reveal a Different Disclosure Timeline appeared first on Cyber Security News.