Aggregator
Meet GREYVIBE, the Russia-Linked Hacking Group Using AI to Target Ukraine and Still Making Rookie Mistakes
9 hours 7 minutes ago
GREYVIBE, a Russia-linked group active since 2025, targets Ukraine with AI-assisted malware and five attack chains. Researchers say it’s part spy op, part crime gang. Security firm WithSecure has been tracking a previously unknown Russian-linked APT group called GREYVIBE since at least August 2025. The group targets Ukraine and Ukrainian-related organizations across military, government, civilian, […]
Pierluigi Paganini
ChatGPT share links abused to host fake outage pages to deliver malware
9 hours 9 minutes ago
Threat actors are abusing ChatGPT's content-sharing feature to display fake OpenAI outage pages that direct users to download malware disguised as the ChatGPT desktop application. [...]
Lawrence Abrams
California AG sues 23andMe over 2023 breach exposing health data
9 hours 21 minutes ago
California Attorney General Rob Bonta filed a lawsuit against 23andMe, now Chrome Holding Co., over the company's failure to protect sensitive customer genetic and personal information. [...]
Bill Toulas
ChatGPhish Vulnerability Turns ChatGPT Web Summaries Into a Phishing Surface
9 hours 23 minutes ago
Cybersecurity researchers have disclosed details of a vulnerability in OpenAI ChatGPT that leverages the artificial intelligence (AI) assistant's implicit trust in Markdown links and images to trigger prompt injections and open the door to phishing attacks.
The technique has been codenamed ChatGPhish by Permiso Security.
"The chatgpt.com response renderer trusts Markdown links and Markdown
The Hacker News
Top 10 artificial intelligence security actions: A primer - ITSAP.10.049
9 hours 24 minutes ago
Our top AI security actions are designed to help organizations of all sizes and sectors strengthen their cyber resilience.
Canadian Centre for Cyber Security
CVE-2026-10127 | Edimax BR-6478AC 1.23 POST Request /goform/formStaDrvSetup rootAPmac command injection
10 hours ago
A vulnerability classified as critical has been found in Edimax BR-6478AC 1.23. This affects the function formStaDrvSetup of the file /goform/formStaDrvSetup of the component POST Request Handler. This manipulation of the argument rootAPmac causes command injection.
This vulnerability appears as CVE-2026-10127. The attack may be initiated remotely. In addition, an exploit is available.
vuldb.com
CVE-2026-10126 | Edimax BR-6478AC 1.23 POST Request /goform/formQoS selSSID buffer overflow
10 hours ago
A vulnerability described as critical has been identified in Edimax BR-6478AC 1.23. Affected by this issue is the function formQoS of the file /goform/formQoS of the component POST Request Handler. The manipulation of the argument selSSID results in buffer overflow.
This vulnerability is reported as CVE-2026-10126. The attack can be launched remotely. Moreover, an exploit is present.
vuldb.com
CVE-2026-10125 | Edimax BR-6478AC 1.23 POST Request /goform/formPPPoESetup pppUserName stack-based overflow
10 hours ago
A vulnerability marked as critical has been reported in Edimax BR-6478AC 1.23. Affected by this vulnerability is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. The manipulation of the argument pppUserName leads to stack-based buffer overflow.
This vulnerability is documented as CVE-2026-10125. The attack can be initiated remotely. Additionally, an exploit exists.
vuldb.com
CVE-2026-10124 | Shibby Tomato up to 1.28 Zserv /usr/sbin/ripd rip_zebra_read_ipv4 stack-based overflow (IJ9FFG)
10 hours 4 minutes ago
A vulnerability labeled as critical has been found in Shibby Tomato up to 1.28. Affected is the function rip_zebra_read_ipv4 of the file /usr/sbin/ripd of the component Zserv Handler. Executing a manipulation can lead to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is registered as CVE-2026-10124. It is possible to launch the attack remotely. Furthermore, an exploit is available.
This project is superseded by FreshTomato.
vuldb.com
CVE-2026-10123 | TRENDnet TEW-432BRP 3.10B20 formSetDomainFilter stack-based overflow
10 hours 5 minutes ago
A vulnerability identified as critical has been detected in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetDomainFilter of the file /goform/formSetDomainFilter. Performing a manipulation of the argument blocked_domain/permitted_domain/blocked_domain_list/permitted_domain_list results in stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is cataloged as CVE-2026-10123. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."
vuldb.com
CVE-2026-10122 | TRENDnet TEW-432BRP 3.10B20 formSetProtocolFilter protocol_name stack-based overflow
10 hours 5 minutes ago
A vulnerability categorized as critical has been discovered in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetProtocolFilter of the file /goform/formSetProtocolFilter. Such manipulation of the argument protocol_name leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is listed as CVE-2026-10122. The attack may be performed from remote. In addition, an exploit is available.
The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."
vuldb.com
CVE-2026-10121 | TRENDnet TEW-432BRP 3.10B20 /goform/formSetUrlFilter keyword_list/keyword stack-based overflow
10 hours 5 minutes ago
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. It has been rated as critical. The impacted element is the function formSetUrlFilter of the file /goform/formSetUrlFilter. This manipulation of the argument keyword_list/keyword causes stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is tracked as CVE-2026-10121. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."
vuldb.com
CVE-2026-10120 | TRENDnet TEW-432BRP 3.10B20 formSetFirewallRule firewall_name stack-based overflow
10 hours 6 minutes ago
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. It has been declared as critical. The affected element is the function formSetFirewallRule of the file /goform/formSetFirewallRule. The manipulation of the argument firewall_name results in stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is identified as CVE-2026-10120. The attack can be executed remotely. Additionally, an exploit exists.
The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."
vuldb.com
CVE-2026-10119 | TRENDnet TEW-432BRP 3.10B20 /goform/formSetMACFilter filter_name stack-based overflow
10 hours 6 minutes ago
A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. It has been classified as critical. Impacted is the function formSetMACFilter of the file /goform/formSetMACFilter. The manipulation of the argument filter_name leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is referenced as CVE-2026-10119. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."
vuldb.com
CVE-2026-10117 | Open5GS up to 2.7.7 nghttp2-server.c ogs_pool_id_calloc denial of service (Issue 4474)
10 hours 10 minutes ago
A vulnerability was found in Open5GS up to 2.7.7 and classified as problematic. This issue affects the function ogs_pool_id_calloc in the library /lib/sbi/nghttp2-server.c. Executing a manipulation can lead to denial of service.
The identification of this vulnerability is CVE-2026-10117. The attack may be launched remotely. Furthermore, there is an exploit available.
It is best practice to apply a patch to resolve this issue.
vuldb.com
CVE-2026-10116 | Open5GS up to 2.7.7 ue-authentications Endpoint /lib/core/ogs-timer.c ogs_sbi_xact_add denial of service (Issue 4473)
10 hours 10 minutes ago
A vulnerability has been found in Open5GS up to 2.7.7 and classified as problematic. This vulnerability affects the function ogs_sbi_xact_add in the library /lib/core/ogs-timer.c of the component ue-authentications Endpoint. Performing a manipulation results in denial of service.
This vulnerability was named CVE-2026-10116. The attack may be initiated remotely. In addition, an exploit is available.
Applying a patch is the recommended action to fix this issue.
vuldb.com
CVE-2026-10115 | Open5GS up to 2.7.7 Shared NF-profile Parser lib/sbi/nnrf-handler.c denial of service (Issue 4469)
10 hours 10 minutes ago
A vulnerability, which was classified as problematic, was found in Open5GS up to 2.7.7. This affects an unknown part in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. Such manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2026-10115. The attack can be launched remotely. Moreover, an exploit is present.
It is advisable to implement a patch to correct this issue.
vuldb.com
CVE-2026-10114 | Open5GS up to 2.7.7 Shared NF-profile Parser lib/sbi/nnrf-handler.c handle_scp_info out-of-bounds write (Issue 4468)
10 hours 10 minutes ago
A vulnerability, which was classified as problematic, has been found in Open5GS up to 2.7.7. Affected by this issue is the function handle_scp_info in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. This manipulation causes out-of-bounds write.
This vulnerability is handled as CVE-2026-10114. The attack can be initiated remotely. Additionally, an exploit exists.
To fix this issue, it is recommended to deploy a patch.
vuldb.com
CVE-2026-10113 | Open5GS up to 2.7.7 Shared NF-profile Parser lib/sbi/nnrf-handler.c denial of service (Issue 4467)
10 hours 10 minutes ago
A vulnerability classified as problematic was found in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. The manipulation results in denial of service.
This vulnerability is known as CVE-2026-10113. It is possible to launch the attack remotely. Furthermore, an exploit is available.
A patch should be applied to remediate this issue.
vuldb.com