Aggregator
CVE-2026-5331 | OpenCart 4.1.0.3 Extension Installer Page installer.php path traversal
CVE-2026-5330 | SourceCodester/mayuri_k Best Courier Management System 1.0 User Delete ajax.php?action=delete_user ID access control
Submit #780814: OpenCart 4.1.0.3 Path Traversal [Accepted]
Submit #780734: Mayuri K. Gaatitrack Courier Management System 1.0 Broken Access Control [Accepted]
Google links Axios npm supply chain attack to North Korea-linked APT UNC1069
CVE-2026-3877 | VertiGIS FM up to 10.13.402 cross site scripting
CVE-2026-0522 | VertiGIS FM up to 10.11.362 external reference
CVE-2026-35092 | Corosync UDP Packet integer overflow
CVE-2026-35091 | Corosync UDP Packet function return value
Холоднее космоса. Глубже 2 километров. Тише абсолютного нуля. Физики включили ловушку для тёмной материи
CVE-2026-5328 | shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6 ProductItemDao Interface ProductIndexServiceImpl.java listItem sidx/sort sql injection
New Venom Stealer MaaS Platform Automates Continuous Data Theft
Submit #780789: Shopsuite modulithshop 829bac71f507e84684c782b9b062b8bf3b5585d6 SQL Injection [Accepted]
Submit #780776: efforthye fast-filesystem-mcp <= 3.5.1 Command Injection [Accepted]
Exabeam expands ABA to detect AI agent threats across ChatGPT, Copilot, and Gemini
Exabeam has announced the expansion of Exabeam Agent Behavior Analytics (ABA). Without direct visibility into how employees use AI assistants, what they query, what data they share, how frequently they interact, and from where, organizations cannot establish a baseline for normal AI behavior, investigate potential misuse, or detect emerging agentic insider threats. New support to detect agent behavior in OpenAI ChatGPT and Microsoft Copilot, alongside existing visibility into Google Gemini, transforms these agentic services into … More →
The post Exabeam expands ABA to detect AI agent threats across ChatGPT, Copilot, and Gemini appeared first on Help Net Security.
Submit #780773: SourceCodester Leave Application System in PHP and SQLite3 1.0 Improper Authorization [Accepted]
Submit #780766: SourceCodester Simple Customer Relationship Management (CRM) System 1.0 Cross Site Scripting [Accepted]
Submit #780752: priyankark a11y-mcp 1.0.4 Server-Side Request Forgery [Accepted]
Google Cloud’s Vertex AI platform Vulnerability Allow Attackers to Access Sensitive Data
Artificial intelligence agents are rapidly becoming integral to enterprise workflows, but they also introduce new attack surfaces. Security researchers recently uncovered a significant vulnerability within Google Cloud Platform’s Vertex AI Agent Engine. By exploiting default permission scoping, attackers could weaponize deployed AI agents into “double agents” that secretly exfiltrate data and compromise cloud infrastructure. Exploiting […]
The post Google Cloud’s Vertex AI platform Vulnerability Allow Attackers to Access Sensitive Data appeared first on Cyber Security News.