Aggregator
Ideco представит архитектурные изменения Ideco NGFW Novum на вебинаре
CVE-2026-34441 | yhirose cpp-httplib up to 0.39.x HTTP Request request smuggling (GHSA-jv63-rm9j-6jwc / Nessus ID 304631)
CVE-2026-35092 | Corosync UDP Packet integer overflow (Nessus ID 304628)
CVE-2026-35094 | libinput expired pointer dereference (EUVD-2026-17909 / Nessus ID 304629)
CVE-2026-35093 | libinput Lua code injection (EUVD-2026-17907 / Nessus ID 304630)
DarkSword exploit forces Apple to loosen its patching policy
Apple has extended security updates to a wider range of devices still running iOS 18, aiming to protect users from the DarkSword exploit kit. This is not the first time Apple has backported fixes for older devices based on vulnerability severity. Allowing iOS 18 users to receive patches without upgrading to iOS 26, however, signals a shift in its long-standing security approach following the discovery of the DarkSword and Coruna exploit kits. When iOS 26 … More →
The post DarkSword exploit forces Apple to loosen its patching policy appeared first on Help Net Security.
CVE-2026-5418 | appsmithorg appsmith up to 1.97 Dashboard WebClientUtils.java computeDisallowedHosts server-side request forgery (GHSA-9m89-5jw7-q5cr)
CVE-2026-5417 | Dataease SQLbot up to 1.6.0 Elasticsearch es_engine.py get_es_data_by_http address server-side request forgery
WhatsApp Warns Users Targeted by Spyware Attack via Weaponized Version of the App
Meta has officially alerted approximately 200 WhatsApp users, primarily located in Italy, that their devices were compromised by a weaponized, fraudulent version of the messaging application. This malicious software was distributed through social engineering tactics rather than official app stores, tricking targets into installing a spyware-laden clone. The fraudulent application was designed to mimic the […]
The post WhatsApp Warns Users Targeted by Spyware Attack via Weaponized Version of the App appeared first on Cyber Security News.