Aggregator
CVE-2026-41961 | Huawei HarmonyOS 5.1.0/6.0.0/6.1.0 logic error
CVE-2026-41960 | Huawei HarmonyOS/EMUI denial of service
Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA
Cybercriminals behind the Tycoon 2FA phishing kit have added a powerful new weapon to their playbook. By combining their well-known phishing infrastructure with OAuth Device Code abuse, they can now steal access to Microsoft 365 accounts without ever capturing a single password. The Tycoon 2FA phishing kit first gained attention as a Phishing-as-a-Service (PhaaS) platform. […]
The post Tycoon 2FA Operators Adopt OAuth Device Code Phishing to Bypass MFA appeared first on Cyber Security News.
CVE-2017-3266 | Oracle Outside In Technology 8.5.2/8.5.3 Outside In Filters access control (Nessus ID 99236 / ID 371198)
CVE-2017-3267 | Oracle Outside In Technology 8.5.2/8.5.3 Outside In Filters denial of service (Nessus ID 99236 / ID 371198)
CVE-2017-3268 | Oracle Outside In Technology 8.5.2/8.5.3 Outside In Filters denial of service (Nessus ID 99236 / ID 371198)
CVE-2017-3269 | Oracle Outside In Technology 8.5.2/8.5.3 Outside In Filters access control (Nessus ID 99236 / ID 371198)
CVE-2017-3270 | Oracle Outside In Technology 8.5.2/8.5.3 Outside In Filters access control (Nessus ID 99236 / ID 371198)
CVE-2017-3271 | Oracle Outside In Technology 8.5.2/8.5.3 Outside In Filters access control (Nessus ID 99236 / ID 371198)
CVE-2017-3264 | Oracle Siebel CRM 16.1 Open UI (BID-95508 / ID 1037635)
CVE-2017-3263 | Oracle Primavera P6 Enterprise Project Portfolio Management Team Member access control (BID-95535)
CVE-2017-3272 | Oracle Java SE 6u131/7u121/8u112 Libraries memory corruption (Nessus ID 96628 / ID 371523)
CVE-2017-3262 | Oracle Java SE 8u112 Java Mission Control access control (Nessus ID 96628 / ID 236243)
CVE-2017-3273 | Oracle MySQL Server 5.6.34/5.7.16 DDL input validation (Nessus ID 96618 / ID 20029)
CVE-2017-3265 | Oracle MySQL Server 5.5.53/5.6.34/5.7.16 Packaging access control (Nessus ID 96732 / ID 175942)
В Германии задержали предполагаемого главу наркоплощадки Dream Market. Следствие считает, что он менял крипту на золото и отправлял слитки себе домой
Akamai to acquire LayerX for $205 million
Akamai has entered into a definitive agreement to acquire LayerX, a provider of browser-based AI usage control and secure enterprise browser (SEB) technology. LayerX’s solutions will extend Akamai’s protection into the browser, where the majority of enterprise tasks now occur and where today’s workforce engages with generative AI applications, SaaS AI solutions, and AI agents. With this acquisition, Akamai is taking a critical step in the evolution of its zero trust security portfolio and addressing … More →
The post Akamai to acquire LayerX for $205 million appeared first on Help Net Security.
PraisonAI Vulnerability Exploited Within Hours of Public Disclosure
As artificial intelligence frameworks become central to enterprise operations, a critical flaw in a popular AI platform has exposed organizations to serious security risks from threat actors. Within hours of public disclosure, a severe vulnerability in PraisonAI’s legacy API server, tracked as CVE-2026-44338, is already sending shockwaves through the developer community. By shipping with authentication […]
The post PraisonAI Vulnerability Exploited Within Hours of Public Disclosure appeared first on Cyber Security News.
Amazon Redshift JDBC Driver Vulnerabilities Enables Remote Code Execution Attacks
A critical vulnerability in the Amazon Redshift JDBC driver has put enterprise applications at severe risk of Remote Code Execution (RCE). Threat actors can exploit this newly disclosed flaw simply by manipulating database connection URLs. This hidden vulnerability allows attackers to hijack the application process from within, potentially exposing sensitive enterprise data to unauthorized access […]
The post Amazon Redshift JDBC Driver Vulnerabilities Enables Remote Code Execution Attacks appeared first on Cyber Security News.