Posts of last few hours
A vulnerability was found in Legion of the Bouncy Castle BC-JAVA up to 1.84. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component ldapStoreHelper. The manipulation results in injection.
This vulnerability is known as CVE-2026-59652. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/385441
A vulnerability classified as problematic was found in Legion of the Bouncy Castle Bouncy Castle for Java, Bouncy Castle for Java LTS and Bouncy Castle for Java FIPS. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to denial of service.
This vulnerability is tracked as CVE-2026-58059. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
https://vuldb.com/vuln/385463
A vulnerability classified as critical was found in Legion of the Bouncy Castle Bouncy Castle for Java, Bouncy Castle for Java LTS and Bouncy Castle for Java FIPS up to 1.84/2.73.11/bc-fips 1.0.2.6/2.0.1/2.1.2. Impacted is an unknown function of the component Name Constraints. The manipulation results in improper certificate validation.
This vulnerability is cataloged as CVE-2026-8763. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/385435
A vulnerability has been found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2/6.19-rc2 and classified as critical. The affected element is the function fsl_otg_conf. Performing a manipulation results in use after free.
This vulnerability is known as CVE-2025-68781. Access to the local network is required for this attack. No exploit is available.
The affected component should be upgraded.
https://vuldb.com/vuln/340666
A vulnerability was found in Linux Kernel up to 6.6.127/6.12.74/6.18.13/6.19.3. It has been classified as critical. The impacted element is an unknown function of the component inet. The manipulation leads to state issue.
This vulnerability is uniquely identified as CVE-2026-46266. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/368178
https://www.securitylab.ru/analytics/576835.php
A forum actor posting as Keishell, crediting two others, has published what they describe as the myTnT shipment database belonging to pattons.com.au, an Australian business.
https://darkwebinformer.com/pattons-shipping-records-published-free-with-goods-values-and-delivery-details/
Salesforce 把界面交给 Claude,保留数据、业务规则和执行能力。“无头 SaaS”可能加深客户依赖、改善 CRM 数据,也让双方的合作埋下未来平台竞争的伏笔。
https://mp.weixin.qq.com/s?__biz=MzUzOTI4NDQ3NA==&mid=2247485197&idx=1&sn=17776eea48e067f5c3ce68b4fd591f34
Версию кибератаки проверяют после массовых сбоев сразу в нескольких штатах.
https://www.securitylab.ru/news/576813.php
The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week.
https://therecord.media/new-pro-ukraine-hacker-group-custom-ransomware-russia
It’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia yet.
The post Pegasus, NoviSpy variant spyware found on devices of Serbian activists appeared first on CyberScoop.
https://cyberscoop.com/pegasus-novispy-variant-spyware-found-on-devices-of-serbian-activists/
Russian man extradited to US over malware campaign that targeted 80,000 freelance users
https://www.infosecurity-magazine.com/news/russian-man-extradited-malware/
it’s the latest in a sequence of letters to feds from Sen. Ron Wyden, D-Ore., on commercial VPNs.
The post Wyden seeks upgraded NSA security guidance on commercial VPN use appeared first on CyberScoop.
https://cyberscoop.com/wyden-nsa-commercial-vpn-security-guidance/
A vulnerability has been found in Libevent up to 2.1.12 and classified as critical. This impacts the function evhttp_find_header of the file http.c of the component Evhttp Parser. The manipulation leads to crlf injection.
This vulnerability is traded as CVE-2026-63382. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/393810
A vulnerability categorized as problematic has been discovered in Libevent. This vulnerability affects the function bufferevent_socket_set_conn_address_ of the file bufferevent_sock.c of the component AF_UNIX Address Handler. Executing a manipulation can lead to out-of-bounds write.
The identification of this vulnerability is CVE-2026-63388. The attack can only be executed locally. There is no exploit available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/393815
A vulnerability has been found in iperf3 and classified as problematic. This affects an unknown part. This manipulation causes resource consumption.
This vulnerability is tracked as CVE-2026-71217. The attack is possible to be carried out remotely. No exploit exists.
https://vuldb.com/vuln/388028
A vulnerability has been found in Linux Kernel up to 6.12.100/6.18.39/7.1.4 and classified as very critical. This issue affects the function nvmet_execute_auth_receive of the component nvmet-auth. Performing a manipulation results in out-of-bounds write.
This vulnerability was named CVE-2026-72130. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
https://vuldb.com/vuln/390604
A vulnerability identified as very critical has been detected in Linux Kernel up to 6.6.147/6.12.100/6.18.39/7.1.4. Impacted is the function rt_spin_unlock of the component Locking/RT. Performing a manipulation results in use after free.
This vulnerability was named CVE-2026-72069. The attack needs to be approached locally. There is no available exploit.
You should upgrade the affected component.
https://vuldb.com/vuln/390484
This joint guidance explains why effective communications during outages is critical to minimize operational impacts, maintain credibility and situational awareness, and support response efforts.
https://cyber.gc.ca/en/news-events/joint-guidance-best-practices-service-providers-when-communicating-under-pressure
https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188408&idx=1&sn=d492a25528a4bfa8111f644cb566f7ab
Latest Blog Posts
- 1 week 5 days ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 2 weeks ago
- 7 months 1 week ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago