Aggregator
CVE-2026-42588
CVE-2022-41678
CVE-2026-40466
CVE-2016-3088
CVE-2015-5254
CVE-2026-23631
CVE-2024-32114
CVE-2026-34197
CVE-2023-46604
CVE-2025-8088
Apache HTTP Server 2.4.68 Released With Fix For Use-After-Free, DoS, XSS, and Buffer Overflow Flaws
The Apache Software Foundation released Apache HTTP Server version 2.4.68 on June 8, 2026, addressing 13 security vulnerabilities spanning multiple modules. The patched flaws include use-after-free conditions, cross-site scripting, heap-based buffer overflows, denial-of-service, privilege escalation, and out-of-bounds read issues affecting all versions from 2.4.0 through 2.4.67. Administrators running any prior release are strongly urged to […]
The post Apache HTTP Server 2.4.68 Released With Fix For Use-After-Free, DoS, XSS, and Buffer Overflow Flaws appeared first on Cyber Security News.
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
JVN: CamViewのインストーラにおけるDLL読み込みに関する脆弱性
21 0-Day Vulnerabilities in FFmpeg Enables Remote Code Execution Attacks
An autonomous security agent uncovered 21 zero-day vulnerabilities in FFmpeg, the world’s most widely deployed media processing library, including a critical RCE-capable heap buffer overflow reachable with a single 183-byte network packet. FFmpeg quietly powers media processing across browsers, streaming platforms, surveillance systems, and cloud infrastructure, making it one of the most security-critical open-source libraries. […]
The post 21 0-Day Vulnerabilities in FFmpeg Enables Remote Code Execution Attacks appeared first on Cyber Security News.
Remote Code Execution: Critical Flaw in Everest Forms Pro Enables WordPress Invasions
Even a mundane feedback form can morph into an initial attack vector. This transition occurs when a data handler executes submitted text as code. Specifically, adversaries are actively exploiting a critical vulnerability designated as...
The post Remote Code Execution: Critical Flaw in Everest Forms Pro Enables WordPress Invasions appeared first on Information Security News.
Judicial Paradigm Shift: Belgian Court Orders Bank to Reimburse Phishing Victims
An elderly couple in Antwerp, Belgium, suffered a devastating loss of €50,000. Specifically, an impostor masqueraded as a banking official. He seamlessly manipulated the spouses into transferring their funds to an alleged “secure” account....
The post Judicial Paradigm Shift: Belgian Court Orders Bank to Reimburse Phishing Victims appeared first on Information Security News.
Architectural Blueprints: The Security Risks of Exposed Swagger Specifications
An Application Programming Interface description file might seem like an ordinary technical detail. However, for malicious actors, this file often serves as an elegant map of an external service. The Mechanics of API Exposure...
The post Architectural Blueprints: The Security Risks of Exposed Swagger Specifications appeared first on Information Security News.
New Shai-Hulud Attack Compromises 23 PyPI Packages to Target MCP Developers
A new wave of the Shai-Hulud supply chain campaign, adding 23 newly discovered malicious PyPI package-version artifacts to an already alarming operation that previously compromised 37 packages. The broader campaign identified by the Socket Threat Research team, tracked across the Mini Shai-Hulud, Miasma, and Hades threat clusters, now spans 471 total artifacts across npm and PyPI, comprising […]
The post New Shai-Hulud Attack Compromises 23 PyPI Packages to Target MCP Developers appeared first on Cyber Security News.
Vocal Deception: The Pink Extortion Syndicate Weaponizes Social Engineering
Cyber-extortionists increasingly eschew complex digital intrusions. Instead, they initiate malicious campaigns through conventional voice dialogues. Fraudsters smoothly convince employees that they are speaking with internal IT personnel. Subsequently, they manipulate targets into submitting authentication...
The post Vocal Deception: The Pink Extortion Syndicate Weaponizes Social Engineering appeared first on Information Security News.