Aggregator
CVE-2026-39834 | x-crypto up to 0.51.x integer overflow (EUVD-2026-31400 / Nessus ID 316559)
CVE-2026-39832 | x-crypto up to 0.51.x on Go Destination NewKeyring access control (EUVD-2026-31390 / Nessus ID 316565)
CVE-2026-39830 | x-crypto up to 0.51.x on Go SSH Peer Close deadlock (EUVD-2026-31397 / Nessus ID 316570)
CVE-2026-39833 | x-crypto up to 0.51.x NewKeyring security check (EUVD-2026-31389 / Nessus ID 316601)
CVE-2026-39831 | x-crypto up to 0.51.x FIDO/U2F Verify authentication spoofing (EUVD-2026-31395 / Nessus ID 316571)
CVE-2026-12706 | FFmpeg RASC Video Decoder decode_move use after free (WID-SEC-2026-2015)
CVE-2026-39829 | x-crypto up to 0.51.x RSA/DSA inefficient cpu computation (EUVD-2026-31396 / Nessus ID 316561)
Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way
HazyBeacon Weaponizes AWS Lambda Function URLs for Stealth Command-and-Control Relays
HazyBeacon, tracked as CL-STA-1020, is a stealthy cyber-espionage campaign targeting Southeast Asian government networks by abusing AWS Lambda Function URLs as covert command-and-control (C2) relays. Qualys Security researchers have observed attackers leveraging misconfigured serverless features and stolen cloud credentials to blend malicious traffic into trusted AWS infrastructure, making detection significantly harder. Traditional malware relied on […]
The post HazyBeacon Weaponizes AWS Lambda Function URLs for Stealth Command-and-Control Relays appeared first on Cyber Security News.
CVE-2026-11576 | Eclipse ThreadX up to 6.5.0.202601 fx_file_close double free (EUVD-2026-37999)
CVE-2026-56138 | ail-project ail-framework up to 6.7.x Endpoint /objects/item/diff path traversal (EUVD-2026-37998)
CVE-2026-41156 | Imagination Graphics DDK up to 26.1 RTM use after free (EUVD-2026-38002)
CVE-2026-34192 | Imagination Graphics DDK up to 1.18 RTM/23.2 RTM/24.2 RTM/25.3 RTM GPU Page use after free (EUVD-2026-38001)
CVE-2026-8296 | Octopus Deploy Octopus Server up to 2025.4.10677/2026.1.11450/2026.2.13113 cross site scripting (EUVD-2026-38000)
0day в JCE: взломать Joomla теперь быстрее, чем загрузить картинку. Вот что делать прямо сейчас
The Good, the Bad and the Ugly in Cybersecurity – Week 25
Temporary Cloudflare Accounts for AI agents
Stressors, AI Forcing Changes to Cybersecurity Teams
Klue breach lead to Salesforce data theft, Huntress affected
Cybersecurity vendor Huntress was among multiple companies hit by a breach originating at Klue, a market intelligence platform used to integrate CRM and sales data across various business tools. Huntress published a detailed account of the incident on June 18, framing it as a “security domino effect” that began with one compromised integration credential and cascaded into theft of customer data across several connected platforms, including Salesforce. Attack timeline According to Huntress’s writeup, the attackers … More →
The post Klue breach lead to Salesforce data theft, Huntress affected appeared first on Help Net Security.