Aggregator
LummaStealer activity spikes post-law enforcement disruption
CVE-2026-1893 | Orbisius Random Name Generator Plugin up to 1.0.2 on WordPress Shortcode btn_label cross site scripting (CNNVD-202602-2050)
CVE-2025-15400 | Pix Para Woocommerce Plugin up to 2.13.3 on WordPress Payment Gateway Configuration authorization (CNNVD-202602-2039)
CVE-2026-26079 | Roundcube Webmail up to 1.5.12/1.6.12 Cascading Style Sheet inclusion of functionality from untrusted control sphere (CNNVD-202602-2040)
CVE-2026-1231 | Beaver Builder Page Builder Plugin up to 2.10.0.5 on WordPress save_global_settings cross site scripting (CNNVD-202602-2051)
Wapens, munitie, materieel en F-16-simulatoren voor Oekraïne
Windows Notepad Markdown feature opens door to RCE (CVE-2026-20841)
Among the many security fixes released by Microsoft on February 2026 Patch Tuesday is one for CVE-2026-20841, a command injection vulnerability in Notepad that could be exploited by attackers to achieve remote code execution on targets’ Windows system. About CVE-2026-20841 For many, many years, Windows Notepad was a simple text editor and a staple tool for everyone who wanted a no-frills way to work with plain text, but in early 2022, Microsoft started redesigning it … More →
The post Windows Notepad Markdown feature opens door to RCE (CVE-2026-20841) appeared first on Help Net Security.
Кто потушил звезду в созвездии Единорога на год? Виноват «Супер-Юпитер» с кольцами в пол-Солнечной системы
AI is Supercharging Romance Scams with Deepfakes and Bots
AI is giving online romance scammers even more ways to hide and accelerate their schemes while making it more difficult for people to detect fraud operations that are resulting in billions of dollars being stolen every year from millions of victims.
The post AI is Supercharging Romance Scams with Deepfakes and Bots appeared first on Security Boulevard.
CVE-2025-15524 | Gallery by FooGallery Plugin up to 3.1.9 on WordPress ajax_get_gallery_info authorization (CNNVD-202602-2052)
CVE-2025-14541 | Lucky Wheel Giveaway Plugin up to 1.0.22 on WordPress conditional_tags code injection (CNNVD-202602-2053)
CVE-2025-13431 | SlimStat Analytics Plugin up to 5.3.1 on WordPress args sql injection (CNNVD-202602-2054)
CVE-2026-1571 | TP-Link Archer C60 v3 prior V3_260206 cross site scripting (CNNVD-202602-2055)
Black Duck expands Polaris platform with unified, automated security across all major SCMs
Black Duck has announced the availability of a set of enhanced Black Duck Polaris Platform integrations across all major source code management (SCM) platforms, including GitHub, GitLab, Azure DevOps, and Bitbucket. The Polaris Platform is an integrated, software-as-a-service application security platform powered by the static application security testing, software composition analysis, and dynamic application security testing engines. With development teams managing an explosion of human and AI-generated code and increasingly distributed development environments, manual onboarding … More →
The post Black Duck expands Polaris platform with unified, automated security across all major SCMs appeared first on Help Net Security.
Outlook add-in goes rogue and steals 4,000 credentials and payment data
The once popular Outlook add-in AgreeTo was turned into a powerful phishing kit after the developer abandoned the project.
The post Outlook add-in goes rogue and steals 4,000 credentials and payment data appeared first on Security Boulevard.
AMOS infostealer targets macOS through a popular AI app
Google выпустила Android 16, а заодно напомнила миллиарду человек, что их смартфоны пора выбросить
INC
You must login to view this content
Rhysida
You must login to view this content