Aggregator
What Happens to Crypto When No One Can Afford to Mine?
CVE-2026-5124 | osrg GoBGP up to 4.3.0 BGP Header pkg/packet/bgp/bgp.go BGPHeader.DecodeFromBytes access control (ID 3340)
CVE-2026-5123 | osrg GoBGP up to 4.3.0 pkg/packet/bgp/bgp.go DecodeFromBytes data[1] off-by-one (ID 3342)
Submit #780154: raine consult-llm-mcp <=2.5.3 Command Injection [Accepted]
CVE-2026-5122 | osrg GoBGP up to 4.3.0 BGP OPEN Message pkg/packet/bgp/bgp.go DecodeFromBytes domainNameLen access control (ID 3343 / EUVD-2026-17091)
Submit #780189: osrg GoBGP 4.3.0 Improper Input Validation [Accepted]
Submit #780179: osrg GoBGP 4.3.0 Off-by-one Error [Accepted]
New macOS Infinity Stealer uses Nuitka Python payload and ClickFix
New macOS Infinity Stealer uses Nuitka Python payload and ClickFix
CVE-2026-2328 | WAGO Device Sphere/Solution Builder up to 1.2.1 improper filtering of special elements (VDE-2026-010 / EUVD-2026-17064)
Smart Homes Are Getting Smarter—But Post-Breach Guidance Is Falling Behind
Critical Fortinet Forticlient EMS flaw now exploited in attacks
Submit #780124: GoBGP 4.3.0 Improper Handling of Length Parameter Inconsistency [Accepted]
New “Prompt Poaching” Attack Steals Users’ AI Conversations via Malicious Browser Extensions
For many users, engaging with an AI assistant requires opening a dedicated browser tab, which inherently isolates the AI from other browsing activities. While this separation improves privacy, it reduces usefulness and context. To bridge this gap, AI-powered browser extensions have surged in popularity, allowing AI agents to seamlessly interact with emails, corporate portals, and […]
The post New “Prompt Poaching” Attack Steals Users’ AI Conversations via Malicious Browser Extensions appeared first on Cyber Security News.
CVE-2026-5119 | GNOME libsoup HTTP Proxy cleartext transmission (EUVD-2026-17062)
CVE-2025-15379 | MLflow up to 3.8.1 Model _install_model_dependencies_to_env command injection (EUVD-2025-209121)
CVE-2026-3945 | tinyproxy up to 1.11.3 Chunk strtol integer overflow (EUVD-2026-17066 / WID-SEC-2026-0909)
EvilMist: The Ultimate Swiss Army Knife for Azure and Entra ID Red Teaming
EvilMist is a collection of scripts and utilities designed to support cloud security configuration audit, cloud penetration testing
The post EvilMist: The Ultimate Swiss Army Knife for Azure and Entra ID Red Teaming appeared first on Penetration Testing Tools.