Aggregator
CVE-2026-2295 | WPZOOM Addons for Elementor Plugin up to 1.3.2 on WordPress ajax_post_grid_load_more information disclosure
CVE-2025-15096 | Videospirecore Theme Plugin up to 1.0.6 on WordPress Email Address authorization
CVE-2026-1885 | Slideshow Wp Plugin up to 1.1 on WordPress Shortcode sswp-slide sswpid cross site scripting
CVE-2026-1853 | BuddyHolis ListSearch Plugin up to 1.1 on WordPress Shortcode placeholder cross site scripting
CVE-2026-1885 | Slideshow Wp Plugin up to 1.1 on WordPress Shortcode sswp-slide sswpid cross site scripting
CVE-2026-1853 | BuddyHolis ListSearch Plugin up to 1.1 on WordPress Shortcode placeholder cross site scripting
CVE-2026-1827 | Flask Micro code-editor Plugin up to 1.0.0 on WordPress Shortcode Title cross site scripting
CVE-2025-30266 | QNAP Systems Qsync Central prior 5.0.0.4 null pointer dereference (qsa-26-02)
CVE-2025-30269 | QNAP Systems Qsync Central prior 5.0.0.4 format string (qsa-26-02)
CVE-2024-56808 | QNAP Systems Media Streaming add-on prior 500.1.1.6 os command injection (qsa-25-57)
CVE-2024-56807 | QNAP Systems Media Streaming add-on prior 500.1.1.6 out-of-bounds (qsa-25-57)
ThreatsDay Bulletin: AI Prompt RCE, Claude 0-Click, RenEngine Loader, Auto 0-Days & 25+ Stories
CVE-2026-2321 | Google Chrome up to 144.0.7559.132 Ozone use after free (ID 461877 / Nessus ID 298717)
Apple patches zero-day flaw that could let attackers take control of devices
Apple issued security updates for all devices which include a patch for an actively exploited zero-day—tracked as CVE-2026-20700.
The post Apple patches zero-day flaw that could let attackers take control of devices appeared first on Security Boulevard.
Lazarus Group’s ‘Graphalgo’ Fake Recruiter Campaign Exploits GitHub, npm, and PyPI to Distribute Malware
The North Korean state-sponsored hacking team, Lazarus Group, has launched a sophisticated fake recruiter campaign targeting cryptocurrency developers through a malicious operation called “graphalgo.” Active since May 2025, this coordinated attack uses fraudulent job offers to distribute remote access trojans to unsuspecting developers working with blockchain and cryptocurrency technologies. The campaign exploits trusted open-source package […]
The post Lazarus Group’s ‘Graphalgo’ Fake Recruiter Campaign Exploits GitHub, npm, and PyPI to Distribute Malware appeared first on Cyber Security News.
«Вчера было рано, а завтра — поздно». Сбербанк внезапно проиграл конкуренцию ИИ
Pickling the Mailbox: A Deep Dive into CVE-2025-20393
Fortune 500 Tech Enterprise Speeds up Triage and Response with ANY.RUN’s Solutions
In enterprise SaaS, unclear security decisions carry real cost. False positives disrupt customers, while missed threats expose the business. A Fortune 500 cloud provider addressed this risk by embedding ANY.RUN into SOC investigations, giving analysts the behavioral evidence needed to reduce escalations, improve triage confidence, and make proportionate response decisions at scale. Company Context and Security Scope The organization is a […]
The post Fortune 500 Tech Enterprise Speeds up Triage and Response with ANY.RUN’s Solutions appeared first on ANY.RUN's Cybersecurity Blog.