Aggregator
GitBait Phishing Campaign Abuses GitHub Pages to Attack Financial Institutions
A sophisticated phishing campaign called “GitBait” has been caught targeting Mexico’s financial sector with a level of precision rarely seen in credential-theft operations. The campaign abuses GitHub Pages, a widely trusted free hosting service, to deliver fake banking portals that look nearly identical to the real thing. Victims who land on these pages are tricked […]
The post GitBait Phishing Campaign Abuses GitHub Pages to Attack Financial Institutions appeared first on Cyber Security News.
CVE-2026-35069 | Dell PowerFlex sql injection (dsa-2026-066)
CVE-2026-32652 | Dell AIOps up to 1.18.3 Installation default credentials (dsa-2026-231)
CVE-2026-53875 | picklescan up to 1.0.2 torch.load eval injection
CVE-2026-53874 | picklescan up to 1.0.0 deserialization
CVE-2026-53872 | picklescan up to 0.0.34 urllib.request.urlopen path traversal
CVE-2026-35068 | Dell PowerFlex sql injection (dsa-2026-066)
CVE-2026-9675 | undici up to 8.4.x maxPayloadSize Feature resource consumption (EUVD-2026-37752)
CVE-2026-3490 | picklescan up to 1.0.3 builtins.exec permissive list of allowed inputs
CVE-2026-36418 | jeecgboot JimuReport up to 2.3.4 Aviator executeSelectApi privilege escalation
CVE-2026-53873 | picklescan up to 1.0.3 Profile profile.run incomplete blacklist
CVE-2026-20246 | Cisco Umbrella Insights Virtual Appliance up to 3.8.3 privileges management (cisco-sa-umbrella-priv-esc-F4wJB7AU / EUVD-2026-37751)
CVE-2026-20190 | Cisco Identity Services Engine Software 3.4.0/3.5.0 Traffic improper authorization (cisco-sa-ise-multi-G5WP8vv / EUVD-2026-37749)
CVE-2026-20181 | Cisco Identity Services Engine Software up to 3.5.0 HTTP path traversal (cisco-sa-ise-multi-G5WP8vv / EUVD-2026-37748)
CVE-2026-20220 | Cisco Crosswork Network Change Automation up to 7.2.0 Web-based Management Interface injection (cisco-sa-cnc-inj-QNMeEmxk / EUVD-2026-37750)
CVE-2025-26240 | JazzCore Python-pdfkit 1.0.0 from_string privilege escalation
Hackers Abuse Cloud Logging Services to Evade Detection and Defender’s Visibility
Threat actors are increasingly targeting cloud logging services to evade detection and maintain persistent visibility into compromised environments, according to recent research by Palo Alto Networks Unit 42. These services, designed as a critical security layer, are now being weaponized to create blind spots in cloud infrastructure. Cloud logging platforms such as AWS CloudTrail and […]
The post Hackers Abuse Cloud Logging Services to Evade Detection and Defender’s Visibility appeared first on Cyber Security News.