Aggregator
Around 79,000 Records Allegedly Leaked From French Property Management Software MaGestionLocative
4 days 12 hours ago
A threat actor using the alias ChimeraZ has posted what they describe as a partial database of MaGestionLocative (magestionlocative.fr), a French property management software platform used by landlords and real-estate professionals.
Dark Web Informer
3万字讲透AI必懂的60个核心概念(汇总版)
4 days 12 hours ago
What Businesses Should Know Before Migrating Their CMS
4 days 12 hours ago
Plan your CMS migration with clean content audits, SEO safeguards, tested data transfer, integrations, staff training, and a safe launch rollback plan with care.
Owais Sultan
Orphaned AI Agents: How to Find Hidden Access Risks Inside Your Network
4 days 12 hours ago
If an autonomous AI agent interacts with your company's core intellectual property today, can your security team instantly name the person who authorized it?
For most enterprises, the answer is a simple no.
The rush to adopt internal AI tools has left a massive trail of administrative debt: orphaned agents (AI tools left running after their creator leaves the company) and standing privileges (
The Hacker News
CVE-2026-9158 | Eclipse 4diac up to 3.1.0 Management Interface use after free (EUVD-2026-37896)
4 days 12 hours ago
A vulnerability was found in Eclipse 4diac up to 3.1.0. It has been classified as critical. Impacted is an unknown function of the component Management Interface. This manipulation causes use after free.
This vulnerability appears as CVE-2026-9158. The attacker needs to be present on the local network. There is no available exploit.
vuldb.com
CVE-2026-12539 | Docker Sandboxes up to 0.32.x communication channel to intended endpoints (EUVD-2026-37893)
4 days 12 hours ago
A vulnerability was found in Docker Sandboxes up to 0.32.x and classified as problematic. This issue affects some unknown processing. The manipulation results in improper restriction of communication channel to intended endpoints.
This vulnerability is reported as CVE-2026-12539. The attack requires a local approach. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-56012 | David Lingren Media LIbrary Assistant Plugin up to 3.35 on WordPress sql injection (EUVD-2026-37895)
4 days 12 hours ago
A vulnerability has been found in David Lingren Media LIbrary Assistant Plugin up to 3.35 on WordPress and classified as critical. This vulnerability affects unknown code. The manipulation leads to sql injection.
This vulnerability is documented as CVE-2026-56012. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-42488 | Xen
4 days 12 hours ago
A vulnerability, which was classified as problematic, was found in Xen. This affects an unknown part. Executing a manipulation can lead to an unknown weakness.
This vulnerability is registered as CVE-2026-42488. The attack requires access to the local network. No exploit is available.
vuldb.com
CVE-2026-12527 | Shenzhen Liandian Communication V380 IP Camera/AppFHE1 AppFHE1_V1.0.6.020230803 missing authentication (EUVD-2026-37894)
4 days 12 hours ago
A vulnerability, which was classified as critical, has been found in Shenzhen Liandian Communication V380 IP Camera and AppFHE1 AppFHE1_V1.0.6.020230803. Affected by this issue is some unknown functionality. Performing a manipulation results in missing authentication.
This vulnerability is cataloged as CVE-2026-12527. The attack must originate from the local network. There is no exploit available.
vuldb.com
CVE-2026-50141 | woodpecker-ci woodpecker up to 3.14.0 authentication spoofing (ID 21 / EUVD-2026-37897)
4 days 12 hours ago
A vulnerability classified as critical was found in woodpecker-ci woodpecker up to 3.14.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to authentication bypass by spoofing.
This vulnerability is listed as CVE-2026-50141. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-12039 | Docker Sandboxes up to 0.32.x DNS Resolution communication channel to intended endpoints
4 days 12 hours ago
A vulnerability classified as problematic has been found in Docker Sandboxes up to 0.32.x. Affected is an unknown function of the component DNS Resolution Handler. This manipulation causes improper restriction of communication channel to intended endpoints.
This vulnerability is tracked as CVE-2026-12039. The attack is restricted to local execution. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-42487 | Xen improper synchronization
4 days 12 hours ago
A vulnerability described as critical has been identified in Xen. This impacts an unknown function. The manipulation results in improper synchronization.
This vulnerability is identified as CVE-2026-42487. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-42490 | Xen permission
4 days 12 hours ago
A vulnerability marked as critical has been reported in Xen. This affects an unknown function. The manipulation leads to permission issues.
This vulnerability is referenced as CVE-2026-42490. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-42489 | Xen permission
4 days 12 hours ago
A vulnerability labeled as critical has been found in Xen. The impacted element is an unknown function. Executing a manipulation can lead to permission issues.
The identification of this vulnerability is CVE-2026-42489. The attack may be launched remotely. There is no exploit available.
vuldb.com
SearchLeak漏洞:微软365 Copilot如何沦为一键数据窃取工具
4 days 12 hours ago
ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories
4 days 12 hours ago
The internet did not break this week. It got used exactly as designed, which is worse.
Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. Cloud agents looked like helpers until attackers treated them like open shells.
Add exposed edge gear, poisoned packages, cash courier scams,
The Hacker News
Сломанный HTTPS и предупреждения в браузерах. Японская GlobalSign запустила вторую волну отзыва сертификатов у компаний из России
4 days 12 hours ago
Санкции заставили крупнейшего мирового поставщика безопасности блокировать российские ресурсы.
How software development’s speed obsession enabled TeamPCP’s chaos crusade
4 days 12 hours ago
The threat group’s remarkable success targeting open-source software was inevitable and fueled by the industry’s decision to prioritize code shipping over security.
The post How software development’s speed obsession enabled TeamPCP’s chaos crusade appeared first on CyberScoop.
Matt Kapko
CVE-2026-54220 | UBB Systems UBB.threads up to 7.7.5 cross-site request forgery
4 days 13 hours ago
A vulnerability identified as problematic has been detected in UBB Systems UBB.threads up to 7.7.5. The affected element is an unknown function. Performing a manipulation results in cross-site request forgery.
This vulnerability was named CVE-2026-54220. The attack may be initiated remotely. There is no available exploit.
vuldb.com