Aggregator
CVE-2026-4266 | WatchGuard Fireware OS up to 12.11.8/2026.1.2 Access Portal deserialization (wgsa-2026-00007 / EUVD-2026-17079)
CVE-2018-25233 | WebDrive 18.00.5057 Connection Test Username parameters (Exploit 45761 / EUVD-2018-21724)
CVE-2018-25234 | SmartFTP Client 9.0.2615.0 Parameter Host connection return of pointer value outside of expected range (Exploit 45759 / EUVD-2018-21726)
Submit #780192: YunaiV yudao-cloud <=v2026.01 SQL Injection [Accepted]
Submit #780191: YunaiV yudao-cloud <=v2026.01 SQL Injection [Accepted]
CVE-2018-25232 | Softros LAN Messenger 9.2 Parameter Log Files Location Custom Path improper validation of specified index, position, or offset in input (Exploit 45781 / EUVD-2018-21722)
CVE-2018-25231 | HeidiSQL 9.5.0.5196 file path filename control (Exploit 45806 / EUVD-2018-21720)
CVE-2018-25230 | Eusing Free IP Switcher 3.1 Computer Name out-of-bounds write (Exploit 46382 / EUVD-2018-21719)
CVE-2018-25229 | Bpftpserver BulletProof FTP Server 2019.0.0.50 SMTP Configuration Interface SMTP Server assumed-immutable data is stored in writable memory (Exploit 46422 / EUVD-2018-21716)
CVE-2018-25228 | NetSetMan 4.7.1 Workgroup Feature out-of-bounds write (Exploit 46417 / EUVD-2018-21714)
CVE-2018-25227 | Valentina-Db Valentina Studio 9.0.4 Parameter Host return of pointer value outside of expected range (Exploit 46421 / EUVD-2018-21712)
CVE-2018-25226 | FTPShell Server 6.83 FTP Accounts Interface Account name to ban out-of-bounds write (Exploit 46430 / EUVD-2018-21710)
Forrester Threat Intelligence Landscape: Key Takeaways for Security Leaders
Forrester recently published The External Threat Intelligence Service Providers Landscape, Q1 2026, an overview of 34 vendors in the external threat intelligence market — defining market maturity and outlining key dynamics and use cases.
The post Forrester Threat Intelligence Landscape: Key Takeaways for Security Leaders appeared first on Flashpoint.
The post Forrester Threat Intelligence Landscape: Key Takeaways for Security Leaders appeared first on Security Boulevard.
CVE-2026-1612 | AL-KO Robolinho Update Software 8.0.21.0610 hard-coded credentials (EUVD-2026-17077)
CVE-2019-25654 | Coreftp Core FTP Server 2-Build 673 domain out-of-bounds write (Exploit 46371 / EUVD-2019-20046)
Coro launches MCP capabilities to simplify security operations through AI workflows
Coro has announced new Model Context Protocol (MCP) capabilities that extend its AI-driven security platform beyond the Coro interface, allowing users to access, analyze, and take action on security data directly from tools like ChatGPT, Claude, and other AI environments. Coro enables teams to interact with and act on security data without switching tools or navigating complex dashboards, which is important for organizations increasingly relying on AI assistants to manage daily workflows. Coro’s MCP integration … More →
The post Coro launches MCP capabilities to simplify security operations through AI workflows appeared first on Help Net Security.
CVE-2019-25653 | Navicat for Oracle 12.1.15 Parameter Password denial of service (Exploit 46383 / EUVD-2019-20045)
Russian court sentences notorious card fraud ringleader ‘Flint’ and 25 associates
ChatGPT Data Leakage via a Hidden Outbound Channel in the Code Execution Runtime
Key Takeaways What Happened AI assistants now handle some of the most sensitive data people own. Users discuss symptoms and medical history. They ask questions about taxes, debts, and personal finances, upload PDFs, contracts, lab results, and identity-rich documents that contain names, addresses, account details, and private records. That trust depends on a simple expectation: […]
The post ChatGPT Data Leakage via a Hidden Outbound Channel in the Code Execution Runtime appeared first on Check Point Research.