Aggregator
CVE-2026-31542 | Linux Kernel up to 6.6.129/6.12.77/6.18.19/6.19.9 allocation of resources (WID-SEC-2026-1279)
Iranian APT Uses SEO Poisoning to Deliver Fake SQL Developer Malware Installer
A well-known Iranian threat group has found a new way to push malware onto people’s machines. Instead of sending phishing emails, the group built a fake website that impersonated a real database software download page and used search engine tricks to rank it near the top of results. Anyone who searched for the tool online […]
The post Iranian APT Uses SEO Poisoning to Deliver Fake SQL Developer Malware Installer appeared first on Cyber Security News.
CVE-2026-9515 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setUnloadUserData plugin_version os command injection (EUVD-2026-31771)
CVE-2026-9514 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setNetworkDiag os command injection (EUVD-2026-31752)
CVE-2026-9513 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi NTPSyncWithHost host_time os command injection (EUVD-2026-31768)
CVE-2026-9512 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setPasswordCfg admuser/admpass os command injection (EUVD-2026-31762)
CVE-2026-9511 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setWebWlanIdx webWlanIdx os command injection (EUVD-2026-31760)
CVE-2018-25381 | Extro Responsive Portfolio 1.6.1 on Joomla POST Request filter_type_id/filter_pid_id/filter_search sql injection (Exploit 45491 / EUVD-2018-21903)
CVE-2026-47077 | benoitc hackney up to 4.0.0 Housekeeping Message resource consumption (EUVD-2026-31688)
CVE-2026-47073 | benoitc hackney up to 4.0.0 src/hackney_ws.erl frag_buffer resource consumption (EUVD-2026-31694)
CVE-2026-47067 | benoitc hackney up to 4.0.0 URL Parser src/hackney_url.erl allocation of resources (EUVD-2026-31691)
CVE-2018-25380 | Extro eXtroForms 2.1.5 on Joomla filter_type_id/filter_pid_id/filter_search sql injection (Exploit 45472 / EUVD-2018-21901)
CVE-2018-25370 | Admidio 3.3.5 roles_function.php rol_assign_roles/rol_approve_users/rol_edit_user cross-site request forgery (Exploit 45322 / EUVD-2018-21893)
CVE-2018-25374 | Softneta MedDream PACS Server Premium 6.7.1.1 nocache.php path path traversal (Exploit 45347 / EUVD-2018-21897)
CVE-2018-25372 | Softneta MedDream PACS Server Premium 6.7.1.1 POST userSignup.php email sql injection (Exploit 45344 / EUVD-2018-21895)
Cisco refines its risk-based vulnerability disclosure for the AI era
Security teams already struggle with long lists of vulnerabilities and limited time to patch them. Cisco believes AI could increase that pressure by accelerating vulnerability discovery and increasing the number of findings security teams need to review. The company said it is moving further toward a risk-based disclosure approach, placing greater attention on issues under active exploitation or those considered more likely to be used in attacks. “Cisco is actively leveraging advanced AI Models to … More →
The post Cisco refines its risk-based vulnerability disclosure for the AI era appeared first on Help Net Security.