Aggregator
CVE-2026-42877 | NeoRazorX facturascripts up to 2025.92 Warehouse SalesModalHTML.php cross site scripting
CVE-2026-42197 | inducer relate /profile/ get_user cross site scripting
CVE-2026-47161 | inducer relate deserialization
CVE-2026-44635 | kysely-org kysely up to 0.28.16 path traversal (GHSA-pv5w-4p9q-p3v2)
CVE-2026-44888 | leiweibau Pi.Alert prior 2026-05-07 Installation SaveConfigFile code injection
CVE-2026-45108 | himmelblau-idm himmelblau up to 2.3.10/3.1.4 authorization
CVE-2026-44886 | leiweibau Pi.Alert prior 2026-05-07 Web Application Endpoint sql injection
CVE-2026-44887 | leiweibau Pi.Alert prior 2026-05-07 exec code injection
CVE-2026-44681 | Authlib up to 1.6.11/1.7.0 redirect
Google Chrome security advisory (AV26-517)
GHOST STADIUM Phishing Campaign Targets FIFA World Cup Fans With 300+ Fake Domains
As the 2026 FIFA World Cup draws closer, cybercriminals are moving fast to cash in on the excitement. Researchers have uncovered a massive fraud operation targeting fans of the world’s biggest football tournament, with over 300 fake domains already live. The operation is sophisticated, well-funded, and built to deceive even cautious users. With billions of […]
The post GHOST STADIUM Phishing Campaign Targets FIFA World Cup Fans With 300+ Fake Domains appeared first on Cyber Security News.
UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace
Anne Keast-Butler, head of the GCHQ, said her agency was developing an artificial intelligence-powered cyber shield as other nations were deploying AI in warfare.
The post UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace appeared first on CyberScoop.
GitLab security advisory (AV26-516)
Jenkins security advisory (AV26-515)
Hackers Use Grandoreiro Malware to Target Portuguese Banks and Latin American Companies
A banking trojan that has been quietly operating since 2016 is making headlines again. Grandoreiro, one of the most widespread banking malware strains globally, has resurfaced with fresh campaigns targeting Portuguese banks and companies across Spain, Mexico, and Latin America. The attacks are sophisticated, well-organized, and show no sign of slowing down. Grandoreiro has survived […]
The post Hackers Use Grandoreiro Malware to Target Portuguese Banks and Latin American Companies appeared first on Cyber Security News.
Tycoon 2FA AiTM Kit Bypasses MFA on Entra ID and Google Workspace Accounts
A powerful phishing kit known as Tycoon 2FA has been making waves across the cybersecurity world since it first appeared in August 2023. The kit operates as a Phishing-as-a-Service (PhaaS) platform, meaning cybercriminals can rent and deploy it without building anything from scratch. Its primary goal is to steal authenticated session tokens from Microsoft 365 […]
The post Tycoon 2FA AiTM Kit Bypasses MFA on Entra ID and Google Workspace Accounts appeared first on Cyber Security News.