Aggregator
CVE-2026-45718 | budibase up to 3.38.0 Row Action Trigger Endpoint /api/tables/ row authorization
CVE-2026-45716 | budibase up to 3.38.0 Request Body onboard privileges management
CVE-2026-45715 | budibase up to 3.38.0 HTTP Redirect rest.ts server-side request forgery
CVE-2026-45548 | budibase up to 3.34.7 extract.ts processUrlFile server-side request forgery
CVE-2026-45081 | Frappe hrms up to 16.4.x authorization (EUVD-2026-32608)
CVE-2026-42553 | cinnyapp cinny up to 4.10.2 Emote download information disclosure (EUVD-2026-32612)
Hackers Use Fake ChatGPT and Claude Installers to Deploy DinDoor Backdoor
A new malware campaign is targeting content creators, gamers, and AI enthusiasts by disguising itself as popular software tools like ChatGPT and Claude. The attackers are spreading a dangerous backdoor called DinDoor through fake installers hosted on trusted platforms, catching many users completely off guard. The campaign has gained significant traction, partly because it uses […]
The post Hackers Use Fake ChatGPT and Claude Installers to Deploy DinDoor Backdoor appeared first on Cyber Security News.
CVE-2026-44521 | Studio-42 elFinder up to 2.1.67 MySQL Volume Driver sql injection (EUVD-2026-32607)
ИИ заблокирует вашу карту за 200 миллисекунд. Без объяснений. Без человека. И обжаловать это некому
CVE-2026-42328 | ipld go--prime up to 0.22.x DAG-JSON Decoder recursion
CVE-2026-45717 | budibase up to 3.38.0 Read Endpoint :datasourceId authorization
CVE-2026-44346 | BentoML up to 1.4.38 os command injection
Iran’s Nimbus Manticore Used Trojanized Zoom Installers Against US Firms
Hackers Push 22 Versions of npm RAT With Wallet Theft and Persistent Backdoor
A malicious npm package called forge-jsxy has been quietly stealing cryptocurrency wallet keys, browser credentials, and sensitive developer data across Windows, macOS, and Linux systems. Published to the npm registry on May 4, 2026, it pushed out 22 versions in 22 days, making it one of the most actively developed pieces of malware seen on […]
The post Hackers Push 22 Versions of npm RAT With Wallet Theft and Persistent Backdoor appeared first on Cyber Security News.