Aggregator
CVE-2026-40022 | Apache Camel up to 4.14.5/4.18.1 Camel-Platform-HTTP-Main improper authentication (EUVD-2026-25807)
CVE-2026-7113 | NousResearch hermes-agent 0.8.0 Webhooks Endpoint webhook.py _INSECURE_NO_AUTH missing authentication (Issue 6440 / EUVD-2026-25818)
CVE-2026-27172 | Apache Camel up to 4.14.5/4.18.0 camel-consul ConsulRegistry malicious deserialization (EUVD-2026-25815)
CVE-2026-33453 | Apache Camel up to 4.14.4/4.18.0 CoAP URI Query Parameter injection (EUVD-2026-25816)
CVE-2026-22336 | Directorist Booking Plugin up to 2.4.1 on WordPress sql injection (EUVD-2026-25813)
CVE-2026-7114 | code-projects Employee Management System 1.0 370project/edit.php ID sql injection (EUVD-2026-25820)
CVE-2026-7115 | code-projects Employee Management System 1.0 370project/delete.php ID sql injection (EUVD-2026-25821)
CVE-2026-22337 | Directorist Social Login Plugin up to 2.1.1 on WordPress improper authentication (EUVD-2026-25814)
Scaling Our Vision: Welcoming Tamar Nulman and Omri Arnon to the Legit Team
The post Scaling Our Vision: Welcoming Tamar Nulman and Omri Arnon to the Legit Team appeared first on Security Boulevard.
CVE-2022-21722 | PJSIP up to 2.11.1 RTP/RTCP out-of-bounds (GHSA-m66q-q64c-hv36 / EUVD-2022-26904)
CVE-2022-21723 | PJSIP up to 2.11.1 SIP Message out-of-bounds (GHSA-7fw8-54cv-r7pm / EUVD-2022-26905)
CVE-2018-11804 | Spark 1.3.x Zinc Server Request input validation (EUVD-2022-2689 / ID 38748)
CVE-2022-21682 | Flatpak up to 1.10.5/1.12.2 path traversal (GHSA-8ch7-5j3h-g4fx / EUVD-2022-26892)
CVE-2022-21669 | PuddingBot up to 0.0.6-b933652 main.py hard-coded credentials (GHSA-cxgr-xpmj-9qjm / EUVD-2022-26884)
杀虫剂导致北美蝴蝶数量大减
Hackers Using Fake Income Tax Department’s Notice to Deploy Malware
A new phishing campaign is actively targeting Indian taxpayers and businesses by impersonating the Income Tax Department of India. Threat actors have built convincing fake websites that look nearly identical to official government portals, using urgent language to pressure victims into downloading malware-laced files without hesitation. The attack relies on a fraudulent website displaying the […]
The post Hackers Using Fake Income Tax Department’s Notice to Deploy Malware appeared first on Cyber Security News.
Если у вас техника от Samsung или D-Link, у нас плохие новости. Ваши устройства официально признали легкой добычей
China-Backed Groups are Using Massive Botnets in Espionage, Intrusion Campaigns
China-sponsored threat groups like Salt Typhoon and Flax Typhoon are increasingly relying on multiple massive botnets comprising edge and IoT devices to run their cyber espionage and network intrusion campaigns, CISA and other security agencies say. The use of such "covert networks" makes it more difficult to detect and mitigate their campaigns.
The post China-Backed Groups are Using Massive Botnets in Espionage, Intrusion Campaigns appeared first on Security Boulevard.