Aggregator
CVE-2026-40369
Cyber espionage campaign targeted stock exchange executive’s Outlook account
Microsoft Fixes One-Click GitHub Dev Attack That Let Attackers Steal OAuth Tokens
CVE-2021-33012 | Rockwell Automation MicroLogix 1100 RUN Mode denial of service (icsa-21-189-01)
CVE-2024-1202 | XPodas Octopod prior 1.0 authentication bypass
CVE-2024-2865 | Mergen Software Quality Management System up to 25032024 sql injection
CVE-2024-3375 | Havelsan Dialogue 1.83.0 ACL permission assignment
CVE-2024-0851 | Grup Arge Energy and Control Systems Smartpower up to 24.05.27 sql injection
CVE-2024-1100 | Vadi Corporate Information Systems DIGIKENT GIS up to 2.23.5 sql injection
CVE-2024-0336 | EMTA Grup PDKS up to 20240602 access control
CVE-2024-1272 | TNB Mobile Solutions Cockpit Software up to 0.251.0 sensitive information in source
CVE-2024-5683 | Next4Biz CRM & BPM Software Business Process Manangement 6.6.4.4 code injection
CVE-2024-4754 | Next4Biz CRM & BPM Software Business Process Manangement 6.6.4.4 cross site scripting
CVE-2024-3264 | Mia Technology Mia-Med Health Aplication up to 1.0.13 risky encryption
CVE-2024-5862 | Mia Technology Mia-Med Health Aplication up to 1.0.13 excessive authentication
New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS
A new class of indirect prompt injection (IPI) attacks targets Google Gemini’s voice assistant, allowing attackers to silently hijack the AI through malicious payloads delivered via everyday messaging apps, including WhatsApp, Slack, Signal, SMS, Instagram, and Messenger. The research, led by Or Yair, Security Research Team Lead at SafeBreach, builds on the firm’s earlier “Invitation […]
The post New Google Gemini Vulnerability Exploited via Prompt Injections from WhatsApp, Slack, and SMS appeared first on Cyber Security News.
HazyBeacon Camapign Weaponizes Amazon Web Services for Stealthy Communications
A new malware campaign is turning trusted cloud infrastructure against the organizations that rely on it. Known as HazyBeacon and tracked under cluster identifier CL-STA-1020, the campaign targets government networks across Southeast Asia. Rather than using easily blocked servers, the threat actors hide inside one of the world’s most trusted platforms, Amazon Web Services (AWS). […]
The post HazyBeacon Camapign Weaponizes Amazon Web Services for Stealthy Communications appeared first on Cyber Security News.
The Gentlemen Ransomware Group Uses Fortinet Exploits, AI, and Custom C2 Frameworks
A Russian-speaking ransomware crew known as The Gentlemen has quickly risen to become one of the most active threats in 2026, ranking second only to Qilin in ransomware activity. Their toolkit combines Fortinet vulnerability exploitation, AI-assisted operations, and a fully custom command-and-control framework that most security tools simply do not see coming. The group operates […]
The post The Gentlemen Ransomware Group Uses Fortinet Exploits, AI, and Custom C2 Frameworks appeared first on Cyber Security News.