Aggregator
CVE-2026-45777 | ubccr xdmod up to 11.0.2 System Configuration os command injection (GHSA-29qm-7w4v-43fw)
CVE-2026-45758 | guardrails-ai guardrails 0.10.1 malicious code (ID 1473)
CVE-2026-11419 | Altium Enterprise Server up to 8.1.0 path traversal
CVE-2026-45776 | ubccr xdmod up to 11.0.2 HTTPS access control (GHSA-3hfh-m242-8rmh)
CVE-2026-46398 | haxtheweb haxcms-php up to 25.x missing secure attribute (GHSA-g7v2-r32q-jf5v)
CVE-2026-46399 | haxtheweb haxcms-nodejs/haxcms-php up to 25.x external control of setting (GHSA-q759-vxg8-vq5j)
CVE-2026-46395 | haxtheweb haxcms-nodejs up to 25.x PHP Backend hmacBase64 key information disclosure (GHSA-6c8g-9hfh-pq5h)
CVE-2026-45779 | ubccr xdmod up to 10.0.2 sql injection (GHSA-r33r-6g3c-r992)
CVE-2026-11401 | Amazon AWS Advanced Go Wrapper up to 2026-05-26 GlobalDatabasePlugin untrusted search path (GHSA-r236-5pc3-3qcp)
CVE-2026-11400 | Amazon AWS Advanced JDBC Wrapper up to 4.0.0 GlobalDatabasePlugin untrusted search path
CVE-2026-46400 | haxtheweb haxcms-php up to 24.x File Content unrestricted upload (GHSA-ffxv-9qv2-v2v8)
Suspicious Polyfill login prompts pop up on Toshiba, Muji websites
KRYBIT
You must login to view this content
High-Risk Data Leak Detected on Darknet Forum
You must login to view this content
Cybersecurity Hygiene Reinforced by the 2026 Verizon DBIR
RALord
You must login to view this content
Hackers Publish Malicious Python Package Mimicking Legitimate Parsimonious Parser
A deceptive Python package quietly made its way into the PyPI repository, putting thousands of developers at risk before it was caught and removed. The package, named “parsimonius,” was crafted to look almost identical to the widely used “parsimonious” library, a popular Python tool for building expression grammar parsers. The single missing letter was no […]
The post Hackers Publish Malicious Python Package Mimicking Legitimate Parsimonious Parser appeared first on Cyber Security News.
Hackers are Increasingly Weaponizing Trusted Tools to Deploy Notorious Malware
Cybercriminals have found a clever and dangerous new way to slip past defenses. Instead of building custom attack tools that security software can flag, they are turning everyday system utilities into weapons. This shift is reshaping how attacks unfold, and the numbers are hard to ignore. According to ANY.RUN’s Q1 2026 Cyber Risk Report, based […]
The post Hackers are Increasingly Weaponizing Trusted Tools to Deploy Notorious Malware appeared first on Cyber Security News.
New Magecart Attack Turns Stripe into a Malware Command Server
A new form of credit card skimming malware has been discovered hiding inside one of the most trusted payment platforms on the internet. Researchers have found a Magecart attack that uses Stripe, the widely used online payment service, as both its command center and its data dump. Instead of pointing stolen card data to a […]
The post New Magecart Attack Turns Stripe into a Malware Command Server appeared first on Cyber Security News.