Aggregator
CVE-2026-34460 | NamelessMC Nameless up to 2.2.4 state authentication bypass by assumed-immutable data (GHSA-pmpw-2xvh-5xj6)
CVE-2026-1871 | TP-Link Tapo C200 v5 stack-based overflow
CVE-2026-24237 | NVIDIA NVTabular deserialization (EUVD-2026-33985)
CVE-2026-24221 | NVIDIA NVTabular deserialization (EUVD-2026-33984)
CVE-2026-35447 | NamelessMC Nameless 2.2.4 Profile Page profile.php insertion of sensitive information into sent data (GHSA-c9xj-rxgw-g2hq / EUVD-2026-33982)
CVE-2026-35443 | NamelessMC Nameless 2.2.4 ForumPostReactionContext.php view_other_topics authorization (GHSA-wcrf-5gcp-pf64)
CVE-2026-40314 | NamelessMC Nameless 2.2.4 Profile Page ProfilePostReactionContext.php authorization (GHSA-55q9-8qm3-4grc)
CVE-2026-0611 | Spacelabs Healthcare Sentinel up to 11.5.x NET URI Endpoint missing authentication
CVE-2026-45683 | open-telemetry opentelemetry-ebpf-instrumentation up to 0.8.x Kernel Memory bpf_probe_read buffer under-read (GHSA-fjq3-ffvr-vm46)
CVE-2026-9590 | Devolutions Server up to 2026.1.19 Permission Validation access control (DEVO-2026-0014 / EUVD-2026-33935)
CVE-2026-48861 | elixir-mint up to 1.8.x request.ex target crlf injection (GHSA-2pg6-44cx-c49v / EUVD-2026-33938)
CVE-2026-45684 | open-telemetry opentelemetry-ebpf-instrumentation up to 0.8.x iov_iter.count buffer over-read (GHSA-vvmg-8mjr-g6q3)
CVE-2026-45682 | open-telemetry opentelemetry-ebpf-instrumentation up to 0.8.x memory leak (GHSA-962q-hwm5-52x5)
CVE-2026-45681 | open-telemetry opentelemetry-ebpf-instrumentation up to 0.8.x out-of-bounds (GHSA-r6c9-g6q5-qrf9)
CVE-2026-45680 | open-telemetry opentelemetry-ebpf-instrumentation up to 0.8.x resource consumption (GHSA-89c6-vpcj-7vj4)
CVE-2026-45679 | open-telemetry opentelemetry-ebpf-instrumentation up to 0.8.x Status Message neutralization for logs (GHSA-8rrq-wcg8-cv5q)
Threat Actor Claims to Sell 58K Confidential SUNACOOP Venezuela Cooperative Records
Attackers Abuse AWS, Google Cloud, Cloudflare, and Microsoft Services to Hide Malicious Traffic
Cybercriminals are increasingly weaponizing trusted cloud infrastructure, including Amazon Web Services, Google Cloud, Microsoft Azure, Cloudflare, and GitHub, to camouflage malicious traffic, evade detection, and sustain long-lived Command and Control (C2) operations. A recent threat intelligence investigation using ANY.RUN’s Threat Intelligence (TI) Lookup reveals just how deeply this abuse has become embedded in modern attack […]
The post Attackers Abuse AWS, Google Cloud, Cloudflare, and Microsoft Services to Hide Malicious Traffic appeared first on Cyber Security News.
DOD wants to integrate cyber in all operations, and integrate security into AI
Top Pentagon cyber policy official Katherine Sutton said recent conflicts have emphasized the importance of cyber, and that the department can’t make old mistakes with AI security.
The post DOD wants to integrate cyber in all operations, and integrate security into AI appeared first on CyberScoop.