Aggregator
Sha1-Hulud, MacSync Stealer, ScreenConnect: What we know!
1 week 6 days ago
Red Canary, a Zscaler company
Hot takes on the latest cybersecurity trends
1 week 6 days ago
Red Canary, a Zscaler company
Security leaders dive into the best ways to integrate AI into your SOC
1 week 6 days ago
Red Canary, a Zscaler company
Modern app control that works
1 week 6 days ago
Red Canary, a Zscaler company
Safepay
1 week 6 days ago
You must login to view this content
cohenido
BSidesCache 2025 – From Law Enforcement To Cybersecurity: Building Skills That Matter
1 week 6 days ago
BSidesSLC
Author, Creator & Presenter: Andrew Crottym - Warrant Officer (Cyber Warfare), United States Army Reserve
Our thanks to BSidesCache for publishing their Creators, Authors and Presenter’s outstanding BSidesCache 2025 content on the Organizations' YouTube Channel.
The post BSidesCache 2025 – From Law Enforcement To Cybersecurity: Building Skills That Matter appeared first on Security Boulevard.
Marc Handelman
Sinobi
1 week 6 days ago
You must login to view this content
cohenido
Europe sanctions Chinese and Iranian firms for cyberattacks
1 week 6 days ago
The European Union Council has announced sanctions against three entities and two individuals for their involvement in cyberattacks targeting critical infrastructure in the region. [...]
Bill Toulas
CVE-2026-4356 | itsourcecode University Management System 1.0 /add_result.php vr cross site scripting
1 week 6 days ago
A vulnerability categorized as problematic has been discovered in itsourcecode University Management System 1.0. Affected is an unknown function of the file /add_result.php. Executing a manipulation of the argument vr can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-4356. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2026-4355 | Portabilis i-Educar 2.11 Endpoint educar_servidor_curso_lst.php Name cross site scripting
1 week 6 days ago
A vulnerability was found in Portabilis i-Educar 2.11. It has been rated as problematic. This impacts an unknown function of the file /intranet/educar_servidor_curso_lst.php of the component Endpoint. Performing a manipulation of the argument Name results in cross site scripting.
This vulnerability was named CVE-2026-4355. The attack may be initiated remotely. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-32291 | GL-iNet Comet KVM UART missing authentication
1 week 6 days ago
A vulnerability was found in GL-iNet Comet KVM. It has been declared as critical. This affects an unknown function of the component UART. Such manipulation leads to missing authentication.
This vulnerability is uniquely identified as CVE-2026-32291. The attack can be executed directly on the physical device. No exploit exists.
vuldb.com
CVE-2026-32298 | ANGEET ES3 KVM os command injection (EUVD-2026-12614)
1 week 6 days ago
A vulnerability was found in ANGEET ES3 KVM. It has been classified as critical. The impacted element is an unknown function. This manipulation causes os command injection.
This vulnerability is handled as CVE-2026-32298. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-32295 | JetKVM up to 0.5.3 excessive authentication (EUVD-2026-12608)
1 week 6 days ago
A vulnerability was found in JetKVM up to 0.5.3 and classified as problematic. The affected element is an unknown function. The manipulation results in improper restriction of excessive authentication attempts.
This vulnerability is known as CVE-2026-32295. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
Submit #772854: itsourcecode University Management System V1.0 cross site scripting [Accepted]
1 week 6 days ago
Submit #772854 / VDB-351395
sulvant
CVE-2026-32293 | GL-iNet Comet KVM up to 1.7.1 certificate validation
1 week 6 days ago
A vulnerability has been found in GL-iNet Comet KVM up to 1.7.1 and classified as critical. Impacted is an unknown function. The manipulation leads to improper certificate validation.
This vulnerability is traded as CVE-2026-32293. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
Submit #772839: portabilis i-educar 2.11 Injection [Accepted]
1 week 6 days ago
Submit #772839 / VDB-351394
Saipe
CVE-2026-32290 | GL-iNet Comet KVM data authenticity
1 week 6 days ago
A vulnerability, which was classified as critical, was found in GL-iNet Comet KVM. This issue affects some unknown processing. Executing a manipulation can lead to insufficient verification of data authenticity.
This vulnerability appears as CVE-2026-32290. The attack requires local access. There is no available exploit.
vuldb.com
CVE-2026-32294 | JetKVM up to 0.5.3 data authenticity
1 week 6 days ago
A vulnerability, which was classified as problematic, has been found in JetKVM up to 0.5.3. This vulnerability affects unknown code. Performing a manipulation results in insufficient verification of data authenticity.
This vulnerability is reported as CVE-2026-32294. The attack requires a local approach. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-32292 | GL-iNet Comet KVM up to 1.7.1 excessive authentication
1 week 6 days ago
A vulnerability classified as problematic was found in GL-iNet Comet KVM up to 1.7.1. This affects an unknown part. Such manipulation leads to improper restriction of excessive authentication attempts.
This vulnerability is documented as CVE-2026-32292. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com