Aggregator
CVE-2026-32292 | GL-iNet Comet KVM up to 1.7.1 excessive authentication
CVE-2026-32297 | ANGEET ES3 KVM Configuration File missing authentication (EUVD-2026-12612)
CVE-2026-32296 | Sipeed NanoKVM up to 2.3.0 Wi-Fi Configuration Endpoint missing authentication (EUVD-2026-12610)
CVE-2026-25769 | Wazuh up to 4.14.2 deserialization (GHSA-3gm7-962f-fxw5)
CVE-2026-25770 | Wazuh up to 4.14.2 ossec.conf path traversal (GHSA-r4f7-v3p6-79jm)
CVE-2026-21570 | Atlassian Bamboo Data Center up to 9.6.23/10.2.15/12.1.2 privilege escalation
CVE-2026-4354 | TRENDnet TEW-824DRU 1.010B01/1.04B01 Web Interface apply_sec.cgi sub_420A78 Language cross site scripting
Submit #772660: TRENDnet TEW-824DRU v1.04B01 Denial of Service [Accepted]
GitHub security advisory (AV26-246)
Iranian Cyber Ops Maintain US Network Footholds, Target Cameras for Regional Surveillance
Iran’s cyber operations took a sharp turn in early 2026, with state-linked threat actors quietly embedding themselves inside US and Canadian networks while also targeting internet-connected surveillance cameras across the Middle East for battlefield intelligence. The Iranian APT group MuddyWater, tied to Iran’s Ministry of Intelligence and Security (MOIS), maintained unauthorized access to multiple American […]
The post Iranian Cyber Ops Maintain US Network Footholds, Target Cameras for Regional Surveillance appeared first on Cyber Security News.
Google Warns Ransomware Actors Are Shifting Tactics as Profits Fall and Data Theft Rises
The ransomware threat landscape entered a new phase in 2025. Once a highly reliable criminal business model built on encrypting victim files and collecting ransom payments, it is now under significant financial pressure. Ransom payment rates have hit historic lows, average demands have dropped sharply, and organizations are recovering from attacks more effectively than in […]
The post Google Warns Ransomware Actors Are Shifting Tactics as Profits Fall and Data Theft Rises appeared first on Cyber Security News.
Триллион долларов на чипах. Nvidia сделала самый дерзкий финансовый прогноз в истории
Lag N Crash 6.0
Date: March 16, 2026, 4 a.m. — 17 March 2026, 10:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://lagncra.sh/
Rating weight: 25.00
Event organizers: Interpoly
Glassworm Hits Popular React Native Packages With Credential-Stealing npm Malware
A coordinated supply chain attack struck the developer community on March 16, 2026, when a threat actor known as Glassworm backdoored two widely used React Native npm packages, turning them into silent credential and cryptocurrency stealers. The affected packages — [email protected] and [email protected] — were published within minutes of each other by the same publisher, AstrOOnauta, and together accounted […]
The post Glassworm Hits Popular React Native Packages With Credential-Stealing npm Malware appeared first on Cyber Security News.
changedetection.io: Self-Hosted Website Change Monitoring with 30k Stars and 203 Releases
Samsung сделала приложение, которое сломало Windows. Microsoft продавала его в своём магазине. Оба советуют звонить в поддержку
Simple Custom Font Rendering Can Poison ChatGPT, Claude, Gemini, and Other AI Systems
A novel attack technique that exploits a fundamental blind spot in AI web assistants the gap between what a browser renders for a user and what an AI tool actually reads from the underlying HTML. Using nothing more than a custom font file and basic CSS, attackers can silently deliver malicious instructions to users while […]
The post Simple Custom Font Rendering Can Poison ChatGPT, Claude, Gemini, and Other AI Systems appeared first on Cyber Security News.
Large-Scale Sensitive Citizen Data Leak Detected
You must login to view this content