Aggregator
CVE-2025-15552 | Truesec LAPSWebUI up to 2.3 Admin Password session expiration
FBI Calls for Help to Track Steam Malware Campaign
CVE-2026-3024 | Wakyma Application Web Endpoint modelo-formulario-evento cross site scripting
CVE-2026-3023 | Wakyma Application Web Endpoint /pets/print-tags data query logic injection
CVE-2026-3022 | Wakyma Application Web Endpoint generate-hospitalization-summary data query logic injection
CVE-2026-3021 | Wakyma Application Web Endpoint /centro/equipo/empleado data query logic injection
CVE-2026-3020 | Wakyma Application Web authorization
CVE-2026-3110 | Educativa Campus 14.05.00-35 wid_cursoActual access control
CVE-2026-3111 | Educativa Campus 14.05.00-35 thumb_AAxAA.jpg access control
CVE-2025-11500 | tinycontrol Lan Kontroler JSON File Parser weak password encoding
New XWorm 7.1 and Remcos RAT Attacks Abuse Windows Tools to Evade Detection
CVE-2025-15587 | Tinycontrol Lan Kontroler direct request
【安全圈】星巴克数据泄露事件波及员工
【安全圈】FBI 寻找被用于传播恶意软件的 Steam 游戏受害者
【安全圈】央视曝光“AI伪造人脸”大案:5万多条动态人脸视频被批量合成,冒充本人注册账号
Дипфейк вашего CEO уже в сети. Добро пожаловать на форум по ИИ-безопасности
Attackers Abuse Microsoft Teams and Quick Assist to Drop Stealthy A0Backdoor
A newly identified backdoor called A0Backdoor has emerged as part of a calculated social-engineering campaign that abuses Microsoft Teams and the Windows remote assistance tool Quick Assist. The threat group is tracked under aliases including Blitz Brigantine, Storm-1811, and STAC5777, and holds ties to the Black Basta ransomware network. Active since at least August 2025 […]
The post Attackers Abuse Microsoft Teams and Quick Assist to Drop Stealthy A0Backdoor appeared first on Cyber Security News.
ANY.RUN at RootedCON 2026: Meeting Security Teams and Showcasing New Capabilities
From March 5 to March 7, the ANY.RUN team attended RootedCON 2026 in Madrid and showcase some of our latest capabilities developed for modern SOC environments at the conference expo. The event provided a great opportunity to meet our existing clients and connect with security teams exploring advanced threat detection solutions. Meeting the Community and Partners RootedCON is one of the largest cybersecurity conferences in Europe, bringing together thousands of security researchers, SOC […]
The post ANY.RUN at RootedCON 2026: Meeting Security Teams and Showcasing New Capabilities appeared first on ANY.RUN's Cybersecurity Blog.
OpenClaw AI Agents Leaking Sensitive Data in Indirect Prompt Injection Attacks
Attackers can exploit insecure defaults and prompt injection vulnerabilities to turn normal agent behavior into a silent data-exfiltration pipeline. The core issue is not just confusing the AI model; it is manipulating the agent to steal sensitive information without requiring any user interaction. The most alarming demonstration comes from security firm PromptArmor. They revealed how […]
The post OpenClaw AI Agents Leaking Sensitive Data in Indirect Prompt Injection Attacks appeared first on Cyber Security News.