Aggregator
Spring security advisory (AV26-288)
CVE-2026-22901 | QNAP QuNetSwitch 2.0.4.0415 os command injection (qsa-26-11)
CVE-2025-69720 | GNU ncurses 6.4/6.5 progs/infocmp.c analyze_string buffer overflow (Nessus ID 303220)
CVE-2026-22897 | QNAP QuNetSwitch prior 2.0.4.0415 os command injection (qsa-26-11 / EUVD-2026-13716)
CVE-2026-22895 | QNAP QuFTP Service up to 1.4.2/1.5.1/1.6.1 cross site scripting (qsa-26-15 / EUVD-2026-13714)
CVE-2026-22898 | QNAP QVR Pro 2.7.4.14 missing authentication (qsa-26-07 / EUVD-2026-13718)
CVE-2026-22900 | QNAP QuNetSwitch 2.0.4.0415 hard-coded credentials (qsa-26-11 / EUVD-2026-13720)
HPE security advisory (AV26-287)
Coruna, DarkSword & Democratizing Nation-State Exploit Kits
Is the FCC's Router Ban the Wrong Fix?
[Control systems] ABB security advisory (AV26-286)
Automotive Cybersecurity Threats Grow in Era of Connected, Autonomous Vehicles
New ClickFix Attack Leverage Windows Run Dialog Box and macOS Terminal to Deploy Malware
A social engineering technique called ClickFix has resurfaced with significant force, tricking users on both Windows and macOS into manually executing malicious commands that quietly install malware on their devices. First documented in late 2023, the method has rapidly grown from a niche tactic into one of the most widely adopted initial access strategies across […]
The post New ClickFix Attack Leverage Windows Run Dialog Box and macOS Terminal to Deploy Malware appeared first on Cyber Security News.
Leak Bazaar Turns Stolen Corporate Data Into a Structured Criminal Marketplace
A threat actor known as “Snow” from SnowTeam posted an advertisement on the Russian-speaking TierOne (T1) cybercrime forum on March 25, 2026, introducing a new criminal service called Leak Bazaar. The platform is not a traditional data leak site. Instead, it presents itself as a post-exfiltration processing service — one that takes raw stolen corporate […]
The post Leak Bazaar Turns Stolen Corporate Data Into a Structured Criminal Marketplace appeared first on Cyber Security News.