Aggregator
CVE-2026-7518 | Open5GS up to 2.7.7 AMF SBI Endpoint sdmsubscription-notify amf_namf_callback_handle_sdm_data_change_notify changeItem.newValue denial of service (Issue 4395)
Submit #804096: FUJIAN APEX SOFTWARE CO., LTD. LiveBOS <2.1 Remote Code Execution [Accepted]
PyTorch Lightning and Intercom-client Hit in Supply Chain Attacks to Steal Credentials
Всё как на ладони. В популярной в РФ системе бизнес-аналитики «ключи» оставили прямо в «замке»
France investigates 15-year-old over alleged hack of national ID agency
CVE-2026-36960 | U-SPEED N300 Router 1.0.0 API Endpoint cross-site request forgery
CVE-2026-36340 | Krayin CRM 2.1.5 Compose Email privilege escalation
Submit #804023: Open5GS AMF v2.7.7 Denial of Service [Accepted]
CVE-2026-5174 | Progress MOVEit Automation up to 2024.1.7/2025.0.8/2025.1.4 input validation
CVE-2026-4670 | Progress MOVEit Automation up to 2024.1.7/2025.0.8 authentication bypass
CVE-2025-14543 | RTI Connext Professional prior 7.7.0 xml external entity reference
CVE-2026-38940 | RafyMrX TOKO-ONLINE-ROTI 1.0 detail_produk.php cross site scripting
CVE-2026-38939 | andrewtch88 mvc-ecommerce 1.0 product_catalogue.php cross site scripting
Qilin Ransomware Enumerates RDP Authentication History on a Compromised Server
Qilin ransomware is one of the most active and damaging threats in the cyber landscape today. The group has steadily evolved its tactics since it first appeared in 2022, and its latest technique of enumerating Remote Desktop Protocol (RDP) authentication history on compromised servers gives it a fast, quiet way to map out a network […]
The post Qilin Ransomware Enumerates RDP Authentication History on a Compromised Server appeared first on Cyber Security News.
ИИ не нужен разум, чтобы восстать против нас. Эволюция выберет тех, кто игнорирует запреты — и это уже началось
Three Arrested for Hacking Over 610,000 Roblox Accounts
SecWiki News 2026-04-30 Review
更多最新文章,请访问SecWiki
墨思AI AGENT监测发现 PyTorch Lightning 训练框架被投毒,月下载量超1000万
Targeted Large-Scale Campaign Attacking U.S. Organizations with Fake Event Invitations
A large-scale phishing campaign is actively targeting organizations across the United States, using fake event invitations to deceive employees into handing over their corporate login credentials. The operation is wide in reach and strikes some of the most sensitive sectors in the country, including banking, government, technology, and healthcare, pointing to a deliberate effort to […]
The post Targeted Large-Scale Campaign Attacking U.S. Organizations with Fake Event Invitations appeared first on Cyber Security News.