Aggregator
CVE-2026-23255 | Linux Kernel up to 6.18.9 net /proc/net/ptype ptype_seq_next/ptype_seq_show state issue (Nessus ID 319993 / WID-SEC-2026-0790)
CVE-2026-23411 | Linux Kernel up to 7.0-rc3 apparmor i_private privilege escalation (EUVD-2026-17843 / Nessus ID 319993)
CVE-2026-23409 | Linux Kernel up to 7.0-rc3 apparmor encoding error (EUVD-2026-17839 / Nessus ID 319993)
Fortinet FortiSandbox Vulnerability Allows Attackers to Execute Unauthorized Commands
Fortinet has disclosed a critical security vulnerability in its FortiSandbox product line that could allow unauthenticated remote attackers to execute arbitrary OS commands through the web interface. The flaw, tracked as CVE-2026-25089 and assigned a CVSSv3 score of 9.1 (Critical), affects multiple versions of FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS deployments. The vulnerability stems from […]
The post Fortinet FortiSandbox Vulnerability Allows Attackers to Execute Unauthorized Commands appeared first on Cyber Security News.
CVE-2026-11027 | Google Chrome up to 148.0.7778.216 Glic cross-domain policy (ID 497604 / WID-SEC-2026-1794)
CVE-2026-11026 | Google Chrome up to 148.0.7778.216 Extensions access control (ID 497599 / WID-SEC-2026-1794)
CVE-2026-11030 | Google Chrome up to 148.0.7778.216 Network use after free (ID 497722 / WID-SEC-2026-1794)
CVE-2026-11031 | Google Chrome up to 148.0.7778.216 Password Manager clickjacking (ID 497748 / WID-SEC-2026-1794)
CVE-2026-11032 | Google Chrome up to 148.0.7778.216 Password Manager cross-domain policy (ID 497831 / WID-SEC-2026-1794)
CVE-2026-11033 | Google Chrome up to 148.0.7778.216 on macOS WebML uninitialized variable (ID 497926 / WID-SEC-2026-1794)
CVE-2026-11036 | Google Chrome up to 148.0.7778.216 DOM cross-domain policy (ID 497964 / WID-SEC-2026-1794)
SPF, DKIM, DMARC Passed. Malicious Link Passes Every Authentication Check, But CyberCheck360 Caught It
A $12 domain, 72 hours of patience, and your finance team’s credentials — why authentication tells you who sent the email, never where the link goes, and how detection at the click closes the gap your gateway can’t see. A domain is registered on Monday. By Tuesday it serves a pixel-perfect Microsoft 365 login clone. […]
The post SPF, DKIM, DMARC Passed. Malicious Link Passes Every Authentication Check, But CyberCheck360 Caught It appeared first on Cyber Security News.
20 ватт против миллионов — вот цена разницы между мозгом и ИИ. Теперь мы знаем, как это исправить
Google Chrome 0-Day Vulnerability Exploited in the Wild — Update Now
Google has released an emergency security update for Chrome, patching a critical zero-day vulnerability actively exploited in the wild. The Stable channel has been updated to version 149.0.7827.102/.103 for Windows and Mac, and 149.0.7827.102 for Linux, addressing 74 security vulnerabilities, including one confirmed zero-day. Here’s the breakdown of the five actively exploited Chrome zero-days patched […]
The post Google Chrome 0-Day Vulnerability Exploited in the Wild — Update Now appeared first on Cyber Security News.
[Control systems] Siemens security advisory (AV26-566)
Falcon 9 火箭第一级 B 1067 执行了 35 次发射任务
Akira
You must login to view this content
Cisco customers encounter another SD-WAN zero-day under attack
The defect marks the seventh actively exploited zero-day in Cisco SD-WANs this year, and the vendor has yet to release a patch.
The post Cisco customers encounter another SD-WAN zero-day under attack appeared first on CyberScoop.