Aggregator
New SilabRAT Trojan Hijacks Sessions to Steal Crypto
Cyberattack shuts down major Australian sugar mills, disrupting harvest
ServiceNow Discloses Security Incident Exposing Customer Data
Windows Collaborative Translation Framework 0-Day Vulnerability Allows Privilege Escalation
Windows administrators should quickly deploy Microsoft’s June 9, 2026 security updates to fix a newly disclosed zero‑day in the Windows Collaborative Translation Framework (CTFMON), tracked as CVE‑2026‑45586. The flaw allows a local attacker with low privileges to escalate to SYSTEM, making it a valuable post‑exploitation primitive for threat actors. Windows CTF 0-Day Vulnerability CVE‑2026‑45586 is […]
The post Windows Collaborative Translation Framework 0-Day Vulnerability Allows Privilege Escalation appeared first on Cyber Security News.
Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities
CVE-2026-53437 | Jenkins up to 2.554.x Redirect URL redirect (EUVD-2026-36021)
CVE-2026-53438 | Jenkins up to 2.554.x permission (EUVD-2026-36022)
CVE-2026-53439 | Jenkins up to 2.554.x permission (EUVD-2026-36023)
CVE-2026-53440 | Jenkins up to 2.554.x Servlet Container from redirect (EUVD-2026-36024)
CVE-2026-53442 | Jenkins up to 2.554.x Controller File System config.xml permission (EUVD-2026-36026)
CVE-2026-53441 | Jenkins up to 2.482/2.554.x Description config.xml cross site scripting (EUVD-2026-36025)
CVE-2026-44716 | pipecat-ai pipecat up to 1.1.x HTTP Request run.py path path traversal (GHSA-3363-2ph6-35wh / EUVD-2026-35875)
CVE-2026-46542 | nimiq core-rs-albatross up to 1.3.x keys/src/multisig/mod.rs delinearize assertion (GHSA-h9cc-w26m-j342 / EUVD-2026-35884)
Apple встроила ИИ в каждое приложение — от камеры до умного дома. iPhone теперь думает за вас
Langflow Vulnerability CVE-2026-5027 Exploited for Unauthenticated RCE
China-linked JDY botnet expands targeting of U.S. military networks
npm v12 将不再自动执行依赖项
AMD security advisory (AV26-577)
CISA Warns of Google Chromium 0-Day Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a newly discovered zero-day vulnerability in Google Chromium that is actively being exploited in the wild. The flaw, tracked as CVE-2026-11645, affects the Chromium V8 JavaScript engine and could allow attackers to execute arbitrary code within a browser sandbox. According to […]
The post CISA Warns of Google Chromium 0-Day Vulnerability Exploited in Attacks appeared first on Cyber Security News.