Aggregator
Identity theft is turning into a chain reaction for victims
2 weeks ago
For a growing number of victims, identity theft no longer ends with a fraudulent charge or a compromised account. More than one in four people who contacted the Identity Theft Resource Center during the reporting period were dealing with multiple identity-related incidents, according to the organization’s 2026 Trends in Identity Report. The report is based on data from 6,188 individuals who sought assistance between April 2025 and March 2026. “Identity crimes are no longer isolated, … More →
The post Identity theft is turning into a chain reaction for victims appeared first on Help Net Security.
Sinisa Markovic
HPE security advisory (AV26-573)
2 weeks ago
Canadian Centre for Cyber Security
OpenSSL security advisory (AV26-572)
2 weeks ago
Canadian Centre for Cyber Security
CVE-2025-6254 | AmentoTech Doctreat Core Plugin up to 1.6.8 on WordPress doctreat_process_registration privileges management (EUVD-2025-210104)
2 weeks ago
A vulnerability has been found in AmentoTech Doctreat Core Plugin up to 1.6.8 on WordPress and classified as critical. The impacted element is the function doctreat_process_registration. This manipulation causes improper privilege management.
This vulnerability is registered as CVE-2025-6254. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-3018 | contrid Newsletters Plugin up to 4.13 on WordPress sql injection (EUVD-2026-35997)
2 weeks ago
A vulnerability was found in contrid Newsletters Plugin up to 4.13 on WordPress and classified as critical. This affects an unknown function. Such manipulation leads to sql injection.
This vulnerability is documented as CVE-2026-3018. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-24066 | Slate Digital Connect 1.37.0 XPC Service subject.OU improper following of a certificate's chain of trust (EUVD-2026-36002)
2 weeks ago
A vulnerability was found in Slate Digital Connect 1.37.0. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component XPC Service. The manipulation of the argument subject.OU leads to improper following of a certificate's chain of trust.
This vulnerability is traded as CVE-2026-24066. An attack has to be approached locally. There is no exploit available.
vuldb.com
CVE-2026-24067 | Slate Digital Connect 1.37.0 XPC Service toctou (EUVD-2026-36000)
2 weeks ago
A vulnerability categorized as problematic has been discovered in Slate Digital Connect 1.37.0. Affected by this issue is some unknown functionality of the component XPC Service. The manipulation results in time-of-check time-of-use.
This vulnerability is known as CVE-2026-24067. Attacking locally is a requirement. No exploit is available.
vuldb.com
半导体月销售额首次突破 1100 亿美元
2 weeks ago
美国半导体行业协会(SIA)公布的数据显示,4 月全球半导体销售额同比增长 93.9% 达到 1104.8 亿美元。半导体销售额已连续 30 个月实现同比增长,环比增幅为 11%。除销量增长外,价格也显著上升。8GB DDR4 内存价格一年内涨至约 9 倍。三大内存厂商三星电子、SK 海力士和美光科技优先生产 AI 用内存产品,导致通用内存产品的供求关系趋于紧张。按区域来看,拉动销售额增长的是美国和亚洲。
Их взломали, им угрожают, их знают в лицо — но женская редакция NûJINHA продолжает работу
2 weeks ago
Никакие кибератаки не заставят смелых курдских журналисток замолчать.
The 5 Best Practices for Secure Identity Verification
2 weeks ago
Attackers are increasingly bypassing weak authentication through phishing, MFA fatigue, and service desk social engineering. Specops Software breaks down five best practices for stronger identity verification and access security. [...]
Sponsored by Specops Software
Who Runs the Ransomware Group ‘The Gentlemen?’
2 weeks ago
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.
BrianKrebs
Who Runs the Ransomware Group ‘The Gentlemen?’
2 weeks ago
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of any ransom paid by victims. This post examines clues pointing to a real life identity for the administrator of The Gentlemen ransomware group.
BrianKrebs
CVE-2026-42198 | pgjdbc up to 42.7.10 allocation of resources (GHSA-98qh-xjc8-98pq / EUVD-2026-26247)
2 weeks ago
A vulnerability was found in pgjdbc up to 42.7.10. It has been rated as problematic. This impacts an unknown function. Performing a manipulation results in allocation of resources.
This vulnerability is identified as CVE-2026-42198. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-6052 | IBM Db2 up to 11.5.9/12.1.4 denial of service (WID-SEC-2026-1646)
2 weeks ago
A vulnerability, which was classified as problematic, was found in IBM Db2 up to 11.5.9/12.1.4. Affected is an unknown function. The manipulation results in denial of service.
This vulnerability is cataloged as CVE-2026-6052. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-6053 | IBM Db2 up to 11.5.9/12.1.4 allocation of resources (WID-SEC-2026-1646)
2 weeks ago
A vulnerability has been found in IBM Db2 up to 11.5.9/12.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality. This manipulation causes allocation of resources.
This vulnerability is registered as CVE-2026-6053. The attack needs to be launched locally. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-6938 | IBM Db2 up to 12.1.4 improper authorization (WID-SEC-2026-1646)
2 weeks ago
A vulnerability marked as critical has been reported in IBM Db2 up to 12.1.4. Affected by this issue is some unknown functionality. This manipulation causes improper authorization.
This vulnerability appears as CVE-2026-6938. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-13755 | IBM DB2/DB2 Connect Server up to 11.5.9/12.1.4 log file (WID-SEC-2026-1646)
2 weeks ago
A vulnerability was found in IBM DB2 and DB2 Connect Server up to 11.5.9/12.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality. Such manipulation leads to sensitive information in log files.
This vulnerability is traded as CVE-2025-13755. An attack has to be approached locally. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-1718 | IBM Db2 up to 11.5.9/12.1.4 allocation of resources (WID-SEC-2026-1646)
2 weeks ago
A vulnerability has been found in IBM Db2 up to 11.5.9/12.1.4 and classified as problematic. This affects an unknown part. Performing a manipulation results in allocation of resources.
This vulnerability is cataloged as CVE-2026-1718. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-6051 | IBM Db2 up to 11.5.9/12.1.4 resource consumption (WID-SEC-2026-1646)
2 weeks ago
A vulnerability, which was classified as problematic, has been found in IBM Db2 up to 11.5.9/12.1.4. This impacts an unknown function. The manipulation leads to resource consumption.
This vulnerability is listed as CVE-2026-6051. The attack must be carried out locally. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com