Aggregator
CVE-2023-2298 | vcita Online Booking & Scheduling Calendar Plugin up to 4.2.10 on WordPress cross site scripting
CVE-2023-2301 | vcita Contact Form Builder Plugin up to 4.9.1 on WordPress cross-site request forgery
CVE-2023-2300 | vcita Contact Form Builder Plugin up to 4.9.1 on WordPress cross site scripting
Submit #794333: code-projects Simple IT Discussion Forum V1.0 SQL injection [Accepted]
Submit #794332: code-projects Simple IT Discussion Forum V1.0 cross site scripting [Accepted]
«Хватит слать нам отчёты! Денег всё равно не заплатим». HackerOne сообщила о приостановке программы Internet Bug Bounty
Claude helps researcher dig up decade-old Apache ActiveMQ RCE vulnerability (CVE-2026-34197)
In the latest demonstration of how AI assistants can help with bug hunting, Horizon3.ai researcher Naveen Sunkavally used Claude to unearth CVE-2026-34197, a remote code execution vulnerability in Apache ActiveMQ that’s been introduced in the codebase 13 years ago. The vulnerability was patched in late March 2026 and there’s currently no indication that it is being actively exploited by attackers. Neveretheless, with ActiveMQ vulnerabilities having been previously leveraged for ransomware and malware attacks, organizations should … More →
The post Claude helps researcher dig up decade-old Apache ActiveMQ RCE vulnerability (CVE-2026-34197) appeared first on Help Net Security.
Submit #793895: code-projects Online Library Management System in PHP 1.0 Information Disclosure [Accepted]
Submit #793656: jeecgboot web 3.9.1 Improper Access Controls [Accepted]
Edge Decay: How a Failing Perimeter Is Fueling Modern Intrusions
Mallory brings contextual threat intelligence to security operations
Mallory is launching an AI-native threat intelligence platform, purpose-built to answer the questions CISOs and their teams are asking every day: What are the real threat vectors for our organization? What’s actually exploitable in our environment right now? What should we proactively fix? The platform monitors thousands of threat sources, contextualizes them against your actual attack surface, and puts that intelligence to work across hunt, detection, and exposure management use cases. One platform. Answers, not … More →
The post Mallory brings contextual threat intelligence to security operations appeared first on Help Net Security.