Aggregator
Netherlands seizes 800 servers of hosting firm enabling cyberattacks
CVE-2026-37470 | ClipBucket 5.5.2 Authentication Interface privilege escalation
LiteSpeed cPanel Plugin 0-Day Exploited in the wild to Gain Server Root Access
LiteSpeed has disclosed and patched a critical 0‑day privilege escalation flaw in its user-end cPanel plugin that is already being actively exploited to gain root access on Linux hosting servers. The bug is tracked as CVE‑2026‑48172 and affects LiteSpeed cPanel user-end plugin versions from v2.3 up to, but not including, v2.4.5. 0‑Day in LiteSpeed cPanel […]
The post LiteSpeed cPanel Plugin 0-Day Exploited in the wild to Gain Server Root Access appeared first on Cyber Security News.
CVE-2026-28735 | Mattermost up to 10.11.14/11.4.4/11.5.3/11.6.0 Scope authorization
CVE-2026-28444 | baptisteArno typebot.io up to 3.15.x getResultLogs API Endpoint authorization
CVE-2026-28445 | baptisteArno typebot.io up to 3.15.x RatingButton cross site scripting
CoinBase Cartel
You must login to view this content
CVE-2022-25647 | Oracle Financial Services Model Management and Governance Installer / Configuration denial of service (Nessus ID 235116)
CVE-2022-25647 | Oracle BI Publisher 5.9.0.0/6.4.0.0.0/12.2.1.3.0/12.2.1.4.0 Security denial of service (Nessus ID 235116)
CVE-2022-25647 | Oracle Data Integrator 12.2.1.4.0 Runtime Java agent for ODI denial of service (Nessus ID 235116)
CVE-2022-25647 | Oracle Middleware Common Libraries and Tools 12.2.1.3.0/12.2.1.4.0 Thirdparty Patch denial of service (Nessus ID 235116)
CVE-2022-25647 | Oracle Healthcare Data Repository 8.1.1/8.1.2/8.1.3 Install denial of service (Nessus ID 235116)
CVE-2022-25647 | Oracle Healthcare Master Person Index up to 5.0.3 Master Index denial of service (Nessus ID 235116)
CVE-2022-25647 | Oracle Documaker Enterprise Edition 12.6/12.7 Development Tools denial of service (Nessus ID 235116)
CVE-2022-25647 | Oracle PeopleSoft Enterprise PeopleTools 8.58/8.59/8.60 Elastic Search denial of service (Nessus ID 235116)
Квантовые компьютеры выходят с лабораторной кухни. IBM и Минторг США готовят завод для выпуска квантовых пластин
Gunra
You must login to view this content
CISA adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Langflow vulnerability, tracked as CVE-2025-34291, to its Known Exploited Vulnerabilities (KEV) Catalog, signaling active exploitation and urging organizations to remediate immediately. The flaw affects Langflow, a popular tool used for building and deploying AI-driven workflows. The issue stems from an origin validation error […]
The post CISA adds Langflow Origin Validation Flaw to Known Exploited Vulnerabilities Catalog appeared first on Cyber Security News.
Deleted Google API Keys Continue Accessing Gemini, BigQuery, and Maps APIs
A newly disclosed issue with Google Cloud API keys reveals that deleted credentials may remain usable for up to 23 minutes, exposing projects to potential abuse even after revocation. The finding raises concerns about delayed credential invalidation across Google’s infrastructure, particularly for sensitive services such as Gemini, BigQuery, and Google Maps APIs. According to Aikido […]
The post Deleted Google API Keys Continue Accessing Gemini, BigQuery, and Maps APIs appeared first on Cyber Security News.