Aggregator
CVE-2016-6164 | FFmpeg up to 2.8.7/3.0.2/3.1.0 libavformat/mov.c mov_build_index integer overflow (BID-95862)
CVE-2016-6223 | LibTIFF up to 4.0.6 tif_read.c TIFFReadRawStrip1/TIFFReadRawTile1 numeric error (Nessus ID 93322 / ID 171783)
CVE-2016-6517 | Liferay 5.1.0 barebone.jsp minifierBundleDir path traversal (BID-92215)
Максимум заряда в пустом узле решётки: два эксперимента взорвали представления о материи
CVE-2025-68420 | Comarch ERP Optima prior 2026.4 privileges assignment
CVE-2025-68421 | Comarch ERP Optima prior 2026.4 hard-coded credentials
CVE-2026-2347 | Akilli E-Commerce Website up to 4.5.0 authorization
CVE-2025-11024 | Akilli E-Commerce Website up to 4.5.0 sql injection
CVE-2026-8295 | simdjson simdjson-builder up to 4.6.3 escape_and_append integer overflow
CVE-2026-45205 | Apache Commons Configuration up to 2.14.x recursion
CVE-2026-8468 | elixir-plug up to 1.19.1 lib/plug/conn.ex sibling allocation of resources (GHSA-468c-vq7p-gh64)
Abyss
You must login to view this content
FamousSparrow Targeted Oil and Gas Industry via MS Exchange Server Exploit
Cofense adds AI-powered campaign detection to stop phishing attacks
Cofense has announced new advancements to its Phishing Defense Platform aimed at improving detection and response to AI-powered phishing attacks. The updates include AI-driven phishing detection, enhanced triage automation, and AI-assisted training campaign creation designed to strengthen protection across the phishing lifecycle. Phishing threats are no longer one-off emails. Attackers launch coordinated, polymorphic campaigns that deliberately vary content, senders, and delivery patterns to evade both traditional and AI-only detection approaches. The Cofense platform combines AI … More →
The post Cofense adds AI-powered campaign detection to stop phishing attacks appeared first on Help Net Security.
KongTuke hackers now use Microsoft Teams for corporate breaches
Qilin
You must login to view this content
Мошенники тратят $1,22 и зарабатывают тысячи. Кража крипты стала выгоднее большинства легальных профессий
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-20182 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Note: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlined in Emergency Directive 26-03: Mitigate Vulnerabilities in Cisco SD-WAN Systems and Supplemental Direction ED 26-03: Hunt and Hardening Guidance for Cisco SD-WAN Systems. Adhere to the applicable Binding Operational Directive (BOD) 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.