Aggregator
ISMG Editors: Should We Trust Ransomware Gangs?
1 month ago
Ransomware Payouts, AI-Driven Threats and Reshaping Payment Fraud
In this week's panel, four ISMG editors discussed a ransomware case that once again raises questions about paying extortionists, why security leaders fear AI is accelerating attacks faster than humans can respond and how the rise of instant payments is reshaping fraud programs at banks.
In this week's panel, four ISMG editors discussed a ransomware case that once again raises questions about paying extortionists, why security leaders fear AI is accelerating attacks faster than humans can respond and how the rise of instant payments is reshaping fraud programs at banks.
AI Doctors? Lawsuits Say No, Some Doctors Say Yes
1 month ago
License Frontier AI to Practice Medicine, Argues JAMA Article
Scrutiny is intensifying around the quickly evolving role that AI is playing in healthcare. That includes issues around the transparency and safety of consumer health chatbots and also whether a new clinical AI licensing framework is necessary to protect the integrity of medicine.
Scrutiny is intensifying around the quickly evolving role that AI is playing in healthcare. That includes issues around the transparency and safety of consumer health chatbots and also whether a new clinical AI licensing framework is necessary to protect the integrity of medicine.
SecurityScorecard Buys Driftnet for More Internet Visibility
1 month ago
Driftnet Acquisition Adds Real-Time Visibility Into Exposed Assets and AI Risks
SecurityScorecard acquired internet reconnaissance startup Driftnet to expand real-time visibility into hidden infrastructure, exposed assets and AI-driven third-party risks while strengthening threat hunting, attribution and internet-scale intelligence capabilities.
SecurityScorecard acquired internet reconnaissance startup Driftnet to expand real-time visibility into hidden infrastructure, exposed assets and AI-driven third-party risks while strengthening threat hunting, attribution and internet-scale intelligence capabilities.
New Cisco SD-WAN Zero-Day Grants Admin Access
1 month ago
Broken vdaemon Peering Authentication Enables Unauthenticated Admin Access
A maximum-severity vulnerability in Cisco Catalyst SD-WAN Controller is being actively exploited, giving attackers administrative privileges without authentication. The authentication bypass vulnerability stems from a broken peering authentication mechanism.
A maximum-severity vulnerability in Cisco Catalyst SD-WAN Controller is being actively exploited, giving attackers administrative privileges without authentication. The authentication bypass vulnerability stems from a broken peering authentication mechanism.
2026年人工智能技术赋能网络安全应用测试公告
1 month ago
CVE-2026-44504 | Aegra up to 0.9.6 Message thread_id improper authorization (GHSA-m98r-6667-4wq7 / EUVD-2026-30322)
1 month ago
A vulnerability labeled as critical has been found in Aegra up to 0.9.6. Impacted is an unknown function of the component Message Handler. Executing a manipulation of the argument thread_id can lead to improper authorization.
This vulnerability is registered as CVE-2026-44504. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-44514 | kubetail cli/dashboard prior 0.14.0 WebSocket Endpoint missing origin validation in websockets (GHSA-v8j7-hp7c-738f / EUVD-2026-30331)
1 month ago
A vulnerability has been found in kubetail cli and dashboard and classified as problematic. Affected by this issue is some unknown functionality of the component WebSocket Endpoint. The manipulation leads to missing origin validation in websockets.
This vulnerability is uniquely identified as CVE-2026-44514. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-41315 | midoks mdserver-web up to 0.18.4 /modify_crond os command injection (GHSA-3h92-g9hr-xc25 / EUVD-2026-30362)
1 month ago
A vulnerability was found in midoks mdserver-web up to 0.18.4 and classified as critical. Impacted is an unknown function of the file /modify_crond. Such manipulation leads to os command injection.
This vulnerability is uniquely identified as CVE-2026-41315. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-45375 | SiYuan up to 3.6.5 Setting plugin.json cross site scripting (GHSA-27qc-m5gf-jv5r / EUVD-2026-30356)
1 month ago
A vulnerability was found in SiYuan up to 3.6.5. It has been classified as problematic. This vulnerability affects unknown code of the file plugin.json of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-45375. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-24899 | fleetdm fleet up to 4.81.x JWKS Endpoint authentication spoofing (GHSA-ffg9-j72f-j6xm / EUVD-2026-30374)
1 month ago
A vulnerability labeled as critical has been found in fleetdm fleet up to 4.81.x. Affected by this vulnerability is an unknown functionality of the component JWKS Endpoint. Such manipulation leads to authentication bypass by spoofing.
This vulnerability is listed as CVE-2026-24899. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-43904 | AcademySoftwareFoundation OpenImageIO up to 3.0.18.0/3.1.13.0 out-of-bounds write (GHSA-4499-j545-7q33 / EUVD-2026-30392)
1 month ago
A vulnerability has been found in AcademySoftwareFoundation OpenImageIO up to 3.0.18.0/3.1.13.0 and classified as critical. The impacted element is an unknown function. Performing a manipulation results in out-of-bounds write.
This vulnerability is known as CVE-2026-43904. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-43996 | AcademySoftwareFoundation OpenImageIO up to 3.0.18.0/3.1.13.0 TGAInput::decode_pixel out-of-bounds (GHSA-mq8j-73c4-cr55 / EUVD-2026-30417)
1 month ago
A vulnerability described as problematic has been identified in AcademySoftwareFoundation OpenImageIO up to 3.0.18.0/3.1.13.0. Impacted is the function TGAInput::decode_pixel. The manipulation results in out-of-bounds read.
This vulnerability is cataloged as CVE-2026-43996. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-44636 | saitoha libsixel up to 1.8.7-r1 SIXEL Encoder sixel_encode_highcolor heap-based overflow (GHSA-hx93-w8p2-ffh5 / EUVD-2026-30409)
1 month ago
A vulnerability identified as critical has been detected in saitoha libsixel up to 1.8.7-r1. Impacted is the function sixel_encode_highcolor of the component SIXEL Encoder. The manipulation leads to heap-based buffer overflow.
This vulnerability is referenced as CVE-2026-44636. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-44592 | wavelens gradient 1.1.0 NixOS /proto missing authentication (GHSA-49w6-gf3p-96m2 / EUVD-2026-30365)
1 month ago
A vulnerability classified as critical has been found in wavelens gradient 1.1.0. This affects an unknown function of the file /proto of the component NixOS Module. The manipulation leads to missing authentication.
This vulnerability is uniquely identified as CVE-2026-44592. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-44647 | theonedev up to 15.0.1 path traversal (GHSA-59wq-74xg-w85v / EUVD-2026-30478)
1 month ago
A vulnerability was found in theonedev onedev up to 15.0.1. It has been rated as critical. The affected element is an unknown function. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-44647. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
Что представляет собой «ловушка Фукидида», о которой предупреждал Си Цзиньпин Трампа? Уроки древней войны между Афинами и Спартой
1 month ago
История войны Афин и Спарты неожиданно стала рамкой для разговора о США,
CVE-2026-2291 | dnsmasq 2.92rel2 extract_name integer overflow (Nessus ID 314983 / WID-SEC-2026-1468)
1 month ago
A vulnerability was found in dnsmasq 2.92rel2 and classified as critical. Affected is the function extract_name. Such manipulation leads to integer overflow.
This vulnerability is uniquely identified as CVE-2026-2291. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-4890 | dnsmasq 2.92rel2 DNSSEC Validation infinite loop (Nessus ID 314983 / WID-SEC-2026-1468)
1 month ago
A vulnerability was found in dnsmasq 2.92rel2. It has been classified as problematic. This impacts an unknown function of the component DNSSEC Validation. Performing a manipulation results in infinite loop.
This vulnerability is known as CVE-2026-4890. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-4891 | dnsmasq 2.92rel2 DNSSEC Validation out-of-bounds (EUVD-2026-29153 / Nessus ID 314983)
1 month ago
A vulnerability was found in dnsmasq 2.92rel2. It has been declared as problematic. Affected is an unknown function of the component DNSSEC Validation. Executing a manipulation can lead to out-of-bounds read.
This vulnerability is handled as CVE-2026-4891. The attack can be executed remotely. There is not any exploit available.
vuldb.com