Aggregator
Cyberattacks and Unpredictable Targeting Remain an Iran Risk
1 month ago
Experts Urge Preparedness, Nonstop Vigilance, See Ongoing Risk of Online Reprisals
Seven days into the United States and Israel continuing "major combat operations" against Iran, Tehran continues to respond with kinetic attacks against neighboring countries. While no cyberattacks have emerged, experts see unpredictability and continue to urge caution, monitoring and preparedness.
Seven days into the United States and Israel continuing "major combat operations" against Iran, Tehran continues to respond with kinetic attacks against neighboring countries. While no cyberattacks have emerged, experts see unpredictability and continue to urge caution, monitoring and preparedness.
ISMG Editors: Cyber Spillover Looms in Iran-US Conflict
1 month ago
Also: Anthropic Claude Code Security Impact on AppSec, RSAC Conference Preview
In this week's panel, four ISMG editors discuss the potential cyber spillover from escalating tensions in the Iran-Israel-U.S. conflict, the market disruption sparked by Anthropic's Claude Code Security launch and a preview of RSAC Conference 2026.
In this week's panel, four ISMG editors discuss the potential cyber spillover from escalating tensions in the Iran-Israel-U.S. conflict, the market disruption sparked by Anthropic's Claude Code Security launch and a preview of RSAC Conference 2026.
NIST Urged to Go Deep in OT Security Guidance
1 month ago
OT Experts Weigh In on SP-800 82 Revisions
Now is the moment for U.S. federal guidance on securing OT to plunge deeper into the practicalities of securing systems, an extension into actionable advise that reflects a maturing branch of cybersecurity, several OT security specialists told the national Institute of Standards and Technology.
Now is the moment for U.S. federal guidance on securing OT to plunge deeper into the practicalities of securing systems, an extension into actionable advise that reflects a maturing branch of cybersecurity, several OT security specialists told the national Institute of Standards and Technology.
After the Panic, the Reality of Claude Code Security
1 month ago
More Code, More Problems - and More Testing
When Anthropic unveiled Claude Code Security late last month, investors were quick to punish traditional cybersecurity vendors. But analysts say the impact of Anthropic's new service will likely be more nuanced than indicated by early reactions.
When Anthropic unveiled Claude Code Security late last month, investors were quick to punish traditional cybersecurity vendors. But analysts say the impact of Anthropic's new service will likely be more nuanced than indicated by early reactions.
CVE-2026-29788 | miraheze TSPortal up to 29 unverified ownership
1 month ago
A vulnerability classified as problematic has been found in miraheze TSPortal up to 29. The impacted element is an unknown function. The manipulation leads to unverified ownership.
This vulnerability is referenced as CVE-2026-29788. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-30835 | parse-community parse-server up to 8.6.6/9.5.0-alpha.5 Error Message regex information exposure
1 month ago
A vulnerability described as problematic has been identified in parse-community parse-server up to 8.6.6/9.5.0-alpha.5. The affected element is an unknown function of the component Error Message Handler. Executing a manipulation of the argument regex can lead to information exposure through error message.
The identification of this vulnerability is CVE-2026-30835. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-30229 | parse-community parse-server up to 8.6.5/9.5.0-alpha.3 /loginAs authorization
1 month ago
A vulnerability marked as problematic has been reported in parse-community parse-server up to 8.6.5/9.5.0-alpha.3. Impacted is an unknown function of the file /loginAs. Performing a manipulation results in incorrect authorization.
This vulnerability was named CVE-2026-30229. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
FBI is Investigating the ‘Sophisticated’ Hack of Its Surveillance System
1 month ago
The FBI, CISA, and NSA reportedly are investigating the hack by an unnamed "sophisticated" actor of a FBI surveillance system that holds sensitive information. The breach carries the hallmarks of Chinese nation-state groups and comes amid concerns about attacks in the wake of the war against Iran and the shrinking of the federal cybersecurity apparatus.
The post FBI is Investigating the ‘Sophisticated’ Hack of Its Surveillance System appeared first on Security Boulevard.
Jeffrey Burt
CVE-2026-29182 | parse-community parse-server up to 8.6.3/9.4.1-alpha.2 authorization
1 month ago
A vulnerability labeled as problematic has been found in parse-community parse-server up to 8.6.3/9.4.1-alpha.2. This issue affects some unknown processing. Such manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2026-29182. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-30228 | parse-community parse-server up to 8.6.4/9.5.0-alpha.2 File API /files/:filename authorization
1 month ago
A vulnerability identified as problematic has been detected in parse-community parse-server up to 8.6.4/9.5.0-alpha.2. This vulnerability affects unknown code of the file /files/:filename of the component File API. This manipulation causes incorrect authorization.
This vulnerability is handled as CVE-2026-30228. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
Iran internet blackout reaches 6th day as rights groups call for end to digital shutdown
1 month ago
The internet shutdown in Iran entered its sixth day on Friday, with human rights groups calling on the country's leaders to restore digital access.
CVE-2026-29791 | Agentgateway up to 0.11.x input validation
1 month ago
A vulnerability categorized as problematic has been discovered in Agentgateway up to 0.11.x. This affects an unknown part. The manipulation results in improper input validation.
This vulnerability is known as CVE-2026-29791. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-29789 | vitodeploy vito up to 3.20.2 authorization
1 month ago
A vulnerability was found in vitodeploy vito up to 3.20.2. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2026-29789. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
Submit #765093: Jeecgboot 3.9.1 SQL Injection [Accepted]
1 month ago
Submit #765093 / VDB-349569
Saul1213
CVE-2026-3671 | Freedom Factory dGEN1 up to 20260221 org.ethereumphone.walletmanager.testing123 TokenBalanceContentProvider improper authorization
1 month ago
A vulnerability was found in Freedom Factory dGEN1 up to 20260221. It has been declared as problematic. Affected by this vulnerability is the function TokenBalanceContentProvider of the component org.ethereumphone.walletmanager.testing123. Executing a manipulation can lead to improper authorization.
This vulnerability appears as CVE-2026-3671. The attack requires local access. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-3670 | Freedom Factory dGEN1 up to 20260221 com.dgen.alarm improper authorization
1 month ago
A vulnerability was found in Freedom Factory dGEN1 up to 20260221. It has been classified as critical. Affected is an unknown function of the component com.dgen.alarm. Performing a manipulation results in improper authorization.
This vulnerability is reported as CVE-2026-3670. The attack requires a local approach. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-3669 | Freedom Factory dGEN1 up to 20260221 com.dgen.alarm AlarmService improper authorization
1 month ago
A vulnerability was found in Freedom Factory dGEN1 up to 20260221 and classified as critical. This impacts the function AlarmService of the component com.dgen.alarm. Such manipulation leads to improper authorization.
This vulnerability is documented as CVE-2026-3669. The attack needs to be performed locally. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-3668 | Freedom Factory dGEN1 up to 20260221 org.ethosmobile.webpwaemul AndroidEthereum access control
1 month ago
A vulnerability has been found in Freedom Factory dGEN1 up to 20260221 and classified as problematic. This affects the function AndroidEthereum of the component org.ethosmobile.webpwaemul. This manipulation causes improper access controls.
This vulnerability is registered as CVE-2026-3668. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-3667 | Freedom Factory dGEN1 up to 20260221 org.ethosmobile.ethoslauncher FakeAppService improper authorization
1 month ago
A vulnerability, which was classified as critical, was found in Freedom Factory dGEN1 up to 20260221. The impacted element is the function FakeAppService of the component org.ethosmobile.ethoslauncher. The manipulation results in improper authorization.
This vulnerability is cataloged as CVE-2026-3667. The attack must be initiated from a local position. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com