Aggregator
CVE-2026-27386 | DesignThemes Directory Addon Plugin up to 1.8 on WordPress authorization
CVE-2026-27390 | DesignThemes WeDesignTech Ultimate Booking Addon Plugin up to 1.0.1 on WordPress authentication bypass
Mail2Shell Zero-Click Attack lets Hackers Hijack FreeScout Mail Servers
Researchers have uncovered a critical zero-click vulnerability in FreeScout, a widely used open-source help desk and shared mailbox application. Dubbed “Mail2Shell,” this flaw allows attackers to hijack mail servers without any user interaction or authentication. The vulnerability, tracked as CVE-2026-28289, bypasses a recently patched Remote Code Execution (RCE) flaw, escalating it into an unauthenticated zero-click […]
The post Mail2Shell Zero-Click Attack lets Hackers Hijack FreeScout Mail Servers appeared first on Cyber Security News.
2,622 Valid Certificates Exposed: A Google-GitGuardian Study Maps Private Key Leaks to Real-World Risk
GitGuardian partnered with Google to answer: what happens when private keys leak? Using Certificate Transparency, we mapped about 1M leaked keys to 140k certificates. Result: 2,622 were valid as of September 2025, exposing major organizations. Our disclosure campaign achieved 97% remediation.
The post 2,622 Valid Certificates Exposed: A Google-GitGuardian Study Maps Private Key Leaks to Real-World Risk appeared first on Security Boulevard.
Ваше приложение требует внимания (и паролей). Теперь взломщики притворяются государством, чтобы получить скрытый доступ
战火未燃,烽烟先起:DDoS攻击如何成为美伊冲突的“数字前哨”?
2026防火墙的新趋势
CVE-2026-24399:ChatterMate AI 存储型XSS漏洞后端调用链详解
Europol-Led Operation Takes Down Tycoon 2FA Phishing-as-a-Service Linked to 64,000 Attacks
Ваш старый роутер еще повоюет. В OpenWrt 25.12 не стали повышать требования к железу
FBI and Europol Seize LeakBase Forum Used to Trade Stolen Credentials
Zed 编辑器要求用户年满 18 岁才能使用其 AI 功能
CVE-2026-27541 | Wholesale Suite Plugin up to 2.2.1 on WordPress privileges assignment
Google uncovers Coruna iOS Exploit Kit targeting iOS 13–17.2.1
Молитвы с призывом восстать. Зачем израильские хакеры взломали популярный иранский сервис
Dokploy 命令注入漏洞分析 CVE-2026-24841
OnDemand | Fintech & Gaming Leaders: The Identity Model Is Broken
Webinar | Inside FortiSASE Sovereign: Architecting Private, Compliant SASE at Scale
An OT Incident Scoring System Inspired by Natural Disasters
Hurricanes, tornados, earthquakes - and now operational technology cyber incidents - all can receive a numerical score based on their severity, although a new effort promoting an "OT Incident Impact Score" faces an uphill climb to get the traction it needs to succeed.