Aggregator
CVE-2026-26275 | junkurihara httpsig-rs up to 0.0.22 integrity check (GHSA-7v42-g35v-xrch)
CVE-2026-27452 | JonathanWilbur asn1-ts up to 11.0.5 information disclosure (GHSA-h5rw-vxjr-8q79)
CVE-2026-27199 | Pallets Werkzeug up to 3.1.5 send_from_directory windows device name (GHSA-29vq-49wr-vm6x)
CVE-2026-27198 | getformwork up to 2.3.3 Account Creation privileges management (GHSA-34p4-7w83-35g2)
CVE-2026-3057 | a54552239 pearProjectApi up to 2.8.10 Backend Interface Task.php dateTotalForProject projectCode sql injection
CVE-2026-25591 | QuantumNous new-api up to 0.10.8-alpha.9 Token Search Endpoint /api/token/search keyword/token data query logic injection (GHSA-w6x6-9fp7-fqm4)
CVE-2026-26993 | FlintSH Flare 1.7.1 SVG cross site scripting (GHSA-q8fp-w6m5-4gjm)
CVE-2025-37184 | HPE EdgeConnect SD-WAN Orchestrator up to 9.4.4/9.6.0 Orchestrator Service improper authentication
CVE-2024-0756 | Insert or Embed Articulate Content into WordPress Plugin cross site scripting
Ariomex, Iran-based crypto exchange, suffers data leak
Fake Zoom and Google Meet Pages Trick Users Into Installing Monitoring Tool
SloppyLemming Espionage Campaign Uses BurrowShell Backdoor and Rust RAT to Hit Pakistan and Bangladesh Targets
A suspected India-aligned threat group known as SloppyLemming has been conducting a sustained espionage campaign against government agencies, defense organizations, nuclear oversight bodies, and critical infrastructure operators in Pakistan and Bangladesh. Active since 2021 and also tracked as Outrider Tiger and Fishing Elephant, the group deployed two newly documented tools between January 2025 and January […]
The post SloppyLemming Espionage Campaign Uses BurrowShell Backdoor and Rust RAT to Hit Pakistan and Bangladesh Targets appeared first on Cyber Security News.
LexisNexis says hackers accessed legacy data in contained breach
Malvertising Threat Actor ‘D‑Shortiez’ Abuses WebKit Back‑Button Hijack in Forced‑Redirect Browser Campaign
A threat actor tracked as D-Shortiez has been running a persistent malvertising campaign that turns a WebKit browser behavior into a trap, forcing iOS Safari users into scam pages with no easy way out. The campaign is not entirely new in concept — forced redirect attacks have long been a fixture of the online ad […]
The post Malvertising Threat Actor ‘D‑Shortiez’ Abuses WebKit Back‑Button Hijack in Forced‑Redirect Browser Campaign appeared first on Cyber Security News.
Django security advisory (AV26-193)
Play
You must login to view this content
Play
You must login to view this content