Aggregator
CVE-2026-28286 | IceWhaleTech ZimaOS 1.5.2-beta3 Frontend/UI file inclusion
Travel-tinted glasses
When I travel abroad, I become a different person. I find myself doing things i would never do at home. Last week I landed in Billund. It’s small, Danish town, and home of Lego. The hotel was in Aarhus. Perfectly reasonable. Except getting there required taking a coach. A coach. At home, I would rather … Continue reading Travel-tinted glasses →
The post Travel-tinted glasses appeared first on Security Boulevard.
[Control systems] CISA ICS security advisories (AV26–183)
PoC Exploit Released for Windows Error Reporting ALPC Privilege Escalation
A critical local privilege escalation (LPE) vulnerability affecting Microsoft Windows has recently come to light following the public release of a Proof-of-Concept (PoC) exploit. Tracked as CVE-2026-20817, this security flaw resides within the Windows Error Reporting (WER) service. The vulnerability allows an authenticated user with low-level privileges to execute arbitrary malicious code with full SYSTEM […]
The post PoC Exploit Released for Windows Error Reporting ALPC Privilege Escalation appeared first on Cyber Security News.
2nd March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 2nd March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Wynn Resorts, a United States-based casino and hotel operator, has confirmed that employee data was accessed following an extortion threat linked to ShinyHunters. The company said operations were not disrupted. Reports indicate […]
The post 2nd March – Threat Intelligence Report appeared first on Check Point Research.
Alleged India-linked espionage campaign targeted Pakistan, Bangladesh, Sri Lanka
Ubuntu security advisory (AV26-182)
CVE-2026-28403 | textream up to 1.5.0 DirectorServer WebSocket Server origin validation (GHSA-wr3v-x247-337w)
CVE-2026-28412 | textream up to 1.5.0 DirectorServer WebSocket Server resource consumption (GHSA-qr5p-7x47-qxh9)
CVE-2025-52468 | Chamilo LMS up to 1.11.29 CSV File Parser Last Name/First Name/Username cross site scripting
CVE-2025-52469 | Chamilo LMS up to 1.11.29 AJAX Endpoint behavioral workflow
CVE-2025-52563 | Chamilo LMS up to 1.11.29 add_users_to_session.php page cross site scripting
CVE-2025-52476 | Chamilo LMS up to 1.11.29 admin/user_list.php keyword_active cross site scripting
CVE-2025-52475 | Chamilo LMS up to 1.11.29 admin/user_list.php keyword_inactive cross site scripting
CVE-2025-52470 | Chamilo LMS up to 1.11.29 session_category_add.php Category Name cross site scripting
CVE-2025-52998 | Chamilo LMS up to 1.11.29 deserialization
You’re Optimizing for the Wrong AI Engine. And It’s Costing You Enterprise Deals.
Two cybersecurity companies told me they're optimizing for Perplexity. Their buyer? Enterprise CISOs. The data shows ChatGPT leads at 67% enterprise adoption and 87.4% of AI referral traffic. Only 11% of domains get cited by both ChatGPT and Perplexity. Most B2B companies are optimizing wrong.
The post You’re Optimizing for the Wrong AI Engine. And It’s Costing You Enterprise Deals. appeared first on Security Boulevard.