Aggregator
Google Develops Merkle Tree Certificates to Enable Quantum-Resistant HTTPS in Chrome
CVE-2026-28357 | NocoDB up to 0.301.2 cross site scripting (EUVD-2026-9199)
CVE-2026-28401 | NocoDB up to 0.301.2 v-html HTML injection (EUVD-2026-9215)
CVE-2026-23865 | FreeType up to 2.13.3/2.14.1 HVAR/VVAR/MVAR tt_var_load_item_variation_store out-of-bounds (EUVD-2026-9195)
CVE-2025-70252 | Tenda AC6 15.03.06.23 /goform/WifiWpsStart stack-based overflow (EUVD-2025-208181)
CVE-2026-28398 | NocoDB up to 0.301.2 cross site scripting (EUVD-2026-9213)
CVE-2026-28397 | NocoDB up to 0.301.2 cross site scripting (EUVD-2026-9212)
CVE-2025-64427 | IceWhaleTech ZimaOS up to 1.4.x URL server-side request forgery
CVE-2026-28399 | NocoDB up to 0.301.2 unit sql injection
CVE-2026-28361 | NocoDB up to 0.301.2 MCP Token Service authorization
CVE-2026-28360 | NocoDB up to 0.301.2 credentials storage
CVE-2026-28396 | NocoDB up to 0.301.2 Password Reset session expiration
CVE-2026-28359 | NocoDB up to 0.301.2 TipTap Editor cross site scripting
CVE-2026-28358 | NocoDB up to 0.301.2 Password Forgot Endpoint response discrepancy
CVE-2026-28286 | IceWhaleTech ZimaOS 1.5.2-beta3 Frontend/UI file inclusion
Travel-tinted glasses
When I travel abroad, I become a different person. I find myself doing things i would never do at home. Last week I landed in Billund. It’s small, Danish town, and home of Lego. The hotel was in Aarhus. Perfectly reasonable. Except getting there required taking a coach. A coach. At home, I would rather … Continue reading Travel-tinted glasses →
The post Travel-tinted glasses appeared first on Security Boulevard.
[Control systems] CISA ICS security advisories (AV26–183)
PoC Exploit Released for Windows Error Reporting ALPC Privilege Escalation
A critical local privilege escalation (LPE) vulnerability affecting Microsoft Windows has recently come to light following the public release of a Proof-of-Concept (PoC) exploit. Tracked as CVE-2026-20817, this security flaw resides within the Windows Error Reporting (WER) service. The vulnerability allows an authenticated user with low-level privileges to execute arbitrary malicious code with full SYSTEM […]
The post PoC Exploit Released for Windows Error Reporting ALPC Privilege Escalation appeared first on Cyber Security News.
2nd March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 2nd March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Wynn Resorts, a United States-based casino and hotel operator, has confirmed that employee data was accessed following an extortion threat linked to ShinyHunters. The company said operations were not disrupted. Reports indicate […]
The post 2nd March – Threat Intelligence Report appeared first on Check Point Research.