Aggregator
CVE-2025-50198 | Chamilo LMS up to 1.11.29 Configuration import.php configuration_file/course_path/home_path deserialization
Dell security advisory (AV26-181)
DuckDuckGo Browser UXSS Flaw in Auto Consent JS Bridge Enables Cross-Origin Code Execution
A critical Universal Cross-Site Scripting (UXSS) vulnerability was recently discovered in the DuckDuckGo Android browser. This flaw allowed untrusted, cross-origin iframes to execute arbitrary JavaScript in the top-level origin, tracked with a high-severity CVSS score of 8.6. The vulnerability was originally detailed in a Medium post by security researcher Dhiraj Mishra. The vulnerability stems from […]
The post DuckDuckGo Browser UXSS Flaw in Auto Consent JS Bridge Enables Cross-Origin Code Execution appeared first on Cyber Security News.
Chrome Unveils Plan For Quantum-Safe HTTPS Certificates
CVE-2026-3380 | Tenda F453 1.0.0.3 /goform/L7Im frmL7ImForm page buffer overflow (EUVD-2026-9116 / CNNVD-202603-017)
CVE-2026-3379 | Tenda F453 1.0.0.3 /goform/SetIpBind fromSetIpBind page buffer overflow (EUVD-2026-9115 / CNNVD-202603-018)
CVE-2026-3377 | Tenda F453 1.0.0.3 /goform/SafeUrlFilter fromSafeUrlFilter page buffer overflow (EUVD-2026-9113 / CNNVD-202603-020)
CVE-2026-3378 | Tenda F453 1.0.0.3 /goform/qossetting fromqossetting qos buffer overflow (EUVD-2026-9114 / CNNVD-202603-019)
MSHTML Framework 0-Day Exploited by APT28 Hackers Before Feb 2026’s Patch Tuesday Update
A zero-day vulnerability in the Microsoft HTML (MSHTML) framework was actively exploited in the wild. The vulnerability, tracked as CVE-2026-21513, allows attackers to bypass security features and execute arbitrary files. With a CVSS score of 8.8, it impacts all Windows versions. Security researchers at Akamai discovered that the Russian state-sponsored threat group APT28 was targeting […]
The post MSHTML Framework 0-Day Exploited by APT28 Hackers Before Feb 2026’s Patch Tuesday Update appeared first on Cyber Security News.
IBM security advisory (AV26-180)
Western Cybersecurity Experts Brace for Iranian Reprisal
Organizations across the West and allied nations should prepare for Iranian cyberattacks in the wake of Israeli and U.S. ongoing strikes, threat intelligence firms warned as the first signs of the Iranian cyber counteroffensive became clear on Sunday
漏洞管理指标:是时候超越指标幻象了
SecWiki News 2026-03-02 Review
UK warns of Iranian cyberattack risks amid Middle-East conflict
CVE-2026-2269 | Uncanny Automator Plugin up to 7.0.0.3 on WordPress download_url server-side request forgery
CVE-2026-1487 | LatePoint Plugin up to 5.2.7 on WordPress JSON Import sql injection
CVE-2026-2448 | gpriday Page Builder by SiteOrigin Plugin up to 2.33.5 on WordPress locate_template file inclusion
CVE-2026-1336 | Ays Pro AI ChatBot with ChatGPT and Content Generator Plugin store_data/get_chatgpt_api_key authorization
Claude AI Suffers Global Outage: Elevated Errors Disrupt Web Interface and APIs
On March 2, 2026, Anthropic’s artificial intelligence assistant, Claude, experienced a significant global outage that disrupted workflows for users and developers worldwide. Organizations relying on the AI model for daily threat intelligence reporting, code generation, and automated security analysis faced temporary operational downtime as the platform struggled with elevated error rates. The technical difficulties initiated […]
The post Claude AI Suffers Global Outage: Elevated Errors Disrupt Web Interface and APIs appeared first on Cyber Security News.