Aggregator
MSHTML Framework 0-Day Exploited by APT28 Hackers Before Feb 2026’s Patch Tuesday Update
A zero-day vulnerability in the Microsoft HTML (MSHTML) framework was actively exploited in the wild. The vulnerability, tracked as CVE-2026-21513, allows attackers to bypass security features and execute arbitrary files. With a CVSS score of 8.8, it impacts all Windows versions. Security researchers at Akamai discovered that the Russian state-sponsored threat group APT28 was targeting […]
The post MSHTML Framework 0-Day Exploited by APT28 Hackers Before Feb 2026’s Patch Tuesday Update appeared first on Cyber Security News.
IBM security advisory (AV26-180)
Western Cybersecurity Experts Brace for Iranian Reprisal
Organizations across the West and allied nations should prepare for Iranian cyberattacks in the wake of Israeli and U.S. ongoing strikes, threat intelligence firms warned as the first signs of the Iranian cyber counteroffensive became clear on Sunday
漏洞管理指标:是时候超越指标幻象了
SecWiki News 2026-03-02 Review
UK warns of Iranian cyberattack risks amid Middle-East conflict
CVE-2026-2269 | Uncanny Automator Plugin up to 7.0.0.3 on WordPress download_url server-side request forgery
CVE-2026-1487 | LatePoint Plugin up to 5.2.7 on WordPress JSON Import sql injection
CVE-2026-2448 | gpriday Page Builder by SiteOrigin Plugin up to 2.33.5 on WordPress locate_template file inclusion
CVE-2026-1336 | Ays Pro AI ChatBot with ChatGPT and Content Generator Plugin store_data/get_chatgpt_api_key authorization
Claude AI Suffers Global Outage: Elevated Errors Disrupt Web Interface and APIs
On March 2, 2026, Anthropic’s artificial intelligence assistant, Claude, experienced a significant global outage that disrupted workflows for users and developers worldwide. Organizations relying on the AI model for daily threat intelligence reporting, code generation, and automated security analysis faced temporary operational downtime as the platform struggled with elevated error rates. The technical difficulties initiated […]
The post Claude AI Suffers Global Outage: Elevated Errors Disrupt Web Interface and APIs appeared first on Cyber Security News.
CVE-2026-2628 | All-in-One Microsoft 365 & Entra ID and Azure AD SSO Login Plugin improper authentication
CVE-2026-24110 | Tenda W20E 15.11.0.6 addDhcpRule addDhcpRules buffer overflow
CVE-2026-24101 | Tenda AC15 15.03.05.18 /goform/formSetIptv doSystemCmd s1_1 command injection
Criminal IP to Present Decision-Ready Threat Intelligence at RSAC™ 2026
Torrance, United States / California, March 2nd, 2026, CyberNewswire March 23–26, 2026 | Booth N-6555, Moscone Center, San Francisco Criminal IP, an AI-powered cybersecurity platform specializing in Attack Surface Management (ASM) and Cyber Threat Intelligence (CTI), will participate in the RSAC 2026 Conference, taking place from March 23 to 26 at the Moscone Center in […]
The post Criminal IP to Present Decision-Ready Threat Intelligence at RSAC™ 2026 appeared first on Cyber Security News.
CVE-2026-26699 | SourceCodester Personnel Property Equipment System 1.0 admin_change_picture.php privilege escalation
IPFire ships its 200th core update with a new domain blocklist and kernel upgrade
Network firewall distribution IPFire released Core Update 200, marking the 200th incremental update to the 2.29 branch. The release bundles a kernel upgrade, a beta domain blocklist service, security patches for OpenSSL and glibc, and a range of component updates. The kernel has been rebased on Linux 6.18.7 LTS, bringing updated hardware security mitigations alongside network throughput and latency improvements. Linux developers deprecated ReiserFS support in this kernel line, and IPFire installations running on that … More →
The post IPFire ships its 200th core update with a new domain blocklist and kernel upgrade appeared first on Help Net Security.