Aggregator
CVE-2026-28138 | Stylemix uListing Plugin up to 2.2.0 on WordPress deserialization (EUVD-2026-8847)
ANY.RUN & Splunk Enterprise: Stronger Detection, Faster Response in Your SOC
Security teams don’t lack alerts, they lack fast, reliable context for decision-making. When threat analysis and intelligence are not an integrated part of the SOC workflow, investigations slow down, MTTR grows, and the risk of missed incidents increases. Adding behavioral analysis and live intelligence directly into SIEM closes this gap, turning monitoring, triage, and response […]
The post ANY.RUN & Splunk Enterprise: Stronger Detection, Faster Response in Your SOC appeared first on ANY.RUN's Cybersecurity Blog.
CVE-2026-28083 | UX-themes Flatsome Plugin up to 3.20.1 on WordPress cross site scripting (EUVD-2026-8843)
CVE-2026-1696 | arcinfo PcVue up to 12.0.0/15.2.13/16.3.3 HTTP Security Header cross site scripting
CVE-2026-28132 | villatheme WooCommerce Photo Reviews Plugin up to 1.4.4 on WordPress cross site scripting (EUVD-2026-8845)
CVE-2026-1695 | arcinfo PcVue up to 12.0.0/15.2.13/16.3.3 WebVue/WebScheduler/TouchVue/SnapVue client_id cross site scripting
CVE-2026-28136 | VeronaLabs WP SMS Plugin up to 6.9.12 on WordPress sql injection (EUVD-2026-8846)
CVE-2026-28131 | WPVibes Elementor Addon Elements Plugin up to 1.14.4 on WordPress insertion of sensitive information into sent data (EUVD-2026-8844)
CVE-2026-1694 | arcinfo PcVue up to 12.0.0/15.2.13/16.3.3 WebScheduler/TouchVue/SnapVue insertion of sensitive information into sent data
CVE-2026-1698 | arcinfo PcVue up to 15.2.13/16.3.3 HTTP Header /Authentication/Logout Host http headers for scripting syntax (EUVD-2026-8842)
CVE-2026-1692 | arcinfo PcVue up to 12.0.0/15.2.13/16.3.3 WebVue/WebScheduler/TouchVue/SnapVue connect missing origin validation in websockets
CVE-2026-1693 | arcinfo PcVue up to 12.0.0/15.2.13/16.3.3 WebVue/WebScheduler/TouchVue/Snapvue weak authentication
CISA mixup of IOC domains
Интернет защищён от перехвата маршрутов. Кроме случаев, когда DNS не защищён. А DNS не защищён почти везде
Global Cyber Agencies Urge Immediate Patching of Cisco SD-WAN Zero Day
Stealth & Control: Mastering Linux Post-Exploitation with the Eden-RAT GUI
Introduction Eden-RAT is a lightweight remote access tool (RAT) designed for the initial stage of penetration testing. It
The post Stealth & Control: Mastering Linux Post-Exploitation with the Eden-RAT GUI appeared first on Penetration Testing Tools.
The Rogue Peer Threat: CISA Issues Emergency Directive to Thwart Global Cisco SD-WAN Hijacking
The offensives targeting Cisco networking infrastructure have reached such a critical magnitude that United States authorities have invoked
The post The Rogue Peer Threat: CISA Issues Emergency Directive to Thwart Global Cisco SD-WAN Hijacking appeared first on Penetration Testing Tools.
The Chatbot Saboteur: How Claude Was Coerced into a 150GB Heist of Mexican State Intelligence
An unidentified adversary manipulated the Claude chatbot, developed by Anthropic, to orchestrate a series of surgical strikes against
The post The Chatbot Saboteur: How Claude Was Coerced into a 150GB Heist of Mexican State Intelligence appeared first on Penetration Testing Tools.