Aggregator
CVE-2026-2075 | yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4 Role-Permission Binding RoleController.java saveRolePermission access control (Issue 52)
CVE-2026-2074 | O2OA up to 9.0.0 HTTP POST Request check xml external entity reference
Submit #745508: yeqifu warehouse latest(git commit aaf29962ba407d22d991781de28796ee7b4670e4) Im [Accepted]
CVE-2026-2073 | itsourcecode School Management System 1.0 /ramonsys/user/index.php ID sql injection
CVE-2026-2071 | UTT 进取 520W 1.7.7-180627 formP2PLimitConfig strcpy except buffer overflow
CVE-2026-2070 | UTT 进取 520W 1.7.7-180627 formPolicyRouteConf strcpy GroupName buffer overflow
Submit #745486: 浙江兰德纵横网络技术股份有限公司 O2OA v6.1.0 至 v9.0.0 XML实体注入漏洞 [Accepted]
CVE-2026-2069 | ggml-org llama.cpp up to 55abc39 GBNF Grammar llama-grammar.cpp llama_grammar_advance_stack stack-based overflow (Issue 18988 / ID 18993)
Submit #745482: itsourcecode School Management System V1.0 SQL Injection [Accepted]
February 2026 Patch Tuesday forecast: Lots of OOB love this month
Valentine’s Day is just around the corner and Microsoft has been giving us a lot of love with a non-stop supply of patches starting with January 2026 Patch Tuesday. The January releases addressed 92 vulnerabilities in Windows 11 and Server2025, as well as 79 vulnerabilities for Windows 10 and its associated servers. We also saw updates for legacy 2016 versions of Microsoft Office and even a SQL Server update. But these patches came with some … More →
The post February 2026 Patch Tuesday forecast: Lots of OOB love this month appeared first on Help Net Security.
Submit #745265: UTT 进取 520W v3v1.7.7-180627 Buffer Overflow [Accepted]
Submit #745264: UTT 进取 520W v3v1.7.7-180627 Buffer Overflow [Accepted]
Submit #745263: llama.cpp commit 55abc39 Stack-based Buffer Overflow [Accepted]
Kasada Account Intelligence combats manual fraud and abuse
Kasada released Account Intelligence, a new product designed to detect account-level fraud and abuse. The goal is to prevent repeat abuse before it creates financial loss and unnecessary friction for customers. Enterprises are facing account and business-logic abuse that existing bot and fraud tools were never built to detect. In a single session, this human-driven activity often looks legitimate. Risk only becomes clear later, after damage has already occurred. “Teams already know what this kind … More →
The post Kasada Account Intelligence combats manual fraud and abuse appeared first on Help Net Security.
The Human Layer of Security: Why People are Still the Weakest Link in 2026
By 2026 humans remain cybersecurity’s weakest—and most vital—link as AI-enabled social engineering rises; prioritize behavioral design, real‑time interventions, and leadership.
The post The Human Layer of Security: Why People are Still the Weakest Link in 2026 appeared first on Security Boulevard.
Hackers Leveraging Windows Screensaver to Deploy RMM Tools and Gain Remote Access to Systems
Cybersecurity threats are constantly evolving, and a recent campaign highlights a deceptive new tactic where attackers leverage Windows screensaver (.scr) files to compromise systems. This method allows threat actors to deploy legitimate Remote Monitoring and Management (RMM) tools, granting them persistent remote access while effectively bypassing standard security controls. By utilizing trusted software and cloud […]
The post Hackers Leveraging Windows Screensaver to Deploy RMM Tools and Gain Remote Access to Systems appeared first on Cyber Security News.
LogicScan:一种基于大语言模型的智能合约业务逻辑漏洞检测框架
Your PQC Pilot Might Fail, and That’s Okay
Start PQC pilots now—not to prove readiness but to surface interoperability, vendor, inventory, and skills gaps so organizations can manage post-quantum migration risks.
The post Your PQC Pilot Might Fail, and That’s Okay appeared first on Security Boulevard.