Aggregator
CVE-2026-0231 | Palo Alto Cortex XDR Broker VM up to 30.0.48 Cortex UI exposure of sensitive system information to an unauthorized control sphere (EUVD-2026-11251)
CVE-2026-31866 | open-feature flagd up to 0.14.1 Endpoint /ofrep/v1/evaluate/ allocation of resources (GHSA-rmrf-g9r3-73pm)
CVE-2026-31840 | parse-community parse-server up to 8.6.27/9.0.0 9.6.0-alpha.1 Query Parameter sql injection (GHSA-qpr4-jrj4-6f27)
CVE-2026-31871 | parse-community parse-server up to 8.6.30/9.0.0 9.6.0-alpha.4 Parse Server REST API sql injection (GHSA-gqpp-xgvh-9h7h)
CVE-2026-31856 | parse-community parse-server up to 8.6.28/9.0.0 9.6.0-alpha.2 REST API sql injection (GHSA-q3vj-96h2-gwvg)
CVE-2026-31852 | Jellyfin GitHub Action code-quality.yml privileges management (GHSA-7qhm-2m45-7fmh / EUVD-2026-11242)
CVE-2026-31872 | parse-community parse-server up to 8.6.31/9.0.0 9.6.0-alpha.5 protectedFields sort access control (GHSA-r2m8-pxm9-9c4g)
Хьюстон, у нас спам. GitHub завалил программистов бесполезными правками и почему это опасно
Handala
You must login to view this content
Handala
You must login to view this content
CISA orders feds to patch n8n RCE flaw exploited in attacks
Из вашего смартфона доносится шёпот китайского мужчины? Это троян BeatBanker отчаянно пытается удержаться в фоне
Qilin
You must login to view this content
ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites
Salesforce customers have, once again, been targeted by the ShinyHunters group – or, at least, it’s what the group claims. Attackers modified and abused benign tool On Saturday, Saleforce confirmed that its security team has identified an attack campaign by unnamed malicious actors looking to access customers’ data. The attackers are not leveraging a vulnerability in the Salesforce platform, the company said, but are using a modified version of the open-source tool Aura Inspector – … More →
The post ShinyHunters claims new campaign targeting Salesforce Experience Cloud sites appeared first on Help Net Security.
Stretching Cyber Resources in Rural Healthcare
Medical Device Concerns for a Post-Quantum World
Webinar | No More Siloed Security: Aligning SecOps and GRC for Real Impact
How US Ransomware Policy Aims to Break Global Crime Networks
U.S. cyber policy now treats ransomware gangs and fraud networks as transnational criminal organizations. Former FBI cyber leader Cynthia Kaiser explains how sanctions, infrastructure takedowns, and international cooperation could weaken cybercrime ecosystems and reduce attacks.
BlackSanta Malware Shuts Down Protections, Targets HR and Recruiting Operations
Russian threat actors for more than a year have targeted HR and recruiting operations in a sophisticated phishing and infostealing campaign that includes a component, dubbed BlackSanta, that can shut down antivirus tools and EDR protections before deploying the malware that exfiltrates data, Aryaka researchers say.
The post BlackSanta Malware Shuts Down Protections, Targets HR and Recruiting Operations appeared first on Security Boulevard.