Aggregator
OpenAI's Promptfoo Deal Plugs Agentic AI Testing Gap
Alleged Leak of Spanish Ministry of Finance Employee Data Including IDs, IBANs, and Personal Information
Malformed ZIP Files Allows Attackers to Bypass Antivirus and EDR Detections
A critical flaw in how antivirus and Endpoint Detection and Response (EDR) systems process archive files. Tracked as CVE-2026-0866, this weakness allows attackers to use intentionally malformed ZIP headers to sneak malicious payloads past standard security scanners entirely undetected. ZIP archives contain embedded metadata, such as version details, operational flags, and specific compression methods, which […]
The post Malformed ZIP Files Allows Attackers to Bypass Antivirus and EDR Detections appeared first on Cyber Security News.
CVE-2025-15444 | IAMB Crypt::Sodium::XS up to 0.41 vulnerable third-party component (Nessus ID 294915)
CVE-2026-2915 | HP System Event Utility up to 3.2.15 denial of service
CVE-2019-25503 | Blondish PHPads 2.0 click.php3 bannerID sql injection (Exploit 46798)
CVE-2019-25506 | FreeSMS 2.1.2 Login Endpoint crc_handler.php?method=login sql injection (Exploit 46658)
CVE-2019-25505 | Bdtask Tradebox 5.4 POST Request Symbol sql injection (Exploit 46671)
CVE-2025-41257 | Suprema BioStar 2 2.9.11.6 New Password improper authorization
CVE-2025-40931 | CHORNY Apache::Session::Generate::MD5 up to 1.94 on Perl Default Session ID Generator rand generation of predictable numbers or identifiers (Nessus ID 301112)
CVE-2024-57854 | DOUGDUDE Net::NSCA::Client up to 0.009002 on Perl rand weak prng
CVE-2026-26033 | Dell UPS Multi-UPS Management Console 01.06.0001 (A03) unquoted search path
CVE-2026-20149 | Cisco Webex Meetings Link cross site scripting (cisco-sa-webex-xss-TZFTbbwN / EUVD-2026-9473)
CISA Warns SolarWinds and Ivanti Vulnerabilities Are Actively Exploited
Organizations often prioritize patching vulnerabilities based on severity scores, assuming that lower-rated issues pose limited risk. In practice, attackers frequently exploit vulnerabilities that remain unpatched in real environments, regardless of their official severity rating. New reporting from The Hacker News highlights that the Cybersecurity and Infrastructure Security Agency (CISA) has added multiple vulnerabilities affecting products
The post CISA Warns SolarWinds and Ivanti Vulnerabilities Are Actively Exploited appeared first on Seceon Inc.
The post CISA Warns SolarWinds and Ivanti Vulnerabilities Are Actively Exploited appeared first on Security Boulevard.
OpenAI to Acquire Promptfoo to Fix Vulnerabilities in AI Systems
OpenAI has announced its acquisition of Promptfoo, an artificial intelligence security platform designed to help enterprises find and fix vulnerabilities during development. This strategic move aims to secure AI systems against emerging threats, such as prompt injection and jailbreaks, before they are deployed into live business environments. Once the acquisition is finalized, OpenAI plans to […]
The post OpenAI to Acquire Promptfoo to Fix Vulnerabilities in AI Systems appeared first on Cyber Security News.
Ivanti Desktop and Server Management Vulnerability Allows Attackers to Escalate Privileges
Ivanti has issued a security update for its Desktop and Server Management (DSM) software, addressing a high-severity vulnerability that could allow a local authenticated attacker to escalate their privileges on affected systems. The flaw, tracked as CVE-2026-3483, carries a CVSS score of 7.8 and affects all DSM versions up to and including 2026.1. The vulnerability […]
The post Ivanti Desktop and Server Management Vulnerability Allows Attackers to Escalate Privileges appeared first on Cyber Security News.
Iranian APT Hack Targets US Airport Bank and Software Company
Critical infrastructure organizations continue to face sustained pressure from nation-state cyber operations. Airports, financial institutions, and software companies represent high-value targets because of the operational and economic disruption that a successful intrusion can create. New reporting from SecurityWeek details how an Iranian advanced persistent threat group conducted cyber intrusions against organizations, including a U.S. airport,
The post Iranian APT Hack Targets US Airport Bank and Software Company appeared first on Seceon Inc.
The post Iranian APT Hack Targets US Airport Bank and Software Company appeared first on Security Boulevard.
Iranian MOIS Actors & the Cyber Crime Connection
Key Points Iran-linked actors are increasingly engaging with the cyber crime ecosystem. Their activity suggests a growing reliance on criminal tools, services, and operational models in support of state objectives. Iranian actors have long used cyber crime and hacktivism as cover for destructive activity, but the trend now suggests direct engagement with the criminal ecosystem. […]
The post Iranian MOIS Actors & the Cyber Crime Connection appeared first on Check Point Research.