Aggregator
CVE-2026-28477 | OpenClaw up to 2026.2.13 OAuth Call cross-site request forgery (GHSA-7rcp-mxpq-72pj)
CVE-2026-28471 | OpenClaw up to 2026.2.1 Matrix Plugin improper authentication (GHSA-rmxw-jxxx-4cpc)
CVE-2026-29606 | OpenClaw up to 2026.2.13 Publicly Reachable Webhook Endpoint missing authentication (GHSA-c37p-4qqg-3p76)
CISA shortens patch deadline for critical Ivanti, SolarWinds bugs
CVE-2025-11739 | Schneider Electric EcoStruxure Power Monitoring Expert 2022/2023/2024 deserialization (SEVD-2026-069-06)
CVE-2026-2741 | Vaadin Flow up to 14.14.0/23.6.6/24.9.8/25.0.2 ZIP Node.js path traversal
CVE-2026-2742 | Vaadin Flow up to 14.14.0/23.6.6/24.9.7/25.0.1 Endpoint /vaadin access control
CVE-2026-2339 | Tubitak Bilgem Liderahenk up to 3.3.x missing authentication
CVE-2025-13957 | Schneider Electric EcoStruxure IT Data Center Expert SOCKS Proxy hard-coded credentials (SEVD-2026-069-05)
Перекинул файл по AirDrop и остался без миллионов. История одного очень неудачного рабочего дня
Inference protection for LLMs: Keeping sensitive data out of AI workflows
HR, recruiters targeted in year-long malware campaign
An attack campaign targeting HR departments and job recruiters has been stealthily compromising systems, Aryaka researchers have discovered. By avoiding analysis environments and leveraging a specialized module designed to kill antivirus and endpoint detection software, the Russian-speaking attacker(s) behind this campaign have managed to keep their activity largely under the radar. “We currently lack telemetry to determine how widespread the campaign is,” Aditya K. Sood, Aryaka’s VP of Security Engineering & AI Strategy, told Help … More →
The post HR, recruiters targeted in year-long malware campaign appeared first on Help Net Security.
CISA Warns of Ivanti Endpoint Manager Authentication Bypass Vulnerability Exploited in Attacks
A serious security flaw in Ivanti Endpoint Manager has caught federal attention after the Cybersecurity and Infrastructure Security Agency (CISA) added it to the Known Exploited Vulnerabilities (KEV) catalog on March 9, 2026. Tracked as CVE-2026-1603, this authentication bypass vulnerability affects all versions of Ivanti Endpoint Manager prior to the 2024 SU5 release and enables […]
The post CISA Warns of Ivanti Endpoint Manager Authentication Bypass Vulnerability Exploited in Attacks appeared first on Cyber Security News.
Microsoft flips Windows Autopatch to default hotpatch security updates
Microsoft is changing the default behavior in Windows Autopatch so that hotpatch security updates are enabled automatically for eligible devices managed through Microsoft Intune or the Microsoft Graph API starting with the May 2026 Windows security update. Windows Autopatch is a Microsoft-managed service that automates updates for Windows and Office. It also lets IT administrators pause updates and roll them back if devices fail to meet performance targets after installation. Introduced about a year ago, … More →
The post Microsoft flips Windows Autopatch to default hotpatch security updates appeared first on Help Net Security.