Aggregator
Please support the site operations by clicking ads.
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
1 month hence
[Virtual Event] Building a Secure AI Strategy for the Enterprise
1 day hence
Weekly Threat Bulletin – October 7th, 2026
2 hours 50 minutes hence
These are the top threats you should know about this week.
Cyber experts call on CISA to create mandatory federal OT rules
51 minutes 22 seconds ago
The Operational Technology Cybersecurity Coalition released a white paper urging the CISA to create a new directive centered around operational technology, which is used to monitor and control critical infrastructure.
Senate passes healthcare cybersecurity bill after 190 million impacted by Change Healthcare breach
1 hour 5 minutes ago
The Health Care Cybersecurity and Resiliency Act of 2026 was passed by unanimous consent last week, potentially expanding federal cyber requirements for healthcare organizations.
Russian cyberattacks against UK are 'Putin Tax' costing $3.3 billion, says lawmaker
1 hour 24 minutes ago
A report by a Labour MP and an academic argues that if the British public cannot see what Russian activity costs, it cannot weigh that burden against the cost of defending against it.
Shopping online safely – ITSAP.00.071
1 hour 26 minutes ago
Canadian Centre for Cyber Security
FBI, Secret Service add to warnings of FortiBleed credential stealing campaign
2 hours 4 minutes ago
Users of two types of Fortinet hardware should take steps to limit their exposure to a now-global credential stealing campaign, U.S. federal law enforcement says.
NetworkMiner 3.2 Released
3 hours 24 minutes ago
NetworkMiner 3.2 parses RADIUS authentication data and extracts more details from the OT/ICS protocols UMAS and IEC-104. The release also improves several existing protocol parsers and fixes file-reassembly issues, helping analysts extract more information from captured network traffic. OT Protocol[...]
Erik Hjelmvik
CVE-2026-106445
4 hours 37 minutes ago
Currently trending CVE - Hype Score: 7 - Handlebars provides the power necessary to let users build semantic templates. From 4.0.0 until 4.7.10, Handlebars lookupProperty returns Function.prototype.constructor before applying the prototype-access deny list because constructor is an own property of Function.prototype. ...
CVE-2026-86360
4 hours 37 minutes ago
Currently trending CVE - Hype Score: 9 - Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for ...
CVE-2025-54769
4 hours 37 minutes ago
Currently trending CVE - Hype Score: 13 - An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file placed in a location of their choosing. This can be used to overwrite existing PERL modules within the application to achieve remote code execution (RCE) by an ...
CVE-2026-63277
4 hours 37 minutes ago
Currently trending CVE - Hype Score: 10 - LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document. A document could name a Java database driver for such a link to be loaded from a remote location, so opening the document could run Java code from that location. In fixed ...
CVE-2026-42589
4 hours 37 minutes ago
Currently trending CVE - Hype Score: 1 - Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg's /forms/pdfengines/metadata/write HTTP endpoint accepts a JSON metadata object and passes its keys directly to ExifTool via the go-exiftool library. No validation is performed on key ...
CVE-2026-88779
4 hours 37 minutes ago
Currently trending CVE - Hype Score: 9 - Vulnerability in NetScaler ADC and NetScaler Gateway.
This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
CVE-2026-40281
4 hours 37 minutes ago
Currently trending CVE - Hype Score: 1 - Gotenberg is a Docker-powered stateless API for PDF files. In versions 8.30.1 and earlier, the metadata write endpoint validates metadata keys for control characters but leaves metadata values unsanitized. A newline character in a metadata value splits the ExifTool stdin line ...
CVE-2026-61500
4 hours 37 minutes ago
Currently trending CVE - Hype Score: 7 - Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of the same generator to unauthenticated clients during login. A remote attacker can collect a small number of login responses, ...
CVE-2026-60137
4 hours 37 minutes ago
Currently trending CVE - Hype Score: 1 - WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
CVE-2026-63030
4 hours 37 minutes ago
Currently trending CVE - Hype Score: 1 - WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.