Aggregator
CVE-2020-37072 | VictorAlagwu CMSsite 1.0 comment_author cross site scripting (Exploit 48484 / EDB-48484)
CVE-2023-53586 | Linux Kernel up to 5.10.179/5.15.110/6.1.27/6.2.14/6.3.1 scsi deserialization (EUVD-2023-60022 / Nessus ID 297598)
CVE-2023-53580 | Linux Kernel up to 6.1.45/6.4.10 USB gadget.h usb_gadget_deactivate denial of service (EUVD-2023-60028 / WID-SEC-2025-2194)
CVE-2023-53582 | Linux Kernel up to 6.2.2 wifi strreplace out-of-bounds (EUVD-2023-60026 / Nessus ID 276910)
CVE-2023-53579 | Linux Kernel up to 5.15.123/6.1.42/6.4.7 gpio memory leak (EUVD-2023-60029 / WID-SEC-2025-2194)
TeamPCP Industrializes Cloud Misconfigurations Into a Self-Propagating Cybercrime Platform
TeamPCP, also known as PCPcat, ShellForce, and DeadCatx3, emerged in December 2025 as a sophisticated cloud-native threat actor targeting exposed Docker APIs, Kubernetes clusters, Ray dashboards, Redis servers, and React2Shell vulnerabilities. The group launched a massive campaign designed to build a distributed proxy and scanning infrastructure at scale, then compromise servers to exfiltrate data, deploy […]
The post TeamPCP Industrializes Cloud Misconfigurations Into a Self-Propagating Cybercrime Platform appeared first on Cyber Security News.
Тренды февраля: патчи вместо валентинок. Positive Technologies советует обновить Windows
Datawhale Easy-Vibe 开源学习task1-AI 时代,会说话就会编程
North Korean hackers targeted crypto exec with fake Zoom meeting, ClickFix scam
How to Automate AWS Incident Investigation with Tines and AI
CVE-2026-2199 | code-projects Online Reviewer System 1.0 user-delete.php ID sql injection (CNNVD-202602-1398)
CVE-2026-2200 | heyewei JFinalCMS 5.0.0 API Endpoint /admin/admin/save cross site scripting (CNNVD-202602-1397)
CVE-2026-2196 | code-projects Online Reviewer System 1.0 exam-update.php test_id sql injection (CNNVD-202602-1400)
CVE-2026-2197 | code-projects Online Reviewer System 1.0 exam-delete.php test_id sql injection (CNNVD-202602-1401)
CVE-2026-2198 | code-projects Online Reviewer System 1.0 loaddata.php difficulty_id sql injection (CNNVD-202602-1399)
Weekly Threat Bulletin – February 11th, 2026
Imprivata delivers passwordless access to improve security, compliance, and productivity
Imprivata has introduced comprehensive new capabilities to enable the next generation of fast, frictionless, and passwordless access for frontline staff, knowledge workers, and all other enterprise users. Imprivata Enterprise Access Management (EAM) now offers context-aware passwordless authentication, identity verification, and AI-powered risk signaling and behavioral analytics, expanding the company’s solutions for seamless access to personal and shared-use devices and applications. Together, these capabilities provide a complete and integrated platform that enables faster, more secure access … More →
The post Imprivata delivers passwordless access to improve security, compliance, and productivity appeared first on Help Net Security.
Chinese crypto scammer sentenced in absentia to 20 years after fleeing US
Portnox expands ZTNA with passwordless access for RDP, SSH, and enterprise consoles
Portnox has unveiled a major expansion of its zero trust network access (ZTNA) solution, extending credential-free access beyond web and on-premises applications to include enterprise console-based applications. Organizations can eliminate passwords and credentials from administrative access via Remote Desktop Protocol (RDP), Secure Shell (SSH), Virtual Network Computing (VNC), and Teletype Network (Telnet). This removes the attack vector responsible for 80% of data breaches while maintaining the frictionless user experience that has defined Portnox ZTNA. As … More →
The post Portnox expands ZTNA with passwordless access for RDP, SSH, and enterprise consoles appeared first on Help Net Security.