Aggregator
Submit #762427: SourceCodester Doctor Appointment System 1 Cross Site Scripting [Accepted]
Senate moves one step closer to passing health care cyber reforms
A legislative package that would overhaul cybersecurity practices at the Department of Health and Human Services sailed through committee.
The post Senate moves one step closer to passing health care cyber reforms appeared first on CyberScoop.
CVE-2026-20791 | Chargemap Web-based Mapping insufficiently protected credentials (icsa-26-057-05)
CVE-2026-25711 | Chargemap WebSocket Backend session expiration (icsa-26-057-05)
CVE-2026-20792 | Chargemap WebSocket Application Programming Interface excessive authentication (icsa-26-057-05)
CVE-2026-25851 | Chargemap WebSocket Endpoint missing authentication (icsa-26-057-05)
Submit #761297: TOTOLINK N300RH_V4 V6.1c.1353_B20190305 Command Injection [Accepted]
CVE-2026-2362 | WP Accessibility Plugin up to 2.3.1 on WordPress getAttribute alt cross site scripting
CVE-2026-2383 | Simple Download Monitor Plugin up to 4.0.5 on WordPress Custom Fields cross site scripting
CVE-2025-14149 | Xpro Addons Plugin up to 1.4.24 on WordPress Image Scroller Widget cross site scripting
CVE-2026-27141 | x-net-http2 up to 0.50.x HTTP/2 Frame null pointer dereference
CVE-2026-23939 | hexpm lib/hexpm/store/local.ex delete_many path traversal
CVE-2026-22722 | VMware Workstation up to 25H2U1 null pointer dereference
CVE-2026-26979 | Discourse up to 2025.12.1/2026.1.0 Private Category authorization
CVE-2026-26973 | Discourse up to 2025.12.1/2026.1.0 enable_category_group_moderation authorization
CVE-2026-27509 | UnitreeRobotics Unitree Go2 up to 1.1.9 Message actuator_manager.py missing authentication
CVE-2026-27510 | UnitreeRobotics Unitree Go2 up to 1.1.9/1.1.11 com.unitree.doggo2 unitree_go2.db pyCode data authenticity
CVE-2026-1241 | Pelco Sarix Professional IWP 3 up to 02.52 Web Management Interface authentication bypass (icsa-26-057-02)
Phishing‑Led Agent Tesla Campaign Uses Process Hollowing and Anti‑Analysis to Evade Detection
A newly uncovered phishing campaign is delivering Agent Tesla, one of the most widely used credential-stealing malware families, through a multi-stage attack chain that leaves almost no trace on a victim’s machine. The campaign uses business-themed phishing emails, obfuscated scripts, and in-memory execution to silently harvest sensitive data from Windows users. With its ability to […]
The post Phishing‑Led Agent Tesla Campaign Uses Process Hollowing and Anti‑Analysis to Evade Detection appeared first on Cyber Security News.