Aggregator
CVE-2026-7500 | Keycloak Account REST API /account/v1alpha1 checkAccountApiEnabled direct request
Submit #803996: UTT HiPER 1200GW <=v2.5.3-170306 Buffer Overflow [Accepted]
CVE-2026-36957 | Dbit N300 T1 Pro Easy Setup Wireless Wi-Fi Router 1.0.0 URI denial of service
Submit #803995: UTT HiPER 1200GW <=v2.5.3-170306 Buffer Overflow [Accepted]
CVE-2026-36958 | U-SPEED N300 1.0.0 Web Management Interface denial of service
AL26-010 – Cyber Criminals Social‑Engineering‑Enabled Compromise of Enterprise SaaS Environments
April KB5083769 Windows 11 update causes backup software failures
CVE-2026-7510 | OWAP DefectDojo up to 2.55.4 Benchmark/Engagement/Product/Survey authorization (Bug 14375)
Submit #803751: OWASP DefectDojo < 2.56.0 Authorization Bypass [Accepted]
Popular Python Package lightning Hacked in Supply Chain Attack
The widely used PyTorch Lightning framework, which automatically executes credential-stealing malware on import, has also compromised GitHub maintainer accounts. The popular PyPI package lightning — the deep learning framework used to train, deploy, and ship AI products has been compromised in an active supply chain attack. Socket’s Research Team flagged versions 2.6.2 and 2.6.3 as […]
The post Popular Python Package lightning Hacked in Supply Chain Attack appeared first on Cyber Security News.
国际刑警DDoS蜜罐意外曝光:安全研究员意外逼停执法行动
CVE-2026-7508 | Bootstrap CMS 0.9.0-alpha Page Creation show.blade.php body code injection
UserGate предупреждает: ProFTPD с открытым модулем SQL можно взломать за секунды
Email threat landscape: Q1 2026 trends and insights
In early 2026, email threats increased with a rise in credential phishing, QR code phishing, and CAPTCHA-gated campaigns, highlighted by Microsoft’s disruption of the Tycoon2FA phishing platform which led to a 15% volume decrease and shifts in threat actor tactics.
The post Email threat landscape: Q1 2026 trends and insights appeared first on Microsoft Security Blog.
Two new extortion crews are speedrunning the Scattered Spider playbook
CrowdStrike says The Com-affiliated threat groups are using voice phishing and fake SSO pages to break into SaaS environments and steal data fast for extortion.
The post Two new extortion crews are speedrunning the Scattered Spider playbook appeared first on CyberScoop.
Email threat landscape: Q1 2026 trends and insights
In early 2026, email threats increased with a rise in credential phishing, QR code phishing, and CAPTCHA-gated campaigns, highlighted by Microsoft’s disruption of the Tycoon2FA phishing platform which led to a 15% volume decrease and shifts in threat actor tactics.
The post Email threat landscape: Q1 2026 trends and insights appeared first on Microsoft Security Blog.