Aggregator
CVE-2026-40987 | Vmware Spring Integration up to 7.0.4 /SFTP/SMB path traversal (CNNVD-202606-3066)
CVE-2026-10795 | davidanderson UpdraftPlus Plugin up to 1.26.4 on WordPress wp_loaded signature verification (EUVD-2026-36215 / CNNVD-202606-3068)
CVE-2026-2827 | 100plugins Open User Map PRO Plugin up to 1.4.31 on WordPress versions oum_location_notification cross site scripting (EUVD-2026-36198 / CNNVD-202606-3071)
CVE-2026-35273 | Oracle PeopleSoft Enterprise PeopleTools 8.61/8.62 Updates Environment Management missing authentication (EUVD-2026-36199 / CNNVD-202606-3070)
CVE-2026-40985 | Vmware Spring Web Flow up to 2.5.1/3.0.1/4.0.0 expression language injection (EUVD-2026-36200 / CNNVD-202606-3069)
Delinea and Cyera integrate for data-aware identity security
Delinea and Cyera announced a product integration that connects privileged access to sensitive data exposure, automatically correlating identities with the data they can access. Together, Delinea and Cyera help security teams identify, prioritize, and remediate the highest-risk access paths across every human, machine, and AI agent. As identities multiply and AI agents interact with data at machine speed, security teams struggle to govern which privileged identities can reach critical data, and act on that risk … More →
The post Delinea and Cyera integrate for data-aware identity security appeared first on Help Net Security.
Arch Linux 遭遇新一轮 AUR 恶意程序攻击
Critical Microsoft 365 Copilot Vulnerability Allows Attackers to Steal Data in One Click
A critical vulnerability chain in Microsoft 365 Copilot Enterprise that let attackers steal sensitive corporate data, MFA codes, email contents, calendar details, and confidential files with nothing more than a single click on a link pointing to a legitimate Microsoft domain. Dubbed SearchLeak, uncovered by Varonis Threat Labs and tracked as CVE-2026-42824, the flaw earned […]
The post Critical Microsoft 365 Copilot Vulnerability Allows Attackers to Steal Data in One Click appeared first on Cyber Security News.