Posts of last 24 hours
RustDuck is a small, evolving DDoS botnet migrating to Rust. It uses advanced encryption, anti-analysis evasion, and exploits known IoT flaws. Since February 2026, researchers at QiAnXin’s XLab have been tracking a new malware family, called RustDuck, that hijacks routers, cameras, Android set-top boxes, and exposed servers, then uses them to flood targets with junk […]
https://securityaffairs.com/194556/malware/rustduck-the-botnet-thats-still-small-but-engineering-like-it-plans-to-grow.html
A simple implementation flaw allowed email verification to be completed without ever opening the ver
https://buaq.net/go-426385.html
A simple implementation flaw allowed email verification to be completed without ever opening the ver
https://buaq.net/go-426358.html
A vulnerability labeled as critical has been found in cozyvision1 SMS Alert Plugin up to 3.9.5 on WordPress. Affected by this issue is some unknown functionality of the component Password Reset Handler. The manipulation results in improper authentication.
This vulnerability is known as CVE-2026-11387. It is possible to launch the attack remotely. No exploit is available.
https://vuldb.com/vuln/375421
A vulnerability marked as problematic has been reported in rilwis Slim SEO Plugin up to 4.9.8 on WordPress. This affects the function Data::get_post_content of the file /wp-json/slim-seo/meta-tags/ai of the component REST API Endpoint. This manipulation of the argument object.ID causes information disclosure.
This vulnerability is handled as CVE-2026-12408. The attack can be initiated remotely. There is not any exploit available.
https://vuldb.com/vuln/375422
A vulnerability, which was classified as critical, was found in qodeinteractive Qi Blocks Plugin up to 1.4.9 on WordPress. The impacted element is an unknown function of the component Endpoint. The manipulation of the argument page_id results in authorization bypass.
This vulnerability is identified as CVE-2026-10096. The attack can be executed remotely. There is not any exploit available.
https://vuldb.com/vuln/375427
A vulnerability described as problematic has been identified in codename065 Download Manager Plugin up to 3.3.60 on WordPress. Affected by this issue is some unknown functionality of the component Shortcode Handler. Such manipulation of the argument no_data_msg leads to cross site scripting.
This vulnerability is traded as CVE-2026-13733. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/375465
A vulnerability, which was classified as problematic, was found in metagauss RegistrationMagic Plugin up to 6.0.9.1 on WordPress. Affected is the function process_request. Such manipulation leads to cross-site request forgery.
This vulnerability is referenced as CVE-2026-12158. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
https://vuldb.com/vuln/375441
A vulnerability categorized as critical has been discovered in BMC Control-M, Enterprise Manager and Server up to 9.0.20. This affects an unknown function. Executing a manipulation can lead to deserialization.
This vulnerability is registered as CVE-2026-10538. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
https://vuldb.com/vuln/375461
A vulnerability identified as critical has been detected in BMC Control-M and Server up to 9.0.21.200. This impacts an unknown function. The manipulation leads to authentication bypass by primary weakness.
This vulnerability is documented as CVE-2026-10539. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
https://vuldb.com/vuln/375462