Aggregator
CVE-2026-16075 | AstrBotDevs AstrBot up to 4.25.5 session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions Username authorization
CVE-2026-16074 | AstrBotDevs AstrBot up to 4.25.2 Plugin Update plugin.py update_plugin/update_all_plugins download_url/download_urls/proxy server-side request forgery
CVE-2026-16073 | AstrBotDevs AstrBot up to 4.25.2 T2I Feature base.py Star.text_to_image/NetworkRenderStrategy.render cross site scripting
New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets
A financially motivated, Russian-speaking threat actor tracked as UAT-11795, orchestrating a large-scale campaign since at least June 2025. A sophisticated Python-based remote access trojan dubbed “Starland RAT,” alongside a stealthy in-memory PowerShell implant known as the “WLDR agent.” The operation targets users across the United States and parts of Europe, with a primary focus on […]
The post New Starland RAT Steals Browser Credentials and Scans for Over 40 Crypto Wallets appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2024-23567 | HCL Aftermarket EPC 1.0.0 URL Parameter information disclosure
Dairy company Fairlife suspends production in US after cyber incident
Submit #852865: AstrBotDevs AstrBot <= 4.25.5 Improper Link Resolution Before File Access (CWE-59) [Accepted]
Submit #852864: AstrBotDevs AstrBot <= 4.25.5 Authentication Bypass by Spoofing (CWE-290) [Accepted]
Submit #852863: AstrBotDevs AstrBot <= 4.25.5 Authorization Bypass Through User-Controlled Key (CWE-639) [Accepted]
CVE-2024-23564 | HCL Aftermarket EPC Password Recovery redirect
Submit #852842: AstrBotDevs AstrBot 4.25.2 Server-Side Request Forgery (CWE-918) [Accepted]
Submit #852825: AstrBotDevs AstrBot 4.25.2 Cross-site Scripting (CWE-79) [Accepted]
CVE-2026-7488 | IKAS E-Commerce 03062026 information disclosure
[译苑雅集Vol. 15] Own Your Weights: 企业要不要拥有自己的模型?
数据泄露情报2026.7.17 - 看看blackeye的库存
Вы думали, что ваш профиль на OnlyFans никто не найдет? Нейросеть кадровика уже сопоставляет его с вашим лицом в резюме
门票炒到 3000 元的 WAIC,我们找到了 AI 真正的创新
New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access
A Windows zero-day vulnerability, dubbed LegacyHive (MSNightmare), abuses the User Profile Service to enable local privilege escalation, tampering with administrator accounts, and admin-level code execution. LegacyHive targets the Windows User Profile Service (ProfSvc), which is responsible for loading and unloading user profiles and their registry hives during logon and logoff. The public proof‑of‑concept (PoC) from the […]
The post New Windows LegacyHive 0-Day Vulnerability Allows Hackers to Gain Admin Access appeared first on Cyber Security News.