Aggregator
CIS Benchmarks March 2026 Update
The following CIS Benchmarks and CIS Build Kits have been updated or recently released. The Center for Internet Security has highlighted the major updates below. Each Benchmark and Build Kit includes a changelog that references all changes. Updated CIS Benchmarks overview CIS Microsoft Windows 11 Enterprise Benchmark v5.0.0 CIS Oracle Cloud Infrastructure Foundations Benchmark v3.1.0 CIS Apache Cassandra 5.0 Benchmark v1.1.0 CIS Apache Cassandra 4.1 Benchmark v1.2.0 CIS Apache Cassandra 4.0 Benchmark v1.3.0 CIS Microsoft … More →
The post CIS Benchmarks March 2026 Update appeared first on Help Net Security.
Submit #780729: vanna-ai vanna 2.0.2 CORS Origin Reflection with Credentials [Accepted]
Submit #780727: vanna-ai vanna 2.0.2 Missing Authentication on All API Endpoints [Accepted]
Our ongoing commitment to privacy for the 1.1.1.1 public DNS resolver
Russian Hackers Using Remote Access Toolkit “CTRL” for RDP Hijacking
A newly disclosed Russian-linked remote access toolkit called “CTRL” is being used to hijack Remote Desktop Protocol sessions and steal credentials from Windows systems. According to Censys ARC, the malware is a custom .NET framework that combines phishing, keylogging, reverse tunneling, and persistence into one attack chain. Censys ARC said the toolkit was discovered during […]
The post Russian Hackers Using Remote Access Toolkit “CTRL” for RDP Hijacking appeared first on Cyber Security News.
New Chrome Zero-Day Vulnerability Actively Exploited in Attacks — Patch Now
Google has released an emergency security update for its Chrome browser, patching a zero-day vulnerability that is already being actively exploited in the wild. The Stable channel has been updated to version 146.0.7680.177/178 for Windows and Mac, and 146.0.7680.177 for Linux, with the rollout expected to reach all users over the coming days and weeks. […]
The post New Chrome Zero-Day Vulnerability Actively Exploited in Attacks — Patch Now appeared first on Cyber Security News.
Submit #778613: itsourcecode Payroll Management System V1.0 Cross Site Scripting [Accepted]
Block the Prompt, Not the Work: The End of "Doctor No"
Submit #780538: LibRaw 0.22.0 Out-of-bounds Write [Accepted]
Ransomware Groups Exploit Legit IT Tools to Bypass Antivirus
长城杯半决赛三道 Web—从 redis SSRF、ZipSlip 到 glibc iconv 溢出
Submit #780561: nothings stb (stb_vorbis.c) ≤ 1.22 Out-of-bounds Write, Integer Overflow [Accepted]
Submit #780560: nothings stb (stb_vorbis.c) ≤ 1.22 Free of Pointer not at Start of Buffer [Accepted]
Submit #780559: nothings stb (stb_truetype.h) ≤ 1.26 Out-of-Bounds Read [Accepted]
Submit #780558: nothings stb (stb_truetype.h) ≤ 1.26 Out-of-Bounds Read [Accepted]
Submit #780462: nothings stb ≤ 2.30 (latest) Use After Free [Accepted]
Casbaneiro Phishing Targets Latin America and Europe Using Dynamic PDF Lures
HSBC India Asks Customers to use All-Uppercase Passwords
Beginning April 6, 2026, HSBC India will require its internet banking customers to enter their passwords in uppercase letters only. The mandate, communicated via official customer emails, has sparked widespread concern among technical experts regarding the bank’s credential storage practices and overall security posture. The Uppercase Migration According to the bank’s recent communications, customers must […]
The post HSBC India Asks Customers to use All-Uppercase Passwords appeared first on Cyber Security News.