Aggregator
Webinar: Too many tools are slowing network incident response
基于ptrace与/proc/mem的Linux无文件进程注入:攻击实现与内存取证检测
Старое оборудование, новая архитектура и обход Apple. Huawei готовит чип Kirin 9050, который может превзойти топовый процессор Apple
Remembering Tim Wilson, Whose Legacy Lives on at Dark Reading
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-48172 LiteSpeed cPanel Plugin Privilege Escalation Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
[THN Webinar] New AI DDoS Attacks Are Smarter. Learn How to Fight Back
CVE-2026-44468 | CODESYS Development System up to 3.5.21.40 default permission (VDE-2026-055 / EUVD-2026-31798)
CVE-2026-44469 | CODESYS Development System up to 3.5.21.40 Temporary Directory default permission (VDE-2026-055 / EUVD-2026-31797)
CVE-2026-8047 | CODESYS Control RTE 3.5.22.0 HTTP Request improper validation of specified quantity in input (VDE-2026-057 / EUVD-2026-31800)
CVE-2026-8046 | CODESYS Control RTE 3.5.22.0 User Account authorization (VDE-2026-056 / EUVD-2026-31799)
CVE-2026-39655 | TeconceTheme Mayosis Core Plugin up to 5.4.7 on WordPress authorization (EUVD-2026-31801)
CVE-2026-39661 | Magentech SW Core Plugin up to 1.7.18 on WordPress filename control (EUVD-2026-31802)
Major Cyber Attacks in May 2026: Fake Invitations, Agent Tesla, BlobPhish, and More
May 2026 showed how fast routine business activity can turn into real security exposure. ANY.RUN observed phishing campaigns, fileless malware delivery, credential theft, OTP interception, and remote access abuse targeting organizations across industries. From fake invitations and banking portals to compromised B2B websites and Word Online lures, the month’s attacks had one thing in common: they were built […]
The post Major Cyber Attacks in May 2026: Fake Invitations, Agent Tesla, BlobPhish, and More appeared first on ANY.RUN's Cybersecurity Blog.
Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
Personal information of 185,000 people exposed after cyberattack on 7-Eleven
Data belonging to about 185,000 people was exposed following a cyberattack on convenience store chain 7-Eleven that was later claimed by the ShinyHunters extortion gang, according to Have I Been Pwned. The exposed information includes email addresses, names, physical addresses, dates of birth, and phone numbers, while a small number of records also contained additional data fields. 7-Eleven is a convenience store chain with more than 86,000 stores in 19 countries. On April 8, 2026, … More →
The post Personal information of 185,000 people exposed after cyberattack on 7-Eleven appeared first on Help Net Security.
Windows Server 2016 Domain Controller May Fail with 15-Character Hostname
Windows administrators are facing a disruptive bug in Windows Server 2016 following Microsoft’s May 12, 2026, security update KB5087537. The update introduced a critical flaw that caused domain controller discovery to completely fail on servers configured with hostnames exceeding the 15-character NetBIOS limit, leaving administrators unable to perform essential network operations. Microsoft acknowledged the issue […]
The post Windows Server 2016 Domain Controller May Fail with 15-Character Hostname appeared first on Cyber Security News.