Aggregator
CVE-2026-42773 | eMagicOne Store Manager Plugin up to 1.3.2 on WordPress sql injection
CVE-2026-8376 | Perl up to 5.43.10 on 32-bit regcomp_study.c Perl_study_chunk integer overflow (EUVD-2026-31772 / Nessus ID 316506)
Product showcase: F-Secure Internet Security blocks phishing sites, fake stores, and SMS scams
F-Secure Internet Security protects against viruses, ransomware, spyware, infected email attachments, and other cyber threats. It focuses on securing devices and online activity through malware protection, scam prevention, safe browsing, and banking safeguards. The platform supports Windows, macOS, Android, and iOS devices under a single subscription. After downloading the Android app from the Play Store, I created an account and started using it. The setup process included enabling Device Protection, VPN, Scam Protection, and ID … More →
The post Product showcase: F-Secure Internet Security blocks phishing sites, fake stores, and SMS scams appeared first on Help Net Security.
CVE-2026-39436 | bgermann CformsII Plugin up to 15.1.3 on WordPress cross-site request forgery
CVE-2026-45435 | Melapress WP Activity Log Plugin up to 5.6.3 on WordPress cross site scripting
CVE-2026-45216 | StoreApps Smart Manager Plugin up to 8.85.0 on WordPress privileges assignment (EUVD-2026-31767)
CVE-2026-45209 | edward_plainview MyCryptoCheckout Plugin up to 2.161 on WordPress authorization (EUVD-2026-31770)
CVE-2026-24937 | VideoWhisper Broadcast Live Video Plugin up to 7.1.2 on WordPress code injection
CVE-2026-48837 | Unlimited Elements For Elementor Plugin up to 2.0.8 on WordPress sql injection
CVE-2026-45438 | WebToffee Smart Coupons for WooCommerce Plugin up to 2.2.x on WordPress authorization
CVE-2026-41459 | thexerteproject xerteonlinetoolkits up to 3.15.0 GET Request /setup root_path information expsure (ID 1527 / EUVD-2026-25073)
CVE-2026-43568 | OpenClaw up to 2026.4.9 /dreaming authorization (EUVD-2026-27287)
CVE-2026-41937 | givanz Vvveb up to 1.0.8.2 Plugin Upload Endpoint plugin.php unrestricted upload (EUVD-2026-30297)
ALFA: Automated Audit Log Forensic Analysis for Google Workspace
ALFA – Automated Audit Log Forensic Analysis for Google Workspace You can use this tool to acquire all Google Workspace audit logs and to perform automated forensic analysis on the audit logs using statistics...
The post ALFA: Automated Audit Log Forensic Analysis for Google Workspace appeared first on Information Security News.
Manage machine identities: The hidden privileged access layer you need to manage
Why are machine identities becoming the majority of “things with access”? Every automation, integration, and workload needs a way to authenticate and the right permissions to act. That quiet requirement has created a massive population of machine identities, also called non-human identities (NHIs): service accounts, service principals, workload roles, OAuth apps, AI agents, and IAM roles. Machine identities authenticate using credentials like access keys, secrets, and tokens. Many of these identities hold privileges equal to … More →
The post Manage machine identities: The hidden privileged access layer you need to manage appeared first on Help Net Security.
Все ушли в телефоны — а потом вернулись за стол. Почему настолки переживают второй расцвет
The Auto-Bricker: Flawed HP BIOS Updates Pushed via Windows Update Freeze Elite Laptops
Over an extended operational horizon, a substantial contingent of enterprise practitioners utilizing HP’s premium notebook architecture has filed severe telemetry complaints regarding acute device regression post-installation of recent BIOS/UEFI firmware updates. The systemic anomalies...
The post The Auto-Bricker: Flawed HP BIOS Updates Pushed via Windows Update Freeze Elite Laptops appeared first on Information Security News.
The Trillion-Parameter Engineer: Musk Unveils Grok V9-Medium Armed with Cursor Coding Data
Elon Musk recently disclosed exciting news regarding xAI. The company expects to release its nascent frontier model within the next two to three weeks. Code-named Grok V9-Medium, this powerful architecture boasts an immense scale...
The post The Trillion-Parameter Engineer: Musk Unveils Grok V9-Medium Armed with Cursor Coding Data appeared first on Information Security News.
New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems
A critical heap buffer overflow vulnerability has been disclosed in 7-Zip version 26.00, enabling attackers to achieve arbitrary code execution via a vtable hijack by exploiting a defect in the tool’s NTFS archive handler. Tracked as CVE-2026-48095 and assigned advisory GHSL-2026-140, the flaw resides in the CInStream::GetCuSize() function inside NtfsHandler.cpp. The function computes the NTFS […]
The post New 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code and Compromise Systems appeared first on Cyber Security News.