Former ransomware negotiator Angelo Martino gets 70 months in prison for helping BlackCat extort US victims and misuse confidential client data in cyberattacks.
The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON.
Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that propagates malware via counterfeit installers using SEO poisoning techniques, it belies their true organizational
A vulnerability identified as critical has been detected in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp of the component ReadVar Request Handler. This manipulation causes deserialization.
This vulnerability is registered as CVE-2026-15105. The attack requires access to the local network. Furthermore, an exploit is available.
The project was informed of the problem early through an issue report but has not responded yet.
A vulnerability categorized as problematic has been discovered in miurahr py7zr up to 1.1.2. This affects the function PackInfo._read of the file archiveinfo.py of the component Archive Info Handler. Such manipulation of the argument numstreams leads to resource consumption.
This vulnerability is referenced as CVE-2026-55206. It is possible to launch the attack remotely. No exploit is available.
A vulnerability has been found in mvantellingen python-zeep up to 4.3.2 and classified as critical. This issue affects some unknown processing of the component WSDL Parser. The manipulation leads to xml external entity reference.
This vulnerability is documented as CVE-2026-58501. The attack can be initiated remotely. There is not any exploit available.
A vulnerability classified as problematic has been found in GNU patch up to 2.8.0. Impacted is the function fwrite of the component Hunk Handler. This manipulation causes null pointer dereference.
This vulnerability appears as CVE-2026-56288. The attack may be initiated remotely. There is no available exploit.
A vulnerability classified as problematic was found in GNU patch up to 2.8.0. The affected element is an unknown function of the component Hunk Validator. Such manipulation leads to resource consumption.
This vulnerability is traded as CVE-2026-56289. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in iqonicdesign KiviCare Plugin up to 4.4.0 on WordPress. It has been classified as critical. Impacted is an unknown function of the component Authorization Verification. The manipulation of the argument payment_id leads to authorization bypass.
This vulnerability is traded as CVE-2026-11990. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic was found in logichunt Logo Slider Plugin up to 5.5 on WordPress. This vulnerability affects unknown code of the component Tooltip Handler. Such manipulation of the argument lgx_tooltip_position leads to cross site scripting.
This vulnerability is listed as CVE-2026-13247. The attack may be performed from remote. There is no available exploit.
A vulnerability was found in Happyforms Plugin up to 1.26.12 on WordPress and classified as problematic. Affected by this issue is the function happyforms_get_form_partial of the component Form Builder. Such manipulation leads to file inclusion.
This vulnerability is traded as CVE-2025-11977. The attack may be launched remotely. There is no exploit available.
A vulnerability categorized as problematic has been discovered in jegtheme Jeg Kit for Elementor Plugin up to 3.2.6 on WordPress. This affects the function render_body of the component Image Box Widget. Such manipulation of the argument sg_body_description leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-13710. The attack can be launched remotely. No exploit exists.
A vulnerability identified as problematic has been detected in R-SOFT SERWIS DMS up to 3.19-2861. This impacts an unknown function of the component File Download Endpoint. Performing a manipulation results in improper control of resource identifiers.
This vulnerability was named CVE-2026-41878. The attack may be initiated remotely. There is no available exploit.
A vulnerability classified as problematic has been found in R-SOFT SERWIS DMS. This affects an unknown part of the file configuration file of the component Password Hash Storage. This manipulation causes password hash with insufficient computational effort.
This vulnerability is tracked as CVE-2026-41879. The attack is possible to be carried out remotely. No exploit exists.
AI coding tools cost $19-$200/month/user, but security scanning, remediation, and false positives add hidden costs. Are the productivity gains worth it?
A vulnerability was found in c-ares 1.34.7/7.5. It has been rated as critical. This affects the function ares_getaddrinfo. This manipulation causes use after free.
This vulnerability is tracked as CVE-2026-33630. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability labeled as problematic has been found in ONNX up to 1.21.0. Affected by this issue is the function Upsample_6_7::adapt_upsample_6_7 of the file onnx/version_converter/adapters/upsample_6_7.h of the component Version Converter Adapters. Executing a manipulation of the argument inputs can lead to null pointer dereference.
This vulnerability is registered as CVE-2026-44512. It is possible to launch the attack remotely. No exploit is available.
A vulnerability categorized as problematic has been discovered in Linux Kernel up to 6.19.5. This issue affects the function kaweth_set_rx_mode. Such manipulation leads to privilege escalation.
This vulnerability is documented as CVE-2026-43180. The attack requires being on the local network. There is not any exploit available.
It is advisable to upgrade the affected component.