Aggregator
Malicious Windows Shortcuts Use PowerShell and Node.js to Enable Remote Code Execution
A malicious Windows shortcut is being used to turn a routine download into a full remote-code-execution foothold. The campaign begins with convincing booking-themed spam and steers victims toward a ZIP archive that conceals a booby-trapped LNK file. One click can quietly start a chain that installs a backdoor and gives attackers a path to run […]
The post Malicious Windows Shortcuts Use PowerShell and Node.js to Enable Remote Code Execution appeared first on Cyber Security News.
CVE-2026-56814 | elixir-plug up to 1.20.2 Multipart Request-Body Parser multipart.ex parse_multipart/2 filename denial of service
GNU Guix Vulnerabilities Allow Remote Privilege Escalation via Malicious Binary Substitutes
GNU Guix has disclosed four serious security vulnerabilities affecting its package substitution and channel-management features. Three flaws in the guix substitute utility can enable remote privilege escalation, corruption of stored data, and local disclosure of files readable by the build daemon user. At the same time, a fourth issue affects guix pull and guix time-machine. […]
The post GNU Guix Vulnerabilities Allow Remote Privilege Escalation via Malicious Binary Substitutes appeared first on Cyber Security News.
CVE-2026-41877 | R-SOFT SERWIS DMS up to 3.19-2831 File Upload Name cross site scripting (EUVD-2026-42854)
CVE-2026-41880 | R-SOFT SERWIS DMS up to 3.19-2861 OCR Module OCR Function file paths os command injection (EUVD-2026-42855)
CVE-2026-58225 | elixir-ecto postgrex 0.22.2 Notifications handle_connect channel name sql injection (EUVD-2026-42867)
CVE-2026-41876 | R-SOFT SERWIS DMS up to 3.19-2751 Document Converter konwertujAction format os command injection (EUVD-2026-42853)
CVE-2026-6802 | fahadmahmood Easy Upload Files During Checkout Plugin up to 3.0.1 on WordPress File Deletion ufdc_custom_init eufdc-delete authorization (EUVD-2026-42846)
Linux Kernel FUSE Vulnerability Lets Attackers Gain Root Privileges
A Linux kernel vulnerability in the FUSE subsystem can allow a local attacker to gain root privileges by overflowing the page cache with attacker-controlled directory entries. The flaw is tracked as CVE-2026-31694 and affects the code path used when the kernel caches FUSE readdir results. FUSE lets a userspace filesystem talk to the kernel through […]
The post Linux Kernel FUSE Vulnerability Lets Attackers Gain Root Privileges appeared first on Cyber Security News.
Ещё один рекорд телефонного мошенничества: петербуржец лишился 95 млн рублей
CVE-2022-3234 | vim up to 9.0.0404 heap-based overflow (EUVD-2022-42642 / Nessus ID 211239)
CVE-2022-3235 | vim up to 9.0.0483 use after free (EUVD-2022-42643 / Nessus ID 211239)
CVE-2022-3237 | WP Contact Slider Plugin up to 2.4.7 on WordPress Setting cross site scripting (EUVD-2022-42645)
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-48939 iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
- CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Improving Smart Tiered Cache for Public Cloud Regions
Hackers are Turning AI Gateways as Attack Surfaces to Compromise Enterprise Networks
AI gateways are increasingly being targeted as organizations connect generative AI applications to cloud services such as Amazon Bedrock. These gateways sit between users, business applications, and large language models, making them an attractive entry point into enterprise networks. Darktrace recently investigated a compromised Amazon Web Services EC2 instance named “LiteLLM-Proxy.” The instance appeared to […]
The post Hackers are Turning AI Gateways as Attack Surfaces to Compromise Enterprise Networks appeared first on Cyber Security News.