Aggregator
Critical Axios Vulnerability Allows Remote Code Execution – PoC Released
The cybersecurity community is on high alert after the disclosure of a critical security flaw in Axios, a widely used promise-based HTTP client for Node.js and browsers. Security researcher Jason Saayman recently disclosed an unrestricted vulnerability that allows exfiltration of cloud metadata. This dangerous flaw enables attackers to execute remote code or compromise the entire cloud […]
The post Critical Axios Vulnerability Allows Remote Code Execution – PoC Released appeared first on Cyber Security News.
Hackers Abuse MSBuild LOLBin to Evade Detection and Launch Fileless Windows Attacks
Cybercriminals are increasingly turning to tools that already live inside Windows to carry out attacks — and MSBuild.exe has become one of their favorites. This Microsoft-signed build utility, trusted by the operating system itself, is now being weaponized to run malicious code without ever dropping a traditional executable file on the disk. MSBuild.exe was originally […]
The post Hackers Abuse MSBuild LOLBin to Evade Detection and Launch Fileless Windows Attacks appeared first on Cyber Security News.
CVE-2026-36872 | SourceCodester Basic Library System 1.0 /load_book.php sql injection (EUVD-2026-21910)
CVE-2026-36873 | SourceCodester Basic Library System 1.0 /load_admin.php sql injection (EUVD-2026-21912)
CVE-2026-6204 | LibreNMS up to 26.2.x Netcommand Feature os command injection (GHSA-pr3g-phhr-h8fh / EUVD-2026-21908)
CVE-2026-2728 | LibreNMS up to 26.2.x showconfig Page cross site scripting (EUVD-2026-21907)
CVE-2026-36874 | SourceCodester Basic Library System 1.0 /load_student.php sql injection (EUVD-2026-21914)
CVE-2026-36919 | SourceCodester Basic Library System 1.0 exam-update.php sql injection (EUVD-2026-21916)
CVE-2026-36920 | SourceCodester Online Reviewer System 1.0 questions-view.php sql injection (EUVD-2026-21920)
CVE-2026-36923 | SourceCodester Cab Management System 1.0 view_booking.php sql injection (EUVD-2026-21924)
CVE-2026-34476 | Apache SkyWalking MCP up to 0.1.0 Header SW-URL server-side request forgery (EUVD-2026-21918)
CVE-2026-36922 | SourceCodester Cab Management System 1.0 view_category.php sql injection (EUVD-2026-21922)
Apache Tomcat Vulnerabilities Enables Bypass of EncryptInterceptor
The Apache Software Foundation has released emergency security updates to address multiple vulnerabilities in Apache Tomcat. The latest advisories highlight a critical patching error that inadvertently exposed servers to an interception bypass, as well as issues affecting certificate authentication and padding-oracle attacks. Administrators must update their deployments immediately to secure their environments against potential exploitation. […]
The post Apache Tomcat Vulnerabilities Enables Bypass of EncryptInterceptor appeared first on Cyber Security News.