Aggregator
Please support the site operations by clicking ads.
CVE-2026-71641 | ZJU-FAST-Lab EGO-Planner-v2 EGOReplanFSM denial of service
CVE-2026-71644 | Robotics-STAR-Lab RACER FSM missing default case in switch statement
CVE-2026-57842 | NetBSD up to 8.3/9.4/10.1 Compatibility Layer msg_recv_copyin use after free
CVE-2026-57843 | NetBSD up to 9.4/10.1 Device Driver sys/dev/mm.c mm_open information disclosure
CVE-2026-71416 | headroomlabs-ai Headroom up to 0.34.x WebSocket Server Origin improper authentication
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
CVE-2026-89212 | Perforce Akana up to 2024.1.5/2025.1.1/2026.1 JSON xml external entity reference
CVE-2026-11765 | Pardus Pen up to 4.2.0 argument injection
CVE-2026-89298 | Red Hat Keycloak/Single Sign-On Dynamic Client Registration Service information disclosure
CVE-2026-80462 | Progress Chef Automate up to 4.13.515/4.13.519 API Gateway privileges management
Anthropic caught Russia-linked spies using Claude in hacking operations
CVE-2026-84390 | Fortinet FortiMonitorOnSight up to 7.2.2/7.2.7 access control
Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign
A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to distribute malware at scale. The cluster, tracked as CL-CRI-1171, is linked to more than 10,000 distinct samples of a custom loader called OfferLoader, indicating a distribution pipeline far larger than the individual intrusions initially observed. Rather than relying on a […]
The post Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data
Two security vulnerabilities in VLC media player versions 3.0.0 through 3.0.23 could allow attackers to exploit heap memory issues. These vulnerabilities can be triggered by processing a malicious PNG file or connecting to attacker-controlled RealRTSP servers. The more severe vulnerability, tracked as CVE-2026-56711, is a heap out-of-bounds write flaw with a CVSS v4 score of […]
The post VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2026-89256 | WWBN AVideo Bookmark plugin bookmark name cross site scripting
CVE-2026-89258 | Gohugoio Hugo up to 0.164.x Symlink os.ReadFile path traversal
Ukrainian hacker gets four years in US prison over Conti ransomware attacks
CVE-2026-89259 | gohugoio Hugo up to 0.164.x Build Process hugo.toml permission
CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities in MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, warning that these flaws are actively being exploited in the wild. On September 10, CISA listed CVE-2026-67277 and CVE-2026-86060, giving affected organizations until September 13 to implement vendor-recommended mitigations. MikroTik RouterOS Flaws CVE-2026-67277 […]
The post CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.