Aggregator
Investigating suspicious AI workflows in Microsoft Entra Agent ID: Agent’s user account
3 weeks 4 days ago
Entra ID agent users can send malicious content to human users via Microsoft Teams. Here’s what to look out for.
Matt Graeber
Dell security advisory (AV26-528)
3 weeks 4 days ago
Canadian Centre for Cyber Security
Infosecurity Europe: Tabletop Exercise to Test How CISOs Respond to Major Supermarket Cyber-Attack
3 weeks 4 days ago
Semperis is set to bring ‘Enter the War Room: A Tabletop Experience’ to Infosecurity Europe to help cybersecurity leaders prepare to face real incidents
CVE-2026-46174 | Linux Kernel up to 7.1-rc3 x86 privilege escalation (EUVD-2026-32801 / Nessus ID 317933)
3 weeks 4 days ago
A vulnerability identified as critical has been detected in Linux Kernel up to 7.1-rc3. Affected by this vulnerability is an unknown functionality of the component x86. The manipulation leads to privilege escalation.
This vulnerability is documented as CVE-2026-46174. The attack requires being on the local network. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-8716 | GitLab Community Edition/Enterprise Edition up to 18.10.6/18.11.3/19.0.0 name resolution (EUVD-2026-32617 / Nessus ID 317942)
3 weeks 4 days ago
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.10.6/18.11.3/19.0.0. It has been rated as problematic. This issue affects some unknown processing. Performing a manipulation results in incorrectly-resolved name.
This vulnerability was named CVE-2026-8716. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-9807 | GitLab Community Edition/Enterprise Edition up to 18.10.6/18.11.3/19.0.0 Access Token authorization (Nessus ID 317940 / WID-SEC-2026-1727)
3 weeks 4 days ago
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.10.6/18.11.3/19.0.0. It has been classified as problematic. This impacts an unknown function of the component Access Token Handler. The manipulation leads to incorrect authorization.
This vulnerability is traded as CVE-2026-9807. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-47104 | libusb up to 1.0.29 descriptor.c parse_iad_array out-of-bounds (ID 1813 / Nessus ID 317946)
3 weeks 4 days ago
A vulnerability was found in libusb up to 1.0.29. It has been rated as problematic. Affected is the function parse_iad_array of the file descriptor.c. Performing a manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2026-47104. The attack requires a local approach. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-2601 | GitLab Enterprise Edition up to 18.10.6/18.11.3/19.0.0 authorization (EUVD-2026-32621 / Nessus ID 317947)
3 weeks 4 days ago
A vulnerability, which was classified as problematic, was found in GitLab Enterprise Edition up to 18.10.6/18.11.3/19.0.0. Affected is an unknown function. Executing a manipulation can lead to missing authorization.
This vulnerability appears as CVE-2026-2601. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-9759 | Wireshark up to 4.4.15/4.6.5 ROHC Protocol Dissector null pointer dereference (EUVD-2026-32629 / Nessus ID 317943)
3 weeks 4 days ago
A vulnerability identified as problematic has been detected in Wireshark up to 4.4.15/4.6.5. The affected element is an unknown function of the component ROHC Protocol Dissector. The manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2026-9759. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-47760 | TinyMCE up to 7.0.x cross site scripting (GHSA-mh5m-5hw4-5c69 / Nessus ID 317945)
3 weeks 4 days ago
A vulnerability described as problematic has been identified in TinyMCE up to 7.0.x. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-47760. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-44465 | zed-industries zed up to 0.227.0 os command injection (GHSA-fj2r-rmw6-h222 / Nessus ID 317948)
3 weeks 4 days ago
A vulnerability was found in zed-industries zed up to 0.227.0 and classified as critical. The affected element is an unknown function. Executing a manipulation can lead to os command injection.
This vulnerability is registered as CVE-2026-44465. The attack needs to be launched locally. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-6713 | GitLab Community Edition/Enterprise Edition up to 18.10.6/18.11.3/19.0.0 Private Project authorization (EUVD-2026-32618 / Nessus ID 317949)
3 weeks 4 days ago
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 18.10.6/18.11.3/19.0.0. It has been declared as problematic. This vulnerability affects unknown code of the component Private Project Handler. Such manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2026-6713. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
Zero-Click pretalx XSS Flaw Lets Hackers Hijack Conference Organizer Accounts
3 weeks 4 days ago
pretalx XSS flaw lets attackers hijack conference organizer accounts, steal sessions, auto-accept talks, and demote admins. Patched in v2026.1.0.
Deeba Ahmed
IBM security advisory (AV26-527)
3 weeks 4 days ago
Canadian Centre for Cyber Security
Искали советские бомбы, а нашли далекие галактики. Как американские военные спутники случайно открыли гамма-всплески
3 weeks 4 days ago
Военные спутники США случайно открыли самые мощные взрывы во Вселенной.
瑞典政府呼吁家长在陪伴孩子时放下手机
3 weeks 4 days ago
瑞典公共卫生局周一说,研究表明,父母使用电子屏幕会对他们与孩子的互动产生负面影响。此外,经常使用电子屏幕的父母,他们的子女也更容易养成类似习惯。当局在发表的声明中建议:“和孩子在一起时,请把手机收起来
Iranian Hackers Abuse AppDomainManager Hijacking to Evade EDR Detection
3 weeks 4 days ago
Iranian hackers have taken their cyberespionage playbook to a new level, deploying a sophisticated .NET hijacking technique to slip past endpoint defenses and target organizations across the United States, Israel, and the United Arab Emirates. The campaign intensified following a regional conflict that began on February 28, 2026, attributed to an Iran-linked advanced persistent threat […]
The post Iranian Hackers Abuse AppDomainManager Hijacking to Evade EDR Detection appeared first on Cyber Security News.
Tushar Subhra Dutta
Microsoft security advisory – May 2026 monthly rollup (AV26-456) – Update 2
3 weeks 4 days ago
Canadian Centre for Cyber Security
Critical Windows Netlogon RCE flaw now exploited in attacks
3 weeks 4 days ago
The Centre for Cybersecurity Belgium (CCB), the country's national authority for cybersecur