Aggregator
CVE-2026-15161 | SaturdayDrive Ninja Forms Plugin up to 3.3.6 on WordPress AJAX handler save_filter cross site scripting (EUVD-2026-45136)
Submit #856721: Node.js json-schema-library 11.5.1 Prototype Pollution [Accepted]
CVE-2026-15759 | themeatelier ChatHelp Plugin up to 3.5.1 on WordPress Shortcode number/group cross site scripting
CVE-2026-15457 | Kirki Plugin up to 6.0.13 on WordPress Customizer Family path traversal
CVE-2026-13765 | thimpress LearnPress Plugin up to 4.4.1 on WordPress Quiz Answer check_answer information disclosure (EUVD-2026-45137)
CVE-2026-21770 | HCL Traveler for Microsoft Outlook up to 3.0.15 DLL uncontrolled search path (EUVD-2026-45141)
CVE-2026-15349 | wedevs ERP Complete HR Accounting CRM Suite Plugin up to 1.17.6 on WordPress Company Location authorization
CVE-2026-13352 | ProfilePress Plugin up to 4.16.18 on WordPress File Upload allowed_mime_types unrestricted upload
CVE-2026-14503 | ploudapp pCloud WP Backup Plugin up to 2.0.3 on WordPress wp2pcl_ajax_process_request_inner information disclosure
Five-Layer Fileless Malware Uses JScript and PowerShell to Evade AMSI and Load .NET Payload
An active phishing campaign using a five-layer, fileless malware loader to evade Microsoft’s Antimalware Scan Interface (AMSI), static detection controls, and disk-based forensic analysis. The campaign delivers a Windows Script Host JScript payload inside a TAR archive disguised as a purchase order, ultimately loading a .NET assembly directly into memory. The activity was first observed […]
The post Five-Layer Fileless Malware Uses JScript and PowerShell to Evade AMSI and Load .NET Payload appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
ДНК возрастом 50 тысяч лет нашли там, где жара должна была её уничтожить
The five step plan that cuts security budget waste
In this Help Net Security video, Viktor Bulanek, CTO of Penetrify, explains where security budget waste comes from. Budgets get built around vendor categories, compliance checkboxes, and last year’s headlines. Attackers work along attack paths, and that mismatch is where the money goes. He walks through the two big leaks, overlapping tools that flag the same issue three times, and shelfware that covers a third of the estate at 100% of the invoice. The license … More →
The post The five step plan that cuts security budget waste appeared first on Help Net Security.
AnyDesk Zero-Day Flaw Allows Local Attackers to Trigger System-Wide Denial-of-Service
A newly disclosed zero-day vulnerability in AnyDesk has the potential to allow a local attacker to trigger a denial-of-service condition by exploiting the remote-access software’s “Send Support Information” feature. The advisory, tracked as ZDI-26-401 and ZDI-CAN-26645, was published by Trend Micro’s Zero Day Initiative (ZDI) on July 8, 2026. The flaw has been assigned CVE-2026-15682 […]
The post AnyDesk Zero-Day Flaw Allows Local Attackers to Trigger System-Wide Denial-of-Service appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.