Aggregator
GISEC GLOBAL 2026 – The Middle East & Africa’s Largest Cybersecurity Event
2 weeks 2 days hence
Healthcare Cyber Research Programs Escape Budget Knife
8 minutes 43 seconds ago
UPGRADE and DigiSeals Programs at ARPA-H Remain Fully Funded
A U.S. federal grant effort to develop autonomous medical device patching platforms for hospitals evaded the budget-cutting knife of the Trump administration. Program boosters hope to automate cyber defenses so that hospitals of any size can more quickly patch vulnerabilities.
A U.S. federal grant effort to develop autonomous medical device patching platforms for hospitals evaded the budget-cutting knife of the Trump administration. Program boosters hope to automate cyber defenses so that hospitals of any size can more quickly patch vulnerabilities.
Finance Chiefs Warn New AI Models May Rattle Global Banking
8 minutes 43 seconds ago
Officials Warned New Models Could Accelerate Cyber Risks Faster Than Rules
Global finance officials meeting in Washington warned that advanced artificial intelligence models could expose structural weaknesses across banking and payment systems, speeding vulnerability discovery and cyber exploitation faster than regulators can build guardrails.
Global finance officials meeting in Washington warned that advanced artificial intelligence models could expose structural weaknesses across banking and payment systems, speeding vulnerability discovery and cyber exploitation faster than regulators can build guardrails.
Scattered Spider Hacker Pleads Guilty in US Federal Court
8 minutes 43 seconds ago
Tyler Buchanan Pleads Guilty to Conspiracy to Commit Wire Fraud and Identity Theft
A senior figure in the Scattered Spider cybercrime group pleaded guilty to one count of conspiracy to commit wire fraud and one count of aggravated identity theft on Friday in US federal district court. The plea marks the conclusion of a digital crime spree by Tyler Robert Buchanan.
A senior figure in the Scattered Spider cybercrime group pleaded guilty to one count of conspiracy to commit wire fraud and one count of aggravated identity theft on Friday in US federal district court. The plea marks the conclusion of a digital crime spree by Tyler Robert Buchanan.
CVE-2026-2505 | elzahlan Categories Images Plugin up to 3.3.1 on WordPress Shortcode z_taxonomy_image cross site scripting
1 hour 35 minutes ago
A vulnerability has been found in elzahlan Categories Images Plugin up to 3.3.1 on WordPress and classified as problematic. Affected by this vulnerability is the function z_taxonomy_image of the component Shortcode Handler. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-2505. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-0894 | vanderwijk Content Blocks Plugin up to 3.3.9 on WordPress Custom Post Widget content_block cross site scripting
1 hour 36 minutes ago
A vulnerability, which was classified as problematic, was found in vanderwijk Content Blocks Plugin up to 3.3.9 on WordPress. Affected is the function content_block of the component Custom Post Widget. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-0894. The attack can be launched remotely. No exploit exists.
vuldb.com
Nexcorium Mirai variant exploits TBK DVR flaw to launch DDoS attacks
2 hours 5 minutes ago
A Mirai variant called Nexcorium exploits a flaw in TBK DVRs to infect devices and use them in DDoS attacks, along with outdated TP-Link routers. Fortinet researchers found that threat actors are exploiting vulnerabilities in TBK DVRs and end-of-life TP-Link routers to spread a Mirai variant called Nexcorium. “IoT devices are increasingly prime targets for […]
Pierluigi Paganini
Платный ИИ и синяя тоска. Microsoft выпустила обновление Visual Studio, которое опять разозлило программистов
2 hours 10 minutes ago
В Visual Studio 18.5 появился «автопилот» для отладки, но за экономию времени придется платить.
ИИ: «Я нарисую шедевр и добавлю отборный мат». Новый бенчмарк ToxicBench отучит модели портить мемы оскорблениями
3 hours 9 minutes ago
Детекторы годами игнорировали грубость генеративных алгоритмов. Пора это исправить.
CVE-2026-40880 | Zebra Cached Mempool Verification comparison using wrong factors
3 hours 40 minutes ago
A vulnerability, which was classified as problematic, has been found in Zebra. This impacts an unknown function of the component Cached Mempool Verification. Performing a manipulation results in comparison using wrong factors.
This vulnerability is identified as CVE-2026-40880. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-40881 | Zebra addr Message resource consumption
3 hours 41 minutes ago
A vulnerability classified as problematic was found in Zebra. This affects an unknown function of the component addr Message Handler. Such manipulation leads to resource consumption.
This vulnerability is referenced as CVE-2026-40881. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
JavaScript больше не нужен? Появился способ собирать быстрые сайты на привычном Dart
4 hours 10 minutes ago
Некогда сложные правила заменили на интуитивно понятный конструктор.
WRECKCTF 2026
4 hours 10 minutes ago
Name: WRECKCTF 2026 (an WRECKCTF event.)
Date: April 17, 2026, 4 a.m. — 18 April 2026, 04:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: http://wreckctf.com/
Rating weight: 0
Event organizers: Mad H@tters
Date: April 17, 2026, 4 a.m. — 18 April 2026, 04:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: http://wreckctf.com/
Rating weight: 0
Event organizers: Mad H@tters
ZeroSecure CTF 2026
4 hours 10 minutes ago
Name: ZeroSecure CTF 2026 (an ZeroSecure CTF event.)
Date: April 17, 2026, 5:30 a.m. — 18 April 2026, 05:30 UTC [add to calendar]
Format: Jeopardy
On-site
Offical URL: https://www.zerosecurectf.online/
Rating weight: 0.00
Event organizers: CLIENT - ZERO
Date: April 17, 2026, 5:30 a.m. — 18 April 2026, 05:30 UTC [add to calendar]
Format: Jeopardy
On-site
Offical URL: https://www.zerosecurectf.online/
Rating weight: 0.00
Event organizers: CLIENT - ZERO
47CON CTF 2026
4 hours 10 minutes ago
Name: 47CON CTF 2026 (an 47CON CTF event.)
Date: April 17, 2026, 8 a.m. — 18 April 2026, 08:00 UTC [add to calendar]
Format: Jeopardy
On-line
Location: Valladolid (Spain)
Offical URL: https://sugusuva.es/ctfd/
Rating weight: 0
Event organizers: SUGUS
Date: April 17, 2026, 8 a.m. — 18 April 2026, 08:00 UTC [add to calendar]
Format: Jeopardy
On-line
Location: Valladolid (Spain)
Offical URL: https://sugusuva.es/ctfd/
Rating weight: 0
Event organizers: SUGUS
CVE-2026-41254 | Little CMS up to 2.18 CubeSize cmslut.c incorrect behavior order (EUVD-2026-23668)
4 hours 31 minutes ago
A vulnerability classified as problematic has been found in Little CMS up to 2.18. The impacted element is an unknown function of the file cmslut.c of the component CubeSize. This manipulation causes incorrect behavior order.
The identification of this vulnerability is CVE-2026-41254. The attack can only be executed locally. There is no exploit available.
vuldb.com
CVE-2026-40349 | leepeuker movary up to 0.71.0 Endpoint /settings/users/ authorization (GHSA-mcfq-8rx7-w25v)
4 hours 43 minutes ago
A vulnerability described as critical has been identified in leepeuker movary up to 0.71.0. The affected element is an unknown function of the file /settings/users/ of the component Endpoint. The manipulation results in missing authorization.
This vulnerability was named CVE-2026-40349. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-40487 | gitroomhq postiz-app up to 2.21.5 cross site scripting (GHSA-44wg-r34q-hvfx)
4 hours 44 minutes ago
A vulnerability marked as problematic has been reported in gitroomhq postiz-app up to 2.21.5. Impacted is an unknown function. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-40487. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-40346 | nocobase up to 2.0.36 server-side request forgery (GHSA-mvvv-v22x-xqwp)
4 hours 44 minutes ago
A vulnerability labeled as critical has been found in nocobase up to 2.0.36. This issue affects some unknown processing. Executing a manipulation can lead to server-side request forgery.
This vulnerability is handled as CVE-2026-40346. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com