Aggregator
CVE-2026-34912 | Revive Adserver up to 6.0.6 zone-include.php access control
CVE-2026-55767 | Guzzle up to 7.12.0 Cookie Domain SetCookie::matchesDomain origin validation (GHSA-cwxw-98qj-8qjx)
CVE-2026-55766 | guzzle psr7 up to 2.12.0 Message::toString crlf injection (GHSA-vm85-hxw5-5432)
CVE-2026-54320 | daytonaio daytona up to 0.183.x improper authentication (GHSA-m6hx-cffh-3f3h)
CVE-2026-52845 | caddyserver caddy up to 2.11.3 HTTP Header improper authentication (GHSA-f59h-q822-g45g)
CVE-2020-9713 | Adobe Acrobat Reader File out-of-bounds (apsb20-48)
CVE-2026-54007 | open-webui Open WebUI up to 0.9.5 Chat Message /api/v1/chats/new submitPrompt origin validation (GHSA-3vv5-8xxp-4f55)
CVE-2026-44959 | Revive Adserver up to 6.0.6 compiledlimitations code injection
CVE-2026-34916 | Revive Adserver up to 6.0.6 code injection
CVE-2026-54314 | n8n-io n8n up to 2.23.x Compression data amplification (GHSA-jqpw-qww5-cj4c)
CVE-2026-55568 | Guzzle up to 7.12.0 PHP cURL Extension missing encryption (GHSA-wpwq-4j6v-78m3)
CVE-2026-54312 | n8n-io n8n up to 2.23.x table prototype pollution (GHSA-x6p3-m6h9-fx7r)
Hackers Use GoogleErrorReport Scheduled Task for Persistence in Dropping Elephant Campaign
A well-known threat actor called Dropping Elephant has returned with a refined and more dangerous campaign, using a China-themed lure document to drop a reworked remote access trojan (RAT) onto victim machines. The attack is designed to stay hidden, avoid detection tools, and give the attacker full control over compromised systems. What makes this campaign […]
The post Hackers Use GoogleErrorReport Scheduled Task for Persistence in Dropping Elephant Campaign appeared first on Cyber Security News.
Tata Electronics confirms cyberattack as hackers leak data
Qilin
You must login to view this content
Scope of Salesforce Attacks Expands as Icarus Leaks Data
In-Browser Data Inspection Lets Analysts Track Phishing Attack Flow Inside Browser Sessions
Phishing attacks have grown far more complex in recent years. Attackers no longer rely on simple static pages to steal credentials. Instead, they build layered redirect chains, execute dynamic scripts, and load content in stages, making it much harder for security teams to see what a victim experienced when clicking a suspicious link. This shift […]
The post In-Browser Data Inspection Lets Analysts Track Phishing Attack Flow Inside Browser Sessions appeared first on Cyber Security News.