Aggregator
CVE-2026-30040 | FastStone Image Viewer up to 8.3.0.0 JP2 Decoder FSViewer.exe heap-based overflow
Algerian man charged with running two cybercrime marketplaces
Abdellah Belmili allegedly ran two black-market websites selling stolen financial credentials and custom-built phishing kits targeting major American banks, federal prosecutors say.
The post Algerian man charged with running two cybercrime marketplaces appeared first on CyberScoop.
CVE-2026-4983 | Eclipse Open VSX up to 0.34.0 SVG File cross site scripting
CVE-2026-12969 | dnsmasq NXDOMAIN src/rfc1035.c find_soa out-of-bounds
CVE-2026-10857 | AKIN e-Commerce prior 1.25.01.06 cross site scripting
CVE-2026-56301 | Nuxt up to 3.21.6/4.4.6 on Linux default permission (GHSA-534h-c3cw-v3h9)
CVE-2026-10609 | Red Hat OpenShift Logging Subsystem authorization
CVE-2026-11772 | DRIMO CMS up to 1.0 info.php searching q cross site scripting (EUVD-2026-38450)
藏在屏保与小游戏背后:你的电视可能在帮别人转发网络流量
Армия хочет научиться воевать с помощью дешёвых чипов из музыкальных открыток. И нет, это не шутка
GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns
LastPass Customer Data Exposed in Klue Supply Chain Attack
LastPass has disclosed a supply chain security incident involving its third-party vendor, Klue, that resulted in unauthorized access to customer data within its Salesforce environment. The company confirmed that the breach did not affect its core infrastructure or password vaults. However, it highlights ongoing risks associated with SaaS integrations and OAuth token exposure. The incident […]
The post LastPass Customer Data Exposed in Klue Supply Chain Attack appeared first on Cyber Security News.