Aggregator
CVE-2026-46243 | Linux Kernel up to 7.1-rc4 smb upcall_target privilege escalation
CVE-2026-45701 | Sulu up to 2.6.22/3.0.5 Password Reset Tokenand API risky encryption (GHSA-7fv8-6pp7-6h85)
CVE-2026-10581 | DedeCMS 5.7.88 download.php?open=1 base64_decode Link server-side request forgery
USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order
A judge said Democrats and civil groups filed the lawsuit too early to demonstrate harm, but that could change after newly proposed postal regulations.
The post USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order appeared first on CyberScoop.
Submit #829404: DedeCMS DedeCMS Content Management System v5.7.88 Server-Side Request Forgery (SSRF) / Open Redirect [Accepted]
Клетки мозга взялись за Doom. Ученые показали, как живые нейроны учатся стрелять по демонам
What One Predator Case Can Reveal About an Online Platform’s Safety Gaps
Miasma Supply Chain Attack Compromises Red Hat npm Packages with Credential-Stealing Worm
Oracle security advisory – July 2024 quarterly rollup (AV24-401) - Update 1
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
Вторая попытка Дженсена Хуанга. Nvidia выпускает процессоры для Windows, чтобы потеснить Intel и AMD
OpenAI requires stronger authentication for users of its most powerful AI models
Yubico announced its significant role in securing the AI frontier as OpenAI mandates the use of passkeys for individuals that are part of their Trusted Access for Cyber (TAC) program. As a leading global AI research and development company, OpenAI is setting a precedent for empowering its users to take control of their own security posture with more secure authentication options. Starting June 1, 2026, individuals in TAC with access to OpenAI’s most powerful and … More →
The post OpenAI requires stronger authentication for users of its most powerful AI models appeared first on Help Net Security.
IBM WebSphere Server Vulnerable to Remote Code Execution Attack Via Crafted Request
IBM has disclosed a critical security vulnerability in its WebSphere Application Server ecosystem that could allow attackers to execute arbitrary code through specially crafted HTTP requests. The flaw, tracked as CVE-2026-8633, affects environments that use the optional Web Server Plug-ins component, significantly elevating the risk for enterprise deployments that rely on WebSphere infrastructure. The vulnerability […]
The post IBM WebSphere Server Vulnerable to Remote Code Execution Attack Via Crafted Request appeared first on Cyber Security News.
WordPress malware campaign hides payloads in Steam profiles
Critical Magento Cache Plugin Vulnerability Enables Remote Code Execution Attacks
A critical security vulnerability has been discovered in a widely used Magento caching plugin that allows attackers to remotely execute malicious code with no login, configuration changes, or admin access required. Security researchers at Sansec uncovered an unauthenticated PHP object injection flaw in Mirasvit Cache Warmer, a full-page cache extension used by thousands of Magento and […]
The post Critical Magento Cache Plugin Vulnerability Enables Remote Code Execution Attacks appeared first on Cyber Security News.
Critical MCP Toolbox Vulnerability Impacts Enterprise Database onnectors
A newly disclosed vulnerability, tracked as CVE-2026-9739, is raising security concerns across enterprise environments using MCP Toolbox, particularly those that rely on Server-Sent Events (SSE) for database connectivity. The flaw, currently awaiting NVD enrichment, allows attackers to exploit a DNS rebinding weakness that could lead to unauthorized access to backend systems. Security researchers identified that […]
The post Critical MCP Toolbox Vulnerability Impacts Enterprise Database onnectors appeared first on Cyber Security News.