Aggregator
Один удар — четыре банка. Тегеран вернулся в эпоху бумажных расчётов
.
CVE-2026-11860 | OpenSolution Quick.CMS up to 6.8 __wakeup/__destruct deserialization
Anthropic says US government forced it to disable cybersecurity AI models
CVE-2026-50100 | Ricoh/Konica Minolta Printer Driver uncontrolled search path
US Cracks Down on Anthropic AI Models Amid Abuse Concerns
SearchJack Campaign Uses 23 Chrome Extensions to Hijack Searches of 758,000 Users
A coordinated campaign of 23 deceptive Chrome browser extensions has been quietly stealing users’ search queries and routing them through hidden revenue systems. The operation, now dubbed SearchJack, has affected roughly 758,000 Chrome users worldwide without any of them realizing their searches were being hijacked. Each extension presents itself as a useful tool, from satellite […]
The post SearchJack Campaign Uses 23 Chrome Extensions to Hijack Searches of 758,000 Users appeared first on Cyber Security News.
CVE-2026-44188 | Red Hat Ansible Automation Platform 2/2.7 session expiration (RHSA-2026:25928 / WID-SEC-2026-1923)
Webinar: How behavioral AI stops phishing and account takeovers
Handala Hacking Group Claims Breach of California Water Service
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-20262 Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
- CVE-2026-54420 LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies, updating BOD 22-01. BOD 26-04 reinforces the importance of the KEV catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV catalog? Submit for potential addition: KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.