Aggregator
CVE-2026-66390 | Apache Wicket up to 9.23.0/10.9.0 cross site scripting
CVE-2026-66731 | boazsegev facil.io up to 0.7.6 HTTP1.1 Chunked Transfer Encoding Parser http1_parser.h denial of service
CVE-2026-66730 | boazsegev facil.io up to 0.7.6 Multipart Body Parser http_mime_parse denial of service
Google’s solution to hacker name confusion? Yet another naming system
APT-number conventions are out, cryptonyms are in, and security teams now have one more naming system to keep straight.
The post Google’s solution to hacker name confusion? Yet another naming system appeared first on CyberScoop.
CVE-2026-66729 | boazsegev facil.io up to 0.7.6 Multipart MIME Body Parser http_mime_parser.h integer underflow
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
CVE-2026-17192 | Arista VeloCloud Orchestrator On-Prem prior 5.2.3.14/6.1.3.4/6.4.2.4 privileges management
CVE-2026-17191 | Arista VeloCloud Orchestrator On-Prem prior 5.2.3.14/6.1.3.4/6.4.2.4 API improper authorization
CVE-2026-66391 | Apache Wicket up to 9.23.0/10.9.0 random values
CVE-2026-24252 | NVIDIA NeMo Framework os command injection
Microsoft Defender for Endpoint Update Leaves Few Linux Servers Unprotected After Reboot
A recent Microsoft Defender for Endpoint update briefly disabled antivirus protection on Linux servers following an upgrade and reboot, exposing affected machines to threats before Microsoft rolled out a fix. The issue struck Linux platform builds 101.26042.0000 through 101.26042.0009, where the Defender service could become disabled on devices that were upgraded and then rebooted, effectively […]
The post Microsoft Defender for Endpoint Update Leaves Few Linux Servers Unprotected After Reboot appeared first on Cyber Security News.