Aggregator
CVE-2026-47077 | benoitc hackney up to 4.0.0 Housekeeping Message resource consumption (EUVD-2026-31688)
CVE-2026-47075 | benoitc hackney up to 4.0.0 URL Query crlf injection (EUVD-2026-31687)
CVE-2026-47070 | benoitc hackney up to 4.0.0 src/hackney_h3.erl redirect (EUVD-2026-31692)
CVE-2026-47076 | benoitc hackney up to 4.0.0 interpretation conflict (GHSA-pj7v-xfvx-wmjq / EUVD-2026-31689)
CVE-2026-9474 | yashpokharna2555 StudentManagementSystem up to cb2f558ddf8d19396de0f92abf2d224d46a0a203 /studentdel.php confirm_logged_in ID sql injection (EUVD-2026-31707)
CVE-2026-9475 | Totolink A8000RU 7.1cu.643_b20200521 Web Management Interface /cgi-bin/cstecgi.cgi setIpQosRules Comment os command injection (EUVD-2026-31708)
CVE-2026-9476 | Totolink A8000RU 7.1cu.643_b20200521 Web Management Interface /cgi-bin/cstecgi.cgi setPasswordCfg admpass os command injection (EUVD-2026-31709)
CVE-2026-9477 | Totolink A8000RU 7.1cu.643_b20200521 Web Management Interface /cgi-bin/cstecgi.cgi setAccessDeviceCfg mac os command injection (EUVD-2026-31710)
CVE-2026-27768 | Genetec Security Center prior 5.12.2.17/5.13.3.5 sql injection (EUVD-2026-31705)
CVE-2026-9478 | Totolink A8000RU 7.1cu.643_b20200521 Web Management Interface /cgi-bin/cstecgi.cgi setParentalRules enable os command injection (EUVD-2026-31712)
CVE-2026-9479 | Edimax EW-7438RPn 1.31 /goform/formLogout submit-url stack-based overflow (EUVD-2026-31711)
InvisibleFerret Malware Now Ships as .pyd and .so Files to Evade Script Detection
A North Korea-linked hacker group has quietly upgraded one of its most dangerous tools, making it harder for security software to detect. InvisibleFerret, an information-stealing malware tied to the threat actor known as Void Dokkaebi (also tracked as Famous Chollima), has been repackaged into a format that slips past many traditional detection methods. Instead of […]
The post InvisibleFerret Malware Now Ships as .pyd and .so Files to Evade Script Detection appeared first on Cyber Security News.
CVE-2026-9534 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setWiFiWpsConfig PIN os command injection
CVE-2026-9533 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi recvUpgradeNewFw fwUrl/magicid os command injection
CVE-2026-9532 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setUploadUserData FileName os command injection
CVE-2026-9531 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setUpgradeUboot FileName os command injection
CMD
You must login to view this content
Cloud Atlas APT Group Modifies termsrv.dll to Enable Multiple RDP Sessions on Victim Hosts
A well-known advanced persistent threat group called Cloud Atlas has been caught using a dangerous technique to hijack Windows systems without alerting anyone on the network. The group modifies a core Windows file called termsrv.dll to unlock multiple simultaneous Remote Desktop Protocol (RDP) sessions on a victim’s computer. This lets attackers work in the background […]
The post Cloud Atlas APT Group Modifies termsrv.dll to Enable Multiple RDP Sessions on Victim Hosts appeared first on Cyber Security News.