Aggregator
CVE-2026-44054 | Netatalk up to 4.4.2 afpd Session Token random values (Nessus ID 315215)
CVE-2026-44055 | Netatalk up to 4.4.2 os command injection (Nessus ID 315215)
The 1 A.M. Cloud Migration Meltdown
CVE-2026-22554 | MediaArea MediaInfoLib 26.01 Channel heap-based overflow (TALOS-2026-2374)
CVE-2026-8485 | Progress MOVEit Automation up to 2025.0.10/2025.1.6 memory allocation
Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks
CVE-2026-47068 | phenixdigital phoenix_storybook up to 1.0.x Control Message component_iframe_live.ex Query authorization
CVE-2026-21836 | HCL DominoIQ 14.5.1 RAG Feature authorization (KB0130932)
CVE-2026-8469 | phenixdigital phoenix_storybook up to 1.0.x attr allocation of resources
13 моделей и до 96% успеха: голосовой ИИ научились взламывать через звук, который человек почти не слышит
CVE-2026-8467 | phenixdigital phoenix_storybook up to 1.0.x Template String code injection
CVE-2026-24425 | twigphp Twig up to 2.16.x/3.25.x protection mechanism
Webworm APT targets European government organizations with new backdoors
ESET has released an analysis of the 2025 activity of Webworm, a China-aligned APT group tracked as Space Pirates and UAT-8302. Active since at least 2022, the group initially focused on targets in Asia, but has recently expanded its operations into Europe. ESET observed Webworm targeting government organizations in Belgium, Italy, Poland, Serbia, and Spain during 2025. The group also expanded its activity into South Africa, where researchers identified activity involving a local university. Discord … More →
The post Webworm APT targets European government organizations with new backdoors appeared first on Help Net Security.
CVE-2026-32244 | Discourse up to 2026.1.3/2026.3.0/2026.4.0 cache containing sensitive information (GHSA-hjmg-2mww-vfvx / CNNVD-202605-4266)
CVE-2026-32312 | glpi-project glpi up to 11.0.6 authorization (GHSA-cg63-qchq-q626 / CNNVD-202605-4267)
CVE-2026-45585 | Microsoft Windows 11 24H2/11 25H2/11 26H1/Server 2025 YellowKey command injection (WID-SEC-2026-1609 / CNNVD-202605-4268)
On AI Security
Grafana GitHub Breach Linked to TanStack npm Supply Chain Ransomware
Grafana Labs has disclosed a targeted ransomware-linked breach of its GitHub environment, traced to a broader TanStack npm supply chain compromise associated with the “Mini Shai-Hulud” campaign. The incident, detected on May 11, 2026, involved unauthorized access to internal repositories and culminated in a ransom demand issued on May 16 under threat of data disclosure. […]
The post Grafana GitHub Breach Linked to TanStack npm Supply Chain Ransomware appeared first on Cyber Security News.
Akira
You must login to view this content