Aggregator
CVE-2026-8073 | themeum Kirki Plugin up to 6.0.6 on WordPress downloadZIP path traversal (EUVD-2026-30976)
CVE-2026-8096 | themeum Kirki Plugin up to 6.0.6 on WordPress authorization (EUVD-2026-30971)
CVE-2026-41470 | Live555 up to 2026.04.21 RTSP Session Command authorization (EUVD-2026-30973)
Max-severity flaw in ChromaDB for AI apps allows server hijacking
What Will Make AI BOMs Real?
UAC-0184 Malware Chain Uses bitsadmin and HTA Files for Gated Payload Delivery
A newly documented attack chain linked to the threat group UAC-0184 has been observed using Windows’ built-in bitsadmin tool and HTA files to sneak malicious payloads onto targeted systems. The campaign is primarily aimed at Ukraine, with clear indicators pointing toward military-related targets, including individuals connected to the Ukrainian Defence Forces. The level of craft […]
The post UAC-0184 Malware Chain Uses bitsadmin and HTA Files for Gated Payload Delivery appeared first on Cyber Security News.
Verizon DBIR: Enterprises Face a Dangerous Vulnerability Glut
macOS Malware Installs Fake Google Software Update LaunchAgent for Persistence
macOS users are facing a new and sophisticated threat as a variant of the SHub infostealer malware, dubbed “Reaper,” has been observed deploying a fake Google Software Update LaunchAgent to maintain persistent access on infected machines. The malware stays hidden by borrowing the identity of brands that users already trust, making it exceptionally difficult to […]
The post macOS Malware Installs Fake Google Software Update LaunchAgent for Persistence appeared first on Cyber Security News.
Cybercrime service disrupted for abusing Microsoft platform to sign malware
CVE-2026-8605 | ScadaBR 1.2.0 hard-coded credentials (icsa-26-139-03)
CVE-2026-8706 | Mozilla Firefox up to 150.x on iOS Hosted Reader Mode information disclosure
CVE-2025-57798 | laurent22 joplin up to 3.7.0 Local Web Service API Title allocation of resources
CVE-2026-34233 | Ctrlpanel-gg panel up to 1.1.x DataTable Endpoint /admin/ datatable access control (EUVD-2026-30985)
CVE-2026-34216 | Ctrlpanel-gg panel up to 1.1.x Admin Settings Update Endpoint update settings_class externally-controlled input to select classes or code (EUVD-2026-30983)
Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches
Verizon’s annual Data Breach Investigations Report uncovered a surge of exploited vulnerabilities, and a growing lack of critical defect remediation industrywide.
The post Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches appeared first on CyberScoop.