A vulnerability, which was classified as critical , was found in Pj64-Emu Project64 2.3.2 . This issue affects some unknown processing of the component Directories Interface . Executing a manipulation…
cyberintel.kalymoon.com · 42542 articles · updated every 4 hours · grows forever
A vulnerability, which was classified as critical , was found in Pj64-Emu Project64 2.3.2 . This issue affects some unknown processing of the component Directories Interface . Executing a manipulation…
A vulnerability has been found in Apache Storm Prometheus Reporter up to 2.8.6 and classified as critical . Impacted is an unknown function. The manipulation leads to improper certificate validation. …
A vulnerability was found in Apache Storm Client up to 2.8.6 and classified as critical . The affected element is an unknown function of the component TLS Client Authentication Failure Handler . The m…
A vulnerability was found in code-projects Invoice System in Laravel 1.0 . It has been classified as critical . The impacted element is an unknown function of the file /company . This manipulation of …
A vulnerability was found in code-projects Invoice System in Laravel 1.0 . It has been declared as problematic . This affects an unknown function. Such manipulation leads to cross-site request forgery…
A vulnerability was found in code-projects Invoice System in Laravel 1.0 . It has been rated as critical . This impacts an unknown function of the file /item of the component API Endpoint . Performing…
A vulnerability categorized as problematic has been discovered in code-projects Invoice System in Laravel 1.0 . Affected is an unknown function of the file /item . Executing a manipulation of the argu…
Also: Embedded AI in Pharmaceutical Sector, the Story Behind Apple's CEO Change In this week's panel, four ISMG editors examine what’s really behind Apple's CEO transition, how pharmaceutical giants a…
State-sponsored threat actors are actively targeting Cisco Firepower devices by chaining known vulnerabilities to deploy a highly customized backdoor. Cisco Talos recently discovered that the espionag…
Home security giant ADT Inc. has confirmed a data breach after the notorious threat group ShinyHunters claimed to have stolen over 10 million records and issued a ransom ultimatum — “Pay or Leak.” ADT…
A critical scope overreach vulnerability was recently identified in the Microsoft Entra Agent Identity Platform. The newly introduced Agent ID Administrator role allowed accounts to hijack arbitrary s…
OpenAI has announced a new Bio Bug Bounty program for GPT-5.5 as part of its efforts to improve safety controls for advanced AI systems and to address misuse in biology. The initiative invites qualifi…
Anthropic’s “Project Deal” has demonstrated that AI agents can autonomously negotiate and close real-world transactions, but the experiment also surfaced a quiet, troubling asymmetry: not all AI repre…
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding two actively exploited vulnerabilities in SimpleHelp remote support software. Remote access tools are …
PhantomRPC, a newly identified architectural vulnerability in Windows Remote Procedure Call (RPC) that enables local privilege escalation to SYSTEM-level access, potentially affecting every version of…
A critical zero-day vulnerability in the Litecoin network was actively exploited to launch a denial-of-service (DoS) attack, temporarily disrupting operations across major mining pools before develope…
The GlassWorm supply chain attack targeting the Open VSX marketplace has escalated with the discovery of 73 new “sleeper” extensions. Identified in April 2026, this cluster marks a dangerous shift in …
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: SmokedMeat: Open-source tool shows what attackers do inside CI/CD pipelines Boost Security has release…
Dubbed GopherWhisper, the group relies on multiple Go-based backdoors alongside custom loaders and injectors. The post China-Linked APT GopherWhisper Abuses Legitimate Services in Government Attacks a…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities impacting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X series routers to its Known …
Cybersecurity researchers have discovered a new Lua-based malware created years before the notorious Stuxnet worm that aimed to sabotage Iran's nuclear program by destroying uranium enrichment centrif…
A threat group tracked as UNC6692 uses social engineering to deploy a new, custom malware suite named 'Snow' which includes a browser extension, a tunneler, and a backdoor. [...]
Microsoft says it's rolling out a revamped Windows Insider Program experience as part of the broader plans to address performance and reliability concerns affecting Windows 11. [...]
Itron, Inc. has disclosed, via an 8-K filing with the U.S. Securities and Exchange Commission (SEC), a cybersecurity incident in which an unauthorized third party accessed certain internal systems. [.…