A vulnerability was found in projeto-siga siga 11.0.3.18 . It has been rated as problematic . The affected element is an unknown function of the file /sigawf/app/responsavel/novo . Performing a manipu…
cyberintel.kalymoon.com · 42678 articles · updated every 4 hours · grows forever
A vulnerability was found in projeto-siga siga 11.0.3.18 . It has been rated as problematic . The affected element is an unknown function of the file /sigawf/app/responsavel/novo . Performing a manipu…
A vulnerability categorized as critical has been discovered in colinhacks Zod up to 4.3.6 . The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component…
A vulnerability identified as critical has been detected in Linksys MR9600 2.0.6.206937 . This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_central2.sh of the compon…
A vulnerability labeled as problematic has been found in go-kratos kratos up to 2.9.2 . This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux F…
A vulnerability marked as critical has been reported in Envoy up to 1.33.0 . Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the co…
A vulnerability described as problematic has been identified in Authlib up to 1.6.10 . Affected by this vulnerability is the function authlib.integrations.starlette_client.OAuth . Such manipulation le…
A vulnerability classified as problematic has been found in notamitgamer mojic up to 2.1.3 . Affected by this issue is some unknown functionality. Performing a manipulation results in observable timin…
A vulnerability classified as critical was found in budibase up to 3.35.3 . This affects an unknown part of the file /api/global/users/search?x=/api/system/status of the component Query Parameter Hand…
A vulnerability, which was classified as problematic , has been found in pretalx 2.3.1/2.3.2 . This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerabili…
A vulnerability, which was classified as problematic , was found in better-auth oauth-provider up to 1.6.4/1.7.0-beta.1 . This issue affects some unknown processing of the component OAuth Client Creat…
A vulnerability has been found in Espressif arduino-esp32 up to 3.3.7 and classified as critical . Impacted is an unknown function. This manipulation of the argument name_len causes stack-based buffer…
A vulnerability was found in open-telemetry opentelemetry-ebpf-instrumentation up to 0.7.x and classified as critical . The affected element is an unknown function of the component File Creation Handl…
Agencies Urged to Track and Disrupt Coordinated AI Extraction Campaigns The White House is escalating coordination with AI firms after identifying large-scale foreign campaigns using proxy accounts an…
Continuous Integration Has Its Downsides As supply-chain attacks against widely-used, open-source software repositories continue, experts are urging developers to not only rely on code integrity tools…
A North Korea-linked hacking group known as Void Dokkaebi, also tracked as Famous Chollima, is running a campaign that tricks software developers into installing malware through fake job interviews. T…
Cybersecurity researchers have uncovered a purpose-built PowerShell script hosted on Pastebin that is designed to silently steal Telegram session data from both desktop and web-based clients. The scri…
Most internet users are familiar with CAPTCHA tests, simple challenges like selecting traffic lights or typing distorted letters to confirm they are human. But cybercriminals have found a way to weapo…
A recent technical audit by privacy researcher Alexander Hanff has revealed that Anthropic’s Claude Desktop application for macOS silently installs a Native Messaging bridge into the directories of se…
The US Cybersecurity and Infrastructure Security Agency (CISA) does not yet have access to Anthropic’s bug-hunting AI model, Claude Mythos, even though other government agencies do, Axios reported ear…
Another member of the notorious Scattered Spider gang of cyber criminals has pleaded guilty in a US court, and will be sentenced later this year. Tyler Buchanan pleaded guilty in a Florida court to co…
Some 29 people were charged, including a Cambodian senator, and authorities seized more than 500 Web domains tied to fake investment sites.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed federal civilian agency's Cisco Firepower device running Adaptive Security Appliance (ASA) software was co…
A new vulnerability dubbed Pack2TheRoot could be exploited in the PackageKit daemon to allow local Linux users to install or remove system packages and gain root permissions. [...]
Microsoft will roll out passkey support for phishing-resistant passwordless authentication to Microsoft Entra‑protected resources from Windows devices starting late April. [...]