CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  42678 articles  ·  updated every 4 hours · grows forever

42678Total
30426Full Text
Aug 08, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6990 | projeto-siga 11.0.3.18 novo Nome/Descrição cross site scripting (Issue 2491)

A vulnerability was found in projeto-siga siga 11.0.3.18 . It has been rated as problematic . The affected element is an unknown function of the file /sigawf/app/responsavel/novo . Performing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6991 | colinhacks Zod up to 4.3.6 CUID Data Type regexes.ts sql injection

A vulnerability categorized as critical has been discovered in colinhacks Zod up to 4.3.6 . The impacted element is an unknown function of the file packages/zod/src/v4/core/regexes.ts of the component…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6992 | Linksys MR9600 2.0.6.206937 JNAP Action run_central2.sh BTRequestGetSmartConnectStatus pin os command injection

A vulnerability identified as critical has been detected in Linksys MR9600 2.0.6.206937 . This affects the function BTRequestGetSmartConnectStatus of the file /etc/init.d/run_central2.sh of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6993 | go-kratos up to 2.9.2 http.DefaultServeMux Fallback transport/http/server.go NewServer confused deputy (Issue 3810)

A vulnerability labeled as problematic has been found in go-kratos kratos up to 2.9.2 . This impacts the function NewServer of the file transport/http/server.go of the component http.DefaultServeMux F…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-6994 | Envoy up to 1.33.0 Query Parameter header_mutation.cc params.add injection (ID 43502)

A vulnerability marked as critical has been reported in Envoy up to 1.33.0 . Affected is the function params.add of the file source/extensions/filters/http/header_mutation/header_mutation.cc of the co…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41425 | Authlib up to 1.6.10 authlib.integrations.starlette_client.OAuth cross-site request forgery

A vulnerability described as problematic has been identified in Authlib up to 1.6.10 . Affected by this vulnerability is the function authlib.integrations.starlette_client.OAuth . Such manipulation le…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41244 | notamitgamer mojic up to 2.1.3 timing discrepancy

A vulnerability classified as problematic has been found in notamitgamer mojic up to 2.1.3 . Affected by this issue is some unknown functionality. Performing a manipulation results in observable timin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41428 | budibase up to 3.35.3 Query Parameter status improper authentication

A vulnerability classified as critical was found in budibase up to 3.35.3 . This affects an unknown part of the file /api/global/users/search?x=/api/system/status of the component Query Parameter Hand…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41426 | pretalx 2.3.1/2.3.2 cross site scripting

A vulnerability, which was classified as problematic , has been found in pretalx 2.3.1/2.3.2 . This vulnerability affects unknown code. The manipulation leads to cross site scripting. This vulnerabili…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41427 | better-auth oauth-provider up to 1.6.4/1.7.0-beta.1 OAuth Client Creation Endpoint authorization

A vulnerability, which was classified as problematic , was found in better-auth oauth-provider up to 1.6.4/1.7.0-beta.1 . This issue affects some unknown processing of the component OAuth Client Creat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41429 | Espressif arduino-esp32 up to 3.3.7 name_len stack-based overflow

A vulnerability has been found in Espressif arduino-esp32 up to 3.3.7 and classified as critical . Impacted is an unknown function. This manipulation of the argument name_len causes stack-based buffer…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 24, 2026
CVE-2026-41433 | open-telemetry opentelemetry-ebpf-instrumentation up to 0.7.x File Creation path traversal

A vulnerability was found in open-telemetry opentelemetry-ebpf-instrumentation up to 0.7.x and classified as critical . The affected element is an unknown function of the component File Creation Handl…

VulDB Read →
◇ Industry News & Leadership Apr 24, 2026
White House Warns of AI Model 'Extraction' Campaigns

Agencies Urged to Track and Disrupt Coordinated AI Extraction Campaigns The White House is escalating coordination with AI firms after identifying large-scale foreign campaigns using proxy accounts an…

Data Breach Today Read →
◇ Industry News & Leadership Apr 24, 2026
Flurry of Supply-Chain Software Library Attacks

Continuous Integration Has Its Downsides As supply-chain attacks against widely-used, open-source software repositories continue, experts are urging developers to not only rely on code integrity tools…

Data Breach Today Read →
◇ Industry News & Leadership Apr 24, 2026
Void Dokkaebi Hackers Use Fake Job Interviews to Spread Malware via Code Repositories

A North Korea-linked hacking group known as Void Dokkaebi, also tracked as Famous Chollima, is running a campaign that tricks software developers into installing malware through fake job interviews. T…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 24, 2026
Hackers Use Pastebin-Hosted PowerShell Script to Steal Telegram Sessions

Cybersecurity researchers have uncovered a purpose-built PowerShell script hosted on Pastebin that is designed to silently steal Telegram session data from both desktop and web-based clients. The scri…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 24, 2026
Hackers Use Fake CAPTCHA Pages to Trigger Costly International SMS Fraud

Most internet users are familiar with CAPTCHA tests, simple challenges like selecting traffic lights or typing distorted letters to confirm they are human. But cybercriminals have found a way to weapo…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 24, 2026
Claude Desktop Reportedly Adds Browser Access Bridge to Multiple Chromium-Based Browsers

A recent technical audit by privacy researcher Alexander Hanff has revealed that Anthropic’s Claude Desktop application for macOS silently installs a Native Messaging bridge into the directories of se…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 24, 2026
CISA last in line for access to Anthropic Mythos

The US Cybersecurity and Infrastructure Security Agency (CISA) does not yet have access to Anthropic’s bug-hunting AI model, Claude Mythos, even though other government agencies do, Axios reported ear…

CSO Online Read →
◇ Industry News & Leadership Apr 24, 2026
Scattered Spider co-conspirator pleads guilty

Another member of the notorious Scattered Spider gang of cyber criminals has pleaded guilty in a US court, and will be sentenced later this year. Tyler Buchanan pleaded guilty in a Florida court to co…

CSO Online Read →
◇ Industry News & Leadership Apr 24, 2026
US Busts Myanmar Ring Targeting US Citizens in Financial Fraud

Some 29 people were charged, including a Cambodian senator, and authorities seized more than 500 Web domains tied to fake investment sites.

Dark Reading Read →
◇ Industry News & Leadership Apr 24, 2026
FIRESTARTER Backdoor Hit Federal Cisco Firepower Device, Survives Security Patches

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has revealed that an unnamed federal civilian agency's Cisco Firepower device running Adaptive Security Appliance (ASA) software was co…

The Hacker News Read →
◇ Industry News & Leadership Apr 24, 2026
New ‘Pack2TheRoot’ flaw gives hackers root Linux access

A new vulnerability dubbed Pack2TheRoot could be exploited in the PackageKit daemon to allow local Linux users to install or remove system packages and gain root permissions. [...]

Bleeping Computer Read →
◇ Industry News & Leadership Apr 24, 2026
Microsoft to roll out Entra passkeys on Windows in late April

Microsoft will roll out passkey support for phishing-resistant passwordless authentication to Microsoft Entra‑protected resources from Windows devices starting late April. [...]

Bleeping Computer Read →
← Prev 1075 / 1779 Next →