A vulnerability classified as critical was found in Quantum Router QN-I-470 6.1.1.B1 . This issue affects some unknown processing of the component Web-based Management Interface . The manipulation res…
cyberintel.kalymoon.com · 43231 articles · updated every 4 hours · grows forever
A vulnerability classified as critical was found in Quantum Router QN-I-470 6.1.1.B1 . This issue affects some unknown processing of the component Web-based Management Interface . The manipulation res…
A vulnerability, which was classified as problematic , has been found in TYPO3 CMS up to 14.2.x . Impacted is an unknown function of the component User Settings Module . This manipulation of the argum…
A vulnerability, which was classified as problematic , was found in MetaSlider Responsive Slider Plugin up to 3.106.0 on WordPress. The affected element is an unknown function. Such manipulation leads…
A vulnerability has been found in Quantum Router QN-I-470 6.1.1.B1 and classified as critical . The impacted element is an unknown function of the component API Endpoint . Performing a manipulation re…
A vulnerability was found in Navigate CMS up to 2.9.5 and classified as problematic . This affects an unknown function of the file /blog . Executing a manipulation can lead to cross site scripting. Th…
A critical cross-vendor vulnerability class dubbed “Comment and Control” is a new category of prompt injection attacks that weaponizes GitHub pull request titles, issue bodies, and issue comments to h…
The Cybersecurity and Infrastructure Security Agency (CISA) has released a critical alert regarding a severe software supply chain compromise. The attack targets Axios, a massively popular HTTP client…
A critical vulnerability in the SGLang inference server that allows threat actors to execute arbitrary code. Tracked as CVE-2026-5760, this flaw allows hackers to weaponize standard GGUF machine learn…
A massive malware campaign known as “StealTok” involves at least 12 interrelated browser extensions. These extensions masquerade as TikTok video downloaders but secretly track user activity and harves…
Artificial intelligence is reshaping cybercrime in ways that defenders can no longer treat as distant or theoretical. New frontier AI models are showing a growing ability to find software flaws, under…
A new ransomware-as-a-service (RaaS) operation known as “The Gentlemen” has emerged as a serious threat to corporate networks worldwide. Since appearing around mid-2025, this group has rapidly grown i…
North Korea’s Lazarus Group is pegged for a $290m crypto theft at KelpDAO
Cloud app developer Vercel appears to have suffered a security breach
On April 7, six US government agencies issued a critical advisory warning domestic private sector organizations of potential infrastructural cyberattacks conducted by Iranian-affiliated Advanced Persi…
Much of the talk around cybersecurity these days revolves around AI and the threat it poses to corporate systems when used by nefarious actors. But the reality on the ground remains a little more mund…
Identity centric technologies have undergone a significant transformation in recent times. Gone are the days when it was all about logging in and out of any given system. Today, identity has become th…
The hackers targeted LayerZero’s DVN, compromising certain RPCs and DDoSing others to trigger failover to the poisoned infrastructure. The post $290 Million Kelp DAO Crypto Heist Blamed on North Korea…
Data breaches were disclosed by Southern Illinois Dermatology, Saint Anthony Hospital, and North Texas Behavioral Health Authority. The post Data Breaches at Healthcare Organizations in Illinois and T…
CISA expanded the KEV catalog with eight flaws, but five of them have been flagged as exploited before. The post Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities appeared first…
China is spying on India's financial sector, for some reason, and it's not putting much effort into it, judging by some stale TTPs.
Cybersecurity researchers have discovered a vulnerability in Google's agentic integrated development environment (IDE), Antigravity, that could be exploited to achieve code execution. The flaw, since …
Cybersecurity researchers have discovered a new iteration of an Android malware family calledNGate that has been found to abuse a legitimate application called HandyPay instead of NFCGate. "The threat…
The cybersecurity industry has spent the last several years chasing sophisticated threats like zero-days, supply chain compromises, and AI-generated exploits. However, the most reliable entry point fo…
A new variant of the NGate malware that steals NFC payment data is targeting Android users by hiding in a trojanized version of HandyPay, a legitimate mobile payments processing tool. [...]