CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  43367 articles  ·  updated every 4 hours · grows forever

43367Total
30749Full Text
Aug 11, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6675 | cyberchimps Responsive Blocks Plugin up to 2.2.0 on WordPress Public REST API Route input validation

A vulnerability classified as critical was found in cyberchimps Responsive Blocks Plugin up to 2.2.0 on WordPress. This impacts an unknown function of the component Public REST API Route . Such manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40045 | OpenClaw up to 2026.4.1 ws Gateway Endpoint cleartext transmission (GHSA-83f3-hh45-vfw9)

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.4.1 . Affected is an unknown function of the component ws Gateway Endpoint Handler . Performing a manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-6674 | tholstkabelbwde CMS für Motorrad Werkstätten Plugin up to 1.0.0 on WordPress arttype sql injection

A vulnerability, which was classified as critical , was found in tholstkabelbwde CMS für Motorrad Werkstätten Plugin up to 1.0.0 on WordPress. Affected by this vulnerability is an unknown functionalit…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41294 | OpenClaw up to 2026.3.27 Environment Variable external control of setting (GHSA-8rh7-6779-cjqq)

A vulnerability has been found in OpenClaw up to 2026.3.27 and classified as problematic . Affected by this issue is some unknown functionality of the component Environment Variable Handler . The mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41295 | OpenClaw up to 2026.4.1 Workspace Channel inclusion of functionality from untrusted control sphere (GHSA-2qrv-rc5x-2g2h)

A vulnerability was found in OpenClaw up to 2026.4.1 and classified as problematic . This affects an unknown part of the component Workspace Channel Handler . The manipulation results in inclusion of …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40497 | freescout-help-desk freescout up to 1.8.212 Mailbox Signature Field /mailbox/settings/ stripDangerousTags cross site scripting (GHSA-fh99-wr77-pxq3)

A vulnerability was found in freescout-help-desk freescout up to 1.8.212 . It has been classified as problematic . This vulnerability affects the function Helper::stripDangerousTags of the file /mailb…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-5965 | NewSoft NewSoftOA prior 10.1.8.3 os command injection

A vulnerability was found in NewSoft NewSoftOA . It has been declared as critical . This issue affects some unknown processing. Such manipulation leads to os command injection. This vulnerability is d…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41296 | OpenClaw up to 2026.3.30 Remote Filesystem Bridge toctou (GHSA-9p3r-hh9g-5cmg)

A vulnerability was found in OpenClaw up to 2026.3.30 . It has been rated as problematic . Impacted is an unknown function of the component Remote Filesystem Bridge . Performing a manipulation results…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41297 | OpenClaw up to 2026.3.30 Marketplace Plugin server-side request forgery (GHSA-vjx8-8p7h-82gr)

A vulnerability categorized as critical has been discovered in OpenClaw up to 2026.3.30 . The affected element is an unknown function of the component Marketplace Plugin . Executing a manipulation can…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41299 | OpenClaw up to 2026.3.27 Websocket Handshake reliance on untrusted inputs in a security decision (GHSA-6xg4-82hv-cp6f)

A vulnerability identified as critical has been detected in OpenClaw up to 2026.3.27 . The impacted element is an unknown function of the component Websocket Handshake Handler . The manipulation leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41298 | OpenClaw up to 2026.4.1 Read-Scoped Call kill authorization (GHSA-5hff-46vh-rxmw)

A vulnerability labeled as critical has been found in OpenClaw up to 2026.4.1 . This affects an unknown function of the file /sessions/:sessionKey/kill of the component Read-Scoped Call Handler . The …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41300 | OpenClaw up to 2026.3.30 state distinction (GHSA-9f4w-67g7-mqwv)

A vulnerability marked as problematic has been reported in OpenClaw up to 2026.3.30 . This impacts an unknown function. This manipulation causes incomplete internal state distinction. This vulnerabili…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41331 | OpenClaw up to 2026.3.30 Telegram Audio Preflight Transcription amplification (GHSA-m6fx-m8hc-572m)

A vulnerability described as problematic has been identified in OpenClaw up to 2026.3.30 . Affected is an unknown function of the component Telegram Audio Preflight Transcription . Such manipulation l…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41301 | OpenClaw up to 2026.3.30 Nostr DM signature verification (GHSA-h43v-27wg-5mf9)

A vulnerability classified as problematic has been found in OpenClaw up to 2026.3.30 . Affected by this vulnerability is an unknown functionality of the component Nostr DM Handler . Performing a manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41303 | OpenClaw up to 2026.3.27 authorization (GHSA-98hh-7ghg-x6rq)

A vulnerability classified as critical was found in OpenClaw up to 2026.3.27 . Affected by this issue is some unknown functionality. Executing a manipulation can lead to incorrect authorization. The i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41330 | OpenClaw up to 2026.3.30 Environment Variable variable initialization (GHSA-9gp8-hjxr-6f34)

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.3.30 . This affects an unknown part of the component Environment Variable Handler . The manipulation leads …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41329 | OpenClaw up to 2026.3.30 senderIsOwner incorrect privileged apis (GHSA-g5cg-8x5w-7jpm)

A vulnerability, which was classified as critical , was found in OpenClaw up to 2026.3.30 . This vulnerability affects unknown code. The manipulation of the argument senderIsOwner results in incorrect…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41302 | OpenClaw up to 2026.3.30 Marketplace Plugin fetch server-side request forgery (GHSA-9q7v-8mr7-g23p)

A vulnerability has been found in OpenClaw up to 2026.3.30 and classified as critical . This issue affects the function fetch of the component Marketplace Plugin . This manipulation causes server-side…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-34082 | langgenius dify up to 1.13.0 Chat History conversations authorization (GHSA-fxq3-hh7x-c63p)

A vulnerability was found in langgenius dify up to 1.13.0 and classified as problematic . Impacted is an unknown function of the file /console/api/installed-apps/conversations/ of the component Chat H…

VulDB Read →
◉ Threat Intelligence Apr 21, 2026
A .WAV With A Payload, (Tue, Apr 21st)

There have been reports of threat actors using a .wav file as a vector for malware.

SANS ISC Read →
◇ Industry News & Leadership Apr 21, 2026
PoC Exploit Released for Windows Snipping Tool NTLM Hash Leak Vulnerability

A proof-of-concept (PoC) exploit has been publicly released for a newly disclosed vulnerability in Microsoft’s Snipping Tool that allows attackers to silently steal users’ Net-NTLM credential hashes b…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 21, 2026
SideWinder Uses Fake Chrome PDF Viewer and Zimbra Clone to Steal Government Webmail Credentials

A well-known advanced persistent threat group called SideWinder has launched a highly targeted phishing campaign against South Asian government organizations, using a fake Chrome PDF viewer and a pixe…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 21, 2026
Meta and PortSwigger drive offensive security further to find what others miss

Meta Bug Bounty and PortSwigger have formed a partnership to help security researchers sharpen their skills, collaborate more closely, and improve vulnerability discovery. The initiative combines Meta…

Help Net Security Read →
◇ Industry News & Leadership Apr 21, 2026
AI platform ATHR makes voice phishing a one-person job

For $4,000 and a cut of the take, a lone criminal can now run a fully automated voice-phishing operation via ATHR, a plaform that spoofs emails alerts from Google, Microsoft, and Coinbase, buries a ph…

Help Net Security Read →
← Prev 1171 / 1807 Next →