CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  43435 articles  ·  updated every 4 hours · grows forever

43435Total
30784Full Text
Aug 11, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41295 | OpenClaw up to 2026.4.1 Workspace Channel inclusion of functionality from untrusted control sphere (GHSA-2qrv-rc5x-2g2h)

A vulnerability was found in OpenClaw up to 2026.4.1 and classified as problematic . This affects an unknown part of the component Workspace Channel Handler . The manipulation results in inclusion of …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-40497 | freescout-help-desk freescout up to 1.8.212 Mailbox Signature Field /mailbox/settings/ stripDangerousTags cross site scripting (GHSA-fh99-wr77-pxq3)

A vulnerability was found in freescout-help-desk freescout up to 1.8.212 . It has been classified as problematic . This vulnerability affects the function Helper::stripDangerousTags of the file /mailb…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-5965 | NewSoft NewSoftOA prior 10.1.8.3 os command injection

A vulnerability was found in NewSoft NewSoftOA . It has been declared as critical . This issue affects some unknown processing. Such manipulation leads to os command injection. This vulnerability is d…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41296 | OpenClaw up to 2026.3.30 Remote Filesystem Bridge toctou (GHSA-9p3r-hh9g-5cmg)

A vulnerability was found in OpenClaw up to 2026.3.30 . It has been rated as problematic . Impacted is an unknown function of the component Remote Filesystem Bridge . Performing a manipulation results…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41297 | OpenClaw up to 2026.3.30 Marketplace Plugin server-side request forgery (GHSA-vjx8-8p7h-82gr)

A vulnerability categorized as critical has been discovered in OpenClaw up to 2026.3.30 . The affected element is an unknown function of the component Marketplace Plugin . Executing a manipulation can…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41299 | OpenClaw up to 2026.3.27 Websocket Handshake reliance on untrusted inputs in a security decision (GHSA-6xg4-82hv-cp6f)

A vulnerability identified as critical has been detected in OpenClaw up to 2026.3.27 . The impacted element is an unknown function of the component Websocket Handshake Handler . The manipulation leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41298 | OpenClaw up to 2026.4.1 Read-Scoped Call kill authorization (GHSA-5hff-46vh-rxmw)

A vulnerability labeled as critical has been found in OpenClaw up to 2026.4.1 . This affects an unknown function of the file /sessions/:sessionKey/kill of the component Read-Scoped Call Handler . The …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41300 | OpenClaw up to 2026.3.30 state distinction (GHSA-9f4w-67g7-mqwv)

A vulnerability marked as problematic has been reported in OpenClaw up to 2026.3.30 . This impacts an unknown function. This manipulation causes incomplete internal state distinction. This vulnerabili…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41331 | OpenClaw up to 2026.3.30 Telegram Audio Preflight Transcription amplification (GHSA-m6fx-m8hc-572m)

A vulnerability described as problematic has been identified in OpenClaw up to 2026.3.30 . Affected is an unknown function of the component Telegram Audio Preflight Transcription . Such manipulation l…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41301 | OpenClaw up to 2026.3.30 Nostr DM signature verification (GHSA-h43v-27wg-5mf9)

A vulnerability classified as problematic has been found in OpenClaw up to 2026.3.30 . Affected by this vulnerability is an unknown functionality of the component Nostr DM Handler . Performing a manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41303 | OpenClaw up to 2026.3.27 authorization (GHSA-98hh-7ghg-x6rq)

A vulnerability classified as critical was found in OpenClaw up to 2026.3.27 . Affected by this issue is some unknown functionality. Executing a manipulation can lead to incorrect authorization. The i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41330 | OpenClaw up to 2026.3.30 Environment Variable variable initialization (GHSA-9gp8-hjxr-6f34)

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.3.30 . This affects an unknown part of the component Environment Variable Handler . The manipulation leads …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41329 | OpenClaw up to 2026.3.30 senderIsOwner incorrect privileged apis (GHSA-g5cg-8x5w-7jpm)

A vulnerability, which was classified as critical , was found in OpenClaw up to 2026.3.30 . This vulnerability affects unknown code. The manipulation of the argument senderIsOwner results in incorrect…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-41302 | OpenClaw up to 2026.3.30 Marketplace Plugin fetch server-side request forgery (GHSA-9q7v-8mr7-g23p)

A vulnerability has been found in OpenClaw up to 2026.3.30 and classified as critical . This issue affects the function fetch of the component Marketplace Plugin . This manipulation causes server-side…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 21, 2026
CVE-2026-34082 | langgenius dify up to 1.13.0 Chat History conversations authorization (GHSA-fxq3-hh7x-c63p)

A vulnerability was found in langgenius dify up to 1.13.0 and classified as problematic . Impacted is an unknown function of the file /console/api/installed-apps/conversations/ of the component Chat H…

VulDB Read →
◉ Threat Intelligence Apr 21, 2026
A .WAV With A Payload, (Tue, Apr 21st)

There have been reports of threat actors using a .wav file as a vector for malware.

SANS ISC Read →
◇ Industry News & Leadership Apr 21, 2026
PoC Exploit Released for Windows Snipping Tool NTLM Hash Leak Vulnerability

A proof-of-concept (PoC) exploit has been publicly released for a newly disclosed vulnerability in Microsoft’s Snipping Tool that allows attackers to silently steal users’ Net-NTLM credential hashes b…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 21, 2026
SideWinder Uses Fake Chrome PDF Viewer and Zimbra Clone to Steal Government Webmail Credentials

A well-known advanced persistent threat group called SideWinder has launched a highly targeted phishing campaign against South Asian government organizations, using a fake Chrome PDF viewer and a pixe…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 21, 2026
Meta and PortSwigger drive offensive security further to find what others miss

Meta Bug Bounty and PortSwigger have formed a partnership to help security researchers sharpen their skills, collaborate more closely, and improve vulnerability discovery. The initiative combines Meta…

Help Net Security Read →
◇ Industry News & Leadership Apr 21, 2026
AI platform ATHR makes voice phishing a one-person job

For $4,000 and a cut of the take, a lone criminal can now run a fully automated voice-phishing operation via ATHR, a plaform that spoofs emails alerts from Google, Microsoft, and Coinbase, buries a ph…

Help Net Security Read →
◇ Industry News & Leadership Apr 21, 2026
Vercel breached via compromised third-party AI tool

Cloud deployment and hosting platform Vercel has suffered a security breach that resulted in attackers accessing some of its internal systems and compromising Vercel credentials of a “limited subset o…

Help Net Security Read →
◇ Industry News & Leadership Apr 21, 2026
Cybersecurity jobs available right now: April 21, 2026

Application Security Engineer (DevSecOps / Azure DevOps) BEWAHARVEST | Philippines | Hybrid – No longer accepting applications As an Application Security Engineer (DevSecOps / Azure DevOps), you will …

Help Net Security Read →
◇ Industry News & Leadership Apr 21, 2026
Researchers build an encrypted routing layer for private AI inference

Organizations in healthcare, finance, and other sensitive industries want to use large AI models without exposing private data to the cloud servers running those models. A cryptographic technique call…

Help Net Security Read →
◇ Industry News & Leadership Apr 21, 2026
CISA Adds 8 Exploited Flaws to KEV, Sets April-May 2026 Federal Deadlines

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added eight new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including three flaws impacting Cisco C…

The Hacker News Read →
← Prev 1174 / 1810 Next →