CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  43564 articles  ·  updated every 4 hours · grows forever

43564Total
30851Full Text
Aug 11, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-25525 | OpenMage magento-lts up to 20.16.x Dataflow path traversal (GHSA-6vqf-6fhm-7rc6)

A vulnerability was found in OpenMage magento-lts up to 20.16.x and classified as critical . This impacts an unknown function of the component Dataflow Module . Such manipulation leads to path travers…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-41445 | mborgerding kissfft kiss_fftndr.c kiss_fftndr_alloc integer overflow

A vulnerability was found in mborgerding kissfft . It has been classified as critical . Affected is the function kiss_fftndr_alloc of the file kiss_fftndr.c . Performing a manipulation results in inte…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2025-66954 | Buffalo Link Station 1.85-0.01 /nasapi information disclosure

A vulnerability was found in Buffalo Link Station 1.85-0.01 . It has been declared as problematic . Affected by this vulnerability is an unknown functionality of the file /nasapi . Executing a manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-30269 | Doorman 0.1.0/1.0.2 /platform/user/ manage_users role access control

A vulnerability was found in Doorman 0.1.0/1.0.2 . It has been rated as critical . Affected by this issue is the function manage_users of the file /platform/user/ . The manipulation of the argument ro…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-26399 | stm32duino Arduino_Core_STM32 up to 1.6.x pwm_start memory corruption

A vulnerability categorized as critical has been discovered in stm32duino Arduino_Core_STM32 up to 1.6.x . This affects the function pwm_start . The manipulation results in memory corruption. This vul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-26951 | Dell PowerProtect Data Domain up to 7.13.1.60/8.3.1.20/8.6 stack-based overflow (dsa-2026-060)

A vulnerability identified as critical has been detected in Dell PowerProtect Data Domain up to 7.13.1.60/8.3.1.20/8.6 . This vulnerability affects unknown code. This manipulation causes stack-based b…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-35154 | Dell PowerProtect Data Domain appliances up to 7.13.1.60/8.3.1.20/8.7.0.0 privileges management (dsa-2026-060)

A vulnerability labeled as critical has been found in Dell PowerProtect Data Domain appliances up to 7.13.1.60/8.3.1.20/8.7.0.0 . This issue affects some unknown processing. Such manipulation leads to…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-23756 | GFI HelpDesk up to 4.99.8 Troubleshooter Controller_Step.InsertSubmit subject cross site scripting

A vulnerability marked as problematic has been reported in GFI HelpDesk up to 4.99.8 . Impacted is the function Controller_Step.InsertSubmit of the component Troubleshooter Module . Performing a manip…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-25883 | Vexa-ai vexa prior 0.10.0-260419-1910 HTTP POST Request server-side request forgery (GHSA-fhr6-8hff-cvg4)

A vulnerability described as critical has been identified in Vexa-ai vexa . The affected element is an unknown function of the component HTTP POST Request Handler . Executing a manipulation can lead t…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-23758 | GFI HelpDesk up to 4.99.8 POST Parameter Controller_Ticket.EditSubmit editsubject cross site scripting

A vulnerability classified as problematic has been found in GFI HelpDesk up to 4.99.8 . The impacted element is the function Controller_Ticket.EditSubmit of the component POST Parameter Handler . The …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-30266 | DeepCool DeepCreative up to 1.2.7 File permission

A vulnerability classified as critical was found in DeepCool DeepCreative up to 1.2.7 . This affects an unknown function of the component File Handler . The manipulation results in permission issues. …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-41389 | OpenClaw up to 2026.4.14 UNC File file inclusion

A vulnerability, which was classified as problematic , has been found in OpenClaw up to 2026.4.14 . This impacts an unknown function of the component UNC File Handler . This manipulation causes file i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-23752 | GFI HelpDesk up to 4.99.8 Groups Page companyname cross site scripting

A vulnerability, which was classified as problematic , was found in GFI HelpDesk up to 4.99.8 . Affected is an unknown function of the component Groups Page . Such manipulation of the argument company…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-23753 | GFI HelpDesk up to 4.99.8 Languages Page SWIFT_Language::Create charset cross site scripting

A vulnerability has been found in GFI HelpDesk up to 4.99.8 and classified as problematic . Affected by this vulnerability is the function SWIFT_Language::Create of the component Languages Page . Perf…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 20, 2026
CVE-2026-23757 | GFI HelpDesk up to 4.99.9 Reports SWIFT_Report::Create report title cross site scripting

A vulnerability was found in GFI HelpDesk up to 4.99.9 and classified as problematic . Affected by this issue is the function SWIFT_Report::Create of the component Reports Module . Executing a manipul…

VulDB Read →
◉ Threat Intelligence Apr 20, 2026
Making opportunistic cyberattacks harder by design

How Microsoft secures Dynamics 365 and Power Platform by removing credentials, reducing attack surfaces, and using platform engineering to block opportunistic threats. The post Making opportunistic cy…

Microsoft Security Read →
◉ Threat Intelligence Apr 20, 2026
DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy

Key Points The Gentlemen RaaS The Gentlemen ransomware‑as‑a‑service (RaaS) operation is a relatively new group that emerged around mid‑2025. The operators advertise their services across multiple unde…

Check Point Research Read →
◉ Threat Intelligence Apr 20, 2026
20th April – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 20th April, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Booking.com, the Amsterdam-based travel platform, ha…

Check Point Research Read →
◇ Industry News & Leadership Apr 20, 2026
Securing the Hybrid Workplace in the Age of AI-Driven Threats
Data Breach Today Read →
◇ Industry News & Leadership Apr 20, 2026
A Token Flaw Turned Azure's AI Agent Into a Spy

Outsiders Could Exploit Misconfig to Stream Commands, Credentials A misconfiguration in Microsoft's Azure SRE Agent may have allowed any Azure account holder from any company to tap into another organ…

Data Breach Today Read →
◇ Industry News & Leadership Apr 20, 2026
Lovable AI App Builder Reportedly Exposes Thousands of Projects Data via API Flaw

A critical Broken Object Level Authorization (BOLA) vulnerability in Lovable, the popular AI-powered app builder platform, is reportedly allowing unauthorized users to access sensitive project data, i…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 20, 2026
Researchers Say Iranian MOIS Uses Multiple Hacker Personas for One Coordinated Cyber Campaign

Iran’s Ministry of Intelligence and Security (MOIS) has been running a long and carefully organized cyber campaign using three separate hacker identities. These identities, known as Homeland Justice, …

Cybersecurity News Read →
◇ Industry News & Leadership Apr 20, 2026
North Korea-Linked UNC1069 Uses Fake Zoom and Teams Meetings to Hack Crypto Professionals

A North Korean threat group known as UNC1069 has been running a sophisticated campaign that tricks cryptocurrency and Web3 professionals into joining fake online meetings, only to infect their compute…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 20, 2026
Serial-to-IP Devices Hide Thousands of Old and New Bugs

The OT devices that translate machine talk into Internet-speak are riddled with vulnerabilities and more frequently targeted for attacks, researchers say.

Dark Reading Read →
← Prev 1185 / 1816 Next →