A vulnerability labeled as critical has been found in Mozilla thin-vec up to 0.2.15 . The affected element is the function IntoIter::drop/ThinVec::clear . Such manipulation leads to use after free. Th…
cyberintel.kalymoon.com · 43564 articles · updated every 4 hours · grows forever
A vulnerability labeled as critical has been found in Mozilla thin-vec up to 0.2.15 . The affected element is the function IntoIter::drop/ThinVec::clear . Such manipulation leads to use after free. Th…
A vulnerability marked as critical has been reported in ericc-ch copilot-api up to 0.7.0 . The impacted element is the function cors of the file src/server.ts of the component Token Endpoint . Perform…
A vulnerability described as problematic has been identified in GNU sed up to 4.9 . This affects the function open_next_file . Executing a manipulation can lead to time-of-check time-of-use. This vuln…
A vulnerability classified as critical has been found in sglang 0.59 . This impacts the function jinja2.Environment of the file /v1/rerank of the component Reranking Endpoint . The manipulation leads …
A vulnerability classified as critical was found in Progress LoadMaster, ECS Connections Manager, Object Scale Connection Manager and MOVEit WAF . Affected is an unknown function of the component API …
A vulnerability, which was classified as critical , has been found in Progress LoadMaster, ECS Connections Manager, Object Scale Connection Manager and MOVEit WAF . Affected by this vulnerability is a…
A vulnerability, which was classified as critical , was found in Progress LoadMaster, ECS Connections Manager, Object Scale Connection Manager and MOVEit WAF . Affected by this issue is some unknown f…
A vulnerability has been found in Progress LoadMaster, ECS Connections Manager, Object Scale Connection Manager and MOVEit WAF and classified as critical . This affects an unknown part of the componen…
A vulnerability was found in givanz Vvveb up to 1.0.8.0 and classified as critical . This vulnerability affects unknown code of the component Plugin Upload Handler . Executing a manipulation can lead …
A vulnerability was found in Canonical canonical-livepatch up to 10.14.x . It has been classified as critical . This issue affects some unknown processing of the file livepatchd.sock of the component …
A vulnerability was found in givanz Vvveb up to 1.0.8.0 . It has been declared as critical . Impacted is the function getUrl of the component file URL Handler . The manipulation results in server-side…
A vulnerability was found in givanz Vvveb up to 1.0.8.0 . It has been rated as problematic . The affected element is an unknown function of the component Media Upload Handler . This manipulation cause…
Attacker First Compromised AI Tool Used by Vercel Employee, Platform Provider Finds Cloud platform provider Vercel said an attacker breached its systems and stole customer data after compromising a th…
Cisco's Jeetu Patel on How Machine-Speed Threats Drive Need for AI-Led Security Cisco's Jeetu Patel explains how AI models are compressing exploit timelines to minutes, forcing a shift to machine-spee…
The National Security Agency is reportedly deploying Anthropic’s advanced AI model, Mythos Preview. Meanwhile, the Department of Defense has labeled the company a “supply chain risk,” highlighting an …
Microsoft has released Windows 11 Insider Preview Build 26300.8170 to the Dev Channel, introducing notable improvements to Secure Boot visibility, storage management, and the Feedback Hub experience. …
Microsoft is actively working to resolve a service disruption that has left a subset of Teams desktop client users unable to launch the application, with the company now monitoring the rollback of the…
A new ransomware strain known as JanaWare has been quietly targeting home users and small to medium-sized businesses in Turkey, using a customized version of the well-known Adwind Remote Access Trojan…
Threat actors are now weaponizing QEMU, a legitimate open-source machine emulator and virtualizer, as a covert backdoor to steal credentials and deliver ransomware without triggering endpoint security…
A new and deceptive attack campaign has emerged where threat actors are impersonating IT helpdesk personnel through Microsoft Teams to trick employees into granting remote access to their systems. Wha…
FortiGuard Labs has identified a Mirai-based Nexcorium campaign actively exploiting CVE-2024-3721 in TBK DVR devices
Formbook attacks use combination of DLL Side-Loading and Obfuscated JavaScript to stay hidden, researchers at WatchGuard have uncovered
ZionSiphon malware targets OT water systems with sabotage and ICS scanning capabilities