A vulnerability was found in Apache Airflow up to 3.1.7 and classified as problematic . This impacts an unknown function of the component Azure Service Bus . Executing a manipulation of the argument a…
cyberintel.kalymoon.com · 44519 articles · updated every 4 hours · grows forever
A vulnerability was found in Apache Airflow up to 3.1.7 and classified as problematic . This impacts an unknown function of the component Azure Service Bus . Executing a manipulation of the argument a…
A vulnerability was found in Lenovo Software Fix . It has been classified as problematic . Affected is an unknown function of the component Installation Handler . The manipulation leads to uncontrolle…
A vulnerability was found in Lenovo Software Fix . It has been declared as critical . Affected by this vulnerability is an unknown functionality. The manipulation results in link following. This vulne…
A vulnerability was found in Lenovo Service Bridge 4/4.1.0.1/5.0.2.17 . It has been rated as problematic . Affected by this issue is some unknown functionality. This manipulation causes uncontrolled s…
A vulnerability categorized as critical has been discovered in HP DeskJet 2800e All-in-One Printer, DeskJet 4200 All-in-One Printer, DeskJet Ink Advantage 4200 All-in-One Printer, DeskJet 4200e All-in…
A vulnerability identified as critical has been detected in NietThijmen ShoppingCart 0.0.2 . This vulnerability affects unknown code of the component Connect Function . Performing a manipulation of th…
A vulnerability labeled as critical has been found in HP OMEN Gaming Hub up to 1101.2602 . This issue affects some unknown processing. Executing a manipulation can lead to execution with unnecessary p…
A vulnerability marked as critical has been reported in CentSDR e40795 . Impacted is the function Thread1 . The manipulation leads to stack-based buffer overflow. This vulnerability is referenced as C…
A supply chain attack by TeamPCP compromised trusted software tools to harvest credentials at scale, enabling payroll fraud, logistics theft, and ransomware extortion.
A group of trusted WordPress plugins quietly carried a hidden backdoor for eight full months, and nobody noticed until the damage had already been done. The attack, uncovered in April 2026, did not be…
Cybercriminals are always looking for smarter ways to bypass security, and their latest method is both simple and effective. Instead of building suspicious new websites, attackers now use Google Cloud…
A sophisticated cyber campaign bearing strong operational similarities to the MuddyWater threat group has been caught sweeping more than 12,000 internet-exposed systems across multiple regions before …
Adobe has released a critical security bulletin on April 14, 2026, to address multiple vulnerabilities in Adobe Acrobat and Reader for Windows and macOS. According to the official advisory, successful…
PHP Composer released urgent security updates to address two critical command injection vulnerabilities. PHP Composer is an essential dependency management tool used globally by developers, making any…
Microsoft has released urgent security updates to address a critical vulnerability in Windows Active Directory that allows attackers to execute malicious code. Disclosed on April 14, 2026, the vulnera…
Microsoft has officially released the April 2026 Patch Tuesday cumulative update, KB5083769, for Windows 11 versions 25H2 and 24H2. Released on April 14, 2026, this mandatory security update addresses…
In a massive blow to consumer privacy, a new forensic audit reveals that tech giants Google, Microsoft, and Meta are systematically ignoring legally defined privacy opt-out signals. According to the M…
Critical nginx-ui MCP authentication bypass CVE-2026-33032 actively exploited with CVSS 9.8
Huntress uncovers adware deploying AV-killing payloads via signed updates across 23,000 endpoints
The EU cybersecurity agency looks to become the third Top-Level Root CVE Numbering Authority, alongside CISA and MITRE
Enterprise AI agents are supposed to streamline workflows. Instead, two fresh findings show they can just as easily streamline data exfiltration. Security researchers have uncovered prompt-injection v…
Offered as a MaaS to a small number of affiliates, mainly Russian speakers, the RAT can turn devices into residential proxy nodes. The post Mirax RAT Targeting Android Users in Europe appeared first o…
Sophos’ Ross McKerchar discusses leadership at scale, retaining talent, defending against AI-enabled threats, and the industry’s growing trust problem. The post CISO Conversations: Ross McKerchar, CIS…
Published through five accounts, the extensions appear part of a coordinated campaign based on shared C&C infrastructure. The post 100 Chrome Extensions Steal User Data, Create Backdoor appeared first…