CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  44562 articles  ·  updated every 4 hours · grows forever

44562Total
31373Full Text
Aug 15, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-34454 | oauth2-proxy OAuth2 Proxy up to 7.15.1 Logout/Sign-out session expiration (GHSA-f24x-5g9q-753f)

A vulnerability marked as critical has been reported in oauth2-proxy OAuth2 Proxy up to 7.15.1 . Affected by this issue is some unknown functionality of the component Logout/Sign-out . This manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40090 | zarf-dev zarf up to 0.74.1 Metadata.Name path traversal

A vulnerability described as critical has been identified in zarf-dev zarf up to 0.74.1 . This affects an unknown part. Such manipulation of the argument Metadata.Name leads to path traversal. This vu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40499 | radareorg radare2 up to 6.1.3 PDB Parser print_gvars os command injection

A vulnerability classified as critical has been found in radareorg radare2 up to 6.1.3 . This vulnerability affects the function print_gvars of the component PDB Parser . Performing a manipulation res…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-39884 | Flux159 mcp-server-kubernetes up to 3.4.x Model Context Protocol port_forward.ts spawn argument injection

A vulnerability classified as critical was found in Flux159 mcp-server-kubernetes up to 3.4.x . This issue affects the function spawn of the file src/tools/port_forward.ts of the component Model Conte…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-2834 | tokenoftrust Age Verification & Identity Verification by Token of Trust Plugin cross site scripting

A vulnerability, which was classified as problematic , has been found in tokenoftrust Age Verification & Identity Verification by Token of Trust Plugin up to 3.32.3 on WordPress. Impacted is an unknow…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-35032 | Jellyfin up to 10.11.6 /LiveTv/TunerHosts server-side request forgery (GHSA-8fw7-f233-ffr8)

A vulnerability, which was classified as critical , was found in Jellyfin up to 10.11.6 . The affected element is an unknown function of the file /LiveTv/TunerHosts . The manipulation results in serve…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33193 | Docmost up to 0.69.x MIME cross site scripting

A vulnerability has been found in Docmost up to 0.69.x and classified as problematic . The impacted element is an unknown function of the component MIME Handler . This manipulation causes cross site s…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-5397 | Omron Social Solutions PowerAttendant Standard Edition uncontrolled search path (OMSR-2026-001)

A vulnerability was found in Omron Social Solutions PowerAttendant Standard Edition and classified as problematic . This affects an unknown function. Such manipulation leads to uncontrolled search pat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-33806 | Fastify up to 5.8.4 Header Content-Type improper validation of specified type of input

A vulnerability was found in Fastify up to 5.8.4 . It has been classified as problematic . This impacts an unknown function of the component Header Handler . Performing a manipulation of the argument …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-26291 | GROWI up to 7.4.6 cross site scripting

A vulnerability was found in GROWI up to 7.4.6 . It has been declared as problematic . Affected is an unknown function. Executing a manipulation can lead to cross site scripting. The identification of…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40105 | XWiki xwiki-platform up to 16.10.15/17.4.7/17.10.0 templates/changesdoc.vm cross site scripting

A vulnerability was found in XWiki xwiki-platform up to 16.10.15/17.4.7/17.10.0 . It has been rated as problematic . Affected by this vulnerability is an unknown functionality of the file templates/ch…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-30778 | Apache SkyWalking up to 10.3.0 OAP Endpoint /debugging/config/dump information disclosure

A vulnerability categorized as problematic has been discovered in Apache SkyWalking up to 10.3.0 . Affected by this issue is some unknown functionality of the file /debugging/config/dump of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40261 | Composer Perforce Reference command injection

A vulnerability identified as critical has been detected in Composer . This affects an unknown part of the component Perforce Reference Handler . This manipulation causes command injection. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-5160 | yuin goldmark up to 1.7.16 URL Validation cross site scripting

A vulnerability labeled as problematic has been found in yuin goldmark up to 1.7.16 . This vulnerability affects unknown code of the component URL Validation Handler . Such manipulation leads to cross…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-6293 | udamadu Inquiry Form to Posts or pages Plugin up to 1.0 on WordPress check_admin_referer inq_hidden cross-site request forgery

A vulnerability marked as problematic has been reported in udamadu Inquiry Form to Posts or pages Plugin up to 1.0 on WordPress. This issue affects the function check_admin_referer . Performing a mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 15, 2026
CVE-2026-40719 | MaraDNS 3.5.0036 Deadwood control flow

A vulnerability described as problematic has been identified in MaraDNS 3.5.0036 . Impacted is an unknown function of the component Deadwood . Executing a manipulation can lead to incorrect control fl…

VulDB Read →
◉ Threat Intelligence Apr 15, 2026
April 2026 Patch Tuesday: Two Zero-Days and Eight Critical Vulnerabilities Among 164 CVEs
CrowdStrike Read →
◇ Industry News & Leadership Apr 15, 2026
25,000+ Endpoints Exposed by Dragon Boss Solutions Update Domain Supply Chain Attack

What started as a routine adware alert quickly turned into something far more serious. On the morning of March 22, 2026, security alerts began firing across multiple managed environments, all linked t…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 15, 2026
Microsoft Defender 0-Day Vulnerability Enables Privilege Escalation Attack

Microsoft has released patch Tuesday security updates to address a newly discovered zero-day vulnerability in the Microsoft Defender Antimalware Platform. Disclosed on April 14, 2026, the flaw is trac…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 15, 2026
New JanaWare Ransomware Targets Turkish Users Through Customized Adwind RAT

A new ransomware family called JanaWare has begun targeting computer users in Turkey, relying on a customized version of the Adwind remote access trojan (RAT) to gain a foothold on victims’ systems. T…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 15, 2026
13 Fragen gegen Drittanbieterrisiken

Drum prüfe… Miljan Zivkovic | shutterstock.com Die zunehmende Abhängigkeit von IT-Dienstleistern und Software von Drittanbietern vergrößert die Angriffsfläche von Unternehmen erheblich. Das wird auch …

CSO Online Read →
◇ Industry News & Leadership Apr 15, 2026
Mallory Launches AI-Native Threat Intelligence Platform, Turning Global Threat Data Into Prioritized Action

Built by a veteran security team and led by a former Google and Mandiant executive, Mallory delivers intelligence that drives action for enterprise security teams. Mallory is launching a AI-native thr…

CSO Online Read →
◇ Industry News & Leadership Apr 15, 2026
ICS Patch Tuesday: 8 Industrial Giants Publish New Security Advisories

Siemens, Schneider Electric, Aveva, Rockwell Automation, ABB, Phoenix Contact, Mitsubishi Electric, and Moxa patched vulnerabilities. The post ICS Patch Tuesday: 8 Industrial Giants Publish New Securi…

Security Week Read →
◇ Industry News & Leadership Apr 15, 2026
OpenAI Launches GPT-5.4-Cyber with Expanded Access for Security Teams

OpenAI on Tuesday unveiled GPT-5.4-Cyber, a variant of its latest flagship model, GPT‑5.4, that's specifically optimized for defensive cybersecurity use cases, days after rival Anthropic unveiled its …

The Hacker News Read →
← Prev 1289 / 1857 Next →