CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  21946 articles  ·  updated every 4 hours · grows forever

21946Total
18824Full Text
May 22, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-8305 | OpenClaw up to 2026.1.24 bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authentication (Issue 13786)

A vulnerability has been found in OpenClaw up to 2026.1.24 and classified as critical . The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions/bluebubbles/src/moni…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-6909 | ATutor 2.2.4 URL /install/upgrade.php cross site scripting (EUVD-2026-29048)

A vulnerability was found in ATutor 2.2.4 and classified as problematic . This affects an unknown function of the file /install/upgrade.php of the component URL Handler . Executing a manipulation can …

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-6956 | ATutor 2.2.4 URL cross site scripting (EUVD-2026-29049)

A vulnerability was found in ATutor 2.2.4 . It has been classified as problematic . This impacts an unknown function of the component URL Handler . The manipulation leads to cross site scripting. This…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2025-8325 | WSO2 API Control Plane Gateway API permissions (EUVD-2025-209759)

A vulnerability was found in WSO2 API Control Plane, Universal Gateway, Traffic Manager, API Manager, Carbon API Management Implementation and Carbon API Manager Rest API Utility . It has been declare…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2024-0391 | WSO2 Identity Server prior 7.0.0.131 response discrepancy

A vulnerability was found in WSO2 Identity Server, Open Banking IAM, Identity Server as Key Manager, Email OTP Authenticator and Carbon Authenticator Library for EmailOTP . It has been rated as proble…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2025-10470 | WSO2 Identity Server resource consumption (EUVD-2025-209760)

A vulnerability categorized as problematic has been discovered in WSO2 Identity Server and Carbon MagicLink Authenticator Module . Affected by this issue is some unknown functionality. Such manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2025-9973 | WSO2 Identity Server Organization Context missing initialization (EUVD-2025-209762)

A vulnerability identified as problematic has been detected in WSO2 Identity Server and Conditional Authentication User and Roles Related Functions . This affects an unknown part of the component Orga…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2025-43992 | Dell ECS/ObjectScale authentication bypass by assumed-immutable data (dsa-2026-047)

A vulnerability labeled as problematic has been found in Dell ECS and ObjectScale . This vulnerability affects unknown code. Executing a manipulation can lead to authentication bypass by assumed-immut…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-32658 | Dell Automation Platform 1.x authorization (dsa-2026-193)

A vulnerability marked as very critical has been reported in Dell Automation Platform 1.x . This issue affects some unknown processing. The manipulation leads to missing authorization. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-35157 | Dell ECS/ObjectScale csv injection (dsa-2026-047 / EUVD-2026-29045)

A vulnerability described as problematic has been identified in Dell ECS and ObjectScale . Impacted is an unknown function. The manipulation results in csv injection. This vulnerability was named CVE-…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2025-10908 | WSO2 Identity Server Magic Link/Pass Key authorization (EUVD-2025-209756)

A vulnerability classified as problematic has been found in WSO2 Identity Server and Carbon MagicLink Authenticator Module . The affected element is an unknown function of the component Magic Link/Pas…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2025-8154 | WSO2 API Manager Webhook API injection (EUVD-2025-209758)

A vulnerability classified as critical was found in WSO2 API Manager, Universal Gateway, Traffic Manager, API Control Plane, Carbon API Gateway and Carbon API Management Implementation . The impacted …

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-26946 | Dell ECS/ObjectScale privileges management (dsa-2026-047)

A vulnerability, which was classified as critical , has been found in Dell ECS and ObjectScale . This affects an unknown function. Performing a manipulation results in improper privilege management. T…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-40636 | Dell ECS/ObjectScale hard-coded credentials (dsa-2026-047 / EUVD-2026-29046)

A vulnerability, which was classified as critical , was found in Dell ECS and ObjectScale . This impacts an unknown function. Executing a manipulation can lead to hard-coded credentials. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-41951 | GROWI up to 7.5.0 path traversal (EUVD-2026-29047)

A vulnerability has been found in GROWI up to 7.5.0 and classified as critical . Affected is an unknown function. The manipulation leads to path traversal. This vulnerability is listed as CVE-2026-419…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-8318 | VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba PDF Table of Contents pageindex/page_index.py toc_transformer infinite loop (Issue 174)

A vulnerability was found in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba and classified as problematic . Affected by this vulnerability is the function toc_transformer of the fi…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-8319 | aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59 cheshire_cat_core stray_cat.py recall_relevant_memories_to_working_memory resource consumption (Issue 219)

A vulnerability was found in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59 . It has been classified as problematic . Affected by this issue is the function recall_relevant_memories_…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-8320 | jishenghua jshERP up to 3.6 updatePlatformConfigByKey Endpoint UserService.java getUserByWeixinCode weixinUrl server-side request forgery (Issue 152)

A vulnerability was found in jishenghua jshERP up to 3.6 . It has been declared as critical . This affects the function getUserByWeixinCode of the file jshERP-boot/src/main/java/com/jsh/erp/service/Us…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-8321 | inkeep agents 0.58.14 runAuth Middleware runAuth.ts createDevContext authentication bypass (Issue 3024)

A vulnerability was found in inkeep agents 0.58.14 . It has been rated as critical . This vulnerability affects the function createDevContext of the file agents-api/src/middleware/runAuth.ts of the co…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-4802 | Cockpit-HQ Cockpit System Logs User Interface os command injection

A vulnerability categorized as critical has been discovered in Cockpit-HQ Cockpit . This issue affects some unknown processing of the component System Logs User Interface . Executing a manipulation ca…

VulDB Read →
⬡ Vulnerabilities & CVEs May 11, 2026
CVE-2026-7818 | pgAdmin 4 up to 9.14 FileBackedSessionManager path traversal

A vulnerability identified as critical has been detected in pgAdmin 4 up to 9.14 . Impacted is an unknown function of the component FileBackedSessionManager . The manipulation leads to path traversal.…

VulDB Read →
◉ Threat Intelligence May 11, 2026
The State of Ransomware – Q1 2026

Key Findings Ransomware in Q1 2026: Consolidation at Scale During the first quarter of 2026, we monitored more than 70 active data leak sites (DLS) that collectively listed 2,122 new victims. This fig…

Check Point Research Read →
◉ Threat Intelligence May 11, 2026
11th May – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 11th May, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Instructure, the US education technology company behin…

Check Point Research Read →
◉ Threat Intelligence May 11, 2026
GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access

Executive Summary Since our February 2026 report on AI-related threat activity, Google Threat Intelligence Group (GTIG) has continued to track a maturing transition from nascent AI-enabled operations …

Mandiant Read →
← Prev 129 / 915 Next →