CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  46294 articles  ·  updated every 4 hours · grows forever

46294Total
32284Full Text
Aug 21, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2025-58920 | Zootemplate Cerato Plugin up to 2.2.18 on WordPress cross site scripting

A vulnerability, which was classified as problematic , has been found in Zootemplate Cerato Plugin up to 2.2.18 on WordPress. Affected by this issue is some unknown functionality. The manipulation lea…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-40217 | BerriAI LiteLLM test_custom_code unprotected alternate channel

A vulnerability, which was classified as critical , was found in BerriAI LiteLLM bb0639701796218a3447160e55c0f1097446e4e6085df7dfd39f476d4143743f . This affects an unknown part of the file /guardrails…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-36235 | itsourcecode Online Student Enrollment System 1.0 scheduleSubList.php subjcode sql injection

A vulnerability has been found in itsourcecode Online Student Enrollment System 1.0 and classified as critical . This vulnerability affects unknown code of the file scheduleSubList.php . This manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-29861 | PHP-MYSQL-User-Login-System 1.0 login.php Username sql injection

A vulnerability was found in PHP-MYSQL-User-Login-System 1.0 and classified as critical . This issue affects some unknown processing of the file login.php . Such manipulation of the argument Username …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-36234 | itsourcecode Online Student Enrollment System 1.0 newCourse.php coursename sql injection

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0 . It has been classified as critical . Impacted is an unknown function of the file newCourse.php . Performing a manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-23780 | BMC Control-M MFT up to 9.0.22 API Debug Interface path traversal

A vulnerability was found in BMC Control-M MFT up to 9.0.22 . It has been declared as critical . The affected element is an unknown function of the component API Debug Interface . Executing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-36232 | itsourcecode Online Student Enrollment System 1.0 instructorClasses.php classId sql injection

A vulnerability was found in itsourcecode Online Student Enrollment System 1.0 . It has been rated as critical . The impacted element is an unknown function of the file instructorClasses.php . The man…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-36236 | SourceCodester Engineers Online Portal 1.0 update_password.php new_password sql injection

A vulnerability categorized as critical has been discovered in SourceCodester Engineers Online Portal 1.0 . This affects an unknown function of the file update_password.php . The manipulation of the a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-36233 | itsourcecode Online Student Enrollment System 1.0 assignInstructorSubjects.php subjcode sql injection

A vulnerability identified as critical has been detected in itsourcecode Online Student Enrollment System 1.0 . This impacts an unknown function of the file assignInstructorSubjects.php . This manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-23782 | BMC Control-M MFT 9.0.20/9.0.21/9.0.22 API Management Endpoint improper authentication

A vulnerability labeled as critical has been found in BMC Control-M MFT 9.0.20/9.0.21/9.0.22 . Affected is an unknown function of the component API Management Endpoint . Such manipulation leads to imp…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-31262 | Altenar Sportsbook Software Platform 2.0 URL Parameter cross site scripting

A vulnerability marked as problematic has been reported in Altenar Sportsbook Software Platform 2.0 . Affected by this vulnerability is an unknown functionality of the component URL Parameter Handler …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2025-44560 | owntone-server 2ca10d9 buffer overflow (Issue 1873)

A vulnerability described as critical has been identified in owntone-server 2ca10d9 . Affected by this issue is some unknown functionality. Executing a manipulation can lead to buffer overflow. This v…

VulDB Read →
◇ Industry News & Leadership Apr 10, 2026
Turning Military Experience Into Cyber Advantage

Operational Discipline and Judgment Are Critical in Managing Cyber Risk Transitioning from armed forces can feel like stepping into unfamiliar terrain. Nowhere is this perception stronger than in cybe…

Data Breach Today Read →
◇ Industry News & Leadership Apr 10, 2026
Hackers Abuse GitHub and GitLab to Host Malware and Credential Phishing Campaigns

Cybercriminals are now turning two of the most trusted developer platforms in the world — GitHub and GitLab — into tools for spreading malware and stealing login credentials from unsuspecting users. S…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 10, 2026
AI Router Vulnerabilities Allow Attackers to Inject Malicious Code and Steal Sensitive Data

A critical and largely overlooked attack surface in the AI agent ecosystem, third-party API routers that can be weaponized to silently hijack tool calls, drain cryptocurrency wallets, and exfiltrate s…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 10, 2026
Hackers Impersonate Secure Messaging Apps to Deploy ProSpy in Middle East Espionage Attacks

A targeted mobile espionage campaign has been quietly operating across the Middle East since at least 2022, using fake versions of widely trusted secure messaging apps to plant a powerful Android spyw…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 10, 2026
HPE Aruba Private 5G Platform Vulnerability Enables Credential Theft Attacks

Hewlett-Packard Enterprise (HPE) has disclosed a security flaw in its Aruba Networking Private 5G Core On-Prem platform. This vulnerability allows attackers to steal user credentials by exploiting an …

Cybersecurity News Read →
◇ Industry News & Leadership Apr 10, 2026
Hackers Exploit GitHub Copilot Flaw to Exfiltrate Sensitive Data

A recently disclosed high-severity vulnerability in GitHub Copilot Chat allowed attackers to silently siphon sensitive data from private repositories. Tracked as CVE-2025-59145 with a near-perfect CVS…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 10, 2026
Censys Warns 5,219 Rockwell/Allen-Bradley PLCs Are Exposed Amid Iranian APT Activity

The FBI, CISA, NSA, EPA, DOE, and U.S. Cyber Command jointly disclosed on April 7, 2026, that Iranian-affiliated advanced persistent threat (APT) actors are actively targeting internet-facing Rockwell…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 10, 2026
Hackers Use Fake BTS World Tour Ticket Sites to Scam Fans Across Multiple Countries

Cybercriminals are capitalizing on the excitement around BTS’s long-awaited return to the world stage by setting up fraudulent ticket websites that steal money from unsuspecting fans. The campaign has…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 10, 2026
Hungarian government email passwords exposed ahead of election

When voters in the forthcoming Hungarian election assess the current government, its record on internet security will not be one of its proudest achievements. An analysis by open source investigation …

CSO Online Read →
◇ Industry News & Leadership Apr 10, 2026
Hacker Unknown now known, named on Europol’s most-wanted list

German police have pinned a name to one of the world’s most notorious hackers. Danii Shchukin operated under the names of UNKN or Unknown and GandCrab and was, according to German police, the leader o…

CSO Online Read →
◇ Industry News & Leadership Apr 10, 2026
ClickFix campaign delivers Mac malware via fake Apple page

Security researchers at Jamf have uncovered a new ClickFix-style attack targeting Mac users via a fake Apple-themed webpage offering instructions on how to “reclaim disk space on your Mac”. The malici…

Help Net Security Read →
◇ Industry News & Leadership Apr 10, 2026
Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback Friday

The US government has warned that Iran-linked hackers are manipulating PLCs and SCADA systems to cause disruption. The post Industry Reactions to Iran Hacking ICS in Critical Infrastructure: Feedback …

Security Week Read →
← Prev 1419 / 1929 Next →