CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  46355 articles  ·  updated every 4 hours · grows forever

46355Total
32315Full Text
Aug 21, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-5446 | wolfSSL up to 5.9.0 wc_AriaEncrypt nonce re-use

A vulnerability identified as critical has been detected in wolfSSL up to 5.9.0 . Affected by this vulnerability is the function wc_AriaEncrypt . This manipulation causes reusing a nonce. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-40151 | MervinPraison PraisonAI up to 4.5.127 /api/agents allow_origins information disclosure (GHSA-pm96-6xpr-978x)

A vulnerability labeled as problematic has been found in MervinPraison PraisonAI up to 4.5.127 . Affected by this issue is the function allow_origins of the file /api/agents . Such manipulation leads …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-5447 | wolfSSL up to 5.9.0 heap-based overflow

A vulnerability marked as critical has been reported in wolfSSL up to 5.9.0 . This affects an unknown part. Performing a manipulation results in heap-based buffer overflow. This vulnerability is repor…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-35629 | OpenClaw up to 2026.3.24 Destination fetch server-side request forgery (GHSA-rhfg-j8jq-7v2h)

A vulnerability described as critical has been identified in OpenClaw up to 2026.3.24 . This vulnerability affects the function fetch of the component Destination Handler . Executing a manipulation ca…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-35645 | OpenClaw up to 2026.3.24 operator.admin incorrect privileged apis (GHSA-h4jx-hjr3-fhgc)

A vulnerability classified as problematic has been found in OpenClaw up to 2026.3.24 . This issue affects the function operator.admin . The manipulation leads to incorrect use of privileged apis. This…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-40115 | MervinPraison PraisonAI up to 4.5.127 Recipe Registry server.py allocation of resources (GHSA-2xgv-5cv2-47vv)

A vulnerability classified as problematic was found in MervinPraison PraisonAI up to 4.5.127 . Impacted is an unknown function of the file server.py of the component Recipe Registry Handler . The mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-40150 | MervinPraison PraisonAIAgents up to 1.5.127 web_crawl_tools.py server-side request forgery (GHSA-8f4v-xfm9-3244)

A vulnerability, which was classified as critical , has been found in MervinPraison PraisonAIAgents up to 1.5.127 . The affected element is an unknown function of the file praisonaiagents/tools/web_cr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-35634 | OpenClaw up to 2026.3.22 authorizeCanvasRequest authentication bypass (GHSA-6mqc-jqh6-x8fc)

A vulnerability, which was classified as critical , was found in OpenClaw up to 2026.3.22 . The impacted element is the function authorizeCanvasRequest . Such manipulation leads to authentication bypa…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-40148 | MervinPraison PraisonAI up to 4.5.127 _safe_extractall data amplification (GHSA-f2h6-7xfr-xm8w)

A vulnerability has been found in MervinPraison PraisonAI up to 4.5.127 and classified as problematic . This affects the function _safe_extractall . Performing a manipulation results in highly compres…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-5264 | wolfSSL up to 5.9.0 DTLS heap-based overflow

A vulnerability was found in wolfSSL up to 5.9.0 and classified as critical . This impacts an unknown function of the component DTLS Handler . Executing a manipulation can lead to heap-based buffer ov…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-4482 | Rapid7 Insight Agent up to 3.3.0 on Windows Certificate …/bootstrap/common/ssl permission assignment

A vulnerability was found in Rapid7 Insight Agent up to 3.3.0 on Windows. It has been classified as problematic . Affected is an unknown function of the file …/bootstrap/common/ssl of the component Ce…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-5477 | wolfSSL up to 5.9.0 Message wc_CmacUpdate integer overflow (EUVD-2026-21305)

A vulnerability was found in wolfSSL up to 5.9.0 . It has been declared as critical . Affected by this vulnerability is the function wc_CmacUpdate of the component Message Handler . The manipulation r…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-4432 | YITH WooCommerce Wishlist Plugin up to 4.12.x on WordPress AJAX /wishlist/ save_title authorization

A vulnerability was found in YITH WooCommerce Wishlist Plugin up to 4.12.x on WordPress. It has been rated as critical . Affected by this issue is the function save_title of the file /wishlist/ of the…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-28704 | Emocheck uncontrolled search path

A vulnerability categorized as problematic has been discovered in Japan Computer Emergency Response Team Coordination Center Emocheck . This affects an unknown part. Such manipulation leads to uncontr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2025-14545 | YML for Yandex Market Plugin up to 5.0.25 on WordPress code injection

A vulnerability identified as critical has been detected in YML for Yandex Market Plugin up to 5.0.25 on WordPress. This vulnerability affects unknown code. Performing a manipulation results in code i…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 10, 2026
CVE-2026-1115 | parisneo lollms up to 2.1.x __init__.py create_post cross site scripting

A vulnerability labeled as problematic has been found in parisneo lollms up to 2.1.x . This issue affects the function create_post of the file backend/routers/social/__init__.py . Executing a manipula…

VulDB Read →
◉ Threat Intelligence Apr 10, 2026
Obfuscated JavaScript or Nothing, (Thu, Apr 9th)

I spotted an interesting piece of JavaScript code that was delivered via a phishing email in a RAR archive. The file was called “cbmjlzan.JS” (SHA256:a8ba9ba93b4509a86e3d7dd40fd0652c2743e32277760c…

SANS ISC Read →
◇ Industry News & Leadership Apr 10, 2026
AWS Patches Critical RCE and Escalate Privileges in Research and Engineering Studio

Amazon Web Services (AWS) has released an important security bulletin addressing three severe vulnerabilities in its Research and Engineering Studio (RES). These flaws could allow authenticated attack…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 10, 2026
Single Line of Code Can jailbreak 11 AI models Including ChatGPT, Claude, and Gemini

A newly detailed jailbreak technique known as “sockpuppeting” allows attackers to bypass the safety guardrails of 11 major large language models (LLMs) using a single line of code. Unlike complex atta…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 10, 2026
Hackers Use SVG Onload Trick to Hide Magecart Skimmer on Magento Checkout Pages

A massive Magecart campaign compromising 99 Magento e-commerce stores using an innovative evasion technique. Discovered on April 7, 2026, the attack relies on invisible Scalable Vector Graphics (SVG) …

Cybersecurity News Read →
◇ Industry News & Leadership Apr 10, 2026
React Server Components Vulnerability Enables DoS Attacks

A high-severity vulnerability has been discovered in React Server Components, exposing modern web applications to Denial of Service (DoS) attacks. Tracked as CVE-2026-23869, this flaw allows unauthent…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 10, 2026
DesckVB RAT Uses Obfuscated JavaScript and Fileless .NET Loader to Evade Detection

A new Remote Access Trojan known as DesckVB has been targeting systems in 2026, using obfuscated JavaScript and a fileless .NET loader to stay hidden from traditional security tools. The malware gives…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 10, 2026
Juniper Networks Default Password Vulnerability Let Attacker Take Full Control of the Device

A critical security alert warns of a severe default password vulnerability affecting Support Insights Virtual Lightweight Collector (vLWC) appliances. This flaw enables unauthenticated network-based a…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 10, 2026
New infosec products of the week: April 10, 2026

Here’s a look at the most interesting products from the past week, featuring releases from Advenica, Intruder, Mallory, and Secureframe. Mallory brings contextual threat intelligence to security opera…

Help Net Security Read →
← Prev 1426 / 1932 Next →