CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  46885 articles  ·  updated every 4 hours · grows forever

46885Total
32537Full Text
Aug 24, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-37977 | Keycloak on Red Hat JWT azp origin validation (EUVD-2026-19201)

A vulnerability classified as problematic has been found in Keycloak on Red Hat. This vulnerability affects unknown code of the component JWT Handler . This manipulation of the argument azp causes ori…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5676 | Totolink A8000R 5.9c.681_B20180413 /cgi-bin/cstecgi.cgi setLanguageCfg langType missing authentication

A vulnerability classified as critical was found in Totolink A8000R 5.9c.681_B20180413 . This issue affects the function setLanguageCfg of the file /cgi-bin/cstecgi.cgi . Such manipulation of the argu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5677 | Totolink A7100RU 7.4cu.2313_b20191024 /cgi-bin/cstecgi.cgi CsteSystem resetFlags os command injection

A vulnerability, which was classified as critical , has been found in Totolink A7100RU 7.4cu.2313_b20191024 . Impacted is the function CsteSystem of the file /cgi-bin/cstecgi.cgi . Performing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5678 | Totolink A7100RU 7.4cu.2313_b20191024 /cgi-bin/cstecgi.cgi setScheduleCfg mode os command injection

A vulnerability, which was classified as critical , was found in Totolink A7100RU 7.4cu.2313_b20191024 . The affected element is the function setScheduleCfg of the file /cgi-bin/cstecgi.cgi . Executin…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5679 | Totolink A3300R 17.0.0cu.557_B20221024 /cgi-bin/cstecgi.cgi vsetTr069Cfg stun_pass os command injection

A vulnerability has been found in Totolink A3300R 17.0.0cu.557_B20221024 and classified as critical . The impacted element is the function vsetTr069Cfg of the file /cgi-bin/cstecgi.cgi . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5673 | libtheora AVI File Parser avi_parse_input_file out-of-bounds

A vulnerability was found in libtheora and classified as problematic . This affects the function avi_parse_input_file of the component AVI File Parser . The manipulation results in out-of-bounds read.…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5681 | itsourcecode sanitize or validate this input 1.0 Parameter /borrowedequip.php emp_id sql injection

A vulnerability was found in itsourcecode sanitize or validate this input 1.0 . It has been classified as critical . This impacts an unknown function of the file /borrowedequip.php of the component Pa…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5682 | Meesho Online Shopping App up to 27.3 on Android com.meesho.supply /api/endpoint risky encryption

A vulnerability was found in Meesho Online Shopping App up to 27.3 on Android. It has been declared as problematic . Affected is an unknown function of the file /api/endpoint of the component com.mees…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5683 | Tenda CX12L 16.03.53.12 /goform/P2pListFilter fromP2pListFilter page stack-based overflow

A vulnerability was found in Tenda CX12L 16.03.53.12 . It has been rated as critical . Affected by this vulnerability is the function fromP2pListFilter of the file /goform/P2pListFilter . Performing a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5684 | Tenda CX12L 16.03.53.12 webExcptypemanFilter fromwebExcptypemanFilter page stack-based overflow

A vulnerability categorized as critical has been discovered in Tenda CX12L 16.03.53.12 . Affected by this issue is the function fromwebExcptypemanFilter of the file /goform/webExcptypemanFilter . Exec…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5685 | Tenda CX12L 16.03.53.12 /goform/addressNat fromAddressNat page stack-based overflow

A vulnerability identified as critical has been detected in Tenda CX12L 16.03.53.12 . This affects the function fromAddressNat of the file /goform/addressNat . The manipulation of the argument page le…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5686 | Tenda CX12L 16.03.53.12 /goform/RouteStatic fromRouteStatic page stack-based overflow

A vulnerability labeled as critical has been found in Tenda CX12L 16.03.53.12 . This vulnerability affects the function fromRouteStatic of the file /goform/RouteStatic . The manipulation of the argume…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5687 | Tenda CX12L 16.03.53.12 /goform/NatStaticSetting fromNatStaticSetting page stack-based overflow

A vulnerability marked as critical has been reported in Tenda CX12L 16.03.53.12 . This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting . This manipulation of the a…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5688 | Totolink A7100RU 7.4cu.2313_b20191024 /cgi-bin/cstecgi.cgi setDdnsCfg provider os command injection

A vulnerability described as critical has been identified in Totolink A7100RU 7.4cu.2313_b20191024 . Impacted is the function setDdnsCfg of the file /cgi-bin/cstecgi.cgi . Such manipulation of the arg…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5689 | Totolink A7100RU 7.4cu.2313_b20191024 /cgi-bin/cstecgi.cgi setNtpCfg tz os command injection

A vulnerability classified as critical has been found in Totolink A7100RU 7.4cu.2313_b20191024 . The affected element is the function setNtpCfg of the file /cgi-bin/cstecgi.cgi . Performing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5690 | Totolink A7100RU 7.4cu.2313_b20191024 /cgi-bin/cstecgi.cgi setRemoteCfg enable os command injection

A vulnerability classified as critical was found in Totolink A7100RU 7.4cu.2313_b20191024 . The impacted element is the function setRemoteCfg of the file /cgi-bin/cstecgi.cgi . Executing a manipulatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5691 | Totolink A7100RU 7.4cu.2313_b20191024 /cgi-bin/cstecgi.cgi setFirewallType firewallType os command injection

A vulnerability, which was classified as critical , has been found in Totolink A7100RU 7.4cu.2313_b20191024 . This affects the function setFirewallType of the file /cgi-bin/cstecgi.cgi . The manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 06, 2026
CVE-2026-5692 | Totolink A7100RU 7.4cu.2313_b20191024 /cgi-bin/cstecgi.cgi setGameSpeedCfg enable os command injection

A vulnerability, which was classified as critical , was found in Totolink A7100RU 7.4cu.2313_b20191024 . This impacts the function setGameSpeedCfg of the file /cgi-bin/cstecgi.cgi . The manipulation o…

VulDB Read →
◉ Threat Intelligence Apr 06, 2026
6th April – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 30th March, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The European Commission, the European Union’s execut…

Check Point Research Read →
◉ Threat Intelligence Apr 06, 2026
How often are redirects used in phishing in 2026?, (Mon, Apr 6th)

In one of his recent diaries, Johannes discussed how open redirects are actively being sought out by threat actors[1], which made me wonder about how commonly these mechanisms are actually misused…

SANS ISC Read →
◇ Industry News & Leadership Apr 06, 2026
Hackers Using Fake “Microsoft Teams” Domains to Attack Users Via Malicious Payload

Cybercriminals are launching a sophisticated new wave of attacks using fake Microsoft Teams domains. According to recent threat intelligence shared by SEAL Org, hackers are actively tricking corporate…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 06, 2026
Critical Claude Code Flaw Silently Bypasses Developer-Configured Security Rules

A high-severity security bypass vulnerability in Anthropic’s Claude Code AI coding agent allows malicious actors to silently evade user-configured deny rules through a simple command-padding technique…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 06, 2026
Hackers Use Poisoned Axios Package and Phantom Dependency to Spread Cross-Platform Malware

One of the most widely used JavaScript libraries in the world was turned into a weapon on March 30, 2026, when attackers poisoned the Axios npm package and silently deployed malware on developer machi…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 06, 2026
Hackers Compromised ILSpy WordPress Domain to Deliver Malware

A new supply chain attack targeting developers after threat actors compromised the official WordPress domain for ILSpy on April 6, 2026. Instead of providing the legitimate software, the hijacked webs…

Cybersecurity News Read →
← Prev 1516 / 1954 Next →