A vulnerability classified as critical was found in Linux Kernel up to 6.18.16/6.19.6/7.0-rc1 . Impacted is an unknown function of the component amdxdna . Executing a manipulation of the argument Coun…
cyberintel.kalymoon.com · 47356 articles · updated every 4 hours · grows forever
A vulnerability classified as critical was found in Linux Kernel up to 6.18.16/6.19.6/7.0-rc1 . Impacted is an unknown function of the component amdxdna . Executing a manipulation of the argument Coun…
A vulnerability, which was classified as critical , has been found in Linux Kernel up to 6.18.16/6.19.6/7.0-rc1 . The affected element is the function pkvm_init_features_from_host of the component KVM…
A vulnerability, which was classified as critical , was found in Linux Kernel up to 7.0-rc1 . The impacted element is the function logicvc_drm_config_parse of the component logicvc . The manipulation …
A vulnerability has been found in Linux Kernel up to 6.18.16/6.19.6/7.0-rc2 and classified as critical . This affects the function wa_bb_store of the component configfs . This manipulation causes allo…
A vulnerability was found in Mattermost Focalboard up to 8.0 and classified as critical . This impacts an unknown function of the component Category Reorder API . Such manipulation leads to sql inject…
A vulnerability was found in Mattermost Focalboard up to 8.0 . It has been classified as problematic . Affected is an unknown function. Performing a manipulation results in authorization bypass. This …
This is the sixth update to the TeamPCP supply chain campaign threat intelligence report,&#;x26;#;xc2;&#;x26;#;xa0;"When the Security Scanner Became the Weapon"&#;x26;#;xc2;&#;x26;#;xa0;(v3.0, March 2…
A coordinated phishing campaign has been quietly targeting banking customers across the Philippines since early 2024, and it remains active today. The attackers are not relying on crude tricks — they …
Two malicious versions of the popular JavaScript HTTP library Axios were briefly published to the npm registry on March 31, 2026. Each version carried a hidden dependency that installed a remote acces…
A North Korean threat group known as Kimsuky has been caught running a cyberattack campaign that uses malicious Windows shortcut files, known as LNK files, to quietly install a Python-based backdoor o…
A large-scale credential theft campaign targeting senior executives has been linked to a previously unknown automated phishing platform called Venom
Cisco has fixed ten vulnerabilities affecting its Integrated Management Controller (IMC), the most critical of which (CVE-2026-20093) could allow an unauthenticated, remote attacker to bypass authenti…
The vulnerabilities can be chained together to bypass authentication and upload arbitrary files to the server. The post Critical ShareFile Flaws Lead to Unauthenticated RCE appeared first on SecurityW…
Other noteworthy stories that might have slipped under the radar: Symantec vulnerability, anti-ClickFix mechanism added to macOS, FBI hack classified as major incident. The post In Other News: ChatGPT…
A Chinese threat actor exploited the video conferencing platform to perform reconnaissance, escalate privileges, and execute additional payloads. The post TrueConf Zero-Day Exploited in Asian Governme…
Once CrowdStrike's nemesis, Microsoft is now a collaborator. A shared interest in Formula 1 helped thaw the years-long fierce rivalry.
The rebuilt Chainguard platform adds deeper security designed to continuously reconcile open-source artifacts across containers, libraries, Actions and skills.
Or, why the software supply chain should be treated as critical infrastructure with guardrails built in at every layer.
"Skull vibration harmonics generated by vital signs" can be used to sign in to VR, AR, and MR headsets, according to emerging research.
As organizations disclose breaches tied to TeamPCP's supply chain attacks, ShinyHunters and Lapsus$ are getting involved, taking credit, and creating a murky situation for enterprises.
The next major breach hitting your clients probably won't come from inside their walls. It'll come through a vendor they trust, a SaaS tool their finance team signed up for, or a subcontractor nobody …
The maintainer of the Axios npm package has confirmed that the supply chain compromise was the result of a highly-targeted social engineering campaign orchestrated by North Korean threat actors tracke…
Multi-extortion ransomware relies on stolen data to pressure victims with public leaks. Penta Security explains how its D.AMO platform keeps exfiltrated files encrypted and useless to attackers. [...]
AI Security Fundamentals (2026): Threats and Controls Blockchain Council