CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  47735 articles  ·  updated every 4 hours · grows forever

47735Total
32950Full Text
Aug 26, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34835 | Rack up to 3.1.20/3.2.5 Regular Expression Rack::Request improper validation of syntactic correctness of input

A vulnerability marked as problematic has been reported in Rack up to 3.1.20/3.2.5 . Impacted is the function Rack::Request of the component Regular Expression Handler . The manipulation leads to impr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-35387 | OpenSSH up to 10.2 control flow

A vulnerability described as problematic has been identified in OpenSSH up to 10.2 . The affected element is an unknown function. The manipulation results in incorrect control flow. This vulnerability…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-35386 | OpenSSH up to 10.2 Command Line ssh_config incorrect behavior order

A vulnerability classified as problematic has been found in OpenSSH up to 10.2 . The impacted element is the function ssh_config of the component Command Line Handler . This manipulation causes incorr…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-26962 | Rack up to 3.2.5 HTTP Response Header Rack::Multipart crlf injection

A vulnerability classified as problematic was found in Rack up to 3.2.5 . This affects the function Rack::Multipart of the component HTTP Response Header Handler . Such manipulation leads to crlf inje…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34119 | TP-Link Tapo C520WS 2.6 HTTP Parser heap-based overflow

A vulnerability, which was classified as critical , has been found in TP-Link Tapo C520WS 2.6 . This impacts an unknown function of the component HTTP Parser . Performing a manipulation results in hea…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34118 | TP-Link Tapo C520WS 2.6 heap-based overflow (EUVD-2026-18426)

A vulnerability, which was classified as critical , was found in TP-Link Tapo C520WS 2.6 . Affected is an unknown function. Executing a manipulation can lead to heap-based buffer overflow. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34124 | TP-Link Tapo C520WS 2.6 HTTP buffer overflow

A vulnerability has been found in TP-Link Tapo C520WS 2.6 and classified as critical . Affected by this vulnerability is an unknown functionality of the component HTTP Handler . The manipulation leads…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-35388 | OpenSSH up to 10.2 Proxy-mode Multiplexing Session unprotected alternate channel

A vulnerability was found in OpenSSH up to 10.2 and classified as problematic . Affected by this issue is some unknown functionality of the component Proxy-mode Multiplexing Session Handler . The mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34121 | TP-Link Tapo C520WS 2.6 HTTP improper authentication (EUVD-2026-18432)

A vulnerability was found in TP-Link Tapo C520WS 2.6 . It has been classified as critical . This affects an unknown part of the component HTTP Handler . This manipulation causes improper authenticatio…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34577 | gitroomhq postiz-app up to 2.21.2 Endpoint /public/stream server-side request forgery

A vulnerability was found in gitroomhq postiz-app up to 2.21.2 . It has been declared as critical . This vulnerability affects unknown code of the file /public/stream of the component Endpoint . Such …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34122 | TP-Link Tapo C520WS 2.6 Configuration Parameter stack-based overflow (EUVD-2026-18434)

A vulnerability was found in TP-Link Tapo C520WS 2.6 . It has been rated as critical . This issue affects some unknown processing of the component Configuration Parameter Handler . Performing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34524 | SillyTavern up to 1.16.x Chat Endpoint secrets.json avatar_url path traversal

A vulnerability categorized as critical has been discovered in SillyTavern up to 1.16.x . Impacted is an unknown function of the file secrets.json of the component Chat Endpoint . Executing a manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34522 | SillyTavern up to 1.16.x /api/chats/import character_name path traversal

A vulnerability identified as critical has been detected in SillyTavern up to 1.16.x . The affected element is an unknown function of the file /api/chats/import . The manipulation of the argument char…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34576 | gitroomhq postiz-app up to 2.21.2 upload-from-url axios.get server-side request forgery

A vulnerability labeled as critical has been found in gitroomhq postiz-app up to 2.21.2 . The impacted element is the function axios.get of the file /public/v1/upload-from-url . The manipulation resul…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34523 | SillyTavern up to 1.16.x path traversal

A vulnerability marked as critical has been reported in SillyTavern up to 1.16.x . This affects an unknown function. This manipulation causes path traversal. This vulnerability is tracked as CVE-2026-…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-34120 | TP-Link Tapo C520WS 2.6 heap-based overflow (EUVD-2026-18430)

A vulnerability described as critical has been identified in TP-Link Tapo C520WS 2.6 . This impacts an unknown function. Such manipulation leads to heap-based buffer overflow. This vulnerability is li…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-27774 | Acronis True Image up to 42389 uncontrolled search path (EUVD-2026-18418)

A vulnerability classified as problematic has been found in Acronis True Image up to 42389 . Affected is an unknown function. Performing a manipulation results in uncontrolled search path. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-28728 | Acronis True Image up to 42389 uncontrolled search path (EUVD-2026-18420)

A vulnerability classified as problematic was found in Acronis True Image up to 42389 . Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to uncontrolled se…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 02, 2026
CVE-2026-33271 | Acronis True Image up to 42389 permission assignment (EUVD-2026-18424)

A vulnerability, which was classified as critical , has been found in Acronis True Image up to 42389 . Affected by this issue is some unknown functionality. The manipulation leads to incorrect permiss…

VulDB Read →
◉ Threat Intelligence Apr 02, 2026
Cookie-controlled PHP webshells: A stealthy tradecraft in Linux hosting environments

Cookie-gated PHP webshells use obfuscation, php-fpm execution, and cron-based persistence to evade detection in Linux hosting environments. This post examines how this tradecraft conceals execution be…

Microsoft Security Read →
◉ Threat Intelligence Apr 02, 2026
Threat actor abuse of AI accelerates from tool to cyberattack surface

Generative AI is upgrading cyberattacks, from 450% higher phishing click‑through rates to industrialized MFA bypass. The post Threat actor abuse of AI accelerates from tool to cyberattack surface appe…

Microsoft Security Read →
◇ Industry News & Leadership Apr 02, 2026
Hasbro Systems Nerfed by Data Breach; IT Recovery Underway

Transformers, Peppa Pig Toymaker Forecasts Delays, Says Product Shipping Continues Toymaker Hasbro said its IT systems have been breached, leading to data being stolen and some operations being disrup…

Data Breach Today Read →
◇ Industry News & Leadership Apr 02, 2026
Reengineering AML in the Era of Instant Payments

Financial Institutions Are Rethinking Controls to Ensure Frictionless Transactions When the Federal Reserve lifted FedNow's transaction limit from $1 million to $10 million last November, the regulato…

Data Breach Today Read →
◇ Industry News & Leadership Apr 02, 2026
New Akira Lookalike Ransomware Campaign Targeting Windows Users in South America

A new and dangerous ransomware campaign has surfaced across South America, targeting Windows users with a carefully crafted strain that closely imitates the well-known Akira ransomware. While the two …

Cybersecurity News Read →
← Prev 1591 / 1989 Next →