A vulnerability has been found in TP-Link Tapo C520WS 2.6 and classified as critical . Affected by this vulnerability is an unknown functionality of the component HTTP Handler . The manipulation leads…
cyberintel.kalymoon.com · 47777 articles · updated every 4 hours · grows forever
A vulnerability has been found in TP-Link Tapo C520WS 2.6 and classified as critical . Affected by this vulnerability is an unknown functionality of the component HTTP Handler . The manipulation leads…
A vulnerability was found in OpenSSH up to 10.2 and classified as problematic . Affected by this issue is some unknown functionality of the component Proxy-mode Multiplexing Session Handler . The mani…
A vulnerability was found in TP-Link Tapo C520WS 2.6 . It has been classified as critical . This affects an unknown part of the component HTTP Handler . This manipulation causes improper authenticatio…
A vulnerability was found in gitroomhq postiz-app up to 2.21.2 . It has been declared as critical . This vulnerability affects unknown code of the file /public/stream of the component Endpoint . Such …
A vulnerability was found in TP-Link Tapo C520WS 2.6 . It has been rated as critical . This issue affects some unknown processing of the component Configuration Parameter Handler . Performing a manipu…
A vulnerability categorized as critical has been discovered in SillyTavern up to 1.16.x . Impacted is an unknown function of the file secrets.json of the component Chat Endpoint . Executing a manipula…
A vulnerability identified as critical has been detected in SillyTavern up to 1.16.x . The affected element is an unknown function of the file /api/chats/import . The manipulation of the argument char…
A vulnerability labeled as critical has been found in gitroomhq postiz-app up to 2.21.2 . The impacted element is the function axios.get of the file /public/v1/upload-from-url . The manipulation resul…
A vulnerability marked as critical has been reported in SillyTavern up to 1.16.x . This affects an unknown function. This manipulation causes path traversal. This vulnerability is tracked as CVE-2026-…
A vulnerability described as critical has been identified in TP-Link Tapo C520WS 2.6 . This impacts an unknown function. Such manipulation leads to heap-based buffer overflow. This vulnerability is li…
A vulnerability classified as problematic has been found in Acronis True Image up to 42389 . Affected is an unknown function. Performing a manipulation results in uncontrolled search path. This vulner…
A vulnerability classified as problematic was found in Acronis True Image up to 42389 . Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to uncontrolled se…
A vulnerability, which was classified as critical , has been found in Acronis True Image up to 42389 . Affected by this issue is some unknown functionality. The manipulation leads to incorrect permiss…
Cookie-gated PHP webshells use obfuscation, php-fpm execution, and cron-based persistence to evade detection in Linux hosting environments. This post examines how this tradecraft conceals execution be…
Generative AI is upgrading cyberattacks, from 450% higher phishing click‑through rates to industrialized MFA bypass. The post Threat actor abuse of AI accelerates from tool to cyberattack surface appe…
Transformers, Peppa Pig Toymaker Forecasts Delays, Says Product Shipping Continues Toymaker Hasbro said its IT systems have been breached, leading to data being stolen and some operations being disrup…
Financial Institutions Are Rethinking Controls to Ensure Frictionless Transactions When the Federal Reserve lifted FedNow's transaction limit from $1 million to $10 million last November, the regulato…
A new and dangerous ransomware campaign has surfaced across South America, targeting Windows users with a carefully crafted strain that closely imitates the well-known Akira ransomware. While the two …
A threat group recently set up a convincing fake version of Ukraine’s official cybersecurity authority website to trick targets into downloading a dangerous remote access tool. The campaign, now track…
In a mature Security Operations Center, escalation is supposed to work like a scalpel, precise, intentional, and reserved for alerts that genuinely demand deeper expertise. But across many teams today…
Suspected China-nexus attackers have leveraged a zero-day vulnerability (CVE-2026-3502) in the TrueConf client application to distribute malware within government networks in Southeast Asia, Check Poi…
Apple has extended security updates to a wider range of devices still running iOS 18, aiming to protect users from the DarkSword exploit kit. This is not the first time Apple has backported fixes for …
Red Hat has announced Red Hat Enterprise Linux Extended Life Cycle Premium, a new subscription that provides a predictable 14-year life cycle for major Red Hat Enterprise Linux releases. This stand-al…
OpenSSH 10.3 shipped carrying five security fixes alongside feature additions and a set of behavior changes that will break compatibility with older SSH implementations that do not support rekeying. R…