A vulnerability, which was classified as critical , has been found in Endian Firewall 3.3.25 . This affects the function Open of the file /cgi-bin/logs_log.cgi of the component Regular Expression Hand…
cyberintel.kalymoon.com · 47808 articles · updated every 4 hours · grows forever
A vulnerability, which was classified as critical , has been found in Endian Firewall 3.3.25 . This affects the function Open of the file /cgi-bin/logs_log.cgi of the component Regular Expression Hand…
A vulnerability, which was classified as critical , was found in Endian Firewall 3.3.25 . This impacts the function Open of the file /cgi-bin/logs_firewall.cgi of the component Regular Expression Hand…
A vulnerability has been found in Endian Firewall 3.3.25 and classified as critical . Affected is the function Open of the file /cgi-bin/logs_smtp.cgi of the component Regular Expression Handler . Per…
A vulnerability was found in Endian Firewall 3.3.25 and classified as problematic . Affected by this vulnerability is an unknown functionality of the file /manage/dhcp/fixed_leases/ of the component P…
A vulnerability was found in Endian Firewall 3.3.25 . It has been classified as problematic . Affected by this issue is some unknown functionality of the file /cgi-bin/salearn.cgi of the component Par…
Written by: Stuart Carrera Introduction Building on recent BRICKSTORM research from Google Threat Intelligence Group (GTIG), this post explores the evolving threats facing virtualized environments. Th…
This report provides an overview of trends and developments in the cybercriminal ecosystem of Latin America and the Caribbean (LAC) in 2025.
From its GitHub repo: "Vite (French word for "quick", pronounced /vi?t/, like "veet") is a new breed of frontend build tooling that significantly improves the frontend development experience" [https:/…
A widely used JavaScript library called Axios was at the center of a serious supply chain attack that came to light on March 31, 2026. Two updated versions of the Axios npm package — version 1.14.1 an…
A dangerous Android rootkit named NoVoice has been hiding inside over 50 apps on Google Play, compromising more than 2.3 million devices worldwide. Tracked as Operation NoVoice, the malware uses 22 ex…
A critical warning has been issued over a newly discovered zero-day vulnerability in Google Chrome, raising serious concerns for users worldwide. This flaw is actively exploited in the wild, allowing …
A seemingly routine procurement email has become the entry point for a sophisticated six-stage malware attack targeting industrial suppliers and procurement teams. The campaign, tracked as NKFZ5966PUR…
The OpenSSH project released version 10.3 and 10.3p1 on April 2, 2026, addressing a shell injection vulnerability and introducing several security-hardening changes that administrators should review b…
Qilin ransomware group is deploying a sophisticated, multi-stage infection chain via a malicious msimg32.dll that can disable over 300 endpoint detection and response (EDR) drivers from virtually ever…
LNK files use GitHub C2, embedded decoders and PowerShell for persistence and data exfiltration
Halcyon says Akira is now capable of carrying out an entire ransomware attack in less than an hour
iOS/iPadOS 18.7.7 updates expanded to protect older devices from DarkSword web exploit kit
The UK’s cybersecurity agency offered advice to “high-risk’ individuals” on how to protect against social engineering and cyber-attacks
This modern infostealer adopted server-side decryption of stolen credentials to bypass security controls
A new phishing-as-a-service (PhaaS) campaign is abusing Microsoft’s device code authentication flow to gain unauthorized access to user accounts. Sekoia researchers first spotted the toolkit “EvilToke…
The bugs could lead to authentication bypass, remote code execution, information disclosure, and privilege escalation. The post Cisco Patches Critical and High-Severity Vulnerabilities appeared first …
Significant cybersecurity M&A deals announced by Airbus, Cellebrite, Databricks, Quantum eMotion, Rapid7, and OpenAI. The post Cybersecurity M&A Roundup: 38 Deals Announced in March 2026 appeared firs…
Augmented Marauder's multipronged banking-Trojan cyber campaigns are targeting Spanish speakers, evading detection, and replicating rapidly.
AI-driven threats, global leadership shifts, and the future of cybersecurity in a rapidly evolving landscape were among the discussions at RSAC 2026 Conference.