A vulnerability classified as problematic has been found in Tinybeans Private Family Album App 5.9.5-prod . This affects an unknown part. Performing a manipulation results in Local Privilege Escalatio…
cyberintel.kalymoon.com · 48213 articles · updated every 4 hours · grows forever
A vulnerability classified as problematic has been found in Tinybeans Private Family Album App 5.9.5-prod . This affects an unknown part. Performing a manipulation results in Local Privilege Escalatio…
A vulnerability classified as problematic was found in libinput . This vulnerability affects unknown code. Executing a manipulation can lead to expired pointer dereference. This vulnerability is handl…
A vulnerability, which was classified as critical , has been found in libinput . This issue affects some unknown processing of the component Lua Handler . The manipulation leads to code injection. Thi…
A vulnerability, which was classified as problematic , was found in pymanager up to 26.0 . Impacted is an unknown function of the component Working Directory Handler . The manipulation results in an u…
A vulnerability has been found in SourceCodester Pharmacy Product Management System 1.0 and classified as critical . The affected element is an unknown function of the file add-sales.php . This manipu…
A vulnerability was found in SourceCodester Loan Management System 1.0 and classified as problematic . The impacted element is an unknown function of the component Loan Plans Handler . Such manipulati…
A vulnerability was found in Ora Tools PDF Reader App 4.3.5 . It has been classified as critical . This affects an unknown function. Performing a manipulation results in improper access controls. This…
A vulnerability was found in Devolutions Server up to 2026.1.11 . It has been declared as critical . This impacts an unknown function of the component OAuth Login . Executing a manipulation can lead t…
Today, most malware are called “fileless†because they try to reduce their footprint on the infected computer filesystem to the bare minimum. But they need to write something… think about persis…
This is the fifth update to the TeamPCP supply chain campaign threat intelligence report, "When the Security Scanner Became the Weapon" (v3.0, March 25, 2026). Update 004 covered developments through …
Expect Fallout After Remote Access Trojan Added to Popular JavaScript NPM Package A supply-chain attack backdoored versions of Axios, a popular JavaScript library that's present in many different soft…
A sophisticated backdoor called EtherRAT is actively targeting organizations across multiple sectors by hiding its command infrastructure inside the Ethereum blockchain — a move that makes it uniquely…
Beginning April 6, 2026, HSBC India will require its internet banking customers to enter their passwords in uppercase letters only. The mandate, communicated via official customer emails, has sparked …
Google has released an emergency security update for its Chrome browser, patching a zero-day vulnerability that is already being actively exploited in the wild. The Stable channel has been updated to …
A newly disclosed Russian-linked remote access toolkit called “CTRL” is being used to hijack Remote Desktop Protocol sessions and steal credentials from Windows systems. According to Censys ARC, the m…
A recent cybersecurity study reveals that threat actors are moving faster than ever to weaponize new software flaws. According to data collected from a high-interaction honeypot, hackers are actively …
Artificial intelligence agents are rapidly becoming integral to enterprise workflows, but they also introduce new attack surfaces. Security researchers recently uncovered a significant vulnerability w…
Chinese state-backed group TA416 had suspended its cyber espionage operations in Europe since 2023, noted Proofpoint
Venom Stealer malware-as-a-service automates ClickFix social engineering, credential and crypto exfiltration
The following CIS Benchmarks and CIS Build Kits have been updated or recently released. The Center for Internet Security has highlighted the major updates below. Each Benchmark and Build Kit includes …
Exabeam has announced the expansion of Exabeam Agent Behavior Analytics (ABA). Without direct visibility into how employees use AI assistants, what they query, what data they share, how frequently the…
The software supply chain attack that resulted in the compromise of npm packages of Axios, an extremely popular HTTP client library, is believed to be the work of financially-motivated North Korean at…
Join the webcast as we explore what Agentic AI can and cannot solve today, and real world breach scenarios linked to disconnected applications. The post Webinar Today: Agentic AI vs. Identity’s Last M…