A vulnerability classified as critical was found in wevm mppx up to 0.4.10 . This impacts an unknown function. The manipulation results in authentication bypass by capture-replay. This vulnerability i…
cyberintel.kalymoon.com · 48485 articles · updated every 4 hours · grows forever
A vulnerability classified as critical was found in wevm mppx up to 0.4.10 . This impacts an unknown function. The manipulation results in authentication bypass by capture-replay. This vulnerability i…
A vulnerability, which was classified as problematic , has been found in wevm mppx up to 0.4.10 . Affected is an unknown function. This manipulation causes incorrect comparison. This vulnerability is …
A vulnerability, which was classified as critical , was found in OpenClaw up to 2026.3.27 . Affected by this vulnerability is an unknown functionality. Such manipulation leads to incorrect authorizati…
A vulnerability has been found in OpenClaw up to 2026.3.27 and classified as critical . Affected by this issue is some unknown functionality. Performing a manipulation results in incorrect authorizati…
A vulnerability was found in go-git up to 5.17.0 and classified as problematic . This affects an unknown part. Executing a manipulation can lead to improper validation of array index. This vulnerabili…
A vulnerability was found in ZcashFoundation zebra and zebra-chain . It has been classified as problematic . This vulnerability affects unknown code of the component Transaction ID Handler . The manip…
A vulnerability was found in labring FastGPT up to 4.14.7 . It has been declared as critical . This issue affects some unknown processing of the file /api/core/app/httpTools/runTool of the component E…
A vulnerability was found in OpenClaw up to 2026.3.27 . It has been rated as critical . Impacted is an unknown function. This manipulation causes incorrect authorization. This vulnerability appears as…
A vulnerability categorized as critical has been discovered in labring FastGPT up to 4.14.7 . The affected element is the function isInternalAddress of the file /api/core/app/mcpTools/getTools . Such …
A vulnerability identified as critical has been detected in OpenClaw up to 2026.3.23 . The impacted element is an unknown function. Performing a manipulation of the argument alias results in path trav…
A vulnerability labeled as critical has been found in Nhost up to 1.40.x . This affects an unknown function. Executing a manipulation can lead to missing authentication. This vulnerability is handled …
A vulnerability marked as problematic has been reported in go-git up to 5.17.0 . This impacts an unknown function. The manipulation leads to integer underflow. This vulnerability is uniquely identifie…
A vulnerability described as problematic has been identified in Checkmk up to 2.5.0b1 . Affected is an unknown function. The manipulation results in cross site scripting. This vulnerability was named …
A vulnerability classified as problematic has been found in Checkmk up to 2.5.0b1 . Affected by this vulnerability is an unknown functionality of the component Unified Search . This manipulation cause…
A malware campaign uses WhatsApp messages to deliver VBS scripts that initiate a multi-stage infection chain. The attack leverages renamed Windows tools and cloud-hosted payloads to install MSI backdo…
Key Points Introduction At the beginning of 2026, Check Point Research observed a series of targeted attacks against government entities in Southeast Asia carried out via a legitimate TrueConf softwar…
A new remote access trojan known as ResokerRAT has come to light, using Telegram’s bot API as its core communication channel to silently monitor and control infected Windows machines. What makes this …
Google has officially moved its ransomware detection and file restoration features for Google Drive into General Availability. Originally launched in beta in September 2025, the updated security contr…
Ransomware attacks have gone far beyond simple malicious code. Today, attackers operate with the precision of a well-planned business, using trusted Windows tools to quietly tear down defenses before …
TeamPCP is exploring ways to monetize the secrets harvested during supply chain attacks, with identified ties to the Lapsus$ and Vect ransomware gangs
OpenAI has patched vulnerability, which Check Point said was because of a DNS loophole
OpenAI has fixed two flaws in its AI stack that could allow AI agents to move sensitive data in unintended ways. The issues, disclosed by researchers at BeyondTrust and Check Point Research, affect th…
Apple has added a new security feature in macOS Tahoe 26.4 that warns users before they enter commands in Terminal that could cause harm. The goal is to stop ClickFix attacks, a social engineering tri…
Microsoft released Windows 11 Insider Preview Build 29558.1000 to the Canary Channel, part of the optional 29500 build series. The build carries a set of changes focused on the Windows Console, a hand…