CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  49315 articles  ·  updated every 4 hours · grows forever

49315Total
33666Full Text
Sep 02, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-3115 | Mattermost up to 10.11.10/11.2.2/11.3.1/11.4.0 Group Retrieval Endpoint authorization

A vulnerability classified as problematic was found in Mattermost up to 10.11.10/11.2.2/11.3.1/11.4.0 . Affected is an unknown function of the component Group Retrieval Endpoint . The manipulation res…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33442 | kysely up to 0.28.13 sanitizeStringLiteral sql injection (GHSA-fr9j-6mvq-frcv)

A vulnerability, which was classified as critical , has been found in kysely up to 0.28.13 . Affected by this vulnerability is the function sanitizeStringLiteral . This manipulation causes sql injecti…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33487 | russellhaering goxmldsig up to 1.5.x XML Digital Signature validateSignature signature verification

A vulnerability, which was classified as problematic , was found in russellhaering goxmldsig up to 1.5.x . Affected by this issue is the function validateSignature of the component XML Digital Signatu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33490 | h3js h3 up to 2.0.0-0/2.0.1-rc.16/2.0.2-rc.17 mount name resolution

A vulnerability has been found in h3js h3 up to 2.0.0-0/2.0.1-rc.16/2.0.2-rc.17 and classified as problematic . This affects the function mount . Performing a manipulation results in incorrectly-resol…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33468 | kysely-org kysely up to 0.28.13 CreateViewBuilder.as sanitizeStringLiteral sql injection (GHSA-8cpq-38p9-67gx)

A vulnerability was found in kysely-org kysely up to 0.28.13 and classified as critical . This vulnerability affects the function sanitizeStringLiteral of the file CreateViewBuilder.as . Executing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33496 | ory oathkeeper up to 26.1.x oauth2_introspection improper validation of unsafe equivalence in input

A vulnerability was found in ory oathkeeper up to 26.1.x . It has been classified as critical . This issue affects the function oauth2_introspection . The manipulation leads to improper validation of …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33494 | ory oathkeeper up to 26.1.x Path Normalization path traversal

A vulnerability was found in ory oathkeeper up to 26.1.x . It has been declared as critical . Impacted is an unknown function of the component Path Normalization Handler . The manipulation results in …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-32846 | OpenClaw up to 2026.3.23 Path Validation isLikelyLocalPath path traversal (GHSA-f6pf-4gjx-c94r / EUVD-2026-16248)

A vulnerability was found in OpenClaw up to 2026.3.23 . It has been rated as critical . The affected element is the function isLikelyLocalPath of the component Path Validation Handler . This manipulat…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-27828 | EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 handle_session_setup use after free (GHSA-5g3v-qc79-qqwr / EUVD-2026-16228)

A vulnerability categorized as critical has been discovered in EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 . The impacted element is the function ISO15118_chargerImpl::handle_session_setup . Suc…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33503 | ory kratos up to 26.1.x ListCourierMessages Admin API sql injection

A vulnerability identified as critical has been detected in ory kratos up to 26.1.x . This affects an unknown function of the component ListCourierMessages Admin API . Performing a manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-32857 | Firecrawl up to 2.8.0 Playwright Scraping Service server-side request forgery

A vulnerability labeled as critical has been found in Firecrawl up to 2.8.0 . This impacts an unknown function of the component Playwright Scraping Service . Executing a manipulation can lead to serve…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-26074 | EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 std::map race condition (GHSA-p3hg-vqgv-h524)

A vulnerability marked as problematic has been reported in EVerest everest-core 2025.9.0/2025.10.0/2025.12.0 . Affected is the function std::map . The manipulation leads to race condition. This vulner…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-3116 | Mattermost Plugins up to 11.4.x Webhook Endpoint resource consumption

A vulnerability described as problematic has been identified in Mattermost Plugins up to 11.4.x . Affected by this vulnerability is an unknown functionality of the component Webhook Endpoint . The man…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-3109 | Mattermost Plugins up to 10.11.11/11.4.x Webhook Request unusual condition

A vulnerability classified as problematic has been found in Mattermost Plugins up to 10.11.11/11.4.x . Affected by this issue is some unknown functionality of the component Webhook Request Handler . T…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33470 | blakeblackshear frigate 0.17.0 /api/timeline authorization (GHSA-m2mg-pj9p-2r7g / EUVD-2026-16267)

A vulnerability classified as problematic was found in blakeblackshear frigate 0.17.0 . This affects an unknown part of the file /api/timeline . Such manipulation leads to missing authorization. This …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-3113 | Mattermost up to 10.11.11/11.2.3/11.3.1/11.4.0 permission assignment

A vulnerability, which was classified as problematic , has been found in Mattermost up to 10.11.11/11.2.3/11.3.1/11.4.0 . This vulnerability affects unknown code. Performing a manipulation results in …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33402 | sakaiproject sakai up to 23.4/25.1 Description cross site scripting (GHSA-6g62-3898-hpvm / EUVD-2026-16256)

A vulnerability, which was classified as problematic , was found in sakaiproject sakai up to 23.4/25.1 . This issue affects some unknown processing of the component Description Handler . Executing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33469 | blakeblackshear frigate 0.17.0 Configuration /api/config/raw authorization (GHSA-26g3-f8g8-9ffh / EUVD-2026-16266)

A vulnerability has been found in blakeblackshear frigate 0.17.0 and classified as problematic . Impacted is an unknown function of the file /api/config/raw of the component Configuration Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33486 | roadiz core-bundle-dev-app up to 2.3.41/2.5.43/2.6.27/2.7.8 Environment Variable server-side request forgery

A vulnerability was found in roadiz core-bundle-dev-app up to 2.3.41/2.5.43/2.6.27/2.7.8 and classified as critical . The affected element is an unknown function of the component Environment Variable …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 26, 2026
CVE-2026-33504 | ory hydra up to 26.1.x Admin API sql injection

A vulnerability was found in ory hydra up to 26.1.x . It has been classified as critical . The impacted element is an unknown function of the component Admin API . This manipulation causes sql injecti…

VulDB Read →
◉ Threat Intelligence Mar 26, 2026
TeamPCP Supply Chain Campaign: Update 001 - Checkmarx Scope Wider Than Reported, CISA KEV Entry, and Detection Tools Available, (Thu, Mar 26th)

This is the first update to the TeamPCP supply chain campaign threat intelligence report, "When the Security Scanner Became the Weapon" (v3.0, March 25, 2026). That report covers the full campaign fro…

SANS ISC Read →
◇ Industry News & Leadership Mar 26, 2026
Why Vector Databases Put Enterprise AI Data at Risk

Cyborg's Nicolas Dupont on Closing the Encrypted Vector Search Gap Cyborg CEO Nicolas Dupont describes how vector databases concentrate sensitive enterprise data in a structurally unencrypted layer, a…

Data Breach Today Read →
◇ Industry News & Leadership Mar 26, 2026
Speed, Judgment and Behavior: AI's Defense Mandate

Capitol Meridian Partners' Niloofar Razi on Innovation Sandbox, AI-Driven Offense Cybersecurity can no longer stop at the system boundary. Organizations must understand how humans and AI agents behave…

Data Breach Today Read →
◇ Industry News & Leadership Mar 26, 2026
Why Misaligned Incentives Are the CISO's Biggest Problem

Jim DuBois, Former Microsoft CIO and CISO, on Incentives, AI and Cyber's Future As AI reshapes cybersecurity, aligning security and innovation teams is more critical than ever. Former Microsoft CIO an…

Data Breach Today Read →
← Prev 1763 / 2055 Next →