A vulnerability, which was classified as problematic , was found in WWBN AVideo up to 26.0 . This vulnerability affects unknown code of the file objects/userRecoverPass.php of the component Password R…
cyberintel.kalymoon.com · 50868 articles · updated every 4 hours · grows forever
A vulnerability, which was classified as problematic , was found in WWBN AVideo up to 26.0 . This vulnerability affects unknown code of the file objects/userRecoverPass.php of the component Password R…
A vulnerability has been found in WWBN AVideo up to 26.0 and classified as problematic . This issue affects the function getRealIpAddr of the file objects/functions.php of the component HTTP Header Ha…
A vulnerability was found in WWBN AVideo up to 26.0 and classified as problematic . Impacted is the function User::isAdmin of the component JSON API . The manipulation results in missing authorization…
A vulnerability was found in WWBN AVideo up to 26.0 . It has been classified as critical . The affected element is an unknown function of the file plugin/Live/standAloneFiles/control.json.php . This m…
A vulnerability was found in WWBN AVideo up to 26.0 . It has been declared as critical . The impacted element is the function Subscribe::save of the file objects/subscribe.php of the component Databas…
A vulnerability was found in agronholm cbor2 up to 5.8.x . It has been rated as problematic . This affects the function cbor2.loads . Performing a manipulation results in uncontrolled recursion. This …
A vulnerability categorized as critical has been discovered in WWBN AVideo up to 26.0 . This impacts the function Scheduler_commands::getAllActiveOrToRepeat of the file remindMe.json.php . Executing a…
A vulnerability identified as critical has been detected in WWBN AVideo up to 26.0 . Affected is an unknown function of the file plugin/CDN/status.json.php of the component CDN Plugin Endpoint . The m…
A vulnerability labeled as critical has been found in WWBN AVideo up to 26.0 . Affected by this vulnerability is the function Plugin::getDatabaseFileName of the file objects/pluginRunDatabaseScript.js…
A vulnerability marked as problematic has been reported in strongSwan up to 6.0.4 . Affected by this issue is some unknown functionality of the component TTLS AVP Parser . This manipulation of the arg…
A vulnerability described as problematic has been identified in WWBN AVideo up to 26.0 . This affects the function xss_esc of the component Registered User Handler . Such manipulation of the argument …
A vulnerability classified as problematic has been found in TP-Link TD-W8961N 4.0 . This vulnerability affects unknown code of the component Httpd Service . Performing a manipulation results in denial…
Microsoft Defender stopped a human-operated ransomware attack that abused Group Policy Objects (GPOs) to disable defenses and push encryption at scale. This case study breaks down the attacker’s playb…
March 11 Attack Claimed by Iranian Hacktivist Group Handala Medtech maker Stryker on Monday told regulators that it has "contained" a March 11 cyber incident and is "working around the clock" to prior…
A sophisticated macOS infostealer known as MioLab — also tracked as Nova — has emerged as one of the most advanced Malware-as-a-Service (MaaS) platforms targeting Apple users. Advertised on Russian-sp…
A Libyan oil refinery, a telecoms organization, and a state institution fell victim to a coordinated espionage campaign between November 2025 and February 2026. The attacks delivered AsyncRAT, a publi…
Cloud Software Group has released urgent security patches for NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway), addressing two significant vulnerabilities that could…
QNAP has released a critical security advisory addressing a severe vulnerability in its QVR Pro surveillance software. Tracked as CVE-2026-22898, this flaw allows remote, unauthenticated attackers to …
A sophisticated SEO poisoning campaign has been quietly targeting Windows users since at least October 2025, luring them into downloading trojanized installers for more than 25 popular software applic…
Every April, millions of Americans rush to file taxes before the deadline — and attackers count on it. A large-scale malvertising campaign, active since at least January 2026, has been exploiting that…
Tycoon2FA phishing platform resumes activity post-takedown, leveraging AITM techniques to bypass MFA
ISACA survey found that confusion over responsibility and lack of understanding around AI cyber-attacks makes containing them difficult
The North Korean threat actors behind the Contagious Interview campaign, also tracked as WaterPlum, have been attributed to a malware family tracked as StoatWaffle that's distributed via malicious Mic…
The TeamPCP hackers behind the Trivy supply-chain attack continued to target Aqua Security, pushing malicious Docker images and hijacking the company's GitHub organization to tamper with dozens of rep…