CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  50868 articles  ·  updated every 4 hours · grows forever

50868Total
34570Full Text
Sep 08, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33688 | WWBN AVideo up to 26.0 Password Recovery Endpoint userRecoverPass.php response discrepancy

A vulnerability, which was classified as problematic , was found in WWBN AVideo up to 26.0 . This vulnerability affects unknown code of the file objects/userRecoverPass.php of the component Password R…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33690 | WWBN AVideo up to 26.0 HTTP Header objects/functions.php getRealIpAddr less trusted source

A vulnerability has been found in WWBN AVideo up to 26.0 and classified as problematic . This issue affects the function getRealIpAddr of the file objects/functions.php of the component HTTP Header Ha…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33685 | WWBN AVideo up to 26.0 JSON API User::isAdmin authorization

A vulnerability was found in WWBN AVideo up to 26.0 and classified as problematic . Impacted is the function User::isAdmin of the component JSON API . The manipulation results in missing authorization…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33716 | WWBN AVideo up to 26.0 control.json.php streamerURL improper authentication

A vulnerability was found in WWBN AVideo up to 26.0 . It has been classified as critical . The affected element is an unknown function of the file plugin/Live/standAloneFiles/control.json.php . This m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33723 | WWBN AVideo up to 26.0 Database Table objects/subscribe.php Subscribe::save user_id sql injection

A vulnerability was found in WWBN AVideo up to 26.0 . It has been declared as critical . The impacted element is the function Subscribe::save of the file objects/subscribe.php of the component Databas…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-26209 | agronholm cbor2 up to 5.8.x cbor2.loads recursion

A vulnerability was found in agronholm cbor2 up to 5.8.x . It has been rated as problematic . This affects the function cbor2.loads . Performing a manipulation results in uncontrolled recursion. This …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33651 | WWBN AVideo up to 26.0 remindMe.json.php getAllActiveOrToRepeat live_schedule_id sql injection

A vulnerability categorized as critical has been discovered in WWBN AVideo up to 26.0 . This impacts the function Scheduler_commands::getAllActiveOrToRepeat of the file remindMe.json.php . Executing a…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33719 | WWBN AVideo up to 26.0 CDN Plugin Endpoint status.json.php par missing authentication

A vulnerability identified as critical has been detected in WWBN AVideo up to 26.0 . Affected is an unknown function of the file plugin/CDN/status.json.php of the component CDN Plugin Endpoint . The m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33681 | WWBN AVideo up to 26.0 Parameter pluginRunDatabaseScript.json.php getDatabaseFileName path traversal

A vulnerability labeled as critical has been found in WWBN AVideo up to 26.0 . Affected by this vulnerability is the function Plugin::getDatabaseFileName of the file objects/pluginRunDatabaseScript.js…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-25075 | strongSwan up to 6.0.4 TTLS AVP Parser length integer underflow

A vulnerability marked as problematic has been reported in strongSwan up to 6.0.4 . Affected by this issue is some unknown functionality of the component TTLS AVP Parser . This manipulation of the arg…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2026-33683 | WWBN AVideo up to 26.0 Registered User xss_esc About cross site scripting

A vulnerability described as problematic has been identified in WWBN AVideo up to 26.0 . This affects the function xss_esc of the component Registered User Handler . Such manipulation of the argument …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 23, 2026
CVE-2025-15606 | TP-Link TD-W8961N 4.0 Httpd Service denial of service

A vulnerability classified as problematic has been found in TP-Link TD-W8961N 4.0 . This vulnerability affects unknown code of the component Httpd Service . Performing a manipulation results in denial…

VulDB Read →
◉ Threat Intelligence Mar 23, 2026
Case study: How predictive shielding in Defender stopped GPO-based ransomware before it started

Microsoft Defender stopped a human-operated ransomware attack that abused Group Policy Objects (GPOs) to disable defenses and push encryption at scale. This case study breaks down the attacker’s playb…

Microsoft Security Read →
◇ Industry News & Leadership Mar 23, 2026
Stryker: Cyber Incident 'Contained,' Restoration Continues

March 11 Attack Claimed by Iranian Hacktivist Group Handala Medtech maker Stryker on Monday told regulators that it has "contained" a March 11 cyber incident and is "working around the clock" to prior…

Data Breach Today Read →
◇ Industry News & Leadership Mar 23, 2026
MacOS Stealer MioLab Adds ClickFix Delivery, Wallet Theft and Team API Tools

A sophisticated macOS infostealer known as MioLab — also tracked as Nova — has emerged as one of the most advanced Malware-as-a-Service (MaaS) platforms targeting Apple users. Advertised on Russian-sp…

Cybersecurity News Read →
◇ Industry News & Leadership Mar 23, 2026
Libyan Oil Refinery Hit in Long-Running Espionage Campaign Using AsyncRAT

A Libyan oil refinery, a telecoms organization, and a state institution fell victim to a coordinated espionage campaign between November 2025 and February 2026. The attacks delivered AsyncRAT, a publi…

Cybersecurity News Read →
◇ Industry News & Leadership Mar 23, 2026
Critical NetScaler ADC and Gateway Vulnerabilities Enable Remote Attacks on Affected Systems

Cloud Software Group has released urgent security patches for NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway), addressing two significant vulnerabilities that could…

Cybersecurity News Read →
◇ Industry News & Leadership Mar 23, 2026
Critical QNAP QVR Pro Vulnerability Let Remote Attackers Gain Access to the System

QNAP has released a critical security advisory addressing a severe vulnerability in its QVR Pro surveillance software. Tracked as CVE-2026-22898, this flaw allows remote, unauthenticated attackers to …

Cybersecurity News Read →
◇ Industry News & Leadership Mar 23, 2026
SEO Poisoning Campaign Impersonates 25+ Popular Apps to Deliver AsyncRAT Since October 2025

A sophisticated SEO poisoning campaign has been quietly targeting Windows users since at least October 2025, luring them into downloading trojanized installers for more than 25 popular software applic…

Cybersecurity News Read →
◇ Industry News & Leadership Mar 23, 2026
Tax-Themed Google Ads Lead to BYOVD EDR Killer in Huntress-Traced Malvertising Campaign

Every April, millions of Americans rush to file taxes before the deadline — and attackers count on it. A large-scale malvertising campaign, active since at least January 2026, has been exploiting that…

Cybersecurity News Read →
◇ Industry News & Leadership Mar 23, 2026
Tycoon2FA Phishing Service Resumes Activity Post-Takedown

Tycoon2FA phishing platform resumes activity post-takedown, leveraging AITM techniques to bypass MFA

Infosecurity Magazine Read →
◇ Industry News & Leadership Mar 23, 2026
Most Cybersecurity Staff Don’t Know How Fast They Could Stop a Cyber-Attack on AI Systems

ISACA survey found that confusion over responsibility and lack of understanding around AI cyber-attacks makes containing them difficult

Infosecurity Magazine Read →
◇ Industry News & Leadership Mar 23, 2026
North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle Malware

The North Korean threat actors behind the Contagious Interview campaign, also tracked as WaterPlum, have been attributed to a malware family tracked as StoatWaffle that's distributed via malicious Mic…

The Hacker News Read →
◇ Industry News & Leadership Mar 23, 2026
Trivy supply-chain attack spreads to Docker, GitHub repos

The TeamPCP hackers behind the Trivy supply-chain attack continued to target Aqua Security, pushing malicious Docker images and hijacking the company's GitHub organization to tamper with dozens of rep…

Bleeping Computer Read →
← Prev 1889 / 2120 Next →