CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  53432 articles  ·  updated every 4 hours · grows forever

53432Total
35789Full Text
Sep 16, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4506 | Mindinventory MindSQL up to 0.2.1 mindsql_core.py ask_db code injection

A vulnerability classified as critical has been found in Mindinventory MindSQL up to 0.2.1 . Impacted is the function ask_db of the file mindsql/core/mindsql_core.py . Performing a manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4507 | Mindinventory MindSQL up to 0.2.1 mindsql_core.py ask_db sql injection

A vulnerability classified as critical was found in Mindinventory MindSQL up to 0.2.1 . The affected element is the function ask_db of the file mindsql/core/mindsql_core.py . Executing a manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4508 | PbootCMS up to 3.2.12 Member Login MemberController.php checkUsername sql injection

A vulnerability, which was classified as critical , has been found in PbootCMS up to 3.2.12 . The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php o…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4509 | PbootCMS up to 3.2.12 File Upload core/function/file.php black incomplete blacklist

A vulnerability, which was classified as critical , was found in PbootCMS up to 3.2.12 . This affects an unknown function of the file core/function/file.php of the component File Upload . The manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4510 | PbootCMS up to 3.2.12 Parameter MemberController.php alert_location backurl cross site scripting

A vulnerability has been found in PbootCMS up to 3.2.12 and classified as problematic . This impacts the function alert_location of the file apps/home/controller/MemberController.php of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4511 | vanna-ai vanna up to 2.0.2 /src/vanna/legacy exec injection

A vulnerability was found in vanna-ai vanna up to 2.0.2 and classified as critical . Affected is the function exec of the file /src/vanna/legacy . Such manipulation leads to injection. This vulnerabil…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4513 | vanna-ai vanna up to 2.0.2 base.py ask sql injection

A vulnerability was found in vanna-ai vanna up to 2.0.2 . It has been classified as critical . Affected by this vulnerability is the function ask of the file vanna\legacy\base\base.py . Performing a m…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4514 | PbootCMS up to 3.2.12 Backend UserController.php Field access control

A vulnerability was found in PbootCMS up to 3.2.12 . It has been declared as critical . Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4515 | Foundation Agents MetaGPT up to 0.8.1 operator.py code_generate code injection

A vulnerability was found in Foundation Agents MetaGPT up to 0.8.1 . It has been rated as critical . This affects the function code_generate of the file metagpt/ext/aflow/scripts/operator.py . The man…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4516 | Foundation Agents MetaGPT up to 0.8.1 DataInterpreter write_analysis_code.py injection

A vulnerability categorized as critical has been discovered in Foundation Agents MetaGPT up to 0.8.1 . This vulnerability affects unknown code of the file metagpt/actions/di/write_analysis_code.py of …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33369 | Zimbra Collaboration Suite 10.0/10.1 Mailbox SOAP Service ldap injection

A vulnerability identified as critical has been detected in Zimbra Collaboration Suite 10.0/10.1 . This issue affects some unknown processing of the component Mailbox SOAP Service . This manipulation …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33371 | Zimbra Collaboration Suite 10.0/10.1 Exchange Web Service xml external entity reference

A vulnerability labeled as problematic has been found in Zimbra Collaboration Suite 10.0/10.1 . Impacted is an unknown function of the component Exchange Web Service . Such manipulation leads to xml e…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33372 | Zimbra Collaboration Suite 10.0/10.1 Request Header cross-site request forgery

A vulnerability marked as problematic has been reported in Zimbra Collaboration Suite 10.0/10.1 . The affected element is an unknown function of the component Request Header Handler . Performing a man…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33370 | Zimbra Collaboration Suite 10.0/10.1 Briefcase Feature cross site scripting

A vulnerability described as problematic has been identified in Zimbra Collaboration Suite 10.0/10.1 . The impacted element is an unknown function of the component Briefcase Feature . Executing a mani…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33368 | Zimbra Collaboration Suite 10.0/10.1 Webmail REST Interface /h/rest cross site scripting

A vulnerability classified as problematic has been found in Zimbra Collaboration Suite 10.0/10.1 . This affects an unknown function of the file /h/rest of the component Webmail REST Interface . The ma…

VulDB Read →
◇ Industry News & Leadership Mar 20, 2026
Denver’s crosswalks hacked to broadcast anti-Trump messages

Pedestrians crossing a street in Denver, Colorado, got rather more than they bargained for last weekend, when the audio signals at two crosswalks began broadcasting a political message alongside their…

Graham Cluley Read →
◇ Industry News & Leadership Mar 20, 2026
Microsoft Unveils New Teams Optimizations for Windows App on iOS & Android

Microsoft has officially announced the general availability of new Microsoft Teams optimizations for the Windows App on both iOS and Android platforms. Released on March 18, 2026, this update introduc…

Cybersecurity News Read →
◇ Industry News & Leadership Mar 20, 2026
FBI, Thai Partners Target Southeast Asia Scam Centers Behind Cyber Fraud on Americans

The fraud rarely announces itself. It begins with a friendly message on social media, a wrong-number text that turns into a conversation, or a romantic connection that slowly builds over weeks. For te…

Cybersecurity News Read →
◇ Industry News & Leadership Mar 20, 2026
Perseus Android Malware Steals User Notes and Enables Full Device Takeover

A new Android banking trojan named Perseus has emerged in the wild, representing the next step in the ongoing evolution of mobile malware. Built on the leaked source code of Cerberus and drawing direc…

Cybersecurity News Read →
◇ Industry News & Leadership Mar 20, 2026
New VoidStealer Variant Bypasses Chrome ABE Without Injection or Privilege Escalation

A newly identified variant of the VoidStealer infostealer has drawn serious attention from the security community after it became the first malware known to bypass Google Chrome’s Application-Bound En…

Cybersecurity News Read →
◇ Industry News & Leadership Mar 20, 2026
Hackers Compromised 7,500+ Magento Websites to Upload Hidden Malicious Files and Steal Data

A sweeping cyberattack campaign has compromised more than 7,500 Magento-powered e-commerce websites since late February 2026, with attackers uploading hidden malicious files into publicly accessible w…

Cybersecurity News Read →
◇ Industry News & Leadership Mar 20, 2026
Windows 11 March Update Breaks Microsoft Teams and OneDrive Sign-Ins

Microsoft has acknowledged a significant bug introduced by its March 2026 cumulative update that is preventing users from signing into Microsoft Teams Free, OneDrive, and several other Microsoft appli…

Cybersecurity News Read →
◇ Industry News & Leadership Mar 20, 2026
Terminated contract led to $2.5 million cyber extortion scheme

A federal jury convicted Cameron Curry, 27, a Charlotte resident, of carrying out an extensive cyber extortion scheme targeting a Washington, D.C.-based international technology company. He faces up t…

Help Net Security Read →
◇ Industry News & Leadership Mar 20, 2026
Google slows Android sideloading to trip up scammers

Google’s advanced flow for Android changes how apps from unverified developers are installed, adding steps to reduce scam-driven sideloading. The feature is aimed at experienced users and allows sidel…

Help Net Security Read →
← Prev 2034 / 2227 Next →