CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  22485 articles  ·  updated every 4 hours · grows forever

22485Total
19104Full Text
May 25, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7388 | EyouCMS up to 1.7.9 Template File FilemanagerLogic.php editFile code injection (IILDJS)

A vulnerability was found in EyouCMS up to 1.7.9 and classified as critical . Impacted is the function editFile of the file application/admin/logic/FilemanagerLogic.php of the component Template File …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7389 | EyouCMS up to 1.7.9 application/common.php GetSortData sort_asc sql injection (IILFPE)

A vulnerability was found in EyouCMS up to 1.7.9 . It has been classified as critical . The affected element is the function GetSortData of the file application/common.php . The manipulation of the ar…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7390 | SourceCodester Pharmacy Sales and Inventory System 1.0 /index.php?page=customer Name cross site scripting

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0 . It has been declared as problematic . The impacted element is the function Customer of the file /index.php?page=cu…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7391 | SourceCodester Pharmacy Sales and Inventory System 1.0 ajax.php?action=save_supplier ID sql injection

A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0 . It has been rated as critical . This affects the function save_supplier of the file /ajax.php?action=save_supplier…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7392 | SourceCodester Pharmacy Sales and Inventory System 1.0 ajax.php?action=delete_supplier ID sql injection

A vulnerability categorized as critical has been discovered in SourceCodester Pharmacy Sales and Inventory System 1.0 . This impacts the function delete_supplier of the file /ajax.php?action=delete_su…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7393 | SourceCodester Pizzafy Ecommerce System 1.0 File Extension admin_class_novo.php save_menu img unrestricted upload

A vulnerability identified as critical has been detected in SourceCodester Pizzafy Ecommerce System 1.0 . Affected is the function save_menu of the file /admin/admin_class_novo.php of the component Fi…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7394 | SourceCodester Pizzafy Ecommerce System 1.0 GET Parameter /admin/view_order.php ID sql injection

A vulnerability labeled as critical has been found in SourceCodester Pizzafy Ecommerce System 1.0 . Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the …

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7396 | NousResearch hermes-agent 0.8.0 WeChat Work Platform Adapter wecom.py path traversal (Issue 8733)

A vulnerability marked as critical has been reported in NousResearch hermes-agent 0.8.0 . Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component W…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7397 | NousResearch hermes-agent 0.8.0 tools/file_tools.py _check_sensitive_path symlink (Issue 8734)

A vulnerability described as critical has been identified in NousResearch hermes-agent 0.8.0 . This affects the function _check_sensitive_path of the file tools/file_tools.py . The manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs Apr 29, 2026
CVE-2026-7398 | florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54 Upload Endpoint app.py upload Name path traversal

A vulnerability classified as critical has been found in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54 . This vulnerability affects the function Upload of the file bioinfo…

VulDB Read →
◇ Industry News & Leadership Apr 29, 2026
New VECT 2.0 Ransomware Destroys Files Over 128 KB Across Windows, Linux, and ESXi

A newly documented ransomware strain called VECT 2.0 has drawn serious attention from the cybersecurity community for a deeply damaging flaw in its design. Unlike typical ransomware that locks files a…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 29, 2026
Critical Chrome Vulnerabilities Enables Remote Code Execution Attacks

Google has released a critical security update for its Chrome desktop browser to address 30 security vulnerabilities, including four severe flaws that could enable Remote Code Execution (RCE) attacks.…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 29, 2026
Hugging Face LeRobot Vulnerability Enables Unauthenticated RCE Attacks

A critical, currently unpatched remote code execution (RCE) vulnerability has been disclosed in LeRobot, Hugging Face’s popular open-source machine learning framework for real-world robotics. Tracked …

Cybersecurity News Read →
◇ Industry News & Leadership Apr 29, 2026
CISA Warns Microsoft Windows Shell 0-click Vulnerability Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical zero-day vulnerability in Microsoft Windows. On April 28, 2026, the agency officially adde…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 29, 2026
Vimeo Confirms Data Breach – Hackers Accessed Users Database

Video hosting platform Vimeo has confirmed a data breach resulting in unauthorized access to its user database. The security incident stems from a compromise at Anodot, a third-party analytics vendor …

Cybersecurity News Read →
◇ Industry News & Leadership Apr 29, 2026
Minecraft Players Targeted by LofyStealer Using Node.js Loader and In-Memory Browser Injection

A dangerous infostealer malware called LofyStealer is actively targeting Minecraft players by disguising itself as a game cheat tool named “Slinky.” The malware runs a two-stage attack that quietly st…

Cybersecurity News Read →
◇ Industry News & Leadership Apr 29, 2026
A Quarter of Healthcare Organizations Report Medical Device Cyber-Attacks

RunSafe report reveals most attacks on medical devices disrupt patient care

Infosecurity Magazine Read →
◇ Industry News & Leadership Apr 29, 2026
Critical Flaw Turns Vect Ransomware into Data Destroying Wiper

The Vect 2.0 ransomware wipes large files instead of merely encrypting them, making recovery impossible – even for the attackers

Infosecurity Magazine Read →
◇ Industry News & Leadership Apr 29, 2026
AWS leans on prior ingenuity to face future AI and quantum threats

As Amazon celebrates the 20th anniversary of its AWS cloud this year, the world’s biggest cloud computing provider now faces two giant cybersecurity threats — AI and quantum. How the company will navi…

CSO Online Read →
◇ Industry News & Leadership Apr 29, 2026
Critical GitHub RCE bug exposed millions of repositories

A critical remote code execution (RCE) vulnerability in GitHub could potentially allow attackers to execute arbitrary code on GitHub.com and GitHub Enterprise Server. Uncovered by Wiz researchers, the…

CSO Online Read →
◇ Industry News & Leadership Apr 29, 2026
DigitalOcean AI-Native Cloud unifies infrastructure, inference, and agents for production AI

DigitalOcean has introduced the AI-Native Cloud, an end-to-end platform built for the inference and agentic era. Spanning infrastructure, core cloud, inference, data, and managed agents, it already su…

Help Net Security Read →
◇ Industry News & Leadership Apr 29, 2026
Kaseya agentic IT management unifies data and automates ticketing, security and backups

Kaseya has introduced an agentic IT management platform powered by Kaseya Intelligence, combining unified data across IT operations, cybersecurity, and resilience with an execution layer that autonomo…

Help Net Security Read →
◇ Industry News & Leadership Apr 29, 2026
Microchip expands Trust Shield with PQC-ready root of trust and secure boot controllers

Microchip Technology is expanding its portfolio of Trust Shield, PQC‑ready devices with the TS1800 Platform Root of Trust controller and the TS50x secure boot controller. The devices are designed to h…

Help Net Security Read →
◇ Industry News & Leadership Apr 29, 2026
CISA, Microsoft warn of active exploitation of Windows Shell vulnerability (CVE-2026-32202)

Attackers are exploiting CVE-2026-32202, a zero-click Windows Shell spoofing vulnerability that causes victims’ systems to authenticate the attacker’s server, CISA and Microsoft have warned. About CVE…

Help Net Security Read →
← Prev 204 / 937 Next →