A vulnerability was found in OpenClaw up to 2026.2.21 and classified as problematic . This vulnerability affects unknown code of the component Environment Variable Handler . Such manipulation of the a…
cyberintel.kalymoon.com · 53495 articles · updated every 4 hours · grows forever
A vulnerability was found in OpenClaw up to 2026.2.21 and classified as problematic . This vulnerability affects unknown code of the component Environment Variable Handler . Such manipulation of the a…
A vulnerability was found in autobrr qui up to 1.14.1 . It has been classified as problematic . This issue affects some unknown processing. Performing a manipulation results in permissive cross-domain…
A vulnerability was found in mesop-dev mesop up to 1.2.2 . It has been declared as critical . Impacted is the function wsgi_app of the file ai/sandbox/wsgi_app.py . Executing a manipulation can lead t…
A vulnerability was found in alexcrichton tar-rs up to 0.4.44 on Rust. It has been rated as critical . The affected element is the function fs::metadata of the component Tarball Handler . The manipula…
A vulnerability categorized as critical has been discovered in ondata ckan-mcp-server up to 0.4.84 . The impacted element is the function ckan_package_search of the component Internal Network Service …
A vulnerability identified as critical has been detected in GIMP . This affects an unknown function of the component JP2 File Parser . This manipulation causes heap-based buffer overflow. This vulnera…
A vulnerability labeled as critical has been found in GIMP . This impacts an unknown function of the component PSD File Parser . Such manipulation leads to integer overflow. This vulnerability is list…
A vulnerability marked as problematic has been reported in angular ssr . Affected is an unknown function of the component Relative URL Handler . Performing a manipulation results in injection. This vu…
A vulnerability described as critical has been identified in GIMP . Affected by this vulnerability is an unknown functionality of the component PSP File Parser . Executing a manipulation can lead to h…
A vulnerability classified as critical has been found in GIMP . Affected by this issue is some unknown functionality of the component XPM File Parser . The manipulation leads to integer overflow. This…
A vulnerability classified as critical was found in GIMP . This affects an unknown part of the component ANI File Parser . The manipulation results in integer overflow. This vulnerability is reported …
A vulnerability, which was classified as problematic , has been found in Query Monitor Plugin on WordPress. This vulnerability affects unknown code. This manipulation of the argument REQUEST_URI cause…
A vulnerability, which was classified as critical , was found in vim up to 9.2.0201 . This issue affects the function glob . Such manipulation leads to os command injection. This vulnerability is trad…
A Russian state-linked threat actor has launched a targeted cyberattack against a Ukrainian government agency, exploiting a cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite to st…
SILENTCONNECT is a newly discovered multi-stage malware loader that has been silently targeting Windows machines since at least March 2025. It uses VBScript, in-memory PowerShell execution, and PEB ma…
New Report Highlights Surge in Exposed API Keys, Session Tokens, and Machine Identities, and more. SpyCloud , the leader in identity threat protection, today released its annual 2026 Identity Exposure…
Identity & Access Management ist für sicherheitsbewusste Unternehmen im Zero-Trust-Zeitalter Pflicht. Das sind die besten IAM-Anbieter und -Tools. Foto: ne2pi – shutterstock.com Identität wird zum neu…
Threat actors have always sought advantage over their targets. Recently we’ve seen two efforts designed for long-term intelligence gain. This activity surfaced right where you would expect inside the …
Running a large language model on a single machine without cloud access or a container runtime remains a priority for practitioners working in air-gapped or resource-constrained environments. Llamafil…
Here’s a look at the most interesting products from the past week, featuring releases from Intel 471, Kore.ai, NinjaOne, Pindrop, Secure Code Warrior, Token Security, and Xona Systems. NinjaOne Vulner…
In this Help Net Security video, Kat Traxler, Principal Security Researcher – Public Cloud at Vectra AI, walks through two AWS misconfigurations that go beyond the basics of bucket visibility. The fir…
In this Help Net Security interview, Chris Thompson, CISO at West Shore Home, discusses least privilege and credential hygiene for a field-based workforce. He covers access management, authentication …
AppViewX has acquired Eos, an AI-native identity control plane for AI agents and autonomous workloads within the enterprise. By combining AppViewX’s automated CLM and PKI with Eos’s agentic governance…
Bonfy.AI announced Bonfy Adaptive Content Security (Bonfy ACS) 2.0, a platform built to secure enterprise content across all systems, applications, and AI agents – anywhere data moves, resides, or is …