CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  53495 articles  ·  updated every 4 hours · grows forever

53495Total
35812Full Text
Sep 17, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-32032 | OpenClaw up to 2026.2.21 Environment Variable SHELL untrusted search path (GHSA-f8mp-vj46-cq8v)

A vulnerability was found in OpenClaw up to 2026.2.21 and classified as problematic . This vulnerability affects unknown code of the component Environment Variable Handler . Such manipulation of the a…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-30924 | autobrr qui up to 1.14.1 cross-domain policy (GHSA-h8vw-ph9r-xpch)

A vulnerability was found in autobrr qui up to 1.14.1 . It has been classified as problematic . This issue affects some unknown processing. Performing a manipulation results in permissive cross-domain…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33057 | mesop-dev mesop up to 1.2.2 ai/sandbox/wsgi_app.py wsgi_app code injection

A vulnerability was found in mesop-dev mesop up to 1.2.2 . It has been declared as critical . Impacted is the function wsgi_app of the file ai/sandbox/wsgi_app.py . Executing a manipulation can lead t…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33056 | alexcrichton tar-rs up to 0.4.44 on Rust Tarball fs::metadata symlink

A vulnerability was found in alexcrichton tar-rs up to 0.4.44 on Rust. It has been rated as critical . The affected element is the function fs::metadata of the component Tarball Handler . The manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33060 | ondata ckan-mcp-server up to 0.4.84 Internal Network Service ckan_package_search base_url server-side request forgery

A vulnerability categorized as critical has been discovered in ondata ckan-mcp-server up to 0.4.84 . The impacted element is the function ckan_package_search of the component Internal Network Service …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4152 | GIMP JP2 File Parser heap-based overflow

A vulnerability identified as critical has been detected in GIMP . This affects an unknown function of the component JP2 File Parser . This manipulation causes heap-based buffer overflow. This vulnera…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4150 | GIMP PSD File Parser integer overflow

A vulnerability labeled as critical has been found in GIMP . This impacts an unknown function of the component PSD File Parser . Such manipulation leads to integer overflow. This vulnerability is list…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33397 | angular ssr Relative URL injection

A vulnerability marked as problematic has been reported in angular ssr . Affected is an unknown function of the component Relative URL Handler . Performing a manipulation results in injection. This vu…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4153 | GIMP PSP File Parser heap-based overflow

A vulnerability described as critical has been identified in GIMP . Affected by this vulnerability is an unknown functionality of the component PSP File Parser . Executing a manipulation can lead to h…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4154 | GIMP XPM File Parser integer overflow

A vulnerability classified as critical has been found in GIMP . Affected by this issue is some unknown functionality of the component XPM File Parser . The manipulation leads to integer overflow. This…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4151 | GIMP ANI File Parser integer overflow

A vulnerability classified as critical was found in GIMP . This affects an unknown part of the component ANI File Parser . The manipulation results in integer overflow. This vulnerability is reported …

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-4267 | Query Monitor Plugin prior 3.20.4 on WordPress REQUEST_URI cross site scripting

A vulnerability, which was classified as problematic , has been found in Query Monitor Plugin on WordPress. This vulnerability affects unknown code. This manipulation of the argument REQUEST_URI cause…

VulDB Read →
⬡ Vulnerabilities & CVEs Mar 20, 2026
CVE-2026-33412 | vim up to 9.2.0201 glob os command injection

A vulnerability, which was classified as critical , was found in vim up to 9.2.0201 . This issue affects the function glob . Such manipulation leads to os command injection. This vulnerability is trad…

VulDB Read →
◇ Industry News & Leadership Mar 20, 2026
Russian APT Exploits Zimbra XSS to Target Ukrainian Government in ‘Operation GhostMail’

A Russian state-linked threat actor has launched a targeted cyberattack against a Ukrainian government agency, exploiting a cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite to st…

Cybersecurity News Read →
◇ Industry News & Leadership Mar 20, 2026
SILENTCONNECT Uses VBScript, PowerShell and PEB Masquerading to Deploy ScreenConnect

SILENTCONNECT is a newly discovered multi-stage malware loader that has been silently targeting Windows machines since at least March 2025. It uses VBScript, in-memory PowerShell execution, and PEB ma…

Cybersecurity News Read →
◇ Industry News & Leadership Mar 20, 2026
SpyCloud’s 2026 Identity Exposure Report Reveals Explosion of Non-Human Identity Theft

New Report Highlights Surge in Exposed API Keys, Session Tokens, and Machine Identities, and more. SpyCloud , the leader in identity threat protection, today released its annual 2026 Identity Exposure…

CSO Online Read →
◇ Industry News & Leadership Mar 20, 2026
Die besten IAM-Tools

Identity & Access Management ist für sicherheitsbewusste Unternehmen im Zero-Trust-Zeitalter Pflicht. Das sind die besten IAM-Anbieter und -Tools. Foto: ne2pi – shutterstock.com Identität wird zum neu…

CSO Online Read →
◇ Industry News & Leadership Mar 20, 2026
The espionage reality: Your infrastructure is already in the collection path

Threat actors have always sought advantage over their targets. Recently we’ve seen two efforts designed for long-term intelligence gain. This activity surfaced right where you would expect inside the …

CSO Online Read →
◇ Industry News & Leadership Mar 20, 2026
Llamafile, Mozilla’s portable LLM runner, gets GPU support and a rebuilt core

Running a large language model on a single machine without cloud access or a container runtime remains a priority for practitioners working in air-gapped or resource-constrained environments. Llamafil…

Help Net Security Read →
◇ Industry News & Leadership Mar 20, 2026
New infosec products of the week: March 20, 2026

Here’s a look at the most interesting products from the past week, featuring releases from Intel 471, Kore.ai, NinjaOne, Pindrop, Secure Code Warrior, Token Security, and Xona Systems. NinjaOne Vulner…

Help Net Security Read →
◇ Industry News & Leadership Mar 20, 2026
Cloud misconfiguration has evolved and your controls haven’t

In this Help Net Security video, Kat Traxler, Principal Security Researcher – Public Cloud at Vectra AI, walks through two AWS misconfigurations that go beyond the basics of bucket visibility. The fir…

Help Net Security Read →
◇ Industry News & Leadership Mar 20, 2026
Field workers don’t need more access, they need better security

In this Help Net Security interview, Chris Thompson, CISO at West Shore Home, discusses least privilege and credential hygiene for a field-based workforce. He covers access management, authentication …

Help Net Security Read →
◇ Industry News & Leadership Mar 20, 2026
AppViewX acquires Eos to extend identity security to AI agents and workloads

AppViewX has acquired Eos, an AI-native identity control plane for AI agents and autonomous workloads within the enterprise. By combining AppViewX’s automated CLM and PKI with Eos’s agentic governance…

Help Net Security Read →
◇ Industry News & Leadership Mar 20, 2026
Bonfy ACS 2.0 helps organizations control data use in AI environments

Bonfy.AI announced Bonfy Adaptive Content Security (Bonfy ACS) 2.0, a platform built to secure enterprise content across all systems, applications, and AI agents – anywhere data moves, resides, or is …

Help Net Security Read →
← Prev 2044 / 2229 Next →