CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  30466 articles  ·  updated every 4 hours · grows forever

30466Total
23848Full Text
Jun 24, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9351 | NousResearch hermes-agent up to 2026.4.16 read_file Tool tools/file_tools.py _is_blocked_device path traversal

A vulnerability marked as critical has been reported in NousResearch hermes-agent up to 2026.4.16 . This vulnerability affects the function _is_blocked_device of the file tools/file_tools.py of the co…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9352 | NousResearch hermes-agent up to 2026.4.23 Messaging Gateway local.py _make_run_env information disclosure

A vulnerability described as problematic has been identified in NousResearch hermes-agent up to 2026.4.23 . This issue affects the function _make_run_env of the file tools/environments/local.py of the…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9353 | NousResearch hermes-agent up to 2026.4.23 Skills Guard Multi-Word Prompt agent/skills_guard.py THREAT_PATTERNS injection

A vulnerability classified as critical has been found in NousResearch hermes-agent up to 2026.4.23 . Impacted is an unknown function of the file agent/skills_guard.py of the component Skills Guard Mul…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9354 | NousResearch hermes-agent up to 2026.4.16 Slack Agent/Mattermost Agent format_message escape output

A vulnerability classified as critical was found in NousResearch hermes-agent up to 2026.4.16 . The affected element is an unknown function of the component Slack Agent/Mattermost Agent . The manipula…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9355 | SourceCodester Hospitals Patient Records Management System 1.0 Master.php?f=save_patient_history ID sql injection

A vulnerability, which was classified as critical , has been found in SourceCodester Hospitals Patient Records Management System 1.0 . The impacted element is an unknown function of the file /classes/…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9356 | SourceCodester Hospitals Patient Records Management System 1.0 manage_history.php ID sql injection

A vulnerability, which was classified as critical , was found in SourceCodester Hospitals Patient Records Management System 1.0 . This affects an unknown function of the file /admin/patients/manage_hi…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9357 | vBulletin 6.x Login cross site scripting

A vulnerability has been found in vBulletin 6.x and classified as problematic . This impacts an unknown function of the component Login . Performing a manipulation results in cross site scripting. Thi…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9358 | postcss up to 7.1.1 AST Serialization container.js toString recursion

A vulnerability was found in postcss up to 7.1.1 and classified as problematic . Affected is the function toString of the file src/selectors/container.js of the component AST Serialization . Executing…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9359 | Edimax EW-7438RPn 1.28a POST Request /goform/formHwSet command injection

A vulnerability was found in Edimax EW-7438RPn 1.28a . It has been classified as critical . Affected by this vulnerability is the function formHwSet of the file /goform/formHwSet of the component POST…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9360 | Edimax EW-7438RPn 1.28a POST Request /goform/formwlencrypt24g key1 buffer overflow

A vulnerability was found in Edimax EW-7438RPn 1.28a . It has been declared as critical . Affected by this issue is the function formwlencrypt24g of the file /goform/formwlencrypt24g of the component …

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9361 | Edimax EW-7438RPn 1.12 POST Request /goform/formAccep formAccept submit-url command injection

A vulnerability was found in Edimax EW-7438RPn 1.12 . It has been rated as critical . This affects the function formAccept of the file /goform/formAccep of the component POST Request Handler . This ma…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9362 | Edimax EW-7438RPn 1.12 Setting formConnectionSetting max_Conn/timeOut command injection

A vulnerability categorized as critical has been discovered in Edimax EW-7438RPn 1.12 . This vulnerability affects the function formConnectionSetting of the file /goform/formConnectionSetting of the c…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9363 | Edimax EW-7438RPn 1.12 POST Request formEZCHNwlanSetu formEZCHNwlanSetup method command injection

A vulnerability identified as critical has been detected in Edimax EW-7438RPn 1.12 . This issue affects the function formEZCHNwlanSetup of the file /goform/formEZCHNwlanSetu of the component POST Requ…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9364 | projectworlds Online Art Gallery Shop 1.0 /admin/adminHome.php social_linked sql injection

A vulnerability labeled as critical has been found in projectworlds Online Art Gallery Shop 1.0 . Impacted is an unknown function of the file /admin/adminHome.php . Executing a manipulation of the arg…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9365 | Ettercap up to 0.8.3 GG Dissector src/dissectors/ec_gg.c FUNC_DECODER gg heap-based overflow (Issue 1306)

A vulnerability marked as critical has been reported in Ettercap up to 0.8.3 . The affected element is the function FUNC_DECODER of the file src/dissectors/ec_gg.c of the component GG Dissector . The …

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9366 | NousResearch hermes-agent 2026.4.23 agent/prompt_builder.py _scan_context_content injection

A vulnerability described as critical has been identified in NousResearch hermes-agent 2026.4.23 . The impacted element is the function _scan_context_content of the file agent/prompt_builder.py . The …

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9367 | NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63 terminal_tool tools/approval.py detect_dangerous_command os command injection

A vulnerability classified as critical has been found in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63 . This affects the function detect_dangerous_command of the file tools…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9368 | NousResearch hermes-agent up to 2026.4.16 Environment Variable code_execution_tool.py execute_code sandbox

A vulnerability classified as critical was found in NousResearch hermes-agent up to 2026.4.16 . This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environ…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9369 | NousResearch hermes-agent 2026.4.23 CLI web-dashboard Interface hermes_cli/web_server.py _discover_dashboard_plugins HERMES_ENABLE_PROJECT_PLUGINS comparison

A vulnerability, which was classified as problematic , has been found in NousResearch hermes-agent 2026.4.23 . Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py…

VulDB Read →
⬡ Vulnerabilities & CVEs May 23, 2026
CVE-2026-9370 | ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4 Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt (Issue 431)

A vulnerability, which was classified as problematic , was found in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4 . Affected by this vulnerability is the function getSecretKeySaltGenerator of the…

VulDB Read →
◇ Industry News & Leadership May 23, 2026
Hackers Exploit F5 BIG-IP Appliance to Gain SSH Access and Pivot Into Enterprise Linux Networks

A multi-stage intrusion attack where a threat actor exploited an internet-facing F5 BIG-IP edge appliance as the entry point for a widespread, identity-focused attack that ultimately accessed Active D…

Cybersecurity News Read →
◇ Industry News & Leadership May 23, 2026
Nginx-poolslip Vulnerability Enables DoS and Code Execution Attacks — Patch Now!

A newly disclosed flaw in one of the world’s most widely deployed web servers is forcing administrators into another emergency patch cycle. Tracked as CVE-2026-9256 and publicly nicknamed nginx-poolsl…

Cybersecurity News Read →
◇ Industry News & Leadership May 23, 2026
‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains

The stealthy vulnerability impacts roughly 88 million domains and can be exploited to bypass DNS filtering and hide command-and-control traffic. The post ‘Underminr’ Vulnerability Lets Attackers Hide …

Security Week Read →
◇ Industry News & Leadership May 23, 2026
Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based o…

The Hacker News Read →
← Prev 339 / 1270 Next →