CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  20749 articles  ·  updated every 4 hours · grows forever

20749Total
18074Full Text
May 18, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-44196 | smp46 pingvin-share-x up to 1.16.2 improper authentication (GHSA-j679-vp39-qwqq)

A vulnerability categorized as critical has been discovered in smp46 pingvin-share-x up to 1.16.2 . This affects an unknown function. The manipulation results in improper authentication. This vulnerab…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-5146 | Devolutions Server up to 2025.3.19.0/2026.1.15.0 Notification Management Endpoint authorization (DEVO-2026-0012)

A vulnerability identified as critical has been detected in Devolutions Server up to 2025.3.19.0/2026.1.15.0 . This impacts an unknown function of the component Notification Management Endpoint . This…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-41513 | horilla horilla-hr up to 1.5.0 Notification Endpoint redirect (GHSA-vqg4-fc32-cwvw)

A vulnerability labeled as problematic has been found in horilla horilla-hr up to 1.5.0 . Affected is an unknown function of the component Notification Endpoint . Such manipulation leads to open redir…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43892 | AntSwordProject antSword up to 2.1.15 noxss cross site scripting (GHSA-c63g-p4cp-r45x)

A vulnerability marked as problematic has been reported in AntSwordProject antSword up to 2.1.15 . Affected by this vulnerability is the function noxss . Performing a manipulation results in cross sit…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-44183 | Cleanuparr up to 2.9.9 X-Forwarded-For authentication spoofing (GHSA-8q44-v65j-jc3q)

A vulnerability described as critical has been identified in Cleanuparr up to 2.9.9 . Affected by this issue is some unknown functionality of the component X-Forwarded-For Handler . Executing a manipu…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-20714 | Intel QAT software drivers up to 1.12 on Windows out-of-bounds write (intel-sa-01387)

A vulnerability classified as critical has been found in Intel QAT software drivers up to 1.12 on Windows. This affects an unknown part. The manipulation leads to out-of-bounds write. This vulnerabili…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-20767 | Intel QAT software drivers up to 1.12 on Windows input validation (intel-sa-01387)

A vulnerability classified as critical was found in Intel QAT software drivers up to 1.12 on Windows. This vulnerability affects unknown code. The manipulation results in improper input validation. Th…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43929 | felippe-regazio ssrfcheck up to 1.3.0 WHATWG URL Parser isSSRFSafeURL incomplete blacklist (GHSA-j4rj-2jr5-m439)

A vulnerability, which was classified as critical , has been found in felippe-regazio ssrfcheck up to 1.3.0 . This issue affects the function isSSRFSafeURL of the component WHATWG URL Parser . This ma…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-44184 | Cleanuparr up to 2.9.9 API Response AllowCredentials origin validation (GHSA-rwpc-36mg-fpvf)

A vulnerability, which was classified as critical , was found in Cleanuparr up to 2.9.9 . Impacted is the function AllowCredentials of the component API Response Handler . Such manipulation leads to o…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-43891 | dgtlmoon changedetection.io up to 0.55.0 Backup Restore file inclusion (GHSA-8757-69j2-hx56)

A vulnerability has been found in dgtlmoon changedetection.io up to 0.55.0 and classified as problematic . The affected element is an unknown function of the component Backup Restore Handler . Perform…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-44166 | Pocketbase up to 0.22.41/0.37.3 Password Reset improper authentication (GHSA-pq7p-mc74-g65w)

A vulnerability was found in Pocketbase up to 0.22.41/0.37.3 and classified as critical . The impacted element is an unknown function of the component Password Reset Handler . Executing a manipulation…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-44204 | Shelf-nu shelf.nu up to 1.20.0 Query Parameter /assets information disclosure (GHSA-69xv-wmgg-3qp3)

A vulnerability was found in Shelf-nu shelf.nu up to 1.20.0 . It has been classified as problematic . This affects an unknown function of the file /assets of the component Query Parameter Handler . Th…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-42045 | LobeHub up to 2.1.47 IPC Interface index.tsx cross site scripting (GHSA-xq4x-622m-q8fq)

A vulnerability was found in LobeHub up to 2.1.47 . It has been declared as problematic . This impacts an unknown function of the file src/features/Portal/Artifacts/Body/Renderer/index.tsx of the comp…

VulDB Read →
⬡ Vulnerabilities & CVEs May 12, 2026
CVE-2026-42141 | xibosignage xibo-cms up to 4.4.0 server-side request forgery (GHSA-fwq8-c4gw-pxmh)

A vulnerability was found in xibosignage xibo-cms up to 4.4.0 . It has been rated as critical . Affected is an unknown function. This manipulation causes server-side request forgery. This vulnerabilit…

VulDB Read →
◉ Threat Intelligence May 12, 2026
Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise

Microsoft Incident Response investigated an attack operated through legitimate and trusted administrative mechanisms to blend seamlessly into routine operations and remain undetected demonstrating tha…

Microsoft Security Read →
◉ Threat Intelligence May 12, 2026
Defending consumer web properties against modern DDoS attacks

Read how to protect consumer websites and defend against modern DDoS attacks with layered security, resilient architecture, and graceful service degradation. The post Defending consumer web properties…

Microsoft Security Read →
◇ Industry News & Leadership May 12, 2026
What Security Teams are Missing About AI Enabled Threats
Data Breach Today Read →
◇ Industry News & Leadership May 12, 2026
AI-Built Zero-Day Nearly Powered Mass Attack

Google Says Criminals Used AI to Discover and Code Exploit A cybercriminal group came close to launching a mass attack earlier this year, armed with a software exploit that an AI model had built from …

Data Breach Today Read →
◇ Industry News & Leadership May 12, 2026
OpenAI Unlocks Cybersecurity Model for Europe

German Financial Regulator Warns Sector to Step Up Defenses OpenAI is stepping up to do what arch-rival Anthropic still won't. The AI firm will give European authorities and companies access to its ne…

Data Breach Today Read →
◇ Industry News & Leadership May 12, 2026
No Blind Spots: How Top MSSPs Prevent Incidents withLive Threat Visibility

Every incident that damages a client starts with a moment of invisibility: a connection the SIEM didn’t flag, a domain the detection rules didn’t know about, an IOC that was active for two days before…

Cybersecurity News Read →
◇ Industry News & Leadership May 12, 2026
Ivanti Patches Multiple Vulnerabilities in Secure Access, Xtraction, vTM and Endpoint Manager

Ivanti has released its May 2026 Patch Tuesday security updates, disclosing vulnerabilities across four products while revealing that artificial intelligence tools are already helping its engineers un…

Cybersecurity News Read →
◇ Industry News & Leadership May 12, 2026
Open WebUI Vulnerability via File Upload Leads to 1-Click RCE Attack

A single click can allow attackers to exploit a critical, unpatched flaw in Open WebUI to seize control of AI workspaces, execute remote code, hijack accounts, and steal sensitive chat histories. Disc…

Cybersecurity News Read →
◇ Industry News & Leadership May 12, 2026
Critical Fortinet FortiSandbox Vulnerability Enables Code Execution Attacks

A critical security flaw in Fortinet’s FortiSandbox platform is putting enterprise networks at serious risk, allowing unauthenticated attackers to execute arbitrary code or commands remotely, with no …

Cybersecurity News Read →
◇ Industry News & Leadership May 12, 2026
Fortinet Patches Five Vulnerabilities Across FortiAP, FortiOS, and Enterprise Products

Fortinet released security advisories on May 12, 2026, addressing five vulnerabilities spanning its wireless access point controllers, network operating system, and enterprise management platforms, in…

Cybersecurity News Read →
← Prev 58 / 865 Next →