CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  39048 articles  ·  updated every 4 hours · grows forever

39048Total
28538Full Text
Jul 25, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 19, 2026
CVE-2026-22810 | laurent22 joplin up to 3.5.6 path traversal (GHSA-gcmj-c9gg-9vh6)

A vulnerability, which was classified as problematic , was found in laurent22 joplin up to 3.5.6 . Affected is an unknown function. The manipulation results in path traversal: '../filedir'. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs May 19, 2026
CVE-2026-45242 | steipete summarize up to 0.15.0 /v1/summarize authorization

A vulnerability has been found in steipete summarize up to 0.15.0 and classified as problematic . Affected by this vulnerability is an unknown functionality of the file /v1/summarize . This manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs May 19, 2026
CVE-2026-45244 | steipete summarize up to 0.15.0 authorization

A vulnerability was found in steipete summarize up to 0.15.0 and classified as critical . Affected by this issue is some unknown functionality. Such manipulation leads to missing authorization. This v…

VulDB Read →
⬡ Vulnerabilities & CVEs May 19, 2026
CVE-2026-26978 | FreePBX up to 16.0.70/17.0.5 Backup unserialize deserialization (GHSA-5v7h-49gr-jcwr / EUVD-2026-30810)

A vulnerability was found in FreePBX up to 16.0.70/17.0.5 . It has been classified as critical . This affects the function unserialize of the component Backup Module . Performing a manipulation result…

VulDB Read →
⬡ Vulnerabilities & CVEs May 19, 2026
CVE-2026-27130 | dokploy up to 0.26.6 execAsync appName os command injection (GHSA-fcgq-jjfg-hrhj)

A vulnerability was found in dokploy up to 0.26.6 . It has been declared as critical . This vulnerability affects the function execAsync . Executing a manipulation of the argument appName can lead to …

VulDB Read →
⬡ Vulnerabilities & CVEs May 19, 2026
CVE-2026-8851 | Alinto SOGo up to 5.12.7 addUserInAcls Endpoint /acls sogo_acl uid sql injection

A vulnerability was found in Alinto SOGo up to 5.12.7 . It has been rated as critical . This issue affects the function sogo_acl of the file /acls of the component addUserInAcls Endpoint . The manipul…

VulDB Read →
⬡ Vulnerabilities & CVEs May 19, 2026
CVE-2026-47092 | jarrodwatts claude-hud up to 0.0.12 on Windows Environment Variable execFile uncontrolled search path (Issue 485)

A vulnerability categorized as problematic has been discovered in jarrodwatts claude-hud up to 0.0.12 on Windows. Impacted is the function execFile of the component Environment Variable Handler . The …

VulDB Read →
⬡ Vulnerabilities & CVEs May 19, 2026
CVE-2026-27737 | BigBlueButton up to 3.0.18 cross site scripting (GHSA-8vv7-vj94-q2pv)

A vulnerability identified as problematic has been detected in BigBlueButton up to 3.0.18 . The affected element is an unknown function. This manipulation causes cross site scripting. This vulnerabili…

VulDB Read →
⬡ Vulnerabilities & CVEs May 19, 2026
CVE-2026-45231 | DumbWareio DumbAssets up to 1.0.11 Asset API Endpoint cross site scripting

A vulnerability labeled as problematic has been found in DumbWareio DumbAssets up to 1.0.11 . The impacted element is an unknown function of the component Asset API Endpoint . Such manipulation leads …

VulDB Read →
⬡ Vulnerabilities & CVEs May 19, 2026
CVE-2026-45245 | steipete summarize up to 0.15.0 server-side request forgery

A vulnerability marked as critical has been reported in steipete summarize up to 0.15.0 . This affects an unknown function. Performing a manipulation results in server-side request forgery. This vulne…

VulDB Read →
⬡ Vulnerabilities & CVEs May 19, 2026
CVE-2026-45246 | steipete summarize up to 0.15.0 Config File permission assignment (EUVD-2026-30799)

A vulnerability described as problematic has been identified in steipete summarize up to 0.15.0 . This impacts an unknown function of the component Config File . Executing a manipulation can lead to i…

VulDB Read →
⬡ Vulnerabilities & CVEs May 19, 2026
CVE-2026-27964 | NeoRazorX facturascripts up to 2025.7 cross site scripting (GHSA-gq5c-rw37-g46c)

A vulnerability classified as problematic has been found in NeoRazorX facturascripts up to 2025.7 . Affected is an unknown function. The manipulation leads to cross site scripting. This vulnerability …

VulDB Read →
⬡ Vulnerabilities & CVEs May 19, 2026
CVE-2026-21789 | HCL Connections 8.0 authorization (KB0129719)

A vulnerability classified as critical was found in HCL Connections 8.0 . Affected by this vulnerability is an unknown functionality. The manipulation results in incorrect authorization. This vulnerab…

VulDB Read →
◉ Threat Intelligence May 19, 2026
TeamPCP Supply Chain Campaign: Activity Through 2026-05-17, (Mon, May 18th)

Since the last update, the TeamPCP supply chain campaign produced its loudest stretch since the March Trivy disclosure: an officially confirmed Checkmarx Jenkins plugin compromise and a new self-sprea…

SANS ISC Read →
◉ Threat Intelligence May 19, 2026
CISA Admin Leaked AWS GovCloud Keys on Github

Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovC…

Krebs on Security Read →
◇ Industry News & Leadership May 19, 2026
GSK: The AI-Driven Science Factory

AI Rebuilds $50B Pharma Giant's Thinking, Plan Could Help Every Data-Driven Firm GSK is redesigning pharmaceutical research around AI, from data infrastructure to autonomous scientific agents. Its pla…

Data Breach Today Read →
◇ Industry News & Leadership May 19, 2026
Report: Mythos-Like AI Tools Raising Healthcare Cyber Stakes

Déjà Vu: Is Mythos in Hands of Bad Actors Akin to Cobalt Strike, Brute Ratel Abuse? Anthropic's Claude Mythos and similarly powerful artificial intelligence tools pose elevated cyber risk to the healt…

Data Breach Today Read →
◇ Industry News & Leadership May 19, 2026
OpenAI Wins in Court, Jury Says Musk Waited Too Long to File

Musk's Claims Against Altman and Microsoft Dismissed After Less Than Two Hours A federal jury took less than two hours to dismiss Elon Musk's lawsuit against OpenAI and Sam Altman, finding his claims …

Data Breach Today Read →
◇ Industry News & Leadership May 19, 2026
Microsoft May security patch fails for some due to boot partition size glitch

“Something didn’t go as planned. Undoing changes.” That’s all the clue some Windows 11 users will get when Microsoft’s May Security Update fails to install because of insufficient free space on the EF…

CSO Online Read →
◇ Industry News & Leadership May 19, 2026
Boulevard of Broken Dreams: 2 Decades of Cyber Fails

From the MGM and Caesars fiasco and MOVEit's patch nightmare to epic business blunders and the jaded reality of living in a post-breach world, Dark Reading looks back at the mistakes, miscalculations,…

Dark Reading Read →
◇ Industry News & Leadership May 19, 2026
Shai-Hulud Worm Clones Spread After Code Release

The release of Shai-Hulud source code spells trouble for software developers as researchers worry the self-replicating worm could scale.

Dark Reading Read →
◇ Industry News & Leadership May 19, 2026
'Claw Chain' Vulnerabilities Threaten OpenClaw Deployments

The now patched vulnerabilities in the rapidly growing AI agent framework allow attackers to steal credentials, escalate privileges, and maintain persistence.

Dark Reading Read →
◇ Industry News & Leadership May 19, 2026
Microsoft Exchange Zero-Day Under Attack, No Patch Available

CVE-2026-42897 stems from a cross-site scripting (XSS) vulnerability and can allow an attacker to compromise Outlook Web Access (OWA) mailboxes.

Dark Reading Read →
◇ Industry News & Leadership May 19, 2026
SHub macOS infostealer variant spoofs Apple security updates

A new variant of the 'SHub' macOS infostealer uses AppleScript to show a fake security update message and installs a backdoor. [...]

Bleeping Computer Read →
← Prev 754 / 1627 Next →