CyberIntel ⬡ News
★ Saved ◆ Cyber Reads

// Cyber
Intel Feed

cyberintel.kalymoon.com  ·  39175 articles  ·  updated every 4 hours · grows forever

39175Total
28570Full Text
Jul 25, 2026Latest
◈ Women in Cyber ◉ Threat Intelligence ◎ How-To & Tutorials ⬡ Vulnerabilities & CVEs 🔍 Digital Forensics ◍ Incident Response & DFIR ◆ Security Tools & Reviews ◇ Industry News & Leadership ✉ Email Security 🛡 Active Threats ⚠ Critical CVEs ◐ Insider Threat & DLP ◌ Quantum Computing ◬ AI & Machine Learning
🔥 Trending Topics · Last 48h
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2020-37241 | bloofoxCMS up to 0.5.2.1 Admin User Creation Endpoint cross-site request forgery (Exploit 49507)

A vulnerability labeled as problematic has been found in bloofoxCMS up to 0.5.2.1 . Affected is an unknown function of the component Admin User Creation Endpoint . The manipulation results in cross-si…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2020-37243 | Supsystic Pricing Table 1.8.6/1.8.7 GET Parameter getListForTbl sidx sql injection (Exploit 49533)

A vulnerability marked as critical has been reported in Supsystic Pricing Table 1.8.6/1.8.7 . Affected by this vulnerability is the function getListForTbl of the component GET Parameter Handler . This…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8750 | h2oai h2o-3 up to 7402 ImportFile API PersistNFS.java importFiles information disclosure

A vulnerability described as problematic has been identified in h2oai h2o-3 up to 7402 . Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8751 | h2oai h2o-3 up to 7402 JAR Model.java importBinaryModel deserialization

A vulnerability classified as critical has been found in h2oai h2o-3 up to 7402 . This affects the function importBinaryModel of the file h2o-core/src/main/java/hex/Model.java of the component JAR Han…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8752 | h2oai h2o-3 up to 7402 Rapids setproperty Primitive AstSetProperty.java exec access control

A vulnerability classified as critical was found in h2oai h2o-3 up to 7402 . This vulnerability affects the function exec of the file h2o-core/src/main/java/water/rapids/ast/prims/misc/AstSetProperty.…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8753 | kalcaddle Kodbox up to 1.64 fileThumb Plugin VideoResize.class.php parseVideoInfo ffmpegBin command injection

A vulnerability, which was classified as critical , has been found in kalcaddle Kodbox up to 1.64 . This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8754 | AstrBotDevs AstrBot up to 4.23.5 File Upload chat.py post_file filename path traversal

A vulnerability, which was classified as critical , was found in AstrBotDevs AstrBot up to 4.23.5 . Impacted is the function post_file of the file astrbot/dashboard/routes/chat.py of the component Fil…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8755 | fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c Model hiyoriUI.py _get_all_models path traversal

A vulnerability has been found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c and classified as critical . The affected element is the function _get_all_models of the file hiyo…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8756 | fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c Gradio Interface webui_preprocess.py generate_config data_dir path traversal

A vulnerability was found in fishaudio Bert-VITS2 up to 8f7fbd8c4770965225d258db548da27dc8dd934c and classified as critical . The impacted element is the function generate_config of the file webui_pre…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8757 | adenhq hive up to 0.11.0 Delete Request routes_sessions.py _read_events_tail path traversal

A vulnerability was found in adenhq hive up to 0.11.0 . It has been classified as critical . This affects the function _read_events_tail of the file core/framework/server/routes_sessions.py of the com…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8758 | Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06 /common/jsp/upload3.jsp File unrestricted upload

A vulnerability was found in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06 . It has been declared as critical . This impacts an unknown function of the file /common/jsp/upload3.jsp . Executing a manipulati…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8759 | xiandafu beetl up to 3.20.2 SpELFunction SpELFunction.java expression language injection (IIYAWC)

A vulnerability was found in xiandafu beetl up to 3.20.2 . It has been rated as critical . Affected is an unknown function of the file beetl-classic-integration/beetl-spring-classic/src/main/java/org/…

VulDB Read →
◇ Industry News & Leadership May 16, 2026
Funnel Builder Flaw Under Active Exploitation Enables WooCommerce Checkout Skimming

A critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to inject malicious JavaScript code into WooCommerce checkout pages w…

The Hacker News Read →
🔍 Digital Forensics May 16, 2026
Cellebrite Announces Participation in Upcoming Investor Conferences - Sahm

Cellebrite Announces Participation in Upcoming Investor Conferences Sahm

Sahm Read →
🛡 Active Threats May 16, 2026
Illuminate wins another round in court, but it may not all be over

The Supreme Court of California has ruled in J.M. v. Illuminate Education, Inc., a case closely watched by those concerned about holding edtech vendors liable in the event of a data breach. As backgro…

DataBreaches.net Read →
🛡 Active Threats May 16, 2026
Welcome to BlackFile: Inside a Vishing Extortion Operation

Google’s Threat Intelligence Group writes: Google Threat Intelligence Group (GTIG) has continued to track an expansive extortion campaign by UNC6671, a threat actor operating under the “BlackFile” bra…

DataBreaches.net Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8743 | Open5GS up to 2.7.6 AMF/MME src/amf/context.c ran_ue_find_by_amf_ue_ngap_id improper authorization (Issue 4498)

A vulnerability was found in Open5GS up to 2.7.6 . It has been rated as critical . This impacts the function ran_ue_find_by_amf_ue_ngap_id of the file src/amf/context.c of the component AMF/MME . Perf…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8744 | Open5GS up to 2.7.7 NRF /lib/sbi/context.c denial of service (4465/4466)

A vulnerability categorized as problematic has been discovered in Open5GS up to 2.7.7 . Affected is the function ogs_sbi_subscription_data_add/ogs_sbi_nf_service_add in the library /lib/sbi/context.c …

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8745 | Open5GS up to 2.7.7 AUSF nausf-handler.c ogs_timer_add denial of service (Issue 4472)

A vulnerability identified as problematic has been detected in Open5GS up to 2.7.7 . Affected by this vulnerability is the function ogs_timer_add in the library /src/ausf/nausf-handler.c of the compon…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8746 | Open5GS up to 2.7.7 NRF nghttp2-server.c discover_handler use after free (Issue 4476)

A vulnerability labeled as problematic has been found in Open5GS up to 2.7.7 . Affected by this issue is the function discover_handler in the library /lib/sbi/nghttp2-server.c of the component NRF . T…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-8747 | Z-BlogPHP 1.7.4.3430 Commend Approval c_system_event.php CheckComment improper authorization

A vulnerability marked as critical has been reported in Z-BlogPHP 1.7.4.3430 . This affects the function CheckComment of the file zb_system/function/c_system_event.php of the component Commend Approva…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2025-4202 | multicollab Plugin up to 5.2 on WordPress cf_add_comment authorization (EUVD-2025-209886)

A vulnerability described as critical has been identified in multicollab Plugin up to 5.2 on WordPress. This vulnerability affects the function cf_add_comment . Such manipulation leads to missing auth…

VulDB Read →
⬡ Vulnerabilities & CVEs May 16, 2026
CVE-2026-46719 | RRWO Net::Statsd::Lite up to 0.8.x on Perl crlf injection

A vulnerability classified as critical has been found in RRWO Net::Statsd::Lite up to 0.8.x on Perl. This issue affects some unknown processing. Performing a manipulation results in crlf injection. Th…

VulDB Read →
◇ Industry News & Leadership May 16, 2026
Russian hackers turn Kazuar backdoor into modular P2P botnet

The Russian hacker group Secret Blizzard has developed its long-running Kazuar backdoor into a modular peer-to-peer (P2P) botnet designed for long-term persistence, stealth, and data collection. [...]

Bleeping Computer Read →
← Prev 776 / 1633 Next →