Automated AI agent used to breach cybersecurity nonprofit DIVD
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]
BleepingComputer
*** GMail and Validation-Mails *** There seems to be an issue that Gmail is not accepting mails from my server. The reason is that I am currently rebuilding my server infrastructure and the MX-entries are not correctly set. I have activated the accounts using a Gmail-address manually. If you do not receive the validation mail, drop me a note to k.e.klingner@gmail.com.
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]
BleepingComputer
Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations.
Dark Reading
Das Unternehmen kauft sich bei einer bestehenden CA ein, um schneller startklar zu werden. Zertifikate landen voll automatisiert beim Kunden.
heise online
A vulnerability classified as very critical has been found in EVbee DC 80. The affected element is an unknown function. Performing a manipulation results in hard-coded credentials. This vulnerability is reported as CVE-…
vuldb
A vulnerability described as problematic has been identified in EVbee DC-80. Impacted is an unknown function of the component Service Menu. Such manipulation leads to improper privilege management. This vulnerability is…
vuldb
A vulnerability marked as problematic has been reported in MacWarrior ClipBucket up to 5.5.3-#197. This issue affects the function Language Update. This manipulation of the argument language_id causes sql injection. Thi…
vuldb
A vulnerability labeled as problematic has been found in MacWarrior ClipBucket up to 5.5.3-#197. This vulnerability affects the function Admin Video Edit Function. The manipulation of the argument videoid results in sql…
vuldb
A vulnerability identified as problematic has been detected in Pardus Parental Control up to 0.6.x. This affects an unknown part of the file PPCActivator.py of the component Polkit Policy. The manipulation of the argume…
vuldb
A vulnerability categorized as problematic has been discovered in OpenNMT CTranslate2 up to 4.8.0. Affected by this issue is some unknown functionality of the component Binary Model Loader. Executing a manipulation can …
vuldb
A vulnerability was found in OpenNMT CTranslate2 up to 4.8.0. It has been rated as critical. Affected by this vulnerability is an unknown functionality of the component Model Loader. Performing a manipulation results in…
vuldb
Malware operators are hiding code inside the part of a 7-Zip installer that unpacks files. A seemingly ordinary installation can start while a concealed loader contacts an attacker-controlled server. Users and analysts …
CyberSecurityNews
The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe. The post RemoteThreat Launches With $7 Million for Offensive Operations Platform appeared first on SecurityWeek.
SecurityWeek
A vulnerability was found in Freedesktop Poppler up to 26.08.0. It has been declared as problematic. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc. Such manipulation leads to integer o…
vuldb
A vulnerability was found in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. It has been classified as problematic. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFiTrueType.cc. This manipulation cause…
vuldb
A vulnerability was found in Canonical Ubuntu Pro for WSL up to 0.1.19ubuntu1 and classified as problematic. This affects an unknown function of the component Service. The manipulation results in information disclosure.…
vuldb
A vulnerability has been found in NVIDIA BlueField and ConnectX and classified as critical. The impacted element is an unknown function of the component Register Interface. The manipulation leads to improper access cont…
vuldb
A vulnerability, which was classified as very critical, was found in NVIDIA DeepStream up to 9.0.1. The affected element is an unknown function of the component Tensor Handler. Executing a manipulation can lead to integ…
vuldb
A Windows botnet called x47.c can spend victims’ paid AI credits, steal data, and flood websites. Its operator markets it as an attack toolkit for remote use, but the evidence describes advertised capabilities, not conf…
CyberSecurityNews
Meta-spotted flaw could hand attackers arbitrary code execution via a maliciously crafted file
The Register
A vulnerability, which was classified as critical, has been found in risesoft-y9 WorkFlow-Engine up to 9.6.10. Impacted is the function getByIdAndYear of the file CustomHistoricProcessServiceImpl.java of the component O…
vuldb
The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.
Dark Reading
A vulnerability classified as problematic was found in Apache Polaris up to 1.7.x. This issue affects some unknown processing of the component FileIO Client. Such manipulation leads to server-side request forgery. This …
vuldb
Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdow…
The Hacker News
Discover the future of AI agents with Angie Jones, VP of Developer Experience at the Agentic AI Foundation. Learn about open source standards, MCP, and secure agentic engineering on the OpenSSF podcast.
OpenSSF
But what does he know about cybercrime?
Cybernews
A North Korea-linked malware campaign has found a way to keep infected computers connected to its operators. Instead of storing malware on Ethereum, the attackers hide the location of a control server inside cryptocurre…
CyberSecurityNews
The mobile gaming industry is built on an insidious surveillance network, Proton says.
Cybernews
A vulnerability classified as problematic has been found in Parla Auto Automotive Trading DetaWix Mobile Web Portal up to 1.0.18. This vulnerability affects unknown code. This manipulation causes information disclosure.…
vuldb
Identity governance helps control who should have access, but periodic reviews alone may not reveal attacks as they happen. tenfold Software explains how real-time identity telemetry can help security teams investigate …
BleepingComputer
US-Behörden warnen vor einem bevorstehenden Cyberangriff auf Kiteworks-Systeme. Das Unternehmen fährt auch gehostete Kundensysteme herunter. (Sicherheitslücke, Security)
GOLEM
A vulnerability described as critical has been identified in TIBCO Administrator up to 5.13.0. This affects an unknown part. The manipulation results in injection. This vulnerability is reported as CVE-2026-4034. The at…
vuldb
A vulnerability marked as problematic has been reported in dmonad lib0 up to 0.2.117/1.0.0-rc.32. Affected by this issue is the function readUint8Array of the component Binary Decoder. The manipulation leads to out-of-b…
vuldb
A vulnerability labeled as problematic has been found in dmonad lib0 up to 0.2.118. Affected by this vulnerability is the function readFromDataView of the component Decoder. Executing a manipulation can lead to out-of-b…
vuldb
A vulnerability identified as critical has been detected in Mozilla Firefox up to 156. Affected is an unknown function of the component Downloads. Performing a manipulation results in insufficient verification of data a…
vuldb
A vulnerability categorized as critical has been discovered in Mozilla Firefox up to 115.41/140.16/153.3. This impacts an unknown function of the component Canvas2D. Such manipulation leads to use after free. This vulne…
vuldb
A vulnerability was found in Mozilla Firefox up to 153.3/156. It has been rated as critical. This affects an unknown function of the component DOM UI Events/Focus Handler. This manipulation causes use after free. This v…
vuldb
A vulnerability was found in Mozilla Firefox up to 153.3/156. It has been declared as problematic. The impacted element is an unknown function of the component StorageManager. The manipulation results in denial of servi…
vuldb
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp …
The Hacker News
A vulnerability was found in Mozilla Firefox up to 153.3/156. It has been classified as critical. The affected element is an unknown function of the component JIT. The manipulation leads to use after free. This vulnerab…
vuldb
A vulnerability was found in Mozilla Firefox up to 153.3/156 and classified as critical. Impacted is an unknown function of the component Networking HTTP. Executing a manipulation can lead to insufficient verification o…
vuldb
A vulnerability has been found in Mozilla Firefox up to 153.3/156 and classified as critical. This issue affects some unknown processing of the component Places. Performing a manipulation results in improper privilege m…
vuldb
A vulnerability, which was classified as critical, was found in Mozilla Firefox up to 115.41/140.16/153.3/156. This vulnerability affects unknown code of the component Panning/Zooming. Such manipulation leads to imprope…
vuldb
A vulnerability, which was classified as critical, has been found in Mozilla Firefox up to 115.41/140.16/153.3/156. This affects an unknown part of the component XPCOM. This manipulation causes sandbox issue. This vulne…
vuldb
A vulnerability classified as critical was found in Mozilla Firefox up to 140.16/153.3/156. Affected by this issue is some unknown functionality of the component Address Bar. The manipulation results in improper privile…
vuldb
Turns out teaching an AI to keep going can make it rather bad at knowing when to stop
The Register
A vulnerability classified as critical has been found in Mozilla Firefox up to 140.16/153.3/156. Affected by this vulnerability is an unknown functionality of the component Gtk. The manipulation leads to use after free.…
vuldb
A vulnerability described as critical has been identified in Mozilla Firefox up to 156. Affected is an unknown function of the component WebAssembly. Executing a manipulation can lead to Remote Code Execution. This vuln…
vuldb
A vulnerability marked as critical has been reported in Mozilla Firefox up to 153.3/156. This impacts an unknown function of the component Networking Component. Performing a manipulation results in improper isolation or…
vuldb
A vulnerability labeled as critical has been found in Mozilla Firefox up to 153.3/156. This affects an unknown function of the component CSS Parsing/Computation. Such manipulation leads to use after free. This vulnerabi…
vuldb
A vulnerability identified as critical has been detected in Mozilla Firefox up to 153.3/156. The impacted element is an unknown function of the component JIT. This manipulation causes out-of-bounds read. This vulnerabil…
vuldb
A vulnerability categorized as critical has been discovered in Mozilla Firefox up to 156. The affected element is an unknown function of the component JIT. The manipulation results in memory corruption. This vulnerabili…
vuldb
A vulnerability was found in Mozilla Firefox up to 153.3/156. It has been rated as problematic. Impacted is an unknown function of the component Graphics. The manipulation leads to denial of service. This vulnerability …
vuldb
A vulnerability was found in Mozilla Firefox up to 140.16/153.3/156. It has been declared as critical. This issue affects some unknown processing of the component DOM Core/HTML Component. Executing a manipulation can le…
vuldb
A vulnerability was found in Mozilla Firefox. It has been classified as critical. This vulnerability affects unknown code of the component Service Workers. Performing a manipulation results in improper privilege managem…
vuldb
A vulnerability was found in Mozilla Firefox up to 156 and classified as critical. This affects an unknown part of the component DevTools. Such manipulation leads to Remote Code Execution. This vulnerability is referenc…
vuldb
A vulnerability has been found in Mozilla Firefox up to 153.3/156 and classified as problematic. Affected by this issue is some unknown functionality of the component DevTools. This manipulation causes permissive cross-…
vuldb
A vulnerability, which was classified as critical, was found in Mozilla Firefox up to 153.3/156. Affected by this vulnerability is an unknown functionality of the component WebGPU. The manipulation results in uninitiali…
vuldb
A vulnerability, which was classified as critical, has been found in Mozilla Firefox up to 156. Affected is an unknown function of the component Audio/Video. The manipulation leads to use after free. This vulnerability …
vuldb
A vulnerability classified as critical was found in Mozilla Firefox up to 156. This impacts an unknown function of the component Preferences Backend. Executing a manipulation can lead to use after free. This vulnerabili…
vuldb
A vulnerability classified as problematic has been found in Mozilla Firefox up to 115.41/140.16/153.3/156. This affects an unknown function of the component WebExtensions. Performing a manipulation results in permissive…
vuldb