Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Google Docs: A Breeding Ground for Password Exposure

Google Docs became the latest casualty of a common but often overlooked mistake: storing sensitive information in a publicly accessible document. A developer’s decision to store their password in a Google Doc exposed credentials for a company, leading to immediate action by the company and a renewed call to prioritize security best practices.

Published: Thu Aug 13 02:16:06 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Unraveling the SharePoint Authentication Bypass Vulnerability: A Threat Landscape Alert

Unraveling the SharePoint Authentication Bypass Vulnerability: A Threat Landscape Alert. The recent release of a proof-of-concept code for CVE-2026-55040, a critical vulnerability in Microsoft SharePoint, has led to significant exploitation by threat actors. Organizations utilizing SharePoint are advised to keep their instances up-to-date and conduct regular security audits to mitigate the risk posed by this vulnerability.

Published: Thu Aug 13 02:22:17 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

North Korean Lazarus Group Unleashes Operation Dream Job: A Sophisticated Campaign of Social Engineering and Exploitation


The North Korean Lazarus Group has launched a new operation dubbed "Operation Dream Job," utilizing a previously unknown Windows zero-day vulnerability to gain full control of infected computers. The campaign targets defense and aerospace professionals with fake job offers, employing a sophisticated combination of social engineering and exploitation tactics.

Published: Thu Aug 13 02:33:49 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Rise of Storm-1175: A New Player in the Cybersecurity Threat Landscape


A new ransomware strain has replaced Medusa in the latest campaign from China-linked threat actor Storm-1175, further solidifying the group's reputation as a formidable force in the cybersecurity landscape. This development underscores the importance of rapid patching and monitoring to prevent similar attacks from occurring in the future.

Published: Thu Aug 13 03:40:15 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Abuse of Power: A Decade-Long History of CBP Employees Misusing Government Databases

CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues, according to records obtained by WIRED. The misuse includes querying data to look up romantic interests, monitoring family members, exposing personal information, and providing intelligence to suspected smugglers or drug-trafficking organizations. The records reveal a decade-long history of abuse of power and lack of accountability within the agency.

Published: Thu Aug 13 04:59:42 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Flock CEO Admits Mistake, Rolls Out Changes to Address Misuse of Surveillance Tech

Flock CEO Garrett Langley admits that his company got surveillance tech misuse wrong and rolls out policy changes aimed at addressing the issue. The moves come after reports of law enforcement using Flock's tools for nefarious purposes, including stalking ex-romantic partners and others.

Published: Thu Aug 13 09:41:06 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Trump Unveils Ambitious Plan to Outsource Cybersecurity Operations to Private Firms

US President Trump has announced a plan to grant private cyber firms a license to conduct "Cyber Effects Operations" against foreign transnational criminal organizations. The initiative allows participating companies to engage in activities such as cyber surveillance, technical disruptions, and manipulation of information systems to support national operations against criminals.

Published: Thu Aug 13 11:49:56 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Reality Check: Microsoft's Backup Promise Falls Short

While Microsoft 365 and Azure offer powerful tools for business productivity, organizations relying on these services must be aware of the limitations of their provider's native backup and recovery capabilities. By implementing dedicated cloud-to-cloud backup solutions and prioritizing cyber resilience, businesses can protect themselves against catastrophic data loss and ransomware attacks.

Published: Thu Aug 13 11:55:29 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Meta's AI-Powered Scam Detection on WhatsApp: A New Frontier in Combatting Online Scams

Meta has launched an AI-powered Scam Alert feature on WhatsApp, which uses machine learning algorithms to detect suspicious messages and warn users about potential scams. This new feature aims to protect its users from online scams and provide greater peace of mind when using the platform.

Published: Thu Aug 13 13:26:01 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Adobe Commerce CVE-2026-71362: A Critical Vulnerability Exposed to Hackers Shortly After Public Disclosure

Adobe Commerce CVE-2026-71362: A critical vulnerability was exposed to hackers shortly after its public disclosure, allowing attackers to hijack customer accounts and access private data. The company has released an isolated fix and urges users to patch their systems as soon as possible.

Published: Thu Aug 13 13:32:04 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

U.S. CISA Adds Metabase, Windows, and Cisco Secure Firewall Flaws to its Known Exploited Vulnerabilities Catalog: A Growing Concern for Cybersecurity

U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog due to their potential for exploitation by hackers. These high-priority targets highlight the ongoing threat landscape and emphasize the need for organizations to prioritize vulnerability management and patching.

Published: Thu Aug 13 13:40:52 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Trump Administration's Unconventional Approach to Cybersecurity: Private Sector Hackers to Combat Overseas Cybercrime

In a major shift, the Trump administration is allowing private security firms to conduct federal government-authorized cyberattacks against overseas-based cybercriminals. The program aims to combat foreign transnational criminal organizations and has raised both hopes and concerns among cybersecurity experts.

Published: Thu Aug 13 16:07:25 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Trump Administration's New Cybersecurity Framework: Allowing Private Firms to Launch International Cyberattacks


The Trump administration has announced a new cybersecurity framework that allows private firms to launch international cyberattacks. The move aims to combat cybercrime by utilizing the innovative capabilities of the private sector, but cybersecurity experts have raised concerns about potential risks and challenges associated with this approach.

Published: Thu Aug 13 16:16:28 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Private Security Firms to Conduct Authorized Cyberattacks Against Overseas Cybercriminals

Private security firms will soon be authorized to conduct cyberattacks against overseas cybercriminals in a new program announced by the Trump administration. This move marks the first time that private sector companies have been permitted to perform offensive cyberoperations, raising concerns about the potential risks and unintended consequences of this arrangement.

Published: Thu Aug 13 17:27:51 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

The Flock Conundrum: Unpacking the Controversy Surrounding Automatic License Plate Readers

As the use of automatic license plate readers (ALPRs) grows across the US, concerns about data collection, privacy, and abuse are coming under increasing scrutiny. This article provides a detailed look at the controversy surrounding Flock's ALPR deployment and its implications for law enforcement surveillance in America.

Published: Thu Aug 13 17:35:53 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Vulnerability Giving Attackers Full Control of Macs: A Growing Threat Under Active Exploitation

Mac users are advised to take immediate action to protect themselves from a critical vulnerability in macOS that allows attackers to gain full control over Macs under active exploitation. By blocking screen sharing, enabling it only when needed, and staying up-to-date with the latest security patches, users can significantly reduce the risk of falling victim to this exploit.

Published: Sat Aug 15 16:27:44 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

ChainDrop: A Lurking Menace in the npm Supply Chain

ChainDrop, a new variant of the Shai-Hulud malware, has compromised the npm supply chain, infecting hundreds of packages and evading standard defenses. This malicious entity has been identified by Microsoft and other security researchers, and its impact on the open-source community is significant. The article delves into the propagation techniques employed by ChainDrop and the implications for the npm supply chain.

Published: Sat Aug 15 17:18:46 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

French Tax Authority Confirms Data Heist After Alleged Cybercriminal Adverts 2 Million Taxpayer Records



France's General Directorate of Public Finances (DGFiP) has confirmed that an intruder accessed its systems and extracted data in June after an alleged cybercriminal advertised a purported database of 2 million taxpayers. The breach is the latest in a series of security breaches affecting France's public sector this year, highlighting the need for improved security measures and protocols to protect sensitive data.

Published: Sat Aug 15 18:26:30 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Autonomous AI Attacks: A Threat to Critical Infrastructure and Global Security

Autonomous AI attacks on critical infrastructure pose a significant threat to global security, with experts warning that the use of weaponized AI agents could disable safety systems and lead to kinetic disasters. As the threat of autonomous AI attacks continues to evolve, it is essential that governments, industry, and individuals work together to develop effective countermeasures and address the vulnerabilities in critical infrastructure.

Published: Sat Aug 15 19:08:54 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Scotland's Public Prosecution Service Bows to Cyberattack on Leaky Supplier

Scotland's public prosecution service has been left vulnerable to a cyberattack on one of its suppliers, exposing around 300 staff members to potential data breach. The incident has raised concerns about the security of sensitive information and highlights the need for organizations to take proactive measures to protect their data.

Published: Sat Aug 15 20:14:12 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

New Zealand Exposes Chinese Espionage Efforts Through Space Investments and Cyber-Operations

New Zealand's Security Intelligence Service has exposed a significant Chinese espionage effort aimed at gathering military intelligence through space investments and cyber-operations. The revelation highlights the growing threat of China's military capabilities and the need for New Zealand to strengthen its cybersecurity measures to counter this threat.

Published: Sat Aug 15 20:25:49 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

OpenAI's Computer History: A Surveillance Tool with a Twist

OpenAI's new Computer History feature allows users to record their computer interactions across apps and websites, raising concerns about surveillance and privacy. The feature may be useful for improving ChatGPT responses, but it also raises questions about the balance between convenience and security.

Published: Sat Aug 15 20:50:33 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

New York City Lawmakers Push to ‘Ban the Scan’ at Iconic Madison Square Garden

New York City lawmakers are pushing to ban facial recognition technology at Madison Square Garden, citing concerns over privacy and surveillance. The proposed legislation aims to prevent the venue from deploying biometric surveillance, which has been accused of infringing on individuals' right to privacy. With over 27 endorsements from City Council members, the push for stricter regulations on biometric surveillance is gaining momentum.

Published: Sat Aug 15 21:16:20 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Crooks Are Exploiting Expired Domains to Deliver Malware: A Growing Threat



A new trend in cyber threats is the exploitation of expired domains to deliver malware. Attackers are buying expired domains to exploit their reputation, traffic, and DNS history, using them for malware delivery, scams, and C2 infrastructure. The threat of exploited expired domains is a growing concern, and defenders should be vigilant in monitoring their domain's reputation and security.



Published: Sat Aug 15 21:22:04 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

SAP Commerce Cloud Vulnerability CVE-2026-58231: A Critical Unauthenticated Attack Vector



A critical unauthenticated attack vector has been identified in SAP Commerce Cloud, allowing attackers to exploit the system and achieve arbitrary code execution. The vulnerability, tracked as CVE-2026-58231, has already been actively exploited in the wild, just days after SAP released a patch. Organizations using SAP Commerce Cloud must take immediate action to apply the patch and conduct regular vulnerability assessments to ensure their systems are secure. This incident highlights the importance of keeping software up-to-date and the need for continuous monitoring and vulnerability assessment to identify and mitigate potential security risks.



Published: Sat Aug 15 21:29:03 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

macOS Screen Sharing Flaw Exploited to Deploy Monero Miners: A Growing Concern for Cybersecurity

macOS Screen Sharing Flaw Exploited to Deploy Monero Miners: A Growing Concern for Cybersecurity
A critical macOS authentication flaw (CVE-2026-65400) has been exploited to deploy Monero miners on Macs with port 5900 exposed online. The Dutch National Cyber Security Centre (NCSC-NL) has confirmed the exploitation of this vulnerability, which has a CVSS score of 9.8. Mac users are advised to update to the latest version of macOS, disable Screen Sharing, and ensure that port 5900 is not exposed to the internet. This is a growing concern for cybersecurity, and it is essential for users to take proactive measures to protect themselves.

Published: Sat Aug 15 21:35:01 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

GeoServer Zero-Day Vulnerability Sparks Global Worry as Attackers Begin Probing for Exploitation


GeoServer, a widely used geospatial platform, is currently facing a significant security threat due to an unpatched zero-day vulnerability that has already been discovered and is being actively exploited by attackers. The vulnerability, identified as a SQL injection and potentially Remote Code Execution (RCE) issue, has been discovered in the platform's jsonArrayContains functionality. This highlights the speed at which attackers can move once a vulnerability enters the public domain, and the importance of proactive security measures. Organizations using GeoServer must take immediate action to protect themselves and stay vigilant in the face of emerging security threats.

Published: Sat Aug 15 21:41:49 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Apple Warns of Mercenary Spyware Attacks: A Growing Threat to Personal Security



Apple has issued a warning to hundreds of users around the world, alerting them to the presence of mercenary spyware attacks. These sophisticated attacks are designed to target specific individuals or groups, often due to their role, work, or personal connections. By following Apple's advice and taking steps to secure their devices, users can reduce the risk of being targeted by these attacks.

The attacks are considered to be credible, with Apple relying solely on internal threat intelligence information and investigations to detect them. However, the company is unable to provide information about what causes them to issue threat notifications, as this information could be used by the attackers to adapt their behavior and evade detection.

The wider value of these alerts goes beyond the individual device in front of the user. They can reveal that an entire community is being targeted, as people who receive the warnings often seek help and their cases lead investigators to others. Apple has already notified users in over 150 countries since the program began in 2021, and the company expects to continue issuing these warnings as the threat of mercenary spyware attacks continues to grow.



Published: Sat Aug 15 21:48:24 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Chess.com Data Breach: A Case of Large-Scale Scraping of User Data



Chess.com, a popular online chess platform, has suffered a data breach that has exposed the personal data of over 7.3 million users. The breach, which was reported on August 14, 2026, was caused by large-scale scraping of user data, rather than a server breach. The leaked data, which includes user names, email addresses, and chess ratings, has raised concerns about the security of the platform and the potential for misuse of user data. Chess.com users are advised to treat unexpected emails with caution and to check whether the same email address has turned up elsewhere. The breach highlights the need for better data protection measures and user education.

Published: Sat Aug 15 21:56:08 2026 by llama3.2 3B Q4_K_M



Ethical Hacking News

Trump Administration Unveils Groundbreaking Initiative to Authorize Private Cyber Firms to Conduct Offensively Cyber Operations Against Transnational Criminal Networks

President Trump has authorized vetted US cybersecurity firms to conduct government-approved cyber operations against transnational criminal networks, marking a significant shift in the government's approach to combating cybercrime. The program aims to disrupt the cyber-enabled activities of transnational criminal organizations and enhance the government's ability to counter transnational cyber threats and combat cybercrime. The program's establishment is a significant step towards modernizing the government's approach to combating cybercrime, and it marks a new chapter in the government's efforts to leverage the private sector to enhance its cyber capabilities.

Published: Sat Aug 15 22:05:37 2026 by llama3.2 3B Q4_K_M



SecurityWeek

Cybersecurity M&A Roundup: 21 Deals Announced in July 2026

Adobe Commerce Bug Targeted Immediately After Disclosure

WordPress 7.0.4 Patches Remote Code Execution Vulnerability

Venture Firm Team8 Secures Additional $365 Million

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs

Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

SharePoint Vulnerability Exploited Shortly After PoC Release

Mindgard Raises $30 Million to Protect AI Systems

CISA News

CISA Unveils New Cybersecurity Resources for K-12 Schools and Districts

CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors

CISA Guide Helps Federal Agencies Securely and Effectively Use Open Source Software

CISA and Partners Unveil Updated Software Bill of Materials Resource That Improves Transparency, Security and Risk-Informed Decision Making

CISA Joins Australia and Others to Publish Guidance to Isolate Operational Technology and Enabling Systems in Critical Infrastructure

CISA, NSA, FBI and Partners Warn Zimbra Collaboration Suite Users of Ongoing Russian State-Supported Malicious Threat Activity

CISA, FBI, EPA and U.S. Government Partners Update Warning of Iran-Affiliated Threat Actors Targeting Critical Infrastructure Programmable Logic Controllers

CISA and Partners Publish Guidance to Help Software Manufacturers and Online Service Providers Work With Security Researchers

CISA Joins NSA, FBI, DC3 and International Partners Warning of Russian Cyber Threat Activity Targeting Communications, Energy, Government and Other Critical Infrastructure Sectors

CISA Announces New Advisory Council to Strengthen Partnerships and Secure Critical Infrastructure

CISA Blog

Cyber Storm X: 20 Years of Readiness, Resilience, and Real World Impact

Lessons from CISA’s Cyber Incident

Five Eyes Cyber Security Agencies Statement

CISA Offers Vital Resources as Venues Prepare for Key 2026 Events

Patch Smarter, Not Harder

NCSWIC releases additional content in its NCSWIC Video Series

CISA Highlights Vital Resources to Help Event Attendees Stay Safe

Preparing for the World Stage

Securing the American Experience

The End is Just the Beginning of Better Security: Enhanced Vulnerability Management with OpenEoX

All CISA Advisories

Siemens Parasolid

Siemens License Server (SLS)

Siemens Desigo DXR and PXC Controllers

Johnson Controls Inc. Airwall

Johnson Controls Metasys

Siemens Siveillance Video

Flow Neuroscience FL-100

Siemens LOGO! Soft Comfort

ANDRITZ HIPASE-250 and 250 SCALA

Siemens Solid Edge

Siemens Simcenter Femap

Haiwell IoT Cloud HMI Gateway

AVEVA Enterprise SCADA

Hitachi Energy APM Edge Product

Siemens RUGGEDCOM APE1808

Mira Hormone Monitor, Mira Android App

Johnson Controls C-CURE 9000 and Victor application server (Update A)

CISA Adds Three Known Exploited Vulnerabilities to Catalog

Pulsetto Vagus Nerve Stimulator

#StopRansomware: Gunra Ransomware

CISA Adds One Known Exploited Vulnerability to Catalog

CPDLC over ATN-B1 Vulnerabilities

Medixant RadiAnt DICOM

ABB Ability Zenon

Johnson Controls Inc. TL280

CISA Adds One Known Exploited Vulnerability to Catalog

Acrisure KARR BT and DR-100

CISA Adds Three Known Exploited Vulnerabilities to Catalog

Thermo Fisher Applied Biosystems Genetic Analyzers

CISA Adds One Known Exploited Vulnerability to Catalog

Exploit-DB.com RSS Feed

[webapps] Apache Gravitino 1.2.1 - SSRF

[webapps] Blocksy Companion 2.1.46 - RCE

[remote] PraisonAI praisonaiagents 1.6.77 - Remote Code Execution

[remote] mcp-server-kubernetes 3.8.x - Argument Injection

[dos] LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting

[webapps] Planyo_Online_Reservation_System 3.0 - Arbitrary File Read via SSRF

[webapps] Ray 2.56.0 - Directory Traversal & Local File Inclusion

[webapps] OrkesConductor 3.30.2 - Unauthenticated Remote Code Execution

[local] Microsoft Edge 150.0.4078.48 - RCE

[webapps] CorgetGpsDget 2_3.2 - OS Command Injection

[webapps] Joomla 2.9.99.4 - Unauthenticated Remote Code Execution

[webapps] Krayin CRM v2.2.x - Authenticated Remote Code Execution

[webapps] Atarim WordPress Plugin 4.2.2 - Sensitive Information Exposure

[webapps] Langflow 1.9.0 - RCE

[webapps] Joomla Page Builder CK 3.5.10 - Arbitrary File Upload

[webapps] MCPJam Inspector - Remote Code Execution

[local] ProtonVPN v4.4.1 - Unquoted Service Path

[webapps] Flowise 3.1.3 - arbitrary code execution

[remote] Hydra - Stack Buffer Overflow

[webapps] Discuz! X5.0 - Authentication Bypass

[webapps] Tenable Nessus 10.12.1 - SQL Injection

[webapps] WordPress Bricks Builder Theme - RCE

[remote] iOS Bluetooth PAN Exploit - Ethernet Gateway without Adapter

[webapps] Joomla Extension 4.1.4 - PHP Object injection

[webapps] Pulpy 0.1.1-Beta - Filesystem Sandbox Bypass

[local] MEmu Android Emulator 9.2.7.0 - Local Privilege Escalation

[webapps] KeepInMind 0.8.4.2 - Stored XSS

[webapps] KNX visualisering - Broken Access Control

[local] Windows Defender (MsMpEng.exe) - Race Condition

[webapps] WordPress Plugin WPZOOM Portfolio 1.4.21 - Reflected Cross-Site Scripting (XSS)

[webapps] OpenEMR 7.0.2 - Arbitrary File Read

[webapps] WordPress Contest Gallery 28.1.4 - Unauthenticated Blind SQL Injection

[webapps] Drupal Core 10.5.5 - Error-Based SQL Injection

[webapps] WordPress OrderConvo 14 - Path Traversal

[remote] Notepad++ 8.9.6 - Arbitrary Code Execution

[webapps] YAMCS yamcs-core 5.12.7 - No Rate Limiting

[webapps] YAMCS yamcs-core 5.12.7 - User Enumeration

[webapps] YAMCS yamcs-core 5.12.7 - LDAP Injection

[remote] Microsoft - NTLMv2 Hash Capture

[webapps] MikroORM 7.0.13 - SQL Injection

[webapps] Prodigy Commerce 3.3.0 - Local File Inclusion

[webapps] Langflow 1.3.0 - Remote Code Execution

[webapps] Quick Playground for WordPress 1.3.1 - Unauthenticated Remote Code Execution

[local] ImageMagick - Infinite Loop in the MIFF decoder can lead to CPU exhaustion

[local] ZTE Routers - Unauthenticated Denial of Service

[local] ZTE ZXHN H188A V6 - Authentication Bypass

[local] ZTE H298A / H108N - Unauthenticated Credential Exposure

[local] Linux Kernel - Local Privilege Escalation

[webapps] MixPHP Framework 2.2.17 - Unsafe Deserialization Remote Code Execution

[remote] Wing FTP Server 8.1.3 - Authenticated Remote Code Execution

Full Disclosure

APPLE-SA-08-06-2026-2 macOS Sequoia 15.7.9

APPLE-SA-08-06-2026-3 macOS Sonoma 14.8.9

Dangling DNS record for bastion.certb.cdp.bethesda.net

CL.0 desync in www.microsoft.com

CVE-2026-15013 miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC)

[KIS-2026-16] Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation Vulnerability

[KIS-2026-15] Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection Vulnerability

[KIS-2026-14] Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass Vulnerability

[KIS-2026-13] vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability

[SYSS-2026-050]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)

[SYSS-2026-049]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)

[SYSS-2026-048]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)

[SYSS-2026-047]: DICOM Toolkit (DCMTK) - Path traversal (CWE-22)

[SYSS-2026-046]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)

APPLE-SA-07-27-2026-8 Safari 26.6

Open Source Security

CVE-2026-16770: PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document

rsync 3.5.0 released with fixes for 33 CVEs

CVE-2026-64607: Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS

OpenSSL Security Advisory

[OSSN-0107] Ironic-Python-Agent: Container HardwareManager Security Model Misimplemented

Go 1.26.6 and Go 1.25.13 are released with 10 security fixes

[OSSA-2026-035] OpenStack Octavia: Unauthorized QoS policy deletion lock (CVE pending)

CVE-2026-13051: Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an HTML::Tidy diagnostic that validate passes to add_error as a Locale::Maketext template

CVE-2026-13048: Data::MuForm::Localizer versions through 0.05 for Perl execute Perl from a message catalog header, reached at an arbitrary path because load_lexicon interpolates the language attribute into the catalog filename

CVE-2026-66256: Apache Shindig Common, Apache Shindig Social-Api: Remote Code Execution via XStream deserialization (OpenSocial REST API)

CVE-2022-4993: HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_error use error message text built from request data as a Locale::Maketext bracket notation template

CVE-2026-71290: Apache HttpComponents Client: TLS hostname verification silently disabled on the async transport (default config, MITM)

CVE-2026-19487: Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass

CVE-2026-68481: Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider

CVE-2026-68079: Apache CXF: DefaultEncryptingCodeDataProvider allows unlimited authorization code replay








© Ethical Hacking News . All rights reserved.

Privacy | Terms of Use | Contact Us