[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (16 articles)

|

// AI-powered summary generated at 20:00

> Multiples vulnérabilités dans Moodle (29 avril 2026)
De multiples vulnérabilités ont été découvertes dans Moodle. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une injection SQL (SQLi) et une injection de requêtes illégitimes par rebond (CSRF).
> Vulnérabilité dans Elastic Package Registry (29 avril 2026)
Une vulnérabilité a été découverte dans Elastic Package Registry. Elle permet à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.
> [local] GNU InetUtils 2.6 - Telnetd Remote Privilege Escalation
GNU InetUtils 2.6 - Telnetd Remote Privilege Escalation
> Multiples vulnérabilités dans Xen (29 avril 2026)
De multiples vulnérabilités ont été découvertes dans Xen. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.
> [webapps] Craft CMS 5.6.16 - RCE
Craft CMS 5.6.16 - RCE
> [webapps] HAX CMS 24.x - Stored Cross-Site Scripting (XSS)
HAX CMS 24.x - Stored Cross-Site Scripting (XSS)
> 'Mini Shai-Hulud' supply chain attack targets SAP npm packages
Categories: Threat ResearchTags: advisory, NPM, SAP
> [webapps] GeographicLib v2.5.1 - stack buffer overflow
GeographicLib v2.5.1 - stack buffer overflow
> [webapps] phpMyFAQ 4.0.16 - Improper Authorization
phpMyFAQ 4.0.16 - Improper Authorization
> How a Long-Lived API Credential Let an AI Agent Delete Production Data
4 min readWhat began as a routine staging task for a SaaS startup ended in a disaster that  would have been unthinkable just months ago: an AI agent operating as a super insider threat and triggering a worst-case production failure. In a detailed X post, Jer Crane, founder of PocketOS, a software...
> [webapps] FacturaScripts 2025.43 - XSS
FacturaScripts 2025.43 - XSS
> [webapps] JuzaWeb CMS 3.4.2 - Authenticated Remote Code Execution
JuzaWeb CMS 3.4.2 - Authenticated Remote Code Execution
> Australia’s Crypto Crossroads: Regulation is Here, Now Comes the Hard Part
TL;DR Australian exchanges should not treat April 2027 as the first compliance date. AUSTRAC obligations and readiness expectations are already… The post Australia’s Crypto Crossroads: Regulation is Here, Now Comes the Hard Part appeared first on Chainalysis.
> [webapps] GUnet OpenEclass E-learning platform < 4.2 - Remote Code Execution (RCE)
GUnet OpenEclass E-learning platform < 4.2 - Remote Code Execution (RCE)
> [webapps] OpenKM 6.3.12 - Multiple
OpenKM 6.3.12 - Multiple
> FIDO Alliance wants to keep AI agents from going rogue on online payments
AI agents are beginning to shop, log in, and complete tasks with little direct input. That shift is pushing the security industry to rethink how trust works when actions are carried out on a user’s behalf. The FIDO Alliance has announced a set of initiatives to build shared standards for these inter...
> [local] OpenWrt 23.05 - Authenticated Remote Code Execution (RCE)
OpenWrt 23.05 - Authenticated Remote Code Execution (RCE)
> [local] Atlona ATOMERX21 - Authenticated Command Injection
Atlona ATOMERX21 - Authenticated Command Injection
> Spy agency officials say job loss anxiety, moving fast ‘safely’ among top challenges in AI workforce overhaul
While tech leaders think about how to strategically deploy AI tools to support human intelligence needs, rank and filers express concerns about their livelihoods. The post Spy agency officials say job loss anxiety, moving fast ‘safely’ among top challenges in AI workforce overhaul appeared first on...
> [webapps] LangChain Core 1.2.4 - SSTI/RCE
LangChain Core 1.2.4 - SSTI/RCE