Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.
On July 24th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Elementor Pro, a WordPress plugin with an estimated 6,000,000 active installations. This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including execu...
Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.
Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate privileges over a network.
It was discovered that Netty did not properly handle malformed HTTP/2
control frames. An attacker could use this to cause a denial of service
via resource exhaustion. This issue only affects Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2025-55163)
It was discover...
Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.
Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment.
The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet...
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability.
According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScale...
The designation would unlock a range of federal services, tools and resources for an industry that policymakers view as increasingly tied to national and economic security.
The post The push to designate AI as the next critical infrastructure sector appeared first on CyberScoop.
Ubuntu released a security update addressing multiple vulnerabilities in PostgreSQL across various versions, allowing potential arbitrary code execution and sensitive information disclosure by authenticated users.
Twitch added an option to opt out of training Amazon AI with your content—two years after it confirmed that training had begun.
SFR confirme un incident détecté le 2 juillet sur un outil de gestion des raccordements fibre. Un pirate revendique 2,1 millions de lignes de données.
Le post France : SFR confirme une nouvelle fuite de données visant ses abonnés fibre a été publié sur IT-Connect.
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).
The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection tha...
Operation CameraSwarm targeted Dahua cameras across multiple countries, focusing on Russian and CIS telecom netblocks.
The post Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia appeared first on SecurityWeek.
Hack Twins : Un nouveau casino apparaît chez deux groupes de pirates informatiques différents.
Building on the last diary on Using MS Graph and Powershell, let&#;x26;#;39;s look at "Risky" logins.
Research by: Jiřà Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary file and registry operations from Ring 0 – without exploits,...
The data search and AI giant confirmed unauthorized access to its systems during an incident on Tuesday, and said it was investigating the breach.