88Articles
8Categories
2026-03-02Date
🚨
Vulnerability Report - February 2026submitted by cm0002 to cybersecurity 1 points | 0 comments https://www.vulnerability-lookup.org/2026/03/02/vulnerability-report-february-2026/ Introduction This vulnerability report has been generated using data aggregated on Vulnerability-Lookup , with contributions from the pla…
KEV
πŸ›
Angular SSR Flaw Enables Unauthorized Server-Side Requests in Web Apps
πŸ›
APT28 Tied to CVE-2026-21513 MSHTML 0-Day Exploited Before Feb 2026 Patch Tuesday
πŸ›
Langflow CSV Agent Flaw Could Let Attackers Execute Arbitrary Code
πŸ›
OneUptime Command Injection Vulnerability Poses Major Risk of Full System Takeover
πŸ›
Proof-of-Concept Released for Windows ALPC Privilege Escalation via Error Reporting
πŸ›
MSHTML Zero-Day in Windows Exploited by APT28 Prior to Feb 2026 Security Update
KEV
πŸ›
CVE-2026-3102: macOS ExifTool image-processing vulnerability | Kaspersky official blog
πŸ›
New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel
πŸ›
VU#431821: MS-Agent does not properly sanitize commands sent to its shell tool, allowing for RCE
⚠️
OpenClaw 0-Click Flaw Lets Malicious Websites Hijack Developer AI Agents
⚠️
Pixel Perfect Browser Extension Exploited for Stealth Script Injection and Security Header Stripping
⚠️
How CISOs can build a resilient workforce
⚠️
CISA Leadership Shakeup, OpenClaw Hijack, Robot Vacuums and More
⚠️
Middle East AWS Outage Sends Shockwaves Through Cloud Infrastructure Service
⚠️
CISA Alerts on RESURGE Malware Exploiting Ivanti Connect Secure Zero-Days
⚠️
Hackers Launch Massive SonicWall Firewall Attack Using 4,000+ IP Addresses
⚠️
North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for Cross-Platform RAT
⚠️
Project Compass Operation Cracks Down on β€œThe Com” Cybercrime Collective – 30 Arrested, 179 Suspects Identified
⚠️
A scorecard for cyber and risk culture
⚠️
Innovation without exposure: A CISO’s secure-by-design framework for business outcomes
⚠️
GTFire Phishing Campaign Exploits Google Services to Bypass Detection and Harvest Credentials
⚠️
UXSS Vulnerability in DuckDuckGo Browser’s AutoConsent JS Bridge Allows Cross-Origin Attacks
⚠️
TPMS Flaw in Toyota, Mercedes, and Other Major Brands Enables Covert Vehicle Tracking
⚠️
⚑ Weekly Recap: SD-WAN 0-Day, Critical CVEs, Telegram Probe, Smart TV Proxy SDK and More
⚠️
OpenClaw Vulnerability Allowed Websites to Hijack AI Agents
⚠️
hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions
⚠️
Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant
⚠️
Vulnerability monitoring service secures public-sector websites faster
⚠️
New AirSnitch attack bypasses Wi-Fi encryption in homes, offices, and enterprises
⚠️
CyberStrikeAI tool adopted by hackers for AI-powered attacks
πŸ“’
OT Security/business resilience, lack of incentives for securing software & the news - ESW #448
πŸ“’
Nick Andersen Appointed Acting Director of CISA
πŸ“’
CISA warns that RESURGE malware can be dormant on Ivanti devices
πŸ“’
UK warns of Iranian cyberattack risks amid Middle-East conflict
πŸ“’
IBM security advisory (AV26-180)
πŸ“’
Ubuntu security advisory (AV26-182)
πŸ“’
Dell security advisory (AV26-181)
πŸ“’
[Control systems] CISA ICS security advisories (AV26–183)
πŸ“’
Red Hat security advisory (AV26-184)
πŸ“’
VMware security advisory (AV26-186)
πŸ“’
HPE security advisory (AV26-185)
πŸ“’
Veeam security advisory (AV26-188)
πŸ“’
Android security advisory – March 2026 monthly rollup (AV26-187)
πŸ”₯
KomikoAI - 1,060,191 breached accounts
πŸ”₯
Israel hacked BadeSaba, a popular Iranian prayer app with 5M+ installs on Google Play, to send messages urging Iranian military personnel to defect
πŸ”₯
Israel hacked BadeSaba, a popular Iranian prayer app with 5M+ installs on Google Play, to send messages urging Iranian military personnel to defect
πŸ”₯
Quitbro - 22,874 breached accounts
πŸ”₯
Prayer App Used by Millions Hacked to Broadcast Defection Messages Amid U.S.-Israel Strikes on Iran
πŸ”₯
Weekly Update 493
πŸ”₯
Hacker erpressen weniger LΓΆsegeld
πŸ”₯
Lovora - 495,556 breached accounts
πŸ”₯
GUEST ESSAY: Real cyber risks arise when small flaws combine and alerts are viewed in isolation
πŸ”₯
US-Israel and Iran Trade Cyberattacks: Pro-West Hacks Cause Disruption as Tehran Retaliates
πŸ”₯
Canadian Tire Data Breach Impacts 38 Million Accounts - SecurityWeek
πŸ”₯
900+ Sangoma FreePBX Instances Compromised in Ongoing Web Shell Attacks
πŸ”₯
Hackers Weaponize Claude Code in Mexican Government Cyberattack - SecurityWeek
πŸ”₯
Madison Square Garden Data Breach Confirmed Months After Hacker Attack
πŸ”₯
When the Worst Actually Happens
πŸ”₯
Hacktivists claim to have hacked Homeland Security to release ICE contract data
πŸ•΅οΈ
ISC Stormcast For Monday, March 2nd, 2026 https://isc.sans.edu/podcastdetail/9830, (Mon, Mar 2nd)
πŸ•΅οΈ
OCRFix Botnet Uses ClickFix Phishing and EtherHiding to Mask Blockchain C2 Infrastructure
πŸ•΅οΈ
Quick Howto: ZIP Files Inside RTF, (Mon, Mar 2nd)
πŸ•΅οΈ
Wireshark 4.6.4 Released, (Mon, Mar 2nd)
πŸ•΅οΈ
Google Working Towards Quantum-Safe Chrome HTTPS Certificates
πŸ•΅οΈ
North Korean APT Targets Air-Gapped Systems in Recent Campaign
πŸ•΅οΈ
LLM-Assisted Deanonymization
πŸ•΅οΈ
Hackers Use 1Campaign to Hide Malicious Ads From Google Reviewers
πŸ•΅οΈ
AWS Expands Security Hub Into a Cross-Domain Security Platform
πŸ•΅οΈ
The Case for Behavioral AI in Legal Email Security
πŸ•΅οΈ
ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket
πŸ•΅οΈ
Mentorship Monday - Discussions for career and learning!
πŸ•΅οΈ
Link11 Releases European Cyber Report 2026: DDoS Attacks Become a Constant Threat
πŸ•΅οΈ
Google Develops Merkle Tree Certificates to Enable Quantum-Resistant HTTPS in Chrome
πŸ•΅οΈ
An App That Detects Smart Glasses
πŸ•΅οΈ
OAuth redirection abuse enables phishing and malware delivery
πŸ•΅οΈ
News alert: DDoS attacks surge 75% in 2025; Link11 says attacks now sustained, not sporadic
πŸ•΅οΈ
Why Service Providers Must Become Secure AI Factories
🌐
Cyber threat bulletin: Iranian Cyber Threat Response to US/Israel strikes, February 2026
πŸ“‘
Im Fokus: RZ-Modernisierung
πŸ“‘
Anthropic confirms Claude is down in a worldwide outage
πŸ“‘
How to Protect Your SaaS from Bot Attacks with SafeLine WAF
πŸ“‘
Hackers and internet outages hit Iran amid U.S. air strikes
πŸ“‘
How Deepfakes and Injection Attacks Are Breaking Identity Verification
πŸ“‘
Florida woman imprisoned for massive Microsoft license fraud scheme
πŸ“‘
Alabama man pleads guilty to hacking, extorting hundreds of women
πŸ“‘
Fake Google Security site uses PWA app to steal credentials, MFA codes
πŸ“‘
A new app alerts you if someone nearby is wearing smart glasses