76Articles
8Categories
2026-03-30Date
🚨
CISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-3055 Citrix NetScaler Out-of-Bounds Read Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors …
KEV
πŸ›
Critical Citrix NetScaler memory flaw actively exploited in attacks
KEV
πŸ›
Fortinet hit by another exploited cybersecurity flaw
KEV
πŸ›
LangChain path traversal bug adds to input validation woes in AI pipelines
πŸ›
Attackers are exploiting RCE vulnerability in BIG-IP APM systems (CVE-2025-53521) - Help Net Security
πŸ›
ZDI-26-249: NoMachine Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-248: NoMachine External Control of File Path Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-247: NoMachine External Control of File Path Arbitrary File Deletion Vulnerability
πŸ›
ZDI-26-246: (0Day) aws-mcp-server Command Injection Remote Code Execution Vulnerability
πŸ›
ZDI-26-245: (0Day) aws-mcp-server AWS CLI Command Injection Remote Code Execution Vulnerability
πŸ›
ZDI-26-244: (Pwn2Own) QNAP QHora-322 miro_webserver_controllers_api_login_singIn Authentication Bypass Vulnerability
πŸ›
ZDI-26-243: (Pwn2Own) QNAP TS-453E write_file_to_svr External Control of File Path Remote Code Execution Vulnerability
πŸ›
ZDI-26-242: (Pwn2Own) QNAP TS-453E server_handlers.pyc rr2s.kwargs Error Message Information Disclosure Vulnerability
πŸ›
ZDI-26-241: (Pwn2Own) QNAP QHora-322 qvpn_db_mgr username SQL Injection Remote Code Execution Vulnerability
πŸ›
ZDI-26-240: (Pwn2Own) QNAP QHora-322 qvpn_db_mgr role_type Improper Neutralization of Escape Sequences Authentication Bypass Vulnerability
πŸ›
ZDI-26-239: (Pwn2Own) QNAP QHora-322 login.newAuthMiddleware.Authenticator Authentication Bypass Vulnerability
πŸ›
ZDI-26-238: Linux Kernel AoE Driver Use-After-Free Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-237: (Pwn2Own) QNAP QHora-322 ip6_wanifset Improper Restriction of Communication Channel to Intended Endpoints Firewall Bypass Vulnerability
πŸ›
ZDI-26-236: Digilent DASYLab DSB File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
πŸ›
ZDI-26-235: Digilent DASYLab DSA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
πŸ›
ZDI-26-234: Digilent DASYLab DSA File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
πŸ›
ZDI-26-233: Digilent DASYLab DSA File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
πŸ›
ZDI-26-232: (Pwn2Own) Red Hat Enterprise Linux vmwgfx Driver Integer Overflow Local Privilege Escalation Vulnerability
πŸ›
ZDI-26-231: Apple macOS Exposure of Sensitive Information to Unauthorized Sphere Information Disclosure Vulnerability
πŸ›
ZDI-26-230: Apple macOS CoreMedia Framework Out-Of-Bounds Write Remote Code Execution Vulnerability
πŸ›
ZDI-26-229: OpenClaw Client PKCE Verifier Information Disclosure Vulnerability
πŸ›
ZDI-26-228: OpenClaw Canvas Authentication Bypass Vulnerability
πŸ›
ZDI-26-227: OpenClaw Canvas Path Traversal Information Disclosure Vulnerability
πŸ›
VU#221883: CrewAI contains multiple vulnerabilities including SSRF, RCE and local file read
⚠️
Russian State Hackers Go After IoS Devices
⚠️
A Vulnerability in F5 Products Could Allow for Remote Code Execution
⚠️
Multiple Vulnerabilities in NetScaler ADC and NetScaler Gateway Could Allow for Memory Overread
⚠️
Healthcare tech firm CareCloud says hackers stole patient data
⚠️
Hackers exploiting critical F5 BIG-IP flaw in attacks, patch now
⚠️
Critical Fortinet Forticlient EMS flaw now exploited in attacks
⚠️
OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability
⚠️
⚑ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
⚠️
Three China-Linked Clusters Target Southeast Asian Government in 2025 Cyber Campaign
⚠️
Report: There Are Nearly 66 Billion Stolen Identity Records on Criminal Forums
⚠️
Leak reveals Anthropic’s β€˜Mythos,’ a powerful AI model aimed at cybersecurity use cases
⚠️
APIs are the new perimeter: Here’s how CISOs are securing them
⚠️
Why Kubernetes controllers are the perfect backdoor
⚠️
Oops, all Interviews: Switching to Cyber, CISO Reflections, and the State of TPCRM - ESW #452
⚠️
VU#655822: Kyverno is vulnerable to server-side request forgery (SSRF)
⚠️
Cloudflare Client-Side Security: smarter detection, now open to everyone
πŸ“’
Popular AI gateway startup LiteLLM ditches controversial startup Delve
πŸ“’
Automated Audits vs. Manual: The Binary Choice
πŸ”₯
New RoadK1ll WebSocket implant used to pivot on breached networks
πŸ”₯
European Commission confirms data breach after Europa.eu hack
πŸ”₯
HIBP Mega Update: Passkeys, k-Anonymity Searches, Massive Speed Enhancements and a Bulk Domain Verification API
πŸ”₯
Dutch Police discloses security breach after phishing attack
πŸ•΅οΈ
Apple’s Camera Indicator Lights
πŸ•΅οΈ
DeepLoad Malware Uses ClickFix and WMI Persistence to Steal Browser Credentials
πŸ•΅οΈ
ISC Stormcast For Monday, March 30th, 2026 https://isc.sans.edu/podcastdetail/9870, (Mon, Mar 30th)
πŸ•΅οΈ
Addressing the OWASP Top 10 Risks in Agentic AI with Microsoft Copilot Studio
πŸ•΅οΈ
Criminals Are Selling Stolen Tax Forms for Cheap on the Dark Web
πŸ•΅οΈ
FIRESIDE CHAT: AI gives rise to a semantic attack surface, forcing a new class of network defense
πŸ•΅οΈ
Security Leadership Styles: Builder, Fixer, or Scale Operator
πŸ•΅οΈ
Mentorship Monday - Discussions for career and learning!
πŸ•΅οΈ
Security boffins harvest bumper crop of API keys from web β€’ The Register
πŸ•΅οΈ
DevSecOps Tools?
πŸ•΅οΈ
LangChain, LangGraph Flaws Expose Files, Secrets, Databases in Widely Used AI Frameworks
πŸ•΅οΈ
TeamPCP Targets Telnyx Package in Latest Software Supply Chain Attack - Infosecurity Magazine
πŸ•΅οΈ
China Upgrades the Backdoor It Uses to Spy on Telcos Globally
πŸ•΅οΈ
ANY.RUN at RSACβ„’ 2026: Highlights & Industry Recognition
🌐
TeamPCP’s Telnyx Attack Marks a Shift in Tactics Beyond LiteLLM
πŸ“‘
Apple adds macOS Terminal warning to block ClickFix attacks
πŸ“‘
How to Evaluate AI SOC Agents: 7 Questions Gartner Says You Should Be Asking
πŸ“‘
Microsoft pulls KB5079391 Windows update over install issues
πŸ“‘
3 SOC Process Fixes That Unlock Tier 1 Productivity
πŸ“‘
Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels
πŸ“‘
The State of Secrets Sprawl 2026: 9 Takeaways for CISOs
πŸ“‘
DShield (Cowrie) Honeypot Stats and When Sessions Disconnect, (Mon, Mar 30th)
πŸ“‘
Apple will hide your email address from apps and websites, but not cops
πŸ“‘
An iron curtain for AI: how to improve autonomous AI agent security | Kaspersky official blog
πŸ“‘
15 Top Cybersecurity CEOs On The Future Of AI Agents: RSAC 2026