π΅οΈ RESEARCH & DEEP DIVES
-
FeatherPanel subuser privilege escalation flaw CVE-2026-84715 affects versions before 1.3.7.10
A high-severity privilege escalation vulnerability, CVE-2026-84715, has been disclosed in FeatherPanel.- Applies to FeatherPanel users running versions prior to 1.3.7.10.
- CVE-2026-84715 is a high-severity privilege escalation vulnerability involving panel subusers.
π Coverage: thehackerwire.com Β· π via thehackerwire.com (discovered)
-
Security Boulevard outlines 9 enterprise identity trends defining 2026 and beyond
Security Boulevard identifies nine enterprise identity trends expected to shape 2026 and beyond.- Applies to enterprises running identity and access management (IAM) programs as AI agents enter production use.
- Trend one: agentic identity becomes a first-class citizen in IAM, with AI agents already operating in production environments.
- These agents read emails, write code, query databases, post to Slack, file tickets, and call APIs across dozens of enterprise systems.
π Coverage: securityboulevard.com Β· π via securityboulevard.com (discovered)
-
Sality botnet infrastructure dismantled in joint global takedown β BleepingComputer
-
23-Year-Old Sality P2P Botnet Disrupted β SecurityWeek
-
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another β The Hacker News
-
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials β The Hacker News
-
Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads β The Hacker News
-
OAuth Single Sign On 6.25.0 - 7.0.0 - Unauthenticated Account Takeover via Un... β CVE ThreatInt
-
WPvivid Backup & Migration before 0.9.133 - Admin+ SQLi via Upload Cleaner Isolati... β CVE ThreatInt
-
Simple Ajax Chat before 20260827 - Unauthenticated Stored XSS via Chat Message Lin... β CVE ThreatInt
-
FAQ Builder AYS 1.6.3 - 1.8.4 - Unauthenticated Stored XSS via ays_get_user_i... β CVE ThreatInt
-
Theme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creatio... β CVE ThreatInt
-
JetStyleManager before 1.3.9 - Skin Deletion and Modification via CSRFThe JetStyle... β CVE ThreatInt
-
WC Vendors before 2.7.2.1 - Vendor+ Cross-Vendor Product and Arbitrary Post Modifi... β CVE ThreatInt
-
WC Vendors before 2.7.2.1 - Vendor+ Cross-Vendor Order Shipment Status ChangeThe W... β CVE ThreatInt
-
WC Vendors before 2.7.2.1 - Order Shipment Status Change via CSRFThe WC Vendors Wo... β CVE ThreatInt
-
MasterStudy LMS before 3.7.46 - Unauthenticated Student Statistics Disclosure via ... β CVE ThreatInt
-
MasterStudy LMS before 3.7.46 - Instructor+ Cross-Course Curriculum Deletion and T... β CVE ThreatInt
-
MasterStudy LMS before 3.7.46 - Unauthenticated Unpublished Course Title Disclosur... β CVE ThreatInt
-
MasterStudy LMS before 3.7.46 - Instructor+ Quiz Answer Disclosure via IDORThe Mas... β CVE ThreatInt
-
MasterStudy LMS before 3.7.46 - Unauthenticated Student Enrollment Disclosure via ... β CVE ThreatInt
-
MasterStudy LMS before 3.7.46 - Subscriber+ Cross-Instructor Order Data Disclosure... β CVE ThreatInt
-
Advanced Custom Fields: Extended 0.9.2.2 - 0.9.2.6 - Unauthenticated Privileg... β CVE ThreatInt
-
CatalogX before 6.1.3 - Unauthenticated Email Content Injection via Shared Transie... β CVE ThreatInt
-
FormLayer before 1.0.9 - Unauthenticated Form Configuration Disclosure via Form Su... β CVE ThreatInt
-
RegistrationMagic before 6.0.9.9 - Unauthenticated Stored XSS via Rating FieldThe ... β CVE ThreatInt
-
Critical SonicWall Remote Code Execution Vulnerabilities Actively Exploited in Attacks β Cyber Security News
-
Critical HPE Fabric Composer Flaws Let Unauthenticated Attackers Execute Code and Take Over Systems β Cyber Security News
-
Hackers Hide a Full Remote Access Trojan Inside a Real Exodus Crypto Wallet β Cyber Security News
-
Google Fixes 26 Chrome Vulnerabilities, Including 2 Critical Use-After-Free Flaws β Cyber Security News
-
Hugging Face Flaw Lets Malicious AI Models Plant Python Code on User Systems β Cyber Security News
-
OpenAIβs New Astra AI Can Discover Zero-Day Security Flaws and Build Exploits β Cyber Security News
-
-SuperProxy evolves from proxy botnet to loader -UNC3886's FireAnt campaign evolves -Mirage Kitten targets fintech with... β @campuscodi@mastodon.social
-
-BlueSky adds a feature for less visibility -Rust gets perma-maintainers -SweepLED can find hidden cameras -US... β @campuscodi@mastodon.social
-
-BGP hijack delivers malicious Virtualizor updates -Indian authorities take down Telegram doxing bot -Composer packages... β @campuscodi@mastodon.social
-
Coolify RCE via Environment Variable Key Injection β thehackerwire.com (discovered)
-
What Is MCP in Software Development and Why Does It Matter β securityboulevard.com (discovered)
-
Testing systems for high load and denial-of-service conditions β securityboulevard.com (discovered)
-
Best High-Risk Merchant Account Providers for Secure Online Businesses β securityboulevard.com (discovered)