THREAT OPS › Threat News
Threat Intelligence News
12165 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Cisco Webex Contact Center Cross-Site Scripting Vulnerabilitycisco_psirt · 2026-04-15
- What’s New in the BloodHound Query Library: BYOL, OpenGraph, Multi-Server, and Morespecterops · 2026-04-15
- The German Cyber Criminal Überfall: Shifts in Europe's Data Leak Landscapemandiant_gti · 2026-04-15
- [NVD] CVE-2026-0827 (HIGH 7.1) — During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file writenvd · 2026-04-15
- [NVD] CVE-2026-5598 (HIGH 7.5) — Covert timing channel vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA core on all (core modules). This vulnerability is associated with program files FrodoEngine.Java. This issue affects BC-JAVA: from 1.71 before 1.80.2, from 1.81 before 1.81.1, from 1.82 before 1.nvd · 2026-04-15
- [NVD] CVE-2026-5588 (HIGH 7.5) — Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpkix on all (pkix modules), Legion of the Bouncy Castle Inc. BCPKIX-FIPS bcpkix on All (pkix modules), Legion of the Bouncy Castle Inc. BCPIX-LTS bcpkix on All (pkix modulnvd · 2026-04-15
- [NVD] CVE-2026-3505 (HIGH 7.5) — Allocation of resources without limits or throttling, Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcpg on all (pg modules). This vulnerability is associated with program files AEADEncDataPacket.Java, BcAEADUtil.Java, JceAEADUtil.Jnvd · 2026-04-15
- [NVD] CVE-2026-0636 (MEDIUM 6.5) — Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (prov modules). This vulnerability is associated with program files LDAPStoreHelper. This issue affects BC-JAVA: from nvd · 2026-04-15
- [NVD] CVE-2025-14813 (HIGH 7.5) — : Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on all (core modules). This vulnerability is associated with program files G3413CTRBlockCipher. This issue affects BC-JAVA: from 1.59 before 1.80.2, from 1.81 nvd · 2026-04-15
- [Breach] Kemper — 269,299 accounts exposedhibp_breaches · 2026-04-15
- [Breach] Zara — 197,376 accounts exposedhibp_breaches · 2026-04-15
- [NVD] CVE-2026-40683 (HIGH 7.7) — In OpenStack Keystone before 28.0.1, the LDAP identity backend does not convert the user enabled attribute to a boolean when the user_enabled_invert configuration option is False (the default). The _ldap_res_to_model method in the UserApi class only performed string-to-boolean convd · 2026-04-14
- [NVD] CVE-2026-27222 (MEDIUM 5.4) — Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the nvd · 2026-04-14
- [NVD] CVE-2026-27258 (MEDIUM 5.4) — Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the nvd · 2026-04-14
- The April 2026 Security Update Reviewzdi_blog · 2026-04-14
- [NVD] CVE-2026-27238 (MEDIUM 5.4) — Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the nvd · 2026-04-14
- [NVD] CVE-2026-5713 — The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" and "python -m asyncio pstree") features could be used to read and write addresses in a privileged process if that process connected to a malicious or "infected"nvd · 2026-04-14
- Securing non-human identities: automated revocation, OAuth, and scoped permissionscloudflare_security · 2026-04-14
- Scaling MCP adoption: Our reference architecture for simpler, safer and cheaper enterprise deployments of MCPcloudflare_security · 2026-04-14
- Managed OAuth for Access: make internal apps agent-ready in one clickcloudflare_security · 2026-04-14
- [NVD] CVE-2026-2332 (HIGH 7.4) — In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty termnvd · 2026-04-14
- [NVD] CVE-2025-13822 (MEDIUM 5.3) — MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authentication middleware, allowing an unauthenticated attacker to perform actions in the name of other users and using their privileges.nvd · 2026-04-14
- ICS Security Conference 2026jpcert_blog · 2026-04-14
- [Breach] Abrigo — 711,099 accounts exposedhibp_breaches · 2026-04-14
- Phantom in the vault: Obsidian abused to deliver PhantomPulse RATelastic_security · 2026-04-14
- [NVD] CVE-2026-39956 (MEDIUM 6.1) — jq is a command-line JSON processor. Prior to version 1.8.2, the _strindices builtin in jq's src/builtin.c passes its arguments directly to jv_string_indexes() without verifying they are strings, and jv_string_indexes() in src/jv.c relies solely on assert() checks that are strippnvd · 2026-04-13
- [NVD] CVE-2026-4786 (HIGH 7.1) — Mitgation of CVE-2026-4519 was incomplete. If the URL contained "%action" the mitigation could be bypassed for certain browser types the "webbrowser.open()" API could have commands injected into the underlying shell. See CVE-2026-4519 for details.nvd · 2026-04-13
- BloodHound 9.0 — Product Updatesspecterops · 2026-04-13
- [NVD] CVE-2026-6100 (HIGH 8.1) — Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`, `bz2.BZ2Decompressor`, and `gzip.GzipFile` when a memory allocation fails with a `MemoryError` and the decompression instance is re-used. This scenario can be triggered if the process is under memory pressure. The nvd · 2026-04-13
- [NVD] CVE-2026-31420 (MEDIUM 5.5) — In the Linux kernel, the following vulnerability has been resolved: bridge: mrp: reject zero test interval to avoid OOM panic br_mrp_start_test() and br_mrp_start_in_test() accept the user-supplied interval value from netlink without validation. When interval is 0, usecs_to_jifnvd · 2026-04-13
- [NVD] CVE-2026-31419 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: bonding: fix use-after-free in bond_xmit_broadcast() bond_xmit_broadcast() reuses the original skb for the last slave (determined by bond_is_last_slave()) and clones it for others. Concurrent slave enslavenvd · 2026-04-13
- [Breach] Mytheresa — 84,108 accounts exposedhibp_breaches · 2026-04-12
- [Breach] Marcus & Millichap — 1,837,078 accounts exposedhibp_breaches · 2026-04-12
- [NVD] CVE-2026-31845 (CRITICAL 9.3) — A reflected cross-site scripting (XSS) vulnerability exists in Rukovoditel CRM version 3.6.4 and earlier in the Zadarma telephony API endpoint (/api/tel/zadarma.php). The application directly reflects user-supplied input from the 'zd_echo' GET parameter into the HTTP response witnvd · 2026-04-11
- BloodHound Has Changed. Your Course Probably Hasn’t.specterops · 2026-04-11
- [NVD] CVE-2026-32146 (HIGH 7.8) — Improper path validation vulnerability in the Gleam compiler's handling of git dependencies allows arbitrary file system modification during dependency download. Dependency names from gleam.toml and manifest.toml are incorporated into filesystem paths without sufficient validatinvd · 2026-04-11
- [NVD] CVE-2026-40175 (MEDIUM 4.8) — Axios is a promise based HTTP client for the browser and Node.js. Versions prior to 1.15.0 and 0.3.1 are vulnerable to a specific gadget-style attack chain in which prototype pollution in a third-party dependency may be leveraged to inject unsanitized header values into outbound nvd · 2026-04-10
- Ghostwriter v6.3.0 and CLI v1.0.0: New Activity Logging, Faster Installs, and Better Writing QAspecterops · 2026-04-10
- Bringing Rust to the Pixel Basebandgoogle_security · 2026-04-10
- Janus: Listen to Your Logsspecterops · 2026-04-10
- [Breach] McGraw Hill — 13,500,136 accounts exposedhibp_breaches · 2026-04-10
- [NVD] CVE-2026-34486 (HIGH 7.5) — Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.nvd · 2026-04-09
- [NVD] CVE-2026-1584 (HIGH 7.5) — A flaw was found in gnutls. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted ClientHello message with an invalid Pre-Shared Key (PSK) binder value during the TLS handshake. This can lead to a NULL pointer dereference, causing the senvd · 2026-04-09
- Protecting Cookies with Device Bound Session Credentialsgoogle_security · 2026-04-09
- [NVD] CVE-2026-4878 (MEDIUM 6.7) — A flaw was found in libcap. A local unprivileged user can exploit a Time-of-check-to-time-of-use (TOCTOU) race condition in the `cap_set_file()` function. This allows an attacker with write access to a parent directory to redirect file capability updates to an attacker-controllednvd · 2026-04-09
- Mythos, Machine-Speed Exploitation, and the Growing Importance of Identity Attack Pathsspecterops · 2026-04-09
- [NVD] CVE-2025-62718 (CRITICAL 9.9) — Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly handle hostname normalization when checking NO_PROXY rules. Requests to loopback addresses like localhost. (with a trailing dot) or [::1] (IPv6 literal) skip NO_nvd · 2026-04-09
- Master C and C++ with our new Testing Handbook chaptertrailofbits · 2026-04-09
- [NVD] CVE-2026-4901 (MEDIUM 6.5) — AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthoriznvd · 2026-04-09
- [NVD] CVE-2026-34185 (HIGH 8.8) — AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database. This issue was fixed in AlanWeb SCADA versnvd · 2026-04-09
- [NVD] CVE-2026-34184 (CRITICAL 9.1) — AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database. This issue was fixed innvd · 2026-04-09
- Elastic on Defence Cyber Marvel 2026: A Technical overview from the Exercise Floorelastic_security · 2026-04-09
- [NVD] CVE-2026-4398 (MEDIUM 5.4) — GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user could have assigned compliance frameworks from namespaces they were not authorized to accesnvd · 2026-04-08
- [NVD] CVE-2026-3438 (MEDIUM 6.1) — A reflected cross-site scripting vulnerability exists in Sonatype Nexus Repository versions 3.0.0 through 3.90.2 that allows unauthenticated remote attackers to execute arbitrary JavaScript in a victim's browser through a specially crafted URL. Exploitation requires user interactnvd · 2026-04-08
- [NVD] CVE-2026-3199 (HIGH 8.8) — A vulnerability in the task management component of Sonatype Nexus Repository versions 3.22.1 through 3.90.2 allows an authenticated attacker with task creation permissions to execute arbitrary code, bypassing the nexus.scripts.allowCreation security control.nvd · 2026-04-08
- [NVD] CVE-2026-39892 (CRITICAL 9.8) — cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnernvd · 2026-04-08
- [NVD] CVE-2026-39883 (HIGH 7.0) — OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command using a bare name, allowing the same PATH hijacking attack on BSD and Solaris platfnvd · 2026-04-08
- [NVD] CVE-2025-30650 (MEDIUM 6.7) — A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root. This issue affects systems running Junos OS using Linux-based line cards. Affectednvd · 2026-04-08
- [NVD] CVE-2026-32591 (MEDIUM 5.2) — A flaw was found in Red Hat Quay's Proxy Cache configuration feature. When an organization administrator configures an upstream registry for proxy caching, Quay makes a network connection to the specified registry hostname without verifying that it points to a legitimate externalnvd · 2026-04-08
- [NVD] CVE-2026-32590 (HIGH 7.1) — A flaw was found in Red Hat Quay's handling of resumable container image layer uploads. The upload process stores intermediate data in the database using a format that, if tampered with, could allow an attacker to execute arbitrary code on the Quay server.nvd · 2026-04-08
- [NVD] CVE-2026-32589 (HIGH 7.4) — A flaw was found in Red Hat Quay's container image upload process. An authenticated user with push access to any repository on the registry can interfere with image uploads in progress by other users, including those in repositories they do not have access to. This could allow thnvd · 2026-04-08
- [NVD] CVE-2026-2377 (MEDIUM 6.5) — A flaw was found in Red Hat Quay and mirror registry for Red Hat OpenShift. The log export feature in these products allows an authenticated user to specify an arbitrary callback URL. A backend process then makes server-side HTTP requests to this provided URL. This vulnerability,nvd · 2026-04-08
- Node.js Trust Falls: Dangerous Module Resolution on Windowszdi_blog · 2026-04-08
- [NVD] CVE-2026-5795 (HIGH 7.4) — In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals. nvd · 2026-04-08
- [NVD] CVE-2025-57847 (MEDIUM 6.4) — A container privilege escalation flaw was found in certain Ansible Automation Platform images. This issue arises from the /etc/passwd file being created with group-writable permissions during the build process. In certain conditions, an attacker who can execute commands within annvd · 2026-04-08
- Given Enough Agents, All Bugs Become Shallowembracethered · 2026-04-08
- [NVD] CVE-2026-33810 (HIGH 8.2) — When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in thnvd · 2026-04-08
- [NVD] CVE-2026-32283 (HIGH 7.5) — If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.nvd · 2026-04-08
- [NVD] CVE-2026-32280 (HIGH 7.5) — During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tlsnvd · 2026-04-08
- [Breach] 7-Eleven — 185,256 accounts exposedhibp_breaches · 2026-04-08
- [NVD] CVE-2026-29181 (HIGH 7.5) — OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.36.0 to 1.40.0, multi-value baggage: header extraction parses each header field-value independently and aggregates members across values. This allows an attacker to amplify cpu and allocations by sending many baggnvd · 2026-04-07
- Cloudflare targets 2029 for full post-quantum securitycloudflare_security · 2026-04-07
- [NVD] CVE-2026-39363 (HIGH 7.5) — Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fetchModule via the custom WebSocket event vite:invoke and combine fnvd · 2026-04-07
- [NVD] CVE-2025-14821 (HIGH 7.8) — A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communinvd · 2026-04-07
- [NVD] CVE-2026-5745 (MEDIUM 5.5) — A flaw was found in libarchive. A NULL pointer dereference vulnerability exists in the ACL parsing logic, specifically within the archive_acl_from_text_nl() function. When processing a malformed ACL string (such as a bare "d" or "default" tag without subsequent fields), the functnvd · 2026-04-07
- [NVD] CVE-2026-4740 (HIGH 8.2) — A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate that can be approved by the OCnvd · 2026-04-07
- [NVD] CVE-2026-35554 (HIGH 8.7) — A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network request containing that batch is still in flight, the batchnvd · 2026-04-07
- [NVD] CVE-2026-28808 (CRITICAL 9.8) — Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when served via script_alias. When script_alias maps a URL prefix to a directory outside DocumentRoot, mod_auth evaluates directory-basednvd · 2026-04-07
- [NVD] CVE-2026-31842 (HIGH 7.5) — Tinyproxy through 1.11.3 is vulnerable to HTTP request parsing desynchronization due to a case-sensitive comparison of the Transfer-Encoding header in src/reqs.c. The is_chunked_transfer function uses strcmp to compare the header value against "chunked", even though RFC 7230 specnvd · 2026-04-07
- What we learned about TEE security from auditing WhatsApp's Private Inferencetrailofbits · 2026-04-07
- [Breach] My Lovely AI — 106,271 accounts exposedhibp_breaches · 2026-04-07
- [NVD] CVE-2026-35172 (HIGH 7.5) — Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.0, distribution can restore read access in repo a after an explicit delete when storage.cache.blobdescriptor: redis and storage.delete.enabled: true are both enabled. The delete path clearnvd · 2026-04-06
- [NVD] CVE-2025-48651 (MEDIUM 5.5) — In importWrappedKey of KMKeymasterApplet.java, there is a possible way access keys that should be restricted due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploinvd · 2026-04-06
- AI Red Teaming Still Comes Back to Identity, Access, and Attack Pathsspecterops · 2026-04-06
- [NVD] CVE-2026-34986 (HIGH 7.5) — Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JWnvd · 2026-04-06
- [NVD] CVE-2026-5704 (MEDIUM 5.0) — A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce nvd · 2026-04-06
- [NVD] CVE-2026-34982 (HIGH 8.2) — Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbitrary OS command execution when a user opens a crafted file. The `complete`, `guitabtooltip` and `printheader` options are missing the `P_MLE` flag, allowing a nvd · 2026-04-06
- [NVD] CVE-2026-34756 (MEDIUM 6.5) — vLLM is an inference and serving engine for large language models (LLMs). From 0.1.0 to before 0.19.0, a Denial of Service vulnerability exists in the vLLM OpenAI-compatible API server. Due to the lack of an upper bound validation on the n parameter in the ChatCompletionRequest anvd · 2026-04-06
- [NVD] CVE-2026-34755 (MEDIUM 6.5) — vLLM is an inference and serving engine for large language models (LLMs). From 0.7.0 to before 0.19.0, the VideoMediaIO.load_base64() method at vllm/multimodal/media/video.py splits video/jpeg data URLs by comma to extract individual JPEG frames, but does not enforce a frame counnvd · 2026-04-06
- [NVD] CVE-2026-31153 (MEDIUM 5.4) — A stored cross-site scripting (XSS) vulnerability in Bynder v0.1.394 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NOTE: this is disputed by the Supplier because v0.1.394 was never a valid version number, and because there is no available informnvd · 2026-04-06
- [NVD] CVE-2026-3524 (HIGH 8.8) — Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API requests to the plugin's endpoints. Mattermnvd · 2026-04-06
- [Breach] LegionProxy — 10,144 accounts exposedhibp_breaches · 2026-04-06
- Elastic Security Integrations Roundup: Q1 2026elastic_security · 2026-04-04
- [NVD] CVE-2026-3184 (LOW 3.7) — A flaw was found in util-linux. Improper hostname canonicalization in the `login(1)` utility, when invoked with the `-h` option, can modify the supplied remote hostname before setting `PAM_RHOST`. A remote attacker could exploit this by providing a specially crafted hostname, potnvd · 2026-04-03
- [NVD] CVE-2026-0545 (CRITICAL 9.8) — In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the latest version of the repository. If job execution is enabled (`MLFLOW_SERVER_ENABLE_nvd · 2026-04-03
- [NVD] CVE-2026-23459 (HIGH 8.2) — In the Linux kernel, the following vulnerability has been resolved: ip_tunnel: adapt iptunnel_xmit_stats() to NETDEV_PCPU_STAT_DSTATS Blamed commits forgot that vxlan/geneve use udp_tunnel[6]_xmit_skb() which call iptunnel_xmit_stats(). iptunnel_xmit_stats() was assuming tunnenvd · 2026-04-03
- [NVD] CVE-2026-23448 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP16 nframes bounds check cdc_ncm_rx_verify_ndp16() validates that the NDP header and its DPE entries fit within the skb. The first check correctly accounts for ndpoffset: nvd · 2026-04-03
- [NVD] CVE-2026-23447 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: net: usb: cdc_ncm: add ndpoffset to NDP32 nframes bounds check The same bounds-check bug fixed for NDP16 in the previous patch also exists in cdc_ncm_rx_verify_ndp32(). The DPE array size is validated against tnvd · 2026-04-03
- Simplifying MBA obfuscation with CoBRAtrailofbits · 2026-04-03
- [Breach] Amtrak — 2,147,679 accounts exposedhibp_breaches · 2026-04-03