THREAT OPS › Threat News
Threat Intelligence News
12127 reports from 110+ open cyber-threat-intelligence sources — APT activity, malware, vulnerabilities and campaigns, newest first.
- Zscaler and AWS Join Forces to Secure GenAI Across Government, Healthcare, and Educationzscaler_threatlabz · 2026-06-23
- [NVD] CVE-2026-56694 (MEDIUM 5.4) — NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where handleChannelApprovalResponse fails to validate admin privileges over target agent groups. Scoped admins can submit forged or stale connect callback values to wire nvd · 2026-06-23
- [NVD] CVE-2026-56693 (MEDIUM 5.5) — NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that performs privileged central-database writes without host-side authorization checks. Confined agent containers can invoke create_agent to create arbitrary agent grnvd · 2026-06-23
- [NVD] CVE-2026-56692 (MEDIUM 5.5) — NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controlled agents to exfiltrate host-readable files. The host validates attachment filenames using only isSafeAttachmentName before copying with fs.copyFileSync, which nvd · 2026-06-23
- [NVD] CVE-2026-56402 (MEDIUM 6.5) — NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails to verify responder role authorization. Attackers with a valid questionId can approve or reject privileged actions like package installation by submitting appronvd · 2026-06-23
- Scattered Spider Hackers Plead Guilty on Day 1 of Trialkrebs · 2026-06-23
- Payouts King Ransomware Initial Access Broker Deploys New Edgecution Malwarezscaler_threatlabz · 2026-06-23
- [NVD] CVE-2026-12969 (MEDIUM 5.3) — An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section records, extract_name() is called with extrabytes=0, failing to validate that 10 additional bytes exist for fixed-length DNS record fields. A remote attacker contnvd · 2026-06-23
- Sponsored: Trail of Bits and OpenAI patch the planetriskybiz_news · 2026-06-23
- [NVD] CVE-2026-55653 (MEDIUM 4.3) — A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group Exchange (DH-GEX) client path. This occurs during FIPS (Federal Information Processing Standards) mode known-group validation when the client processes attackernvd · 2026-06-23
- [CISA KEV] CVE-2025-67038 — Lantronix EDS5000: Lantronix EDS5000 Code Injection Vulnerabilitycisa_kev · 2026-06-23
- [CISA KEV] CVE-2026-34910 — Ubiquiti UniFi OS: Ubiquiti UniFi OS Improper Input Validation Vulnerabilitycisa_kev · 2026-06-23
- [CISA KEV] CVE-2026-34909 — Ubiquiti UniFi OS: Ubiquiti UniFi OS Path Traversal Vulnerabilitycisa_kev · 2026-06-23
- [CISA KEV] CVE-2026-34908 — Ubiquiti UniFi OS: Ubiquiti UniFi OS Improper Access Control Vulnerabilitycisa_kev · 2026-06-23
- From vulnerability report to CVE draft in minutes: how Elastic automated security advisories with AIelastic_security · 2026-06-23
- The Purchase Scam Tactic Headed for the World Cup | Recorded Futurerecordedfuture · 2026-06-23
- [NVD] CVE-2026-48746 (CRITICAL 9.1) — vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API AuthenticationMiddleware. It allows to use the API nvd · 2026-06-22
- [NVD] CVE-2026-41523 (HIGH 7.5) — vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation function loading allows any unauthenticated attacker to achieve arbitrary code execution on the server by publishing a malicious HuggingFnvd · 2026-06-22
- The Global Namespace Risk: Universal Bucket Hijacking Technique for Cloud Data Exfiltrationunit42 · 2026-06-22
- Between Two Nerds: The PRC vs AIriskybiz_news · 2026-06-22
- [NVD] CVE-2026-54293 (HIGH 7.5) — NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path traversal via URL-encoded path separators andnvd · 2026-06-22
- [NVD] CVE-2026-54280 (HIGH 7.5) — AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be nvd · 2026-06-22
- [NVD] CVE-2026-54276 (MEDIUM 6.1) — AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vulnerability or similar on the target domain fnvd · 2026-06-22
- Transforming Mission Partner Data Exchange: Moving Past the Networkszscaler_threatlabz · 2026-06-22
- AI Security Guidelines for Employees: An Acceptable‑Use Policy You Can Enforcezscaler_threatlabz · 2026-06-22
- SpecterOps and OpenAI: Helping to Build a New Security Frontier with Daybreakspecterops · 2026-06-22
- Introducing Patch the Planettrailofbits · 2026-06-22
- [NVD] CVE-2026-12725 (MEDIUM 5.9) — A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of DS or DNSKEY replies containing unsupported algorithm or digest types can cause dnsmasq to write past the end of an internal logging buffer. A remote attacker nvd · 2026-06-22
- Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Cross-Site Scripting Vulnerabilitiescisco_psirt · 2026-06-22
- [NVD] CVE-2026-54100 (HIGH 8.3) — A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server host key. An adjacent-network attacker who can intercept or redirect WMCO's SSH senvd · 2026-06-22
- [NVD] CVE-2026-54099 (HIGH 8.8) — A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organization system:wicd-nodes but does not reject additional organization values such as nvd · 2026-06-22
- Why doctrine is becoming a technology requirement for modern defense intelligenceeclecticiq · 2026-06-22
- Risky Bulletin: Klue breach impacts security firmsriskybiz_news · 2026-06-22
- [NVD] CVE-2026-8918 — A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update for Armoury Crate App ' section on the ASUSnvd · 2026-06-22
- Zero Trust, Zero Downtime: Ensure Security and Compliance Through Outages and Disruptionszscaler_threatlabz · 2026-06-20
- Why SAP User Experience Starts with End to End Visibilityzscaler_threatlabz · 2026-06-19
- [NVD] CVE-2023-54357 (HIGH 7.5) — Joomla com_booking component 2.4.9 contains an information disclosure vulnerability that allows unauthenticated attackers to enumerate user accounts by exploiting the getUserData function in the customer controller. Attackers can send GET requests to index.php with option=com_boonvd · 2026-06-19
- An update on FortiBleed — what’s happening with victim orgsdoublepulsar · 2026-06-19
- [NVD] CVE-2019-25762 (HIGH 7.5) — Joomla! Component JoomProject 1.1.3.2 contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive user data by exploiting the projects endpoint. Attackers can send requests to index.php with option=com_jpprojects&view=projects&tmpl=cnvd · 2026-06-19
- [NVD] CVE-2019-25761 (HIGH 7.1) — Joomla! Component JoomCRM 1.1.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the deal_id parameter. Attackers can send GET requests to index.php with option=com_joomcrm&view=contacnvd · 2026-06-19
- [NVD] CVE-2019-25760 (MEDIUM 6.2) — Joomla! Component Easy Shop 1.2.3 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by supplying base64-encoded file paths. Attackers can send GET requests to index.php with the option parameter set to com_easyshop, task snvd · 2026-06-19
- [NVD] CVE-2019-25757 (HIGH 7.1) — Joomla vWishlist 1.0.1 contains an SQL injection vulnerability that allows authenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vproductid and userid parameters. Attackers can send POST requests to the component with crafted SQL payloadnvd · 2026-06-19
- [NVD] CVE-2019-25756 (HIGH 8.2) — Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vid parameter. Attackers can send GET requests to the vaccount-dashboard/expense endpoint with cnvd · 2026-06-19
- [NVD] CVE-2019-25755 (HIGH 8.2) — Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cmId parameter. Attackers can send POST requests to the editReview task endpoint with URL-encodednvd · 2026-06-19
- [NVD] CVE-2019-25754 (HIGH 8.2) — Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keysearch parameter. Attackers can send POST requests to the menu-listing-layout endpoint withnvd · 2026-06-19
- [NVD] CVE-2026-56211 (HIGH 7.1) — A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal envd · 2026-06-19
- [NVD] CVE-2026-56210 (HIGH 7.1) — A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an onvd · 2026-06-19
- [NVD] CVE-2026-56209 (HIGH 7.1) — An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via craftenvd · 2026-06-19
- [NVD] CVE-2026-56208 (HIGH 7.6) — A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. Thisnvd · 2026-06-19
- [NVD] CVE-2017-20275 (HIGH 8.2) — Joomla! Component PHP-Bridge 1.2.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_phpbridge&view=phpvnvd · 2026-06-19
- [NVD] CVE-2017-20273 (HIGH 8.2) — Joomla Event Registration Pro Calendar 4.1.3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the id parameter. Attackers can send GET requests to index.php with option=com_registratnvd · 2026-06-19
- [NVD] CVE-2017-20271 (HIGH 8.2) — Joomla StreetGuessr Game 1.1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the catid parameter. Attackers can send GET requests to index.php with the option=com_streetguess&viewnvd · 2026-06-19
- [NVD] CVE-2017-20270 (HIGH 8.2) — Joomla! Component Twitch Tv 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the username and id parameters. Attackers can send GET requests to index.php with option=com_twitchtvnvd · 2026-06-19
- [NVD] CVE-2017-20269 (HIGH 8.2) — Joomla! Component KissGallery 1.0.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the component URL path. Attackers can supply malicious SQL code in the kissgallery endpoint to execute arbitrary database queries and envd · 2026-06-19
- [NVD] CVE-2017-20268 (HIGH 8.2) — Joomla! Component Zap Calendar Lite 4.3.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'eid' parameter. Attackers can send GET requests to the RSVP plugin endpoint with craftnvd · 2026-06-19
- WhatsApp Accuses NSO of Fresh Pegasus Targetingcitizenlab · 2026-06-19
- [NVD] CVE-2026-52910 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace period. Eulgyu Kim reported the splat below with a repro. [0] The repro sets up a UDP reuseport group with a cBPF prog and replaces it with a new one while anothernvd · 2026-06-19
- [NVD] CVE-2026-54414 (CRITICAL 9.8) — FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover. The upload filename is validated by FolderController with basename and REGEX_FILnvd · 2026-06-19
- Risky Bulletin: Creds for 74,000 Fortinet devices leakedriskybiz_news · 2026-06-19
- Lost in relocation: analysis of a new loader distributing CASTLESTEALERelastic_security · 2026-06-19
- Azure AD Graph Activity Logs: Ingestion and threat detection to close the visibility gapelastic_security · 2026-06-19
- Build your own vulnerability harnesscloudflare_security · 2026-06-18
- ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firmkrebs · 2026-06-18
- [NVD] CVE-2026-55205 (MEDIUM 5.3) — Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send repeated or concurrent requests to exhaust nvd · 2026-06-18
- First to Market, Built to Last: How Zscaler Secures the Agentic AI Era with Zero Trustzscaler_threatlabz · 2026-06-18
- BloodHound MCP, One Year Later: What I Learned About MCPs, Models, and Contextspecterops · 2026-06-18
- May 2026 Threat Trend Report on Ransomwareahnlab · 2026-06-18
- [NVD] CVE-2026-54419 (CRITICAL 9.8) — claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1c104212cd62be2bfca21e5) contains multiple unauthenticated SQL injection vulnerabilities. The application has no authentication mechanism and passes user-supplienvd · 2026-06-18
- SmartApeSG Launches Okendo Reviews Supply Chain Attackzscaler_threatlabz · 2026-06-18
- Operation FanTrap: Inside the FIFA 2026 Fraud Ecosystemcyble · 2026-06-18
- [NVD] CVE-2026-55746 (HIGH 7.6) — Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage (PFS) module. A folder title (pff_title) is imported with the 'TXT' filter, which does not strip or encode HTML (the tag check in cot_import is disabled), so anvd · 2026-06-18
- [NVD] CVE-2026-55745 (MEDIUM 5.4) — Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.editfolder.php, the folder update action ('a=update') updates folder metadata (title, description, public/gallery flags) winvd · 2026-06-18
- [NVD] CVE-2026-55744 (HIGH 8.1) — Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage (PFS) module. In modules/pfs/inc/pfs.main.php, the file upload action ('a=upload') processes uploaded files without calling cot_check_xg to validate the anti-CSnvd · 2026-06-18
- [NVD] CVE-2026-55742 (CRITICAL 9.6) — Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights handler. In system/admin/admin.rights.php, the rights update action ('a=update') modifies group access rights (including via cot_auth_add_group) without callingnvd · 2026-06-18
- [NVD] CVE-2026-55741 (HIGH 8.8) — Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configuration handler. In system/admin/admin.config.php, the configuration update action ('a=update') processes POST data via cot_config_update_options without callingnvd · 2026-06-18
- Srsly Risky Biz: Anthropic has artificial, but not emotional, intelligenceriskybiz_news · 2026-06-18
- [NVD] CVE-2026-55740 (CRITICAL 9.8) — Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthenticated SQL injection vulnerability in bus_info.php. The busid parameter received via HTTP POST is concatenated directly into a MySQL query (select * from bus_nvd · 2026-06-18
- [NVD] CVE-2026-12505 (HIGH 7.8) — A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to nvd · 2026-06-18
- [NVD] CVE-2026-12569 (CRITICAL 9.8) — A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. * This advisory also applies to all CPS versions * The identified vulnerabilitynvd · 2026-06-18
- [CISA KEV] CVE-2026-20253 — Splunk Enterprise: Splunk Enterprise Missing Authentication for Critical Function Vulnerabilitycisa_kev · 2026-06-18
- Entra Agent ID: Inside a cross-tenant agent compromisedatadog_seclabs · 2026-06-18
- [Breach] Operation Endgame 4.0 — 4,348,526 accounts exposedhibp_breaches · 2026-06-18
- [Breach] Inter-Con Security — 276,114 accounts exposedhibp_breaches · 2026-06-18
- [NVD] CVE-2026-55200 (HIGH 8.1) — libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt hnvd · 2026-06-17
- [NVD] CVE-2026-55198 (MEDIUM 6.5) — Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The _handle_session_export handler in api/routes.py fails to verify active-profile ownership before snvd · 2026-06-17
- [NVD] CVE-2026-55197 (MEDIUM 6.5) — Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can bypass profile boundary checks by directly querying session IDs belonging to othernvd · 2026-06-17
- [NVD] CVE-2026-55196 (CRITICAL 9.1) — Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allows unauthenticated remote attackers to register arbitrary passkeys. When HERMES_WEBUI_PASSKEY=1 is enabled with no existing credentials, POST /api/auth/passkey/nvd · 2026-06-17
- [NVD] CVE-2026-53871 (HIGH 8.1) — Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can forge the hermes_profile cookie value to bypass profile-scopednvd · 2026-06-17
- How Freedom Tech Is Pushing Back Against Digital Authoritarianismcitizenlab · 2026-06-17
- [NVD] CVE-2026-9697 (HIGH 7.4) — Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthornvd · 2026-06-17
- [NVD] CVE-2026-7300 (MEDIUM 6.5) — Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Filter Failure through Buffer Overflow. This issue affects Connext Professional: from 7.4.0 before 7.7.0.1, from 7.0.0 before 7.3.1.3,nvd · 2026-06-17
- [NVD] CVE-2026-6734 (HIGH 7.5) — Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended destinvd · 2026-06-17
- [NVD] CVE-2026-3894 (CRITICAL 9.1) — Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 5.2.nvd · 2026-06-17
- [NVD] CVE-2026-30799 (HIGH 8.1) — Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.6, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from nvd · 2026-06-17
- [NVD] CVE-2026-2675 (MEDIUM 6.5) — Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*,nvd · 2026-06-17
- [NVD] CVE-2026-2674 (HIGH 8.1) — Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffers. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*.nvd · 2026-06-17
- [NVD] CVE-2026-2467 (HIGH 8.1) — Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.3, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 befonvd · 2026-06-17
- ClickFix Campaign Generated Via AI Delivers SmartRATzscaler_threatlabz · 2026-06-17
- [NVD] CVE-2026-12151 (HIGH 7.5) — Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame andnvd · 2026-06-17
- Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerabilitycisco_psirt · 2026-06-17