ZCyberNews
中文

Articles

460 articles

Yeti JWT Flaw CVE-2024-46508 Lets Attackers Forge Auth TokensHIGH
Vulnerabilities

Yeti JWT Flaw CVE-2024-46508 Lets Attackers Forge Auth Tokens

CVE-2024-46508 (CVSS 7.5) in Yeti platform before 2.1.12 lets attackers forge valid JWT tokens when the default secret key is unchanged — full account takeover risk.

CVE-2024-46508
3 min read
Braintrust Breach Exposes AI Provider API Keys, Urges RotationHIGH
Industry News

Braintrust Breach Exposes AI Provider API Keys, Urges Rotation

Braintrust disclosed a breach on May 4 where attackers accessed an AWS account, compromising AI provider API keys for firms like Box and Stripe. At least one customer affected.

3 min read
CVE-2026-7891: DIVD VerySecureApp Leaks All Records to Anonymous UsersHIGH
Vulnerabilities

CVE-2026-7891: DIVD VerySecureApp Leaks All Records to Anonymous Users

CVE-2026-7891 in DIVD's VerySecureApp (Mendix Studio Pro 11.8.0 Beta) exposes all stored records to anonymous users via an authorization misconfiguration — no access rights...

CVE-2026-7891
3 min read
GitHub Enterprise Server Flaw Lets Attackers Steal Admin CredentialsHIGH
Vulnerabilities

GitHub Enterprise Server Flaw Lets Attackers Steal Admin Credentials

CVE-2026-8106: Reflected HTML injection in GitHub Enterprise Server Management Console login page enables credential theft via crafted redirect_to parameter.

CVE-2026-8106
3 min read
GitHub Enterprise Server SSRF Lets Attackers Reach Internal ServicesHIGH
Vulnerabilities

GitHub Enterprise Server SSRF Lets Attackers Reach Internal Services

CVE-2026-8034: A server-side request forgery flaw in GitHub Enterprise Server notebook viewer exploits URL parser confusion, letting attackers access internal services.

CVE-2026-8034
3 min read
Go ReverseProxy Flaw CVE-2026-39825 Leaks Query ParametersHIGH
Vulnerabilities

Go ReverseProxy Flaw CVE-2026-39825 Leaks Query Parameters

CVE-2026-39825 in Go's ReverseProxy allows query parameters invisible to Rewrite functions to be forwarded, bypassing sanitization in net/http.

CVE-2026-39825
3 min read
JeecgBoot SQLi Flaw CVE-2026-8114 Exploit Publicly AvailableMEDIUM
Vulnerabilities

JeecgBoot SQLi Flaw CVE-2026-8114 Exploit Publicly Available

CVE-2026-8114 (CVSS 6.5) in JeecgBoot up to 3.9.1 enables remote SQL injection via the /sys/dict/loadTreeData endpoint. Exploit code is public.

CVE-2026-8114
3 min read
NWHStealer Uses Bun JavaScript Runtime to Evade DetectionHIGH
Malware

NWHStealer Uses Bun JavaScript Runtime to Evade Detection

Attackers repurpose the Bun JavaScript runtime to distribute NWHStealer, a Rust-based infostealer targeting browsers, crypto wallets, and FTP apps via game lures and fake software.

3 min readNWHStealer
OceanLotus APT Uses PyPI Packages to Deliver ZiChatBot MalwareHIGH
Malware

OceanLotus APT Uses PyPI Packages to Deliver ZiChatBot Malware

Kaspersky attributes a PyPI supply chain campaign to OceanLotus APT, using fake wheel packages to drop ZiChatBot malware that abuses Zulip chat APIs for C2 on Windows and Linux.

4 min readOceanLotus
OpenStack Cyborg API Flaw Lets Low-Privilege Users Reprogram FPGAsHIGH
Vulnerabilities

OpenStack Cyborg API Flaw Lets Low-Privilege Users Reprogram FPGAs

CVE-2026-40213 (CVSS 7.4) in OpenStack Cyborg before 16.0.1 uses rule:allow as default policy, letting any authenticated Keystone token holder reprogram FPGA bitstreams on...

CVE-2026-40213
3 min read
PamDOORa Backdoor Steals SSH Credentials via Linux PAM ModulesHIGH
Malware

PamDOORa Backdoor Steals SSH Credentials via Linux PAM Modules

A new Linux backdoor named PamDOORa, sold for $1,600 on the Rehub forum, uses PAM modules to steal SSH credentials via a magic password and TCP port combination.

3 min readdarkworm
Quasar Linux RAT Targets Developers for Supply Chain AttacksHIGH
Malware

Quasar Linux RAT Targets Developers for Supply Chain Attacks

A new Linux implant codenamed QLNX steals developer credentials, keystrokes, and clipboard data. Targets DevOps environments for software supply chain compromise.

3 min readQuasar Linux RAT
← PrevPage 15 of 39Next →