ZCyberNews
中文

Articles

460 articles

Spring Cloud Config Server Leaks Secrets in Trace LogsMEDIUM
Vulnerabilities

Spring Cloud Config Server Leaks Secrets in Trace Logs

CVE-2026-41004 (CVSS 4.4): Spring Cloud Config Server writes plaintext secrets to logs when trace logging is enabled. Affects versions 3.1.0–3.1.13 and 4.1.0–4.1.9.

CVE-2026-41004
3 min read
TCLBANKER Trojan Targets 59 Banks, Spreads via WhatsApp and OutlookHIGH
Malware

TCLBANKER Trojan Targets 59 Banks, Spreads via WhatsApp and Outlook

Elastic Security Labs tracks REF3076 — a Brazilian banking trojan called TCLBANKER that targets 59 financial platforms and spreads via WhatsApp worms and Outlook email propagation.

3 min readTCLBANKER
Boost Security Raises $4M, Acquires SecureIQx and Korbit.ai
Industry News

Boost Security Raises $4M, Acquires SecureIQx and Korbit.ai

Boost Security raised $4M to expand its AI-native SDLC defense platform, acquiring SecureIQx for reachability analysis and Korbit.ai for code review.

3 min read
Chrome 148 Patches 127 Flaws, Three Critical Use-After-Free BugsCRITICAL
Vulnerabilities

Chrome 148 Patches 127 Flaws, Three Critical Use-After-Free Bugs

Google's Chrome 148 fixes 127 vulnerabilities including three critical-severity bugs (CVE-2026-7896, CVE-2026-7897, CVE-2026-7898) — integer overflow in Blink and use-after-free...

CVE-2026-7896CVE-2026-7897CVE-2026-7898
3 min read
Ivanti EPMM Zero-Day CVE-2026-6973 Exploited in Limited AttacksHIGH
Vulnerabilities

Ivanti EPMM Zero-Day CVE-2026-6973 Exploited in Limited Attacks

Ivanti warns CVE-2026-6973, a high-severity RCE in EPMM 12.8.0.0 and earlier, is under limited zero-day exploitation. Patches available; 850+ EPMM instances exposed online.

CVE-2026-6973CVE-2026-5786CVE-2026-5787+4
4 min read
PCPJack Worm Steals Cloud Credentials, Wipes TeamPCP InfectionsHIGH
Malware

PCPJack Worm Steals Cloud Credentials, Wipes TeamPCP Infections

SentinelLabs uncovers PCPJack, a credential-stealing worm targeting Docker, Kubernetes, Redis, and MongoDB that actively removes rival TeamPCP access from compromised cloud...

CVE-2025-29927CVE-2025-55182CVE-2026-1357+2
4 min readPCPJack
ZiChatBot Malware Spreads via PyPI Packages Using Zulip C2HIGH
Malware

ZiChatBot Malware Spreads via PyPI Packages Using Zulip C2

Three PyPI packages deliver ZiChatBot malware on Windows and Linux using Zulip chat APIs for stealthy C2 — Kaspersky identifies 12+ victim organizations globally.

4 min readZiChatBot
APT37 Targets Ethnic Koreans in China With Android BirdCall MalwareHIGH
Malware

APT37 Targets Ethnic Koreans in China With Android BirdCall Malware

ESET says APT37 compromised Sqgame card game platform to deliver BirdCall backdoor to Android devices, stealing SMS, call logs, and private keys from ethnic Koreans in Yanbian.

4 min readAPT37
Cisco DoS Flaw CVE-2026-20188 Requires Manual Reboot to RecoverHIGH
Vulnerabilities

Cisco DoS Flaw CVE-2026-20188 Requires Manual Reboot to Recover

CVE-2026-20188: Unauthenticated attackers can crash Cisco Crosswork Network Controller and NSO via low-complexity exploit. No patch for older releases; manual reboot required.

CVE-2026-20188CVE-2025-20362CVE-2025-20333+3
3 min read
MOVEit Automation CVE-2026-5174 Raises Patch Urgency After Cl0p HistoryHIGH
Vulnerabilities

MOVEit Automation CVE-2026-5174 Raises Patch Urgency After Cl0p History

CVE-2026-5174 is a high-severity MOVEit Automation privilege-escalation flaw. No APT or Cl0p exploitation is confirmed, but the 2023 MOVEit compromise history makes rapid patching urgent.

CVE-2026-5174CVE-2026-4670
5 min read
Palo Alto PAN-OS CVE-2026-0300 Attacked via Captive PortalCRITICAL
Vulnerabilities

Palo Alto PAN-OS CVE-2026-0300 Attacked via Captive Portal

CVE-2026-0300 is a critical PAN-OS buffer overflow in the User-ID Authentication Portal. Fixed builds are upcoming, so disable or restrict the portal immediately.

CVE-2026-0300
4 min read
USB Drop Attack That Defined Social Engineering Turns 20INFORMATIONAL
Industry News

USB Drop Attack That Defined Social Engineering Turns 20

Steve Stasiukonis's 2006 USB drop test at a credit union — 15 of 20 drives plugged in by employees — became the blueprint for physical social engineering assessments still used…

2 min read
← PrevPage 16 of 39Next →