ZCyberNews
中文

Articles

460 articles

Secret Blizzard Upgrades Kazuar Backdoor Into P2P BotnetHIGH
Malware

Secret Blizzard Upgrades Kazuar Backdoor Into P2P Botnet

Secret Blizzard evolved Kazuar into a modular P2P botnet with 150 config options, AMSI/ETW bypass, and silent-mode nodes. Microsoft details the three-module architecture.

3 min readSecret Blizzard
Silicon Labs SixG301xxx DPA Countermeasure Flaw Weakens Crypto KeysHIGH
Vulnerabilities

Silicon Labs SixG301xxx DPA Countermeasure Flaw Weakens Crypto Keys

CVE-2025-14972: Silicon Labs SixG301xxx devices use non-random DPA countermeasures in the SYMCRYPTO engine, enabling key recovery. Affects KSU keys.

CVE-2025-14972
3 min read
ZITADEL LDAP Filter Injection CVE-2026-44671 Allows UnauthenticatedHIGH
Vulnerabilities

ZITADEL LDAP Filter Injection CVE-2026-44671 Allows Unauthenticated

CVE-2026-44671 (CVSS 7.5): ZITADEL identity platform fails to escape usernames in LDAP filters, letting unauthenticated attackers inject arbitrary filter logic during login.

CVE-2026-44671
3 min read
Aegra IDOR CVE-2026-44504 Exposes Cross-Tenant Data in SharedHIGH
Vulnerabilities

Aegra IDOR CVE-2026-44504 Exposes Cross-Tenant Data in Shared

CVE-2026-44504: Aegra prior to 0.9.7 allows authenticated attackers to read checkpoint state and inject messages into other users' threads via cross-tenant IDOR. Patch available.

CVE-2026-44504
3 min read
aria2c EKU Validation Flaw CVE-2026-8367 Enables TLS CertificateMEDIUM
Vulnerabilities

aria2c EKU Validation Flaw CVE-2026-8367 Enables TLS Certificate

CVE-2026-8367 (CVSS 4.8) in aria2c fails to validate Extended Key Usage on server certificates, allowing attackers to reuse certificates issued for other purposes in TLS...

CVE-2026-8367
3 min read
Chrome 148 Patches 79 Flaws, 14 Critical Including Heap OverflowCRITICAL
Vulnerabilities

Chrome 148 Patches 79 Flaws, 14 Critical Including Heap Overflow

Google's Chrome 148 update fixes 79 vulnerabilities, 14 critical — including heap buffer overflow CVE-2026-8509 ($43K bounty) and integer overflow CVE-2026-8510 in Skia ($25K...

CVE-2026-8509CVE-2026-8510
4 min read
fast-xml-builder Flaw CVE-2026-44664 Enables XML Injection viaMEDIUM
Vulnerabilities

fast-xml-builder Flaw CVE-2026-44664 Enables XML Injection via

CVE-2026-44664 (CVSS 6.1) in fast-xml-builder lets attackers break out of XML comments and inject arbitrary content via triple-dash sequences; fixed in version 1.1.6.

CVE-2026-44664CVE-2026-41650
4 min read
GitHub Copilot CLI Flaw CVE-2026-45033 Enables RCE via Malicious ReposCRITICAL
Vulnerabilities

GitHub Copilot CLI Flaw CVE-2026-45033 Enables RCE via Malicious Repos

CVE-2026-45033 (CVSS 9.8) in GitHub Copilot CLI before 1.0.43 lets attackers achieve remote code execution by embedding a malicious bare git repository in a project directory.

CVE-2026-45033
3 min read
Gremlin Stealer Evolves: Crypto Clipping, Session Hijacking, PackedHIGH
Malware

Gremlin Stealer Evolves: Crypto Clipping, Session Hijacking, Packed

Unit 42 details a new Gremlin stealer variant using XOR-encrypted resource sections, crypto clipper, WebSocket session hijacking, and a commercial packer with instruction...

5 min readGremlin Stealer
Lenovo Personal Cloud Storage Flaw CVE-2026-6282 Enables Lateral FileHIGH
Vulnerabilities

Lenovo Personal Cloud Storage Flaw CVE-2026-6282 Enables Lateral File

CVE-2026-6282 (CVSS 8.1) in Lenovo Personal Cloud Storage lets authenticated users move or access other users' files via improper path validation. No patch yet.

CVE-2026-6282
3 min read
Libsixel Heap Overflow CVE-2026-44636 Lets Attackers Trigger RCEHIGH
Vulnerabilities

Libsixel Heap Overflow CVE-2026-44636 Lets Attackers Trigger RCE

CVE-2026-44636 (CVSS 7.8): A signed integer overflow in libsixel 1.8.7-r1 and earlier lets attackers trigger a heap buffer overflow via crafted SIXEL images, enabling potential...

CVE-2026-44636
3 min read
Metasploit Adds Vim Plugin Persistence, Exploits for Three CVEsHIGH
Tools & Techniques

Metasploit Adds Vim Plugin Persistence, Exploits for Three CVEs

Rapid7's Metasploit Framework adds Vim plugin persistence, exploits for CVE-2025-6793 (Marvell QConvergeConsole), CVE-2024-48760 (GestioIP), and CVE-2023-30253 (Dolibarr).

CVE-2025-6793CVE-2024-48760CVE-2023-30253
3 min read
← PrevPage 6 of 39Next →