BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

Latest
Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableThe Hacker News · 3h agoSuspicious Polyfill login prompts pop up on Toshiba, Muji websitesBleepingComputer · 9h agoFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesTechCrunch Security · 11h agoCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · 12h agoMiasma Malware Hits 32 Red Hat Packages via Compromised GitHub AccountHackRead · 12h agoChinese APT deploys new malware to keep access to hacked networksBleepingComputer · 13h agoIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News · 13h agoDark web Nemesis Market vendor gets 26 years for selling drugsBleepingComputer · 14h agoAtlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service UsersHackRead · 14h agoWeekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer EnumRapid7 · 14h agoSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Security · 15h agoGoogle and FBI warn of ransomware group that sends fake IT workers to hack victims in personTechCrunch Security · 15h agoAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map AppsThe Hacker News · 17h agoOver 900 US gas station tank gauge systems exposed to attacksBleepingComputer · 17h agoNSA said to be readying Anthropic’s Mythos for use in cyber operationsTechCrunch Security · 17h agoCisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch AvailableThe Hacker News · 3h agoSuspicious Polyfill login prompts pop up on Toshiba, Muji websitesBleepingComputer · 9h agoFormer cyber executive turned whistleblower accuses IBM of covering up several data breachesTechCrunch Security · 11h agoCISA: Hackers now exploit SolarWinds Serv-U flaw to crash serversBleepingComputer · 12h agoMiasma Malware Hits 32 Red Hat Packages via Compromised GitHub AccountHackRead · 12h agoChinese APT deploys new malware to keep access to hacked networksBleepingComputer · 13h agoIronWorm and New Miasma Worm Variant Hit npm in Supply Chain AttacksThe Hacker News · 13h agoDark web Nemesis Market vendor gets 26 years for selling drugsBleepingComputer · 14h agoAtlas Menu Data Breach Exposes 64,000 GTA V and CS2 Cheat Service UsersHackRead · 14h agoWeekly Metasploit Update: Apache ActiveMQ RCE, Gogs Rebase RCE, and Windows Kernel Pointer EnumRapid7 · 14h agoSecuring CI/CD in an agentic world: Claude Code Github action caseMicrosoft Security · 15h agoGoogle and FBI warn of ransomware group that sends fake IT workers to hack victims in personTechCrunch Security · 15h agoAndroid Spyware Asin Targets Arabic Users via Fake News, PDF and War Map AppsThe Hacker News · 17h agoOver 900 US gas station tank gauge systems exposed to attacksBleepingComputer · 17h agoNSA said to be readying Anthropic’s Mythos for use in cyber operationsTechCrunch Security · 17h ago

Security & IT News

Live

Real-time news from 13+ trusted sources — BleepingComputer, The Hacker News, Krebs on Security, Dark Reading & more.

753 results in Vulnerability

VulnerabilityThe Hacker News·52d ago
108 Malicious Chrome Extensions Steal Google and Telegram Data, Affecting 20,000 Users

Cybersecurity researchers have discovered a new campaign in which a cluster of 108 Google Chrome extensions has been found to communicate with the same command-and-control (C2) infrastructure with the goal of collecting user data and enabling browser-level abuse by injecting ads and arbitrary JavaScript code into every web page visited. According to Socket, the extensions (complete list

VulnerabilityFortinet PSIRT·53d ago
2FA request can be replayed without a valid token after one successful request

CVSSv3 Score: 6.7 An Improper authentication vulnerability [CWE-287] in FortiSOAR web GUI may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA request. The attack requires being able to intercept and decrypt authentication traffic and precise timing to replay the request before token expiration. Revised on 2026-04-14 00:00:00

VulnerabilityFortinet PSIRT·53d ago
Arbitrary directory delete on vmimages delete feature

CVSSv3 Score: 6.2 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiSandbox, FortiSandbox Cloud, FortiSandbox PaaS and FortiSandbox Cloud WEB UI may allow a privileged attacker with super-admin profile and CLI access to delete an arbitrary directory via HTTP crafted requests. Revised on 2026-04-14 00:00:00

VulnerabilityFortinet PSIRT·53d ago
Heap-based buffer overflow in oftpd daemon

CVSSv3 Score: 7.3 A heap-based buffer overflow vulnerability [CWE-122] in FortiAnalyzer Cloud oftpd daemon may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation Revised on 2026-04-14 00:00:00

VulnerabilityFortinet PSIRT·53d ago
Missing Authentication for critical function in CAPWAP daemon

CVSSv3 Score: 6.2 A missing authentication for critical function vulnerability [CWE-306] in FortiOS and FortiSwitchManager CAPWAP daemon may allow a local unauthenticated attacker on the same local IP subnet to write device configuration via specially crafted requests. To be successful, this attack requires the targeted FortiGate device to run a specific, non default configuration. Revised on 2026-04-14 00:00:00

VulnerabilityFortinet PSIRT·53d ago
Multiple SQL Injections

CVSSv3 Score: 7.1 An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiClientEMS may allow an authenticated attacker to run arbitrary SQL queries on the database via sending crafted requests. Revised on 2026-04-14 00:00:00

VulnerabilityFortinet PSIRT·53d ago
Multiple Stored XSS

CVSSv3 Score: 4.3 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiSandbox and FortiSandbox Cloud may allow a privileged attacker to perform a stored XSS attack via crafted HTTP requests. Revised on 2026-04-14 00:00:00

VulnerabilityThe Hacker News·53d ago
CISA Adds 6 Known Exploited Flaws in Fortinet, Microsoft, and Adobe Software

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added half a dozen security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list of vulnerabilities is as follows - CVE-2026-21643 (CVSS score: 9.1) - An SQL injection vulnerability in Fortinet FortiClient EMS that could allow an unauthenticated attacker to

VulnerabilityThe Hacker News·53d ago
FBI and Indonesian Police Dismantle W3LL Phishing Network Behind $20M Fraud Attempts

The U.S. Federal Bureau of Investigation (FBI), in partnership with the Indonesian National Police, has dismantled the infrastructure associated with a global phishing operation that leveraged an off-the-shelf toolkit called W3LL to steal thousands of victims' account credentials and attempt more than $20 million in fraud. In tandem, authorities detained the alleged developer, who has&