Vulnerability News
الذهاب إلى القناة على Telegram
Every day new posts about vulnerabilities and cybersecurity news. Get the latest news about the cyberspace! Group: @VulnerabilityNewsGroup
إظهار المزيد5 236
المشتركون
+324 ساعات
+327 أيام
+9830 أيام
جاري تحميل البيانات...
القنوات المماثلة
سحابة العلامات
الإشارات الواردة والصادرة
---
---
---
---
---
---
جذب المشتركين
أغسطس '26
أغسطس '26
+153
في 0 قنوات
يوليو '26
+185
في 0 قنوات
Get PRO
يونيو '26
+156
في 0 قنوات
Get PRO
مايو '26
+204
في 0 قنوات
Get PRO
أبريل '26
+187
في 0 قنوات
Get PRO
مارس '26
+254
في 0 قنوات
Get PRO
فبراير '26
+116
في 0 قنوات
Get PRO
يناير '26
+166
في 0 قنوات
Get PRO
ديسمبر '25
+134
في 0 قنوات
Get PRO
نوفمبر '25
+139
في 0 قنوات
Get PRO
أكتوبر '25
+8
في 0 قنوات
Get PRO
سبتمبر '25
+12
في 0 قنوات
Get PRO
أغسطس '25
+13
في 0 قنوات
Get PRO
يوليو '25
+11
في 0 قنوات
Get PRO
يونيو '25
+12
في 0 قنوات
Get PRO
مايو '25
+18
في 1 قنوات
Get PRO
أبريل '25
+14
في 0 قنوات
Get PRO
مارس '25
+21
في 0 قنوات
Get PRO
فبراير '25
+17
في 0 قنوات
Get PRO
يناير '25
+15
في 1 قنوات
Get PRO
ديسمبر '24
+262
في 1 قنوات
Get PRO
نوفمبر '24
+206
في 1 قنوات
Get PRO
أكتوبر '24
+166
في 0 قنوات
Get PRO
سبتمبر '24
+146
في 0 قنوات
Get PRO
أغسطس '24
+137
في 0 قنوات
Get PRO
يوليو '24
+96
في 1 قنوات
Get PRO
يونيو '24
+91
في 0 قنوات
Get PRO
مايو '24
+95
في 0 قنوات
Get PRO
أبريل '24
+104
في 0 قنوات
Get PRO
مارس '24
+149
في 0 قنوات
Get PRO
فبراير '24
+279
في 0 قنوات
Get PRO
يناير '24
+395
في 0 قنوات
Get PRO
ديسمبر '23
+327
في 0 قنوات
Get PRO
نوفمبر '23
+38
في 0 قنوات
Get PRO
أكتوبر '23
+32
في 0 قنوات
Get PRO
سبتمبر '23
+47
في 0 قنوات
Get PRO
أغسطس '23
+53
في 0 قنوات
Get PRO
يوليو '23
+51
في 0 قنوات
Get PRO
يونيو '23
+42
في 0 قنوات
Get PRO
مايو '23
+43
في 0 قنوات
Get PRO
أبريل '23
+67
في 0 قنوات
Get PRO
مارس '23
+65
في 0 قنوات
Get PRO
فبراير '23
+45
في 0 قنوات
Get PRO
يناير '23
+67
في 0 قنوات
Get PRO
ديسمبر '22
+62
في 0 قنوات
Get PRO
نوفمبر '22
+71
في 0 قنوات
Get PRO
أكتوبر '22
+70
في 0 قنوات
Get PRO
سبتمبر '22
+55
في 0 قنوات
Get PRO
أغسطس '22
+44
في 0 قنوات
Get PRO
يوليو '22
+54
في 0 قنوات
Get PRO
يونيو '22
+78
في 0 قنوات
Get PRO
مايو '22
+46
في 0 قنوات
Get PRO
أبريل '22
+77
في 0 قنوات
Get PRO
مارس '22
+105
في 0 قنوات
Get PRO
فبراير '22
+48
في 0 قنوات
Get PRO
يناير '22
+61
في 0 قنوات
Get PRO
ديسمبر '21
+99
في 0 قنوات
Get PRO
نوفمبر '21
+68
في 0 قنوات
Get PRO
أكتوبر '21
+170
في 0 قنوات
Get PRO
سبتمبر '21
+72
في 0 قنوات
Get PRO
أغسطس '21
+104
في 0 قنوات
Get PRO
يوليو '21
+72
في 0 قنوات
Get PRO
يونيو '21
+292
في 0 قنوات
Get PRO
مايو '21
+1 344
في 0 قنوات
| التاريخ | نمو المشتركين | الإشارات | القنوات | |
| 31 أغسطس | +1 | |||
| 30 أغسطس | +4 | |||
| 29 أغسطس | +10 | |||
| 28 أغسطس | +4 | |||
| 27 أغسطس | +4 | |||
| 26 أغسطس | +7 | |||
| 25 أغسطس | +6 | |||
| 24 أغسطس | +8 | |||
| 23 أغسطس | +3 | |||
| 22 أغسطس | +3 | |||
| 21 أغسطس | +5 | |||
| 20 أغسطس | +6 | |||
| 19 أغسطس | +3 | |||
| 18 أغسطس | +2 | |||
| 17 أغسطس | +1 | |||
| 16 أغسطس | +3 | |||
| 15 أغسطس | +5 | |||
| 14 أغسطس | +2 | |||
| 13 أغسطس | +5 | |||
| 12 أغسطس | +5 | |||
| 11 أغسطس | +9 | |||
| 10 أغسطس | +5 | |||
| 09 أغسطس | +3 | |||
| 08 أغسطس | +6 | |||
| 07 أغسطس | +7 | |||
| 06 أغسطس | +3 | |||
| 05 أغسطس | +6 | |||
| 04 أغسطس | +7 | |||
| 03 أغسطس | +6 | |||
| 02 أغسطس | +4 | |||
| 01 أغسطس | +10 |
منشورات القناة
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell.
"While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex
https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html
| 2 | Anthropic is cutting Claude Code's current weekly limits by 17%
Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds. [...]
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-is-cutting-claude-codes-current-weekly-limits-by-17-percent/ | 100 |
| 3 | Chrome Web Store extensions caught stealing crypto, browser data
Multiple extensions for Google Chrome and Microsoft Edge delivered a malware framework that deployed modules to steal cryptocurrency, sensitive data, and browser history, as well as inject ClickFix lures. [...]
https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/ | 73 |
| 4 | Anthropic warns infostealer malware is hijacking Claude sessions to drain usage
Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/ | 56 |
| 5 | FulcrumSec claims Manchester Airports hack, theft of 86 GB of data
FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]
https://www.bleepingcomputer.com/news/security/fulcrumsec-claims-manchester-airports-hack-theft-of-86-gb-of-data/ | 64 |
| 6 | Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution.
The vulnerabilities, according to Wordfence and Patchstack, are listed below -
CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in
https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html | 106 |
| 7 | TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance.
The post TerminalFix campaign deploys a reverse tunnel through multistage intrusion appeared first on Microsoft Security Blog.
https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/ | 93 |
| 8 | Hasbro Data Breach Exposed Employee Personal Information
A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach.
The post Hasbro Data Breach Exposed Employee Personal Information appeared first on SecurityWeek.
https://www.securityweek.com/hasbro-data-breach-exposed-employee-personal-information/ | 75 |
| 9 | Brave browser adds email aliases to help users evade tracking
The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]
https://www.bleepingcomputer.com/news/security/brave-browser-adds-email-aliases-to-help-users-evade-tracking/ | 76 |
| 10 | 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities.
The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active
https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html | 115 |
| 11 | ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines.
The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of
https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html | 104 |
| 12 | Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks.
Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting.
"This new privacy standard works in tandem
https://thehackernews.com/2026/08/android-17-adds-os-wide-ech-to-hide.html | 88 |
| 13 | Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening.
"This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's
https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html | 69 |
| 14 | Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands.
The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment
https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html | 60 |
| 15 | PaperCut Releases Emergency Patch for Exploited Zero-Day
A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.
The post PaperCut Releases Emergency Patch for Exploited Zero-Day appeared first on SecurityWeek.
https://www.securityweek.com/papercut-releases-emergency-patch-for-exploited-zero-day/ | 49 |
| 16 | Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says
New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.
The post Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says appeared first on SecurityWeek.
https://www.securityweek.com/think-youve-eliminated-chinese-ai-check-the-models-lineage-cisco-says/ | 37 |
| 17 | Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge
Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated.
The post Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge appeared first on SecurityWeek.
https://www.securityweek.com/tech-cybersecurity-giants-unite-behind-openai-led-cyber-defense-pledge/ | 41 |
| 18 | OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.
The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek.
https://www.securityweek.com/openai-agents-exploited-linux-kernel-flaw-on-companys-own-systems/ | 29 |
| 19 | ATF Confirms Cyber Incident After Ransomware Group Claims Attack
The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.
The post ATF Confirms Cyber Incident After Ransomware Group Claims Attack appeared first on SecurityWeek.
https://www.securityweek.com/atf-confirms-cyber-incident-after-ransomware-group-claims-attack/ | 29 |
| 20 | In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions
Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.
The post In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions appeared first on SecurityWeek.
https://www.securityweek.com/in-other-news-log4j-rce-scare-minimus-shutdown-iranian-hacker-sanctions/ | 31 |
