Breaches & RansomwareEmerging1 src
South Korea’s President Lee Jae Myung orders thorough probe into data breaches at local banks
Lee Hyo-jin reports: President Lee Jae Myung on Sunday ordered a thorough investigation into a string of recent data breaches at financial institutions, as artificial intelligence (AI)-powered cyberattacks increasingly target them. According to Cheong Wa Dae, Lee was briefed on recent data breaches at financial and public institutions and their responses to the incidents. “The…
Source
South Korea's President Lee Jae Myung orders thorough probe into data breaches at local banks - DataBreaches.Net
Breaches & RansomwareEmerging1 src
Slate Valley Unified School District voted not to pay ransom demand; Kairos likely to leak data
The Slate Valley Unified School District in Fair Haven, Vermont, has been responding to a security incident since September 3. On October 2, Kairos threat actors contacted DataBreaches to alert us to the incident and their response to the district’s claim that they believed student data had not been compromised. They were also angry that…
Source
Slate Valley Unified School District voted not to pay ransom demand; Kairos likely to leak data - DataBreaches.Net
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105217 - Cockpit CMS 2.12.0 before 2.14.1 Disabled TLS Verification via cron.php
CVE ID : CVE-2026-105217
Published : Oct. 4, 2026, 6:16 p. m.
• 1 hour, 15 minutes ago
Description : Cockpit CMS 2. 12. 0 before 2. 14. 1 disables TLS certificate verification in the cron. php web worker restart request, allowing network attackers to capture the worker token. Man-in-the-middle attackers on the outbound path to site_url can present any certificate to steal the worker/web/token value and start the web worker.
Severity: 3.1
• LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105216 - go-micro before 6.0.0 Disabled TLS Certificate Verification via tls.Config Helper
CVE ID : CVE-2026-105216
Published : Oct. 4, 2026, 6:16 p. m.
• 1 hour, 15 minutes ago
Description : go-micro before 6. 0. 0 contains an improper certificate validation vulnerability that allows network attackers to impersonate services because the shared TLS helper sets InsecureSkipVerify to true by default.
Man-in-the-middle attackers can present any certificate to intercept or modify gRPC transport, HTTP and RabbitMQ broker, and Consul or etcd registry traffic, including authentication tokens and credentials.
Severity: 9.1
• CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105218 - gopay before 1.5.119 Disabled TLS Certificate Verification in xhttp Client
CVE ID : CVE-2026-105218
Published : Oct. 4, 2026, 6:16 p. m.
• 1 hour, 15 minutes ago
Description : gopay before 1. 5. 119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client. go, allowing man-in-the-middle attackers to impersonate payment provider APIs. Attackers can present any certificate to read merchant credentials, signatures and transaction data, and modify payment, refund and order query responses.
Severity: 9.1
• CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105219 - Mammoth.js 1.3.0 before 1.12.3 ReDoS via Style Map Tokeniser
CVE ID : CVE-2026-105219
Published : Oct. 4, 2026, 6:16 p. m.
• 1 hour, 15 minutes ago
Description : Mammoth. js 1. 3. 0 before 1. 12. 3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser. js due to overlapping regex alternatives. Attackers can supply a crafted . docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to block the Node. js event loop.
Severity: 8.7
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105161 - invariant-systems-ai aiir Policy Gate signature verification
CVE ID : CVE-2026-105161
Published : Oct. 4, 2026, 6:16 p. m.
• 1 hour, 15 minutes ago
Description : A flaw has been found in invariant-systems-ai aiir up to 1. 7. 0. The affected element is an unknown function of the component Policy Gate Handler. Executing a manipulation can lead to improper verification of cryptographic signature. The attack can be executed remotely. It is advisable to upgrade the affected component. The GitHub repository of this project is not available anymore.
This vulnerability only affects products that are no longer supported by the maintainer.
Severity: 6.9
• MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Threat Actors & CampaignsEmerging1 src
South Korea Orders Full Security Probe After Bank Cyberattacks
President Lee Jae Myung ordered a thorough investigation into a series of cyberattacks and data breaches affecting South Korean financial institutions, including Shinhan Bank, KB Kookmin Bank, and Hana Bank.
The post South Korea Orders Full Security Probe After Bank Cyberattacks appeared first on CyberUpdates365
• Latest Cybersecurity News & Vulnerabilities .
Vendors & MarketEmerging1 src
OpenCourant: Rocky Linux Developers Create Community Fork Of OpenRadioss
This week was the surprising and unfortunate decision of Siemens shutting down the OpenRadioss project as the four year old open-source project started by Altair Engineering with their prominent Radioss finite element solver. Siemens didn't just end the project but they shutdown the GitHub repository that hosted the open-source code and removed other resources that had built around it.
Fortunately, there's a new community fork of OpenRadioss as OpenCourant...
Policy & RegulationEmerging1 src
ShinyHunters hacker detained in Jordan – now he’s helping FBI hunt down his own crew - Cybernews
ShinyHunters hacker detained in Jordan – now he’s helping FBI hunt down his own crew Cybernews
Breaches & RansomwareEmerging1 src
🏴☠️ Emperador has just published a new victim : OMUR HIRDAVAT LTD
A Turkish company engaged in the wholesale and retail trade of construction and household fittings The archives contain several thousand documents with personnel and customer data [Sector: Manufacturing]
I stopped saving all my passwords in Chrome; you might want to think twice too
I used to let my browser remember almost every password I used online. It was convenient, and modern browsers do a lot to protect saved credentials, including encryption, phishing protection, and breach warnings.
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105086 - WWBN AVideo 12.4 through 29.2.0 Stored XSS via Double-Encoded Video Title
CVE ID : CVE-2026-105086
Published : Oct. 4, 2026, 4:16 p. m.
• 3 hours, 15 minutes ago
Description : WWBN AVideo 12. 4 through 29. 2. 0 contains a stored cross-site scripting vulnerability that allows authenticated uploaders to inject HTML by submitting doubly-encoded entities in video titles. Because safeString() strips tags before decoding entities and runs twice via setTitle() and save(), attackers can store markup that executes in trending, gallery, embed, and playlist pages.
Severity: 9.3
• CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105224 - YesWiki before 4.6.7 Stored XSS via Bazar valeur Action
CVE ID : CVE-2026-105224
Published : Oct. 4, 2026, 4:16 p. m.
• 3 hours, 15 minutes ago
Description : YesWiki before 4. 6. 7 contains a cross-site scripting vulnerability in the Bazar valeur action that allows page editors to inject script by rendering unescaped HTML fetched from a remote URL. Attackers can point tools/bazar/actions/valeur. php at a controlled server returning BAZ_fiche_titre markup with an img onerror handler, executing script in every viewer's browser.
Severity: 5.4
• MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105089 - WWBN AVideo through 29.2.0 Stored XSS via trailer1 in YouPHPFlix2 Templates
CVE ID : CVE-2026-105089
Published : Oct. 4, 2026, 4:16 p. m.
• 3 hours, 15 minutes ago
Description : WWBN AVideo through 29. 2. 0 contains a stored cross-site scripting vulnerability that allows users with upload permission to inject script by setting a malicious video trailer1 URL. The value is rendered unescaped in YouPHPFlix2 templates and channel playlists, letting attackers break out of onclick strings or iframe src attributes to execute JavaScript in victims' browsers.
Severity: 9.3
• CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-104402 - WordPress Mindio Magic MCP plugin = 0.5.6 - Sensitive Data Exposure vulnerability
CVE ID : CVE-2026-104402
Published : Oct. 4, 2026, 4:16 p. m.
• 3 hours, 15 minutes ago
Description : Insertion of Sensitive Information Into Sent Data vulnerability in farvisun Mindio Magic MCP mindio-magic-mcp allows Retrieve Embedded Sensitive Data. This issue affects Mindio Magic MCP: from n/a through 0. 5. 6.
Severity: 4.3
• MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
SECURITY AFFAIRS AI-CYBERSECURITY NEWSLETTER ROUND 2
Security Affairs AI-CYBERSECURITY newsletter includes a collection of the best articles and research on AI in the international landscape
Artificial intelligence is rapidly changing cybersecurity, reshaping both the techniques used by attackers and the tools available to defenders. AI agents can automate tasks, analyze large amounts of data, discover vulnerabilities and accelerate offensive operations. At the same time, AI is creating new capabilities for threat detection, incident analysis and response.
Security Affairs’ new newsletter follows this evolution, covering every week the latest threats, attacks, vulnerabilities and developments at the intersection of AI and cybersecurity.
Breaches & RansomwareEmerging1 src
🏴☠️ Booba project has just published a new victim : MorseLife Health System, Inc.
Hospitals and Health Care Stolen data: 344 GB.
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105209 - ZITADEL before 3.4.15 and 4.17.1 Cross-Organization Account Takeover via Passkey Enrollment
CVE ID : CVE-2026-105209
Published : Oct. 4, 2026, 3:16 p. m.
• 4 hours, 15 minutes ago
Description : ZITADEL 3. x before 3. 4. 15 and 4. x before 4. 17. 1 contains an improper authorization vulnerability: when issuing passkey or passwordless enrollment codes, it checks only the organization in the x-zitadel-orgid header, not the target user's organization.
Attackers with user-write permission in one organization can obtain an enrollment code for a user in another organization on the same instance and register their own authenticator to take over that account.
Severity: 9.6
• CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105212 - ZITADEL before 3.4.14 and 4.16.2 Account Takeover via Passkey Enrollment
CVE ID : CVE-2026-105212
Published : Oct. 4, 2026, 3:16 p. m.
• 4 hours, 15 minutes ago
Description : ZITADEL 3. x before 3. 4. 14 and 4. x before 4. 16. 2 contains an authentication bypass in the hosted Login V1 and Login V2 UIs that accepts passkey or other authenticator enrollment on identify-only login sessions, before any primary factor is verified.
Unauthenticated attackers knowing only a victim's login name can register an attacker-controlled authenticator and log in as that user, bypassing existing passwords and MFA.
Severity: 8.7
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105211 - ZITADEL before 4.17.1 Authentication Bypass via Login V2 OTP returnCode
CVE ID : CVE-2026-105211
Published : Oct. 4, 2026, 3:16 p. m.
• 4 hours, 15 minutes ago
Description : ZITADEL before 4. 17. 1 contains an authentication bypass vulnerability in Login V2 that allows unauthenticated attackers to take over accounts by obtaining OTP codes via the returnCode delivery type. Attackers knowing a login name of a victim with OTP-Email and OTP-SMS enrolled can read both codes from server-action responses to gain MFA-authenticated sessions, including administrator takeover.
Severity: 9.2
• CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105213 - ZITADEL before 4.17.1 Authentication Bypass via Login V2 for Deactivated Organizations
CVE ID : CVE-2026-105213
Published : Oct. 4, 2026, 3:16 p. m.
• 4 hours, 15 minutes ago
Description : ZITADEL 4. x before 4. 17. 1 does not check an organization's inactive state during Login V2 authentication, verifying only the individual user's status. Users of a deactivated organization who hold valid credentials, an existing session, or a refresh token can still sign in, create sessions, and obtain or refresh tokens.
Severity: 8.8
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105215 - ZITADEL before 4.16.2 Account Pre-Hijacking via Forged External IdP Callback
CVE ID : CVE-2026-105215
Published : Oct. 4, 2026, 3:16 p. m.
• 4 hours, 15 minutes ago
Description : ZITADEL before 3. 4. 14 and 4. x before 4. 16. 2 contains an authentication bypass in the hosted Login V1 UI because the 'external account not found' registration endpoint trusts client-supplied external identity fields without a completed IdP callback.
Unauthenticated attackers can submit forged IDPConfigID and ExternalUserID values to pre-create an account bound to a victim's external IdP identity, which the victim's later genuine external login then signs into.
Severity: 9.3
• CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105214 - Zitadel before 4.16.2 SSRF via Organization Domain HTTP Verification
CVE ID : CVE-2026-105214
Published : Oct. 4, 2026, 3:16 p. m.
• 4 hours, 15 minutes ago
Description : Zitadel before 4. 16. 2 contains a server-side request forgery vulnerability that allows attackers to make the server request internal resources through organization domain HTTP verification. The challenge fetch uses Go's default http.
Get instead of the protected client, so attackers can register domains that redirect to loopback, internal, or cloud metadata addresses to scan ports and map internal networks.
Severity: 2.3
• LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105210 - ZITADEL before 4.17.1 Unauthenticated MFA Enrollment via Login V1 Init Handlers
CVE ID : CVE-2026-105210
Published : Oct. 4, 2026, 3:16 p. m.
• 4 hours, 15 minutes ago
Description : ZITADEL 3. x before 3. 4. 15 and 4. x before 4. 17. 1 contains a missing authentication flaw in the hosted Login V1 UI, whose second-factor enrollment and initialization handlers act on an identify-only session before any primary factor is verified.
Attackers knowing only a victim's login name can enroll attacker-controlled TOTP, OTP-SMS, OTP-Email, or U2F factors, overwrite the verified phone number, and enumerate users through discrepant errors.
Severity: 8.8
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105205 - SiYuan before 3.8.5 Information Disclosure via /api/block/getDocInfo and getDocsInfo
CVE ID : CVE-2026-105205
Published : Oct. 4, 2026, 3:16 p. m.
• 4 hours, 15 minutes ago
Description : SiYuan before 3. 8. 5 contains an information disclosure vulnerability that allows publish-mode readers to learn backlink block IDs and reference counts from password-protected and publish-disabled documents by querying a published document.
Attackers can send POST requests to /api/block/getDocInfo or getDocsInfo for a published document ID to obtain refIDs and refCount of hidden referencing blocks, bypassing the publish confidentiality boundary.
Severity: 6.9
• MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105206 - ZITADEL before 4.17.3 Cross-Organization Authentication Method Enumeration via User Service
CVE ID : CVE-2026-105206
Published : Oct. 4, 2026, 3:16 p. m.
• 4 hours, 15 minutes ago
Description : ZITADEL 3. 0. 0 through 3. 4. 15 and 4. x before 4. 17. 3 contains an incorrect authorization flaw in the User Service API, which verifies user. read against the caller's organization rather than the organization owning the target user. An authenticated member holding org-scoped user.
read can query GET /v2/users/{userId}/authentication_methods to learn which authentication method types users in other organizations have registered.
Severity: 5.3
• MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105207 - ZITADEL before 4.17.3 Account Takeover via External IdP Linking
CVE ID : CVE-2026-105207
Published : Oct. 4, 2026, 3:16 p. m.
• 4 hours, 15 minutes ago
Description : ZITADEL 3. 0. 0 through 3. 4. 15 and 4. 0. 0 before 4. 17. 3 creates links between user accounts and external identity providers without verifying a primary factor or the caller's permission, including on identify-only Login V2 sessions and via the User Service V2 AddIDPLink endpoint.
An unauthenticated attacker knowing a victim's login name can bind their own external IdP identity to the victim's account and then sign in as the victim.
Severity: 9.8
• CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105158 - RainyGao DocSys Database Management BaseController.java BaseController.createDBForMysql sql injection
CVE ID : CVE-2026-105158
Published : Oct. 4, 2026, 3:16 p. m.
• 4 hours, 15 minutes ago
Description : A vulnerability was detected in RainyGao DocSys up to 2. 02. 85. The impacted element is the function BaseController. createDBForMysql of the file BaseController. java of the component Database Management. The manipulation of the argument url results in sql injection. The attack can be executed remotely. The exploit is now public and may be used.
The project was informed of the problem early through an issue report but has not responded yet.
Severity: 7.5
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105208 - ZITADEL before 4.17.3 Session Hijacking via Forgeable IdP Intent Tokens
CVE ID : CVE-2026-105208
Published : Oct. 4, 2026, 3:16 p. m.
• 4 hours, 15 minutes ago
Description : ZITADEL 4. x before 4. 17. 3 and 3. x through 3. 4. 15 protects IdP intent tokens with unauthenticated, malleable encryption, allowing authenticated users to tamper with their own token so it is accepted for another user's external login intent.
An attacker who predicts a victim's in-flight intent identifier and wins a timing race can call /v2/idp_intents or /v2/sessions to steal the victim's IdP tokens or hijack their session.
Severity: 8.7
• HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105156 - YzmCMS MD5 system.func.php password weak password hash
CVE ID : CVE-2026-105156
Published : Oct. 4, 2026, 3:16 p. m.
• 4 hours, 15 minutes ago
Description : A weakness has been identified in YzmCMS up to 7. 6. Impacted is the function Password of the file /common/function/system. func. php of the component MD5 Handler. Executing a manipulation of the argument pass can lead to password hash with insufficient computational effort. The attack may be launched remotely. This attack is characterized by high complexity. The exploitability is considered difficult.
The exploit has been made available to the public and could be used for attacks. The vendor kindly explains: "Our regular release cycle is about 6 months. The last release was in the previous month, and our next scheduled version will be released in March 2027. We will implement the backward-compatible gradual hash migration feature in this upcoming release. (...)
Vulnerabilities & PatchesEmerging1 src
CVE-2026-105157 - RainyGao DocSys Document Controller doGetTmpFile.do DocController.doGetTmp path traversal
CVE ID : CVE-2026-105157
Published : Oct. 4, 2026, 3:16 p. m.
• 4 hours, 15 minutes ago
Description : A security vulnerability has been detected in RainyGao DocSys up to 2. 02. 85. The affected element is the function DocController. doGetTmp of the file /Doc/doGetTmpFile. do of the component Document Controller. The manipulation of the argument path/fileName leads to path traversal. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
The project was informed of the problem early through an issue report but has not responded yet.
Severity: 4.3
• MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Threat Actors & CampaignsEmerging1 src
국내 이메일로 유포 되는 악성코드-Ziraat Bankası - Ödeme Onayı.pdf(104KB).jar
오늘은 국내 이메일로 유포되는 악성코드로 유포되는 악성코드인 Ziraat Bankası - Ödeme Onayı. pdf(104KB). jar에 대해서 분석을 하는 시간을 가져 보겠습니다. 일단 이번 분석은 자신이 없는 분석입니다. 오류가 ..
국내 이메일로 유포 되는 악성코드-Ziraat Bankası - Ödeme Onayı. pdf(104KB). jar
Breaches & RansomwareEmerging1 src
🏴☠️ Storm has just published a new victim : Nipigon District Memorial Hospital
Nipigon District Memorial Hospital offers a range of healthcare services including diagnostic imaging, lab services, physiotherapy, and an assisted living program. The hospital aims to serve patients and residents in the Nipigon district, focusing on community health and well-being. They also provide specialized services such as Ontario Telemedicine Services and Meals on Wheels.
The hospital is committed to strategic planning for future healthcare needs, as outlined in their CARE 2030 initiative. The company headquarters is located in 125 Hogan Road, Nipigon, ON P0T 2J0, Canada. 51-200 Employees