Track CVEs, attack groups, malware, vendors and training in one place.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
CVE-2026-60112 is a critical vulnerability in NASA's AIT-GUI before version 2.5.1, allowing unauthenticated network attackers to obtain a valid session and issue arbitrary spacecraft commands via Sessions.create() without credential checks. Rated 9.3 on CVSS…
CVE-2026-47731 is an unreviewed GitHub advisory describing a path traversal vulnerability in the AMMOS Instrument Toolkit that allows arbitrary file append over…
CVE-2026-71214 is a critical vulnerability in the NASA-AMMOS Aerie/PlanDev sequencing server, as listed in the GitHub Advisory Database. Details are limited but…
CVE-2026-71289 is a critical vulnerability in the Asynchronous Network Management System reference implementation, as listed in the GitHub Advisory Database. It affects…
Security researchers at Cycode have disclosed a chain of vulnerabilities in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit.…
Cybersecurity researchers have disclosed two denial-of-service (DoS) attack techniques, collectively named "CDN Tsunami," that exploit how major content delivery networks (CDNs) convert…
Cybersecurity researchers have disclosed a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker…
Phishing has evolved from malicious content (Phishing 1.0) to malicious intent (Phishing 2.0) and now to AI-powered, multi-channel attacks (Phishing 3.0). In…
Cybersecurity researchers at Hunt.io have disclosed a campaign, dubbed Operation CameraSwarm, that compromised more than 14,530 Dahua devices between June 17 and…
GoldFactory is a Chinese-speaking threat actor linked to multiple Android and iOS banking malware families, including GoldDigger, GoldPickaxe, GoldDiggerPlus, and GoldKefu. The…
A newly uncovered cyber espionage operation dubbed SilkParasite has been targeting government bodies in Central Asia, according to a technical report from…
AI-assisted malwareBitdefenderBLOODALCHEMYCentral Asia
GoldPickaxe was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
GoldDiggerPlus was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
GoldKefu was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Cybersecurity researchers have uncovered significant updates to the Android banking trojans ToxicPanda (aka TgToxic) and GoldDigger, both of which now feature enhanced…
Researchers presented a survey of Ledger breach victims at USENIX Security '23, documenting spam, scams, phishing, and safety concerns following the 2020…
ISO/IEC 27001:2022 is an international information security management standard. Its Annex A includes access control and identity management controls that organizations can…
AIT-GUI is a browser-based operator console for NASA/JPL's AMMOS Instrument Toolkit, used to send commands to spacecraft and instruments. Critical vulnerabilities were…
The AMMOS Instrument Toolkit is an open-source framework for building ground data systems, enabling command and telemetry processing for spacecraft. It is…
NASA/JPL's open-source AMMOS Instrument Toolkit and its AIT-GUI console were found to have critical vulnerabilities that could allow unauthenticated attackers to issue…
ThreatFabric, a Dutch security company, discovered and analyzed the Manic Android malware. Their technical report details the malware's capabilities, including financial fraud,…
OpenSSL Project was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs,…
Seven malicious Firefox extensions use threat actor-controlled Supabase projects to dynamically serve phishing or decoy content, abusing the platform's infrastructure.
The 37 sports-score shell extensions share a hard-coded credential for API-Sports, a legitimate sports data service, indicating coordinated infrastructure.