CVE-2026-17482 — Critical vulnerability brief
CVSS 9.8IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
CybersecurityBoard.com brings together vulnerability intelligence, security news, MITRE ATT&CK group profiles, cyber events, certifications, training, products, companies and service providers.
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.
Apple paid a $150,000 bounty for a path traversal vulnerability in darwin-init, tracked as CVE-2026-20685, which could allow privileged network attackers to…
A newly disclosed zero-day vulnerability in GeoServer is being actively exploited in the wild, according to threat intelligence firm watchTowr. The flaw,…
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server.…
CVE-2024-6387 is a critical vulnerability in OpenSSH that was exploited by APT36 in their campaign targeting Afghan telecom and Indian critical infrastructure.…
rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending…
Threat actors are increasingly acquiring expired domains—known as "dropcatch domains"—to inherit their reputation and traffic, redirecting victims to scams and malware. According…
Identity and Access Management (IAM) compliance is the practice of proving that access controls are not just documented but actively enforced across…
Apple has issued a fresh batch of threat notifications to customers in 110 countries, warning that they may be targeted by mercenary…
Cybersecurity researchers at CTM360 have exposed a large-scale, global recruitment-themed phishing campaign that leverages Browser-in-the-Browser (BitB) windows to steal Google and Facebook…
Cybersecurity researchers at SpecterOps have detailed a post-exploitation technique that enables the Chrome DevTools Protocol (CDP) inside a running Google Chrome or…
A new White House memo signed by U.S. President Donald Trump directs the National Coordination Center (NCC) to establish a program allowing…
Swiping Squirrel is a financially motivated threat actor active since at least 2022, controlling over 3,000 domains. It sends fraudulent traffic to…
SocGholish is a malware campaign that regained access to thousands of compromised sites by teaming up with Shady Squirrel shortly after its…
Sable Squirrel is a Vietnam-based threat actor that has spent nearly $7 million acquiring expired domains to build a criminal enterprise. It…
Stuffy Squirrel is a financially motivated threat actor active since at least 2020, controlling over 500 domains. It operates a traffic distribution…
NanoCore is a remote access trojan that has been identified in malware samples communicating with Sable Squirrel's infrastructure, highlighting its role in…
njRAT is a remote access trojan that has been detected in malware samples communicating with Sable Squirrel's infrastructure, contributing to the threat…
HiddenTear is a ransomware family whose signatures have been found in artifacts communicating with Sable Squirrel's infrastructure, indicating potential ransomware activity within…
Mustang Panda (aka HoneyMyte) has been observed deploying an updated version of the CoolClient backdoor that includes a signed Windows kernel-mode rootkit,…
Microsoft's August 2026 Patch Tuesday included patches for 421 security flaws, including 236 in Windows, and addressed critical vulnerabilities such as CVE-2026-50656,…
USENIX WOOT is a security conference where the research on SIM card attacks was presented. The paper highlights the attack surface of…
ISO/IEC 27001:2022 is an international information security management standard. Its Annex A includes access control and identity management controls that organizations can…
The GCIH certification demonstrates proficiency in incident handling and response, often pursued after SANS SEC504 training.
The SEC660 course at SANS Network Security 2026 teaches how to leverage AI for automating tasks while maintaining deep manual understanding of…
SANS SEC504 is a training course covering hacker tools, techniques, and incident handling, leading to GCIH certification.
The Orchid Security platform operates in the identity observability category, discovering identities from applications and infrastructure, verifying how access is actually used,…
Apple's iPhone displays threat notifications on the Lock Screen and in Settings to alert users who may be targeted by mercenary spyware.…
Lockdown Mode is an Apple security feature that provides an extreme level of protection against sophisticated cyberattacks, including mercenary spyware. Apple recommends…
CDP-Enable-BOF is a Beacon Object File (BOF) developed by SpecterOps that activates the Chrome DevTools Protocol inside an already running Chrome or…
Albertsons was part of the proposed merger with Kroger, which used the domain krogeralbertsons.com. The domain was later acquired by Sable Squirrel…
DropCatch.com is a custom drop catching service that tracks domains approaching deletion and automatically attempts to register them on behalf of customers.…
Dynabot is a domain registrar that has been used by Sable Squirrel to purchase expired domains at auctions, contributing to the threat…
General Electric launched the health initiative healthymagination.com in 2009. The domain was later acquired by Sable Squirrel for illegal sports-streaming operations.
AstrillVPN is a VPN service whose exit nodes were identified in the investigation as part of the infrastructure used by suspected DPRK…
Vultr is a cloud infrastructure provider that was used to host the fake crypto startup's infrastructure in the undercover operation. The researchers…
Gorilla Servers is a hosting provider that was used in the undercover operation to host infrastructure. The researchers noted that the operatives'…
Bugcrowd is a crowdsourced security platform that facilitated the disclosure of the RovoBlast vulnerability in Atlassian Rovo. The platform rated the issue…