BreachFeed

Security news

Everything BreachFeed is tracking across the industry, as it publishes.

Trending this week

Spotlight

Insecure.Org·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujmtju05d9hmu2o6godz46

[0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2)

Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] Royal Server 5.04.50529.0 Local privilege escalation to LocalSystem on the execution path without credential override (7.2) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in Royal Server 5.04.50529.0. Type: Local privilege escalation to LocalSystem on the execution path without credential override (CWE-250) CVSS: 7.2...

Insecure.Org·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujmtju05dahmu26nazetq5

[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8)

Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in core-admin 1.0.164 (build 16468). Type: Systemic shell command injection via ineffective quote escaping (CWE-78) CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)...

Insecure.Org·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujmtju05dbhmu28xed0go9

[0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)

Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in OP5 Monitor 9.20. Type: Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (CWE-78) CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Impact:...

Insecure.Org·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujmtju05dchmu2mzc1bxn9

[0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)

Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in QuantaStor 6.8.3.018. Type: Command injection in the alert-mail command via the smtpPassword field (CWE-78) CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Impact:...

Insecure.Org·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujmtju05ddhmu28ix8jr3u

[0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2)

Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] SmarterMail 100.0.9693 (Build 9693) Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (7.2) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in SmarterMail 100.0.9693 (Build 9693). Type: Antivirus command-line configuration executing as NT AUTHORITY\SYSTEM (CWE-250) CVSS: 7.2...

Insecure.Org·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujmtju05dehmu238rpjebv

[0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8)

Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6) Unauthenticated SOAP with hard-coded credentials leading to OS command execution (9.8) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in Jitterbit Agent 12.8.1.6 (Docker jitterbit/agent:12.8.1.6). Type: Unauthenticated SOAP with hard-coded credentials leading...

Also reported by 1 other source
Insecure.Org·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujmtju05dfhmu2n50vsjve

[0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8)

Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] Accurate Online Private Cloud on-prem (current) Unauthenticated Hessian deserialization leading to JNDI remote class loading (9.8) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in Accurate Online Private Cloud on-prem (current). Type: Unauthenticated Hessian deserialization leading to JNDI remote class loading...

Insecure.Org·2 sources
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujmtju05dhhmu2vpjvocar

**Subject:** CVE-2026-2035703: Tozed ZLT X300 5G CPE — Unauthenticated Remote Root Code Execution via TR-069 Command Injection (CVSS 9.8)

Posted by Surf free on Sep 08 Tozed ZLT X300 5G CPE Router firmware 6.01.3 contains an OS command injection vulnerability (CWE-78) in the TR-069/CWMP client daemon (netcwmpd). The IPPingDiagnostics Host parameter is passed unsanitized into sprintf, which constructs a shell command executed via system_by_root() as root. An attacker operating a rogue LTE base station using SDR hardware (~$300) can impersonate the carrier's Auto Configuration Server and inject arbitrary...

Insecure.Org·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmtujmtju05dihmu2iz12d3la

CVE-2026-52307: Stored XSS in 1CMS v5.6

Posted by 懒-癌-症~ via Fulldisclosure on Sep 08 CVE-2026-52307: 1CMS v5.6 Authenticated Stored XSS Vulnerability Vulnerability Description An authenticated stored cross-site scripting (XSS) vulnerability exists in the Column Management component of ClassCMS 1CMS v5.6. Attackers can execute arbitrary web scripts or HTML by injecting a crafted payload into the title field. - Vulnerability Type: Cross Site Scripting (XSS) - Vendor: ClassCMS - Affected Product: 1CMS v5.6 - Affected Component:...

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015ghmu27w5pj5jt

CISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting production

On a conventional server, disabling an unused service is usually a routine hardening task. On a Siemens S7 controller, the supposedly unused service may carry remote I/O traffic, supply process values to an HMI or provide the maintenance team’s only path to diagnostics. Close it without checking those dependencies and the security team may cause the outage it intended to prevent. That is the implementation problem inside joint cybersecurity advisory AA26-231A, issued on August 19 by the NSA,…

Also reported by 1 other source
The Hacker News·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1yjq001thnu24kuzjgl7

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment

SecurityWeek·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttk1ye80018hnu2a24ql2m3

Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta

The startup founded by Palo Alto Networks’ Nir Zuk has raised $290 million to build an AI-native security platform for highly regulated organizations that cannot rely on the public cloud. The post Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta appeared first on SecurityWeek.

CSO Online·
Share

Link — click to select, then copy:

https://breachfeed.com/article/cmttlze94015hhmu2cp7cqihm

Mars Security Debuts Automated Threat Engine Processing Live Cyber Intelligence Into Validated Rules Within Minutes

Mars Security, an autonomous threat hunting and detection engineering platform founded by offensive cybersecurity veterans, today announced Real-Time Intel-Based Detection. The milestone expansion equips enterprise security operations centers (SOCs) to convert newly published threat intelligence advisories into production-ready, validated detection rules within minutes of release. Developed by former military red team operators, the capability systematically ingests threat reports from…