theinfosecnews
CISA KEVCVE-2026-3502CVE-2026-5281CVE-2026-3055CVE-2025-53521CVE-2026-33634CISA KEVCVE-2026-3502CVE-2026-5281CVE-2026-3055CVE-2025-53521CVE-2026-33634
V
vulnerability

Critical SQL Injection Vulnerability in OpenSTAManager Exposed

CVE-2026-35470 is a critical SQL injection vulnerability in OpenSTAManager versions before 2.10.2, allowing attackers with authentication to execute arbitrary SQL commands. Update to version 2.10.2 immediately.

NVD·31m ago·3 min read
Read full story
Allvulnerability94policy22malware18breach17apt9ransomware9
Ppolicy

Microsoft Deprecates SaRA: Implications for Security Teams

Microsoft has phased out the Support and Recovery Assistant (SaRA) from Windows updates as of March 10, 2023. The removal affects the diagnostic tools used within enterprises, urging a shift to alternative methods for system troubleshooting. IT departments need to adopt new protocols and ensure continued system security.

BleepingComputer·1h ago·3 min read
Rransomware

Storm-1175 Exploits Zero-Day Vulnerabilities in Medusa Ransomware Attack

Storm-1175, a China-based cybercriminal group, exploited zero-day vulnerabilities in Medusa ransomware attacks against enterprises in October 2023. The group's methods included leveraging vulnerabilities in Microsoft Exchange and Oracle WebLogic. Affected companies face ransom demands and data leaks.

BleepingComputer·2h ago·3 min read
Vvulnerability

CISA Warns of Active Exploits Targeting FortiClient EMS Vulnerability

CISA has mandated federal agencies to secure FortiClient EMS against an actively exploited vulnerability, CVE-2023-27997. The flaw, an authentication bypass, threatens unauthorized access and data breaches. Agencies must apply patches, monitor traffic, and restrict access to prevent exploitation.

BleepingComputer·3h ago·3 min read