Intelligence / Cybersecurity

Cybersecurity Intelligence

Live cybersecurity intelligence from CISA, NIST, NVD, SEC EDGAR, BLS, and other authoritative sources. DecipherU is a cybersecurity career platform; every item here connects to career implications for security professionals.

4,542 items·Updated 12h ago·RSS
cve12h ago

CVE-2026-1255, The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Expos...

The YS LeadGen plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1.4 due to the 'ysleadgen_get_captured_data' AJAX action being accessible to unauthenticated users. This makes it possible for unauthenticated attackers to retrieve all captured form submission data, including personally identifiable information (PII) such as names, email addresses, and message content submitted through YS LeadGen forms.

Read more
cve13h ago

CVE-2026-85658, The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User ...

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.17.2 This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes.

Read more
cve13h ago

CVE-2026-4327, The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution i...

The The Welcomizer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to and including 2.8.1. This is due to missing authorization checks on the twiz_ajax_callback AJAX action's 'savesection' handler combined with the use of eval() to execute user-supplied 'custom logic' code on the frontend. The AJAX handler at twiz-ajax.php verifies a nonce but performs no current_user_can() capability check for the ACTION_SAVE_SECTION case. Furthermore, the nonce is exposed to any authenticated user through the directly-accessible twiz-ajax.js.php file which loads WordPress and outputs the nonce. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary PHP code via the twiz_custom_logic POST parameter when saving a section with output choice 'twiz_logic_output'.

Read more
cve13h ago

CVE-2026-15664, The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for ...

The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Multiple Choice 'Other' Value in all versions up to, and including, 5.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected script executes in the context of the WordPress admin results view, making administrators the primary target when reviewing submitted form entries.

Read more
cve18h ago

CVE-2026-92807, The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitra...

The Save as PDF Plugin by PDFCrowd plugin for WordPress is vulnerable to Arbitrary Function Invocation in all versions up to, and including, 4.6.1 via the `pdf_created_callback` shortcode attribute. The `eval_shortcode()` function copies any non-`button_`/non-`email_` shortcode attribute verbatim into a custom options array without sanitization, allowlist enforcement, or capability checks, and `create_button()` AES-encrypts that array — including the attacker-supplied callback value — and embeds the resulting blob in the rendered button HTML; when the blob is later POSTed to the unauthenticated `wp_ajax_nopriv_save_as_pdf_pdfcrowd` endpoint, `save_as_pdf_pdfcrowd()` decrypts it and invokes `$options['pdf_created_callback']` as a PHP callable at line 1722 with no `is_callable()` guard, no allowlist, and no capability check. This makes it possible for authenticated attackers, with Contributor-level access and above, to invoke arbitrary PHP functions or static class methods with plugin option data as the sole argument, enabling disclosure of the site's stored PDFCrowd API key and username or further server-side abuse. Note that the encryption boundary does not mitigate this vector because the server itself encrypts the attacker-chosen callback during shortcode rendering, supplying any authenticated Contributor with a cryptographically valid blob that any unauthenticated visitor can subsequently replay to trigger invocation.

Read more
cve18h ago

CVE-2026-87909, The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execut...

The WP Photo Album Plus plugin for WordPress is vulnerable to Remote Code Execution in all versions via the wppa_image_magick function. This is due to insufficient sanitization of the multipart upload filename before concatenation into an ImageMagick command string executed via exec(), with only escapeshellcmd() applied to the whole command rather than quoting individual arguments. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute code on the server. escapeshellcmd() escapes shell metacharacters but does not prevent argument injection because spaces remain as argument separators, and the filename sanitization applied at the database layer is never applied to the physical temporary file path used for ImageMagick processing.

Read more
cve18h ago

CVE-2026-13354, The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stor...

The Asset CleanUp: Page Speed Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content in all versions up to, and including, 1.4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable on instances where combine_loaded_css has been enabled.

Read more
cve21h ago

CVE-2026-93923, SiYuan through 3.8.4 fails to escape heading style attributes when rendering out...

SiYuan through 3.8.4 fails to escape heading style attributes when rendering outline and bookmark dock HTML, allowing stored cross-site scripting. Attackers can supply crafted notebooks or call administrative endpoints to inject malicious style values that execute in the Electron renderer with full system access.

Read more
cve21h ago

CVE-2026-93922, SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker...

SiYuan through 3.8.4 renders notebook names as raw HTML in the Daily Note picker dialog without escaping, allowing stored cross-site scripting in the Electron renderer. Attackers can create notebooks with HTML payloads in names that execute JavaScript with Node.js access when the picker opens, enabling operating system command execution.

Read more
Bruce Schneier / Schneier on Security1d ago

Friday Squid Blogging: On Squid Egg Sacs

Bruce Schneier, security technologist and author, published analysis on this topic. Schneier's commentary is widely read by security professionals and often shapes industry perspective. Read his full analysis at the link. Source: Schneier on Security.

Read more
cve1d ago

CVE-2026-84034, IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulne...

IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the hardware_assess/obstore binaries. A low-privileged authenticated user can recover hardcoded product master secrets, potentially resulting in unauthorized access to the internal database and compromise of sensitive system information.

Read more
cve1d ago

CVE-2026-82896, IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to...

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to traverse directories on the system due to a path traversal vulnerability.

Read more
cve1d ago

CVE-2026-82893, IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated ...

IBM Guardium Data Protection 12.2 could allow a local attacker to gain elevated privileges due to improper privilege management.

Read more
cve1d ago

CVE-2026-82892, IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbit...

IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Read more
cve1d ago

CVE-2026-82887, IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to...

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

Read more
cve1d ago

CVE-2026-82885, IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to...

IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to gain elevated privileges due to missing authorization in the REST API.

Read more
cve1d ago

CVE-2026-81937, IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerabi...

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the import remotelog_config file CLI command. A highly privileged authenticated user can inject shell commands through the filename parameter, potentially resulting in arbitrary command execution with root privileges and impact to the confidentiality, integrity, and availability of the affected system.

Read more
cve1d ago

CVE-2026-81933, IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability...

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Analytic Grid Service Handler. A low-privileged authenticated user can inject SQL statements through the analytic cases grid endpoint, potentially resulting in unauthorized access to sensitive data and impact to the confidentiality, integrity, and availability of the affected system.

Read more
cve1d ago

CVE-2026-81669, IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerabi...

IBM Guardium Data Protection 12.2 is vulnerable to a command injection vulnerability in the create csr wildcard CLI command. An authenticated privileged CLI user can inject arbitrary shell commands through the alias input, resulting in command execution with root privileges.

Read more
cve1d ago

CVE-2026-81656, IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability...

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the New Query Builder REST Processor. A low-privileged authenticated user can inject SQL statements through the newQueryBuilder REST endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.

Read more
cve1d ago

CVE-2026-81626, IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability...

IBM Guardium Data Protection 12.2 is vulnerable to a SQL injection vulnerability in the Load Balancer Groups component. An unauthenticated user can inject SQL statements through the Load Balancer Servlet endpoint, potentially resulting in unauthorized access to data and impact to the confidentiality, integrity, and availability of the affected system.

Read more
cve1d ago

CVE-2026-17619, IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send sp...

IBM Platform RTM is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information in the back-end database.

Read more
cve1d ago

CVE-2026-11727, IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remo...

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 IBM MQ C client could allow a remote attacker to cause a denial of service or potentially execute arbitrary code due to improper validation of queue manager responses when requesting AMS policy data.

Read more
cve1d ago

CVE-2026-11726, IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac...

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to obtain sensitive information or cause a denial of service due to improper validation of message header offset values.

Read more
cve1d ago

CVE-2026-11725, IBM MQ could allow an authenticated attacker to cause a denial of service or pot...

IBM MQ could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code due to an integer overflow in MQINQ request processing.

Read more
cve1d ago

CVE-2026-11716, IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attac...

IBM MQ for HPE NonStop 8.1.0 through 8.1.0.40 could allow an authenticated attacker to cause a denial of service or potentially execute arbitrary code during queue manager startup due to improper validation of cluster migration data.

Read more
cve1d ago

CVE-2017-20284, Caucho Resin contains a path traversal vulnerability in the documentation webapp...

Caucho Resin contains a path traversal vulnerability in the documentation webapp (resin-doc) that allows remote unauthenticated attackers to read arbitrary files by supplying a relative path through the inputFile request parameter of the jndi-appconfig tutorial servlet. Attackers can craft requests with directory traversal sequences to the servlet endpoint to read files outside the intended tutorial directory on the underlying system. Exploitation evidence was first observed by the Shadowserver Foundation on 2021-12-10.

Read more
cisa1d ago

Read more
cve1d ago

CVE-2021-48008, Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows ...

Chanjet CRM contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by manipulating the site_id GET parameter in the webservice endpoint. Attackers can exploit the lack of input sanitization or parameterization through UNION-based injection techniques to extract sensitive data from the underlying database. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-18.

Read more
cve1d ago

CVE-2019-25776, Weaver E-cology contains an unauthenticated SQL injection vulnerability that all...

Weaver E-cology contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL queries by submitting malicious input through the userIdentifiers GET parameter in the mobile plugin endpoint. Attackers can bypass space-based filter controls by wrapping SQL keywords in parentheses to perform UNION-based injection and extract sensitive data including administrator credential hashes from the database. Exploitation evidence was first observed by the Shadowserver Foundation on 2022-07-28.

Read more
cve1d ago

CVE-2026-93749, source-map-js through 1.2.1 fails to validate the per-section offset line value ...

source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event loop blocking for extended periods, preventing the service from handling other requests.

Read more
cve1d ago

CVE-2026-93559, A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0...

A vulnerability was identified in Forget-C Jellyfish AI Short Drama Studio 0.1.0-alpha/0.2.0/0.3.0/0.3.1/0.3.2. This affects an unknown function of the file backend/app/dependencies.py of the component FastAPI. The manipulation leads to missing authentication. It is possible to initiate the attack remotely. The reported GitHub issue was closed automatically due to inactivity.

Read more
cve1d ago

CVE-2026-91149, A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this...

A flaw was found in Cockpit. An unauthenticated remote attacker can exploit this vulnerability by initiating and sustaining numerous simultaneous connections to the `cockpit-tls` service. This forces the service to create an unbounded number of detached threads, consuming system resources such as memory and file descriptors. The primary consequence is a denial of service (DoS), leading to degradation or complete unavailability of the Cockpit service for legitimate users.

Read more
cve1d ago

CVE-2026-93690, uri-js through 4.4.1 contains a denial of service vulnerability in the removeDot...

uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely when a path segment begins with Unicode line or paragraph separators. Attackers can trigger this by calling removeDotSegments directly or through normalize/resolve functions with IRI handling enabled, causing the Node.js event loop to block indefinitely until heap exhaustion.

Read more
cve1d ago

CVE-2026-93688, SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV tra...

SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstrap_room values, allowing unbounded transfer state allocation. Unauthenticated attackers can reach the decode engine's POST /generate endpoint and submit arbitrary bootstrap_room values to exhaust prefill process memory until out-of-memory termination.

Read more
cve1d ago

CVE-2026-81942, PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions bef...

PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contain an OS command injection vulnerability in the web server. User-supplied input is passed to system() without sufficient filtering, allowing a remote authenticated attacker to execute arbitrary commands on the underlying operating system and escalate privileges to root.

Read more

Where the field is heading

AI is compressing entry-level SOC Tier-1 work (alert triage, routine log review) faster than it's creating junior roles to replace it: SANS' 2026 workforce survey found 52% of security professionals expect AI to reduce entry-level demand specifically. The roles growing instead sit on top of that compression: adversarial testing of the AI systems doing the compressing, and governing how they get deployed.

AI Red Teamer career guide

NIS2, DORA, and the EU AI Act have created what European recruiters describe as a sustained compliance-hiring wave, not a spike, because none of the three are optional and all three require role-specific, documented, auditable training. Each EU member state transposes NIS2 into its own national law on its own timeline, so tracking which version applies where is now a real part of the job.

NIS2 transposition tracker

"AI security" is splitting into distinct disciplines rather than staying a sub-skill inside general security work: adversarial testing, model governance, and third-party AI risk are becoming separate hiring lines with their own job titles.

NIS2 & DORA Compliance Manager career guide
Last verified: April 2026?Report an inaccuracy