Aggregator
CVE-2026-65608 | getgrav Grav up to 2.0.8 FlexDirectory dynamicDataField os command injection
Mount Here, Read There: Twin Path Traversal CVEs in Kubernetes Storage
Mount Here, Read There: Twin Path Traversal CVEs in Kubernetes Storage
CVE-2026-65607 | siyuan-note SiYuan up to 3.7.1 Export kernel/server/serve.go serveExport path traversal
Why Customer Lifetime Value Begins on the Network
New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs
A new shellcode loader, dubbed “TriBack Loader,” to a China-nexus intrusion cluster tracked as JadeProx, with the malware explicitly engineered to evade modern EDR by abusing signed binaries and uncommon Win32 callback APIs. Across at least four observed variants, the loader underpins simultaneous espionage campaigns in South-East Asia and Latin America, including targeting of a […]
The post New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Cobalt adds Autonomous Pentest to scale application security testing
Cobalt has introduced Cobalt Autonomous Pentest, a new offering that enables continuous offensive security across an organization’s application portfolio by delivering actionable penetration testing results in as little as 24 hours. AI-assisted development enables organizations to ship software faster than ever, while attackers are using AI to automate reconnaissance and accelerate exploitation. Pentesting performed quarterly or even monthly, can no longer keep pace. As security teams face growing attack surfaces and constrained budgets, organizations need … More →
The post Cobalt adds Autonomous Pentest to scale application security testing appeared first on Help Net Security.