Cyber News

    Dashboard / Cyber News

    Imperva Customers Protected Against Novel HTTP Desync Attacks
    Or
    Or Gozlan-2026-08-07

    Imperva Customers Protected Against Novel HTTP Desync Attacks

    TL;DR: Recent Portswigger research introduced novel HTTP desync techniques discovered through an AI-assisted research system called the HTTP Terminator. The findings expand the range of unusual HTTP behaviors that can cause front-end and back-end systems to interpret the same traffic differently. Imperva Cloud WAF and On-Prem WAF customers are protected against practical attack patterns described in the research. Imperva’s existing security engine already blocked malicious […]

    The post Imperva Customers Protected Against Novel HTTP Desync Attacks appeared first on Blog.

    Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
    -2026-07-30

    Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

    Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

    Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
    -2026-07-15

    Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

    Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

    Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution
    -2026-07-01

    Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution

    Multiple vulnerabilities have been discovered in Mozilla products, the most severe of which could allow for arbitrary code execution. 


    • Mozilla Firefox is a web browser used to access the Internet.
    • Thunderbird is a free, open-source email, calendar, and chat application.


    Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.

    Vulnerabilities in fzf software
    CE
    CERT Polska-2026-06-30

    Vulnerabilities in fzf software

    CERT Polska has received a report about 2 vulnerabilities (CVE-2026-53432 and CVE-2026-53433) found in fzf software.