Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.8 THN:090748905BC...

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV_THN:090748905BCD2E05CB2679EBE28F1EAD

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKqQ4Uk8lGWwF7f6lrmP6dRHkEmQTJsqFs8xvJ5256xUcHTeWMNVMkPguALNqLPpJWneU9XWIEzi4jSUVTiS...

N/A N/A THN
HIGH 7.5 MS:CVE-2026-3039

BIND 9 server memory exhaustion during GSS-API TKEY negotiation_MS:CVE-2026-3039

{“lastseen”:”2026-05-23T07:16:22″,”description”:””,”published”:”2026-05-23T08:01:...

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-5946

Invalid handling of CLASS != IN_MS:CVE-2026-5946

{“lastseen”:”2026-05-23T07:16:22″,”description”:””,”published”:”2026-05-23T08:01:...

N/A N/A MSCVE
CRITICAL 9.8 MS:CVE-2026-3593

Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation_MS:CVE-2026-3593

{“lastseen”:”2026-05-23T07:16:22″,”description”:””,”published”:”2026-05-23T08:01:...

N/A N/A MSCVE
MEDIUM 5.3 MS:CVE-2026-5950

Unbounded resend loop in BIND 9 resolver_MS:CVE-2026-5950

{“lastseen”:”2026-05-23T07:16:22″,”description”:””,”published”:”2026-05-23T08:01:...

N/A N/A MSCVE
HIGH 7.5 MS:CVE-2026-5947

SIG(0) validation during query flood may lead to undefined behavior_MS:CVE-2026-5947

{“lastseen”:”2026-05-23T07:16:22″,”description”:””,”published”:”2026-05-23T08:01:...

N/A N/A MSCVE
NONE TRENDMICROBLOG:...

Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware_TRENDMICROBLOG:FE3D9CADB53C53E2D8C590C90EE9B230

Void Dokkaebi, a North Korea-aligned intrusion set, has updated its information-stealing malware, InvisibleFerret, shifting its delivery format to ...

N/A N/A TRENDMICROBLOG
NONE SCHNEIER:9C4AB9...

Friday Squid Blogging: Regulating Squid Fishing in the South Pacific_SCHNEIER:9C4AB9C86E9BE62671E4466A4E88CB49

The South Pacific Regional Fisheries Management Organization (SPRFMO) needs to regulate squid fishing in the South Pacific. As usual, you can also...

N/A N/A SCHNEIER
NONE HACKREAD:45C003...

FBI Warns of Kali365 Phishing Service Targeting Microsoft 365 Account_HACKREAD:45C003C5A59860BFA699BD566E6C693E

FBI warns of Kali365, a PaaS scam kit that lets cybercriminals bypass MFA and hijack Microsoft 365 accounts without passwords.

N/A N/A HACKREAD
NONE MSSECURE:6FAAED...

Microsoft Security success stories: How St. Luke’s and ManpowerGroup are securing AI foundations_MSSECURE:6FAAED0D112EA09294B2837050982CB0

AI is reshaping how work gets done—and how risks emerge across cloud, data, identity, and more. Many organizations want AI-powered productivity, bu...

N/A N/A MSSECURE