[QILIN] - Ransomware Victim: Global Security Concepts - https://www.redpacketsecurity.com/qilin-ransomware-victim-global-security-concepts/
RedPacket Security
[QILIN] - Ransomware Victim: Global Security Concepts - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
CVE Alert: CVE-2026-105386 - onetwothreeneth - HospitalManagementSystem - https://www.redpacketsecurity.com/cve-alert-cve-2026-105386-onetwothreeneth-hospitalmanagementsystem/
RedPacket Security
CVE Alert: CVE-2026-105386 - onetwothreeneth - HospitalManagementSystem - RedPacket Security
A vulnerability was identified in onetwothreeneth HospitalManagementSystem up to 9ef91ed6007314b6473110ed699dff76d158f61d. Affected by this issue is the
CVE Alert: CVE-2026-105387 - girishsaraf - Online-Appointment-Booking-System - https://www.redpacketsecurity.com/cve-alert-cve-2026-105387-girishsaraf-online-appointment-booking-system/
RedPacket Security
CVE Alert: CVE-2026-105387 - girishsaraf - Online-Appointment-Booking-System - RedPacket Security
A security flaw has been discovered in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function
CVE Alert: CVE-2026-105468 - girishsaraf - Online-Appointment-Booking-System - https://www.redpacketsecurity.com/cve-alert-cve-2026-105468-girishsaraf-online-appointment-booking-system/
RedPacket Security
CVE Alert: CVE-2026-105468 - girishsaraf - Online-Appointment-Booking-System - RedPacket Security
A vulnerability was found in girishsaraf Online-Appointment-Booking-System up to f427b4757128ca253d33d0cc4e87bbb9c999a4d5. This affects the function
CVE Alert: CVE-2026-105392 - Lybbn - Django-Vue-Lyadmin - https://www.redpacketsecurity.com/cve-alert-cve-2026-105392-lybbn-django-vue-lyadmin/
RedPacket Security
CVE Alert: CVE-2026-105392 - Lybbn - Django-Vue-Lyadmin - RedPacket Security
**Risk verdict:** Treat this as high priority for internet-facing deployments: unauthenticated remote exploitation is plausible and exploit material is
CVE Alert: CVE-2026-77226 - Camunda - Camunda 7 - https://www.redpacketsecurity.com/cve-alert-cve-2026-77226-camunda-camunda-7/
RedPacket Security
CVE Alert: CVE-2026-77226 - Camunda - Camunda 7 - RedPacket Security
Camunda 7.24.0 before 7.24.15 contains an incorrect authorization vulnerability in the Admin web application's first-run setup endpoint, where SetupResource
Linux Backdoors Target Telecoms and Disguise Traffic as Email - https://www.redpacketsecurity.com/new-stealthy-linux-backdoors-target-telecoms-masquerade-as-email-traffic/
RedPacket Security
Linux Backdoors Target Telecoms and Disguise Traffic as Email - RedPacket Security
In research published October 2, Rapid7 reported a newly observed BPFDoor variant and a BPF Rekoobe build used against South Korean targets. The researchers
UK Schools Cybersecurity: Faster Recovery, but Gaps Remain - https://www.redpacketsecurity.com/more-uk-schools-are-recovering-faster-from-cyber-incidents/
RedPacket Security
UK Schools Cybersecurity: Faster Recovery, but Gaps Remain - RedPacket Security
UK schools are recovering more quickly from cyber incidents, but new government figures show that important cybersecurity gaps remain. While fewer schools
Google Open-Source Bug Bounty Suspended Amid Surge in AI Reports - https://www.redpacketsecurity.com/google-suspends-open-source-bug-bounty-due-to-ai-vulnerability-reports/
RedPacket Security
Google Open-Source Bug Bounty Suspended Amid Surge in AI Reports - RedPacket Security
Google has paused its open-source bug bounty program after a sharp increase in automated vulnerability submissions, most of which the company says are
ClingSTUN Malware Exploits Unpatched IoT Devices to Create Proxy Nodes - https://www.redpacketsecurity.com/clingstun-malware-turns-unpatched-iot-devices-into-proxy-nodes/
RedPacket Security
ClingSTUN Malware Exploits Unpatched IoT Devices to Create Proxy Nodes - RedPacket Security
FortiGuard Labs identified the threat as ClingSTUN and tracked its activity across three campaign periods, each using a different download server. The
Citrix NetScaler Zero-Day: Targeted Attacks Could Disrupt Service - https://www.redpacketsecurity.com/citrix-netscaler-targeted-via-new-zero-day/
RedPacket Security
Citrix NetScaler Zero-Day: Targeted Attacks Could Disrupt Service - RedPacket Security
Citrix has warned customers about targeted attacks exploiting a new zero-day vulnerability in its NetScaler ADC and NetScaler Gateway products. The flaw could
Frontline Education Breach Exposes K-12 School District Staff Data - https://www.redpacketsecurity.com/frontline-education-breach-impacts-k-12-school-district-staff/
RedPacket Security
Frontline Education Breach Exposes K-12 School District Staff Data - RedPacket Security
Frontline Education provides administration software used by thousands of K-12 school districts. Its platform helps school teams manage human resources,
Zero-Day Vulnerabilities Exploited in Attack on Dutch Institute for Vulnerability Disclosure - https://www.redpacketsecurity.com/two-zero-days-exploited-in-attack-on-dutch-institute-for-vulnerability-disclosure/
RedPacket Security
Zero-Day Vulnerabilities Exploited in Attack on Dutch Institute for Vulnerability Disclosure - RedPacket Security
The original article text was not included. Please provide it so I can rewrite the full article while preserving its facts, details, and links.
CVE Alert: CVE-2026-105471 - girishsaraf - Online-Appointment-Booking-System - https://www.redpacketsecurity.com/cve-alert-cve-2026-105471-girishsaraf-online-appointment-booking-system/
CVE Alert: CVE-2026-105469 - girishsaraf - Online-Appointment-Booking-System - https://www.redpacketsecurity.com/cve-alert-cve-2026-105469-girishsaraf-online-appointment-booking-system/
CVE Alert: CVE-2026-105571 - n/a - PickMall Lilishop - https://www.redpacketsecurity.com/cve-alert-cve-2026-105571-n-a-pickmall-lilishop/
RedPacket Security
CVE Alert: CVE-2026-105571 - n/a - PickMall Lilishop - RedPacket Security
A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the
CVE Alert: CVE-2026-105470 - girishsaraf - Online-Appointment-Booking-System - https://www.redpacketsecurity.com/cve-alert-cve-2026-105470-girishsaraf-online-appointment-booking-system/
CVE Alert: CVE-2026-105486 - OSSRS - srs - https://www.redpacketsecurity.com/cve-alert-cve-2026-105486-ossrs-srs/
CVE Alert: CVE-2026-75962 - saadiqbal - Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App - https://www.redpacketsecurity.com/cve-alert-cve-2026-75962-saadiqbal-post-smtp-complete-email-delivery-and-smtp-solution-with-email-logs-alerts-backup-smtp-mobile-app/
RedPacket Security
CVE Alert: CVE-2026-75962 - saadiqbal - Post SMTP – Complete Email Delivery and SMTP Solution with Email Logs, Alerts, Backup SMTP…
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to
CVE Alert: CVE-2026-105835 - planka - planka - https://www.redpacketsecurity.com/cve-alert-cve-2026-105835-planka-planka/
RedPacket Security
CVE Alert: CVE-2026-105835 - planka - planka - RedPacket Security
PLANKA 2.2.0 through 2.2.1 fails to limit incorrect TOTP codes submitted to POST /api/access-tokens/verify-totp, allowing attackers to brute force two-factor
CVE Alert: CVE-2026-105701 - Mauro Cassani - ACPT (Premium) - https://www.redpacketsecurity.com/cve-alert-cve-2026-105701-mauro-cassani-acpt-premium/
RedPacket Security
CVE Alert: CVE-2026-105701 - Mauro Cassani - ACPT (Premium) - RedPacket Security
The ACPT (Premium) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.66 via the render function. This is