Yazoul - Cybersecurity Alerts

22 Followers
25 Following
732 Posts

๐Ÿ” Yazoul Security โ€” CVE Advisories ยท Data Breaches ยท Cyber News

Automated security intelligence: daily CVE alerts, breach reports, correlated news, and learning resources.

๐ŸŒ www.yazoul.net
๐Ÿ“จ Newsletter: www.yazoul.net/
๐Ÿ”— @[email protected]

#InfoSec #Cybersecurity #CVE #ThreatIntel #DataBreach

๐Ÿšจ New security advisory:

CVE-2026-33557 affects multiple systems.

โ€ข Impact: Remote code execution or complete system compromise possible
โ€ข Risk: Attackers can gain full control of affected systems
โ€ข Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-33557-kafka-oauth-jwt-bypass-grants-unauth-access

#Cybersecurity #SecurityPatching #HackerNews

Kafka OAuth JWT bypass grants unauth access (CVE-2026-33557)

CVE-2026-33557: Apache Kafka 4.1.0-4.1.1 OAuth JWT validation flaw allows unauthenticated access (CVSS 9.1). Update to 4.1.2/4.2.0 or manually set the `sasl.oauthbearer.jwt.validator.class` config.

Yazoul Security

๐ŸŸ  New security advisory:

CVE-2026-5807 affects multiple systems.

โ€ข Impact: Significant security breach potential
โ€ข Risk: Unauthorized access or data exposure
โ€ข Mitigation: Apply patches within 24-48 hours

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-5807-vault-unauth-denial-of-service-blocks-admin

#Cybersecurity #ZeroDay #ThreatIntel

Vault unauth denial-of-service blocks admin (CVE-2026-5807)

CVE-2026-5807: Unauthenticated attackers can cause a denial-of-service in HashiCorp Vault by blocking root token generation and rekey operations (CVSS 7.5). Update to Vault Community or Enterprise 2.0.0.

Yazoul Security

๐Ÿ›ก THREAT INTEL | McCuaig and associates Engineering

๐ŸŸ  Actor "coinbasecartel" claims Undisclosed

โš ๏ธ Unverified claim

https://www.yazoul.net/intel/claim/2026-04-19-mccuaig-and-associates-hit-by-coinbasecartel-ransomware-apr-2026

#DarkWeb #DataBreach #ThreatIntel #CyberSecurity #InfoSec

McCuaig and Associates Hit by CoinbaseCartel Ransomware (Apr 2026)

The CoinbaseCartel ransomware group claims an attack on engineering firm McCuaig and Associates. The unverified post alleges data theft. Learn the potential impact.

Yazoul Security

๐ŸŸ  New security advisory:

CVE-2025-40899 affects multiple systems.

โ€ข Impact: Significant security breach potential
โ€ข Risk: Unauthorized access or data exposure
โ€ข Mitigation: Apply patches within 24-48 hours

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2025-40899-assets-and-nodes-stored-xss-in-admin-panel

#InfoSec #VulnerabilityManagement #CyberSec

Assets and Nodes stored XSS in admin panel (CVE-2025-40899)

CVE-2025-40899: A high-severity stored XSS vulnerability (CVSS 8.9) in the Assets and Nodes panel lets attackers hijack admin sessions. Patch now to prevent data modification and unauthorized access.

Yazoul Security

๐Ÿ”ถ DATA BREACH ALERT

Amtrak - 2.1M accounts exposed

Compromised data:
Email Addresses, Names, Physical Addresses

Check if you're affected and what to do:
https://www.yazoul.net/breaches/breach/amtrak-breach-2-1m-emails-names-addresses-exposed-2026

#DataPrivacy #IdentityTheft #Cybersecurity

Amtrak Breach: 2.1M Emails, Names & Addresses Exposed (2026)

In April 2026, the hacking group ShinyHunters claimed they had breached Amtrak . The group typically compromises organisations' Salesforce instances before demanding a ransom and later, if not paid, dumping the data publicly. They subsequently published the alleged data which contained over 2M uniqu...

Yazoul Security

๐Ÿ”ด New security advisory:

CVE-2026-27245 affects multiple systems.

โ€ข Impact: Remote code execution or complete system compromise possible
โ€ข Risk: Attackers can gain full control of affected systems
โ€ข Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-27245-adobe-connect-reflected-xss-unauthenticated

#Cybersecurity #PatchNow #InfoSecCommunity

Adobe Connect reflected XSS, unauthenticated (CVE-2026-27245)

CVE-2026-27245: Adobe Connect 2025.3/12.10 and earlier affected by a critical reflected XSS vulnerability (CVSS 9.3). Update to the latest version to prevent attackers from executing scripts in user browsers.

Yazoul Security

๐Ÿ›ก THREAT INTEL | Gastroenterology & Hepatology of CNY

๐Ÿ”ด Actor "exitium" claims Undisclosed

Allegedly exposed (+4 more)
โ€ข Email addresses
โ€ข Phone numbers
โ€ข Physical addresses

โš ๏ธ Unverified claim

https://www.yazoul.net/intel/claim/2026-04-15-gastroenterology-hepatology-of-cny-hit-by-exitium-apr-2026

#DarkWeb #DataBreach #ThreatIntel #CyberSecurity #InfoSec

Gastroenterology & Hepatology of CNY Hit by Exitium (Apr 2026)

Exitium ransomware group claims attack on NY healthcare provider, alleging theft of data for 167k+ patients including SSNs and sensitive diagnoses. Unverified claim.

Yazoul Security

๐Ÿง  Formbook Daily Report

โฌ†๏ธ Trend: rising (229%)
๐Ÿ“Š 24 new samples
๐ŸŒ 55 C2 servers

Full analysis, IOCs, and hashes:
https://www.yazoul.net/malware/formbook/reports/2026-04-15

#CyberSecurity #MalwareAnalysis #SOC

Formbook Malware: 24 Samples, Rising Trend (Apr 2026)

24 new Formbook samples detected โ€” Rising trend (229%). IOCs, hashes, C2 servers, and detection rates. View full report.

Yazoul Security

๐Ÿ”ด New security advisory:

CVE-2026-40288 affects multiple systems.

โ€ข Impact: Remote code execution or complete system compromise possible
โ€ข Risk: Attackers can gain full control of affected systems
โ€ข Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-40288-praisonai-workflow-engine-unauthenticated-rce

#InfoSec #SecurityPatching #HackerNews

PraisonAI workflow engine unauthenticated RCE (CVE-2026-40288)

CVE-2026-40288: PraisonAI workflow engine allows arbitrary command and code execution via malicious YAML files (CVSS 9.8). Update to PraisonAI 4.5.139 or praisonaiagents 1.5.140.

Yazoul Security

๐Ÿ”ด New security advisory:

CVE-2026-27681 affects multiple systems.

โ€ข Impact: Remote code execution or complete system compromise possible
โ€ข Risk: Attackers can gain full control of affected systems
โ€ข Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-27681-sap-bpc-bw-sql-injection-unauth-data-access

#InfoSec #SecurityPatching #HackerNews

SAP BPC/BW SQL injection, unauth data access (CVE-2026-27681)

CVE-2026-27681: SAP Business Planning and Consolidation and SAP Business Warehouse SQL injection flaw (CVSS 9.9). An authenticated attacker can read, modify, or delete all database data. Apply SAP Security Note 3421055.

Yazoul Security