Perl is a tool tracked across 12 threat clusters and 14 intelligence report mentions on ThreatCluster. First observed February 4, 2026; most recent activity July 23, 2026.
A security vulnerability has been identified in the HTTP-Daemon affecting various Ubuntu versions, including 26.04 LTS and earlier releases down to 14.04 LTS. The flaw allows remote attackers to execute arbitrary…
Mageia has released updates for several Perl packages to address critical security vulnerabilities. Notable issues include CVE-2026-14803, which allows memory exhaustion in Mojo::JSON versions before 9.47, and…
A critical vulnerability has been identified in Starman versions prior to 0.4018, allowing HTTP Request Smuggling due to improper header precedence. The issue arises when both 'Content-Length' and 'Transfer-Encoding:…
A critical vulnerability has been identified in the HTML-Parser library used in various Ubuntu versions. The flaw arises from improper handling of entity references, allowing attackers to potentially access sensitive…
Multiple vulnerabilities affecting Oracle Coherence and Oracle Access Manager have been disclosed. CVE-2026-60248 and CVE-2026-60295 are critical vulnerabilities in Oracle Coherence, allowing attackers to potentially…
Fedora versions 42 and 43 are affected by high-severity vulnerabilities in the perl-YAML-Syck module, specifically versions up to and including 1.36. These vulnerabilities include a heap buffer overflow in the YAML…
Fedora has released updates for perl-Apache-Session to address CVE-2026-8503, which involves predictable session IDs that can lead to unauthorized system access. The vulnerability stems from the use of a low-entropy…
Bug bounty programs are experiencing significant changes due to the rise of AI-assisted research and the emergence of validated vulnerabilities at machine speed. These trends have led to an influx of low-signal…
The ShadowHS malware framework has been identified as a significant threat to Linux environments, utilizing a fileless architecture for stealthy operations. Discovered by Cyble Research & Intelligence Labs on January…
A new Linux variant of the SystemBC remote access trojan has infected over 10,000 IP addresses worldwide, primarily targeting web servers. Discovered by Silent Push, the compromised servers include those hosting…