Aggregator
CVE-2026-33929 | Apache PDFBox Examples up to 2.0.36/3.0.7 ExtractEmbeddedFiles path traversal (WID-SEC-2026-1687)
CVE-2026-34785 | Rack up to 2.2.22/3.1.20/3.2.5 Request Path /css Rack::Static partial string comparison (GHSA-h2jq-g4cq-5ppq / Nessus ID 305959)
CVE-2026-34230 | Rack up to 2.2.22/3.1.20/3.2.5 Rack::Utils resource consumption (GHSA-v569-hp3g-36wr / Nessus ID 304839)
CVE-2026-34763 | Rack up to 2.2.22/3.1.20/3.2.5 Regular Expression Rack::Directory permissive regular expression (GHSA-7mqq-6cf9-v2qp / Nessus ID 304833)
CVE-2026-33195 | rails activestorage prior 7.2.3.1/8.0.4.1/8.1.2.1 DiskService#path_for path traversal (GHSA-9xrj-h377-fr87 / WID-SEC-2026-1687)
CVE-2026-33202 | rails activestorage prior 7.2.3.1/8.0.4.1/8.1.2.1 DiskService#delete_prefixed injection (GHSA-73f9-jhhh-hr5m / WID-SEC-2026-1687)
信息安全漏洞周报(2026年第21期)
CVE-2026-33176 | rails activesupport prior 7.2.3.1/8.0.4.1/8.1.2.1 resource consumption (GHSA-2j26-frm8-cmj9 / Nessus ID 313174)
CVE-2026-33173 | rails activestorage prior 7.2.3.1/8.0.4.1/8.1.2.1 DirectUploadsController intent by broadcast receiver (GHSA-qcfx-2mfw-w4cg / WID-SEC-2026-1687)
CVE-2026-33174 | rails activestorage up to 7.2.3.1/8.0.4.1/8.1.2.1 memory allocation (GHSA-r46p-8f7g-vvvg / WID-SEC-2026-1687)
CVE-2026-33170 | rails activesupport prior 7.2.3.1/8.0.4.1/8.1.2.1 html_unsafe cross site scripting (GHSA-89vf-4333-qx8v / WID-SEC-2026-1687)
CVE-2026-26961 | Rack up to 2.2.22/3.1.20/3.2.5 Content-Type Header Rack::Multipart interpretation conflict (GHSA-vgpv-f759-9wx3 / Nessus ID 307009)
CVE-2026-33169 | rails activesupport prior 7.2.3.1/8.0.4.1/8.1.2.1 Regular Expression resource consumption (GHSA-cg4j-q9v8-6v38 / WID-SEC-2026-1687)
CVE-2026-33168 | rails actionview prior 7.2.3.1/8.0.4.1/8.1.2.1 Attribute cross site scripting (GHSA-v55j-83pf-r9cq / WID-SEC-2026-1687)
日本太空企业AstroX计划从气球上发射火箭
IEEE Transactions 主编亲授:如何撰写高水平论文
奇安信代码安全实验室研究成果入选国际顶会IEEE SP 2026
Algorithmic Infiltration: Unveiling the SolarWinds Penetration of the United States Treasury
The Magnitude of the Compromise The adversaries behind the notorious SolarWinds breach intercepted official correspondence within the United States Department of the Treasury. Recently disclosed records indicate that the architectural subversion was far more...
The post Algorithmic Infiltration: Unveiling the SolarWinds Penetration of the United States Treasury appeared first on Information Security News.
The Neutralization of Glassworm: A Coordinated Inversion of Multi-Tiered Supply Chain Infrastructure
CrowdStrike recently announced the successful disruption of the notorious Glassworm botnet. This malicious apparatus systematically targeted software developers globally. To achieve this, operators weaponized code editor extensions, npm registries, Python packages, and compromised GitHub...
The post The Neutralization of Glassworm: A Coordinated Inversion of Multi-Tiered Supply Chain Infrastructure appeared first on Information Security News.