Aggregator
Phishing Campaign Abuses eCards to Deploy RMM Tools
HPE security advisory (AV26-700)
CVE-2025-68777 | Linux Kernel up to 6.19-rc1 ti_am335x_tsc off-by-one (Nessus ID 298404 / WID-SEC-2026-0086)
CVE-2025-68775 | Linux Kernel up to 6.6.119/6.12.63/6.18.2/6.19-rc1 remove_pending reference count (Nessus ID 283670 / WID-SEC-2026-0086)
CVE-2025-68774 | Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 hfs_bnode_get reference count (Nessus ID 283662 / WID-SEC-2026-0086)
美国众议院通过了永久性夏令时法案
CVE-2026-48618 | Node.js up to 22.22.3/24.16.0/26.3.0 unicode encoding (Nessus ID 323047)
CVE-2026-48933 | Node.js up to 22.22.3/24.16.0/26.3.0 subtle.encrypt integer overflow (Nessus ID 323047)
Critical Cursor 0-Day Flaw Allows Malicious Git Repos to Trigger Automatic Windows Code Execution
A critical unpatched vulnerability in Cursor, the popular AI-powered code editor used by over 7 million developers, allows attackers to achieve arbitrary code execution on Windows systems. Simply opening a malicious repository is sufficient to trigger this execution path, requiring no user clicks, prompt confirmations, or authorization approvals. The flaw was discovered by security firm […]
The post Critical Cursor 0-Day Flaw Allows Malicious Git Repos to Trigger Automatic Windows Code Execution appeared first on Cyber Security News.
CVE-2026-48619 | Node.js up to 22.22.3/24.16.0/26.3.0 resource consumption (Nessus ID 323047)
CVE-2026-48934 | Node.js up to 22.22.3/24.16.0/26.3.0 information disclosure (Nessus ID 323047)
CVE-2026-48935 | Node.js up to 22.22.3/24.16.0/26.3.0 default permission (Nessus ID 323047)
CVE-2026-48930 | Node.js up to 22.22.3/24.16.0/26.3.0 access control (Nessus ID 323047)
CVE-2026-48928 | Node.js up to 22.22.3/24.16.0/26.3.0 access control (Nessus ID 323047)
CVE-2026-48615 | Node.js up to 22.22.3/24.16.0/26.3.0 Error Message private personal information (Nessus ID 323047)
100 дней против неизвестного вируса. Как человечество готовится к пандемии, которой ещё нет
Insignary Launches Clarity On-Demand: SBOMs, No Annual Commitment Required
Toronto, Canada, July 15th, 2026, CyberNewswire Enterprise-grade binary software verification for one project, one team, or one compliance deadline — without an annual commitment. According to Insignary Inc., a leader in software supply chain security and binary software composition analysis (SCA), most organizations cannot independently verify what is actually inside the software they deploy because […]
The post Insignary Launches Clarity On-Demand: SBOMs, No Annual Commitment Required appeared first on Cyber Security News.
Hacker Used Gemini CLI to Build a Live C&C Botnet in 6 Minutes
A Russian-speaking threat actor known as “bandcampro” has weaponized Google’s Gemini CLI AI agent to migrate, deploy, and operate a live command-and-control (C&C) botnet. Remarkably, the attacker completed the entire infrastructure migration in just six minutes, contributing only 11% of the total work himself while the AI performed the rest. TrendAI™ Research published these findings […]
The post Hacker Used Gemini CLI to Build a Live C&C Botnet in 6 Minutes appeared first on Cyber Security News.