Aggregator
CVE-2026-0522 | VertiGIS FM up to 10.11.362 external reference
CVE-2026-35092 | Corosync UDP Packet integer overflow
CVE-2026-35091 | Corosync UDP Packet function return value
CVE-2026-5328 | shsuishang modulithshop up to 829bac71f507e84684c782b9b062b8bf3b5585d6 ProductItemDao Interface ProductIndexServiceImpl.java listItem sidx/sort sql injection
SandboxJS 连环沙箱逃逸漏洞深度解析(CVE-2026-26954)
New Venom Stealer MaaS Platform Automates Continuous Data Theft
Submit #780789: Shopsuite modulithshop 829bac71f507e84684c782b9b062b8bf3b5585d6 SQL Injection [Accepted]
Submit #780776: efforthye fast-filesystem-mcp <= 3.5.1 Command Injection [Accepted]
Exabeam expands ABA to detect AI agent threats across ChatGPT, Copilot, and Gemini
Exabeam has announced the expansion of Exabeam Agent Behavior Analytics (ABA). Without direct visibility into how employees use AI assistants, what they query, what data they share, how frequently they interact, and from where, organizations cannot establish a baseline for normal AI behavior, investigate potential misuse, or detect emerging agentic insider threats. New support to detect agent behavior in OpenAI ChatGPT and Microsoft Copilot, alongside existing visibility into Google Gemini, transforms these agentic services into … More →
The post Exabeam expands ABA to detect AI agent threats across ChatGPT, Copilot, and Gemini appeared first on Help Net Security.
Submit #780773: SourceCodester Leave Application System in PHP and SQLite3 1.0 Improper Authorization [Accepted]
Submit #780766: SourceCodester Simple Customer Relationship Management (CRM) System 1.0 Cross Site Scripting [Accepted]
黑心中转站的安全风险---上下文膨胀、模型造假与提示词投毒
Submit #780752: priyankark a11y-mcp 1.0.4 Server-Side Request Forgery [Accepted]
Google Cloud’s Vertex AI platform Vulnerability Allow Attackers to Access Sensitive Data
Artificial intelligence agents are rapidly becoming integral to enterprise workflows, but they also introduce new attack surfaces. Security researchers recently uncovered a significant vulnerability within Google Cloud Platform’s Vertex AI Agent Engine. By exploiting default permission scoping, attackers could weaponize deployed AI agents into “double agents” that secretly exfiltrate data and compromise cloud infrastructure. Exploiting […]
The post Google Cloud’s Vertex AI platform Vulnerability Allow Attackers to Access Sensitive Data appeared first on Cyber Security News.
Submit #780733: Mayuri K. Gaatitrack Courier Management System 1.0 Unrestricted Upload [Duplicate]
Submit #780731: AlejandroArciniegas mcp-data-vis 1.0.0 SQL Injection [Accepted]
Физики целый век считали неправильно. Вселенная расширяется — и фотон внезапно стал тяжелым
Hackers Actively Exploiting Critical WebLogic RCE Vulnerabilities in Attacks
A recent cybersecurity study reveals that threat actors are moving faster than ever to weaponize new software flaws. According to data collected from a high-interaction honeypot, hackers are actively exploiting a newly disclosed, maximum-severity vulnerability in Oracle WebLogic Server. The critical flaw, tracked as CVE-2026-21962, carries a CVSS score of 10.0. It allows unauthenticated attackers […]
The post Hackers Actively Exploiting Critical WebLogic RCE Vulnerabilities in Attacks appeared first on Cyber Security News.