Aggregator
CVE-2012-10024 | XBMC Media Center up to 11.0 path traversal (EUVD-2012-6581)
CVE-2012-10032 | Maxthon International Maxthon3 Browser up to 3.2 cross site scripting (EUVD-2012-6576 / EDB-23225)
CVE-2012-10047 | Cyclope-Series Cyclope Employee Surveillance Solution 6.x Username sql injection (EUVD-2012-6589 / EDB-20393)
CVE-2012-10060 | Sysax Multi Server up to 5.54 SSH Service stack-based overflow (EUVD-2012-6601 / EDB-18535)
CVE-2011-10023 | MJM QuickPlayer 2010 stack-based overflow
CVE-2010-20042 | Xion Audio Player up to 1.0.126 stack-based overflow
CVE-2025-34163 | Qingdao Dongsheng Weiye Dongsheng Logistics Software up to 2025 POST Request UploadMailFile unrestricted upload
CVE-2025-34162 | Feijiu Medical Bian Que Feijiu Intelligent Emergency and Quality Control System WebServiceForFirstaidApp.asmx sql injection
CVE-2025-34523 | Arcserve Unified Data Protection up to 10.1 heap-based overflow (EUVD-2025-26166)
CVE-2025-34186 | Ilevia EVE X1 Server/EVE X5 Server up to 4.7.18.0.eden system improper authentication (EUVD-2025-29645)
CVE-2022-27224 | Galleon NTS-6002 Web-Management Interface ping_address/trace_address/nslookup_address os command injection
[Control systems] ABB security advisory (AV26-510)
Агрессор — твой друг: 60% жертв цифрового насилия знают обидчика лично
Anthropic: Claude Mythos identified 10,000+ software flaws
Anthropic and its Project Glasswing partners have identified more than 10,000 high- or critical-severity vulnerabilities in critical software systems, the company announced in an update on the project’s progress. Mythos identifies thousands of high-severity vulnerabilities In April 2026, Anthropic introduced Claude Mythos Preview, a new large language model that can autonomously find zero-day vulnerabilities and create exploits for them. The company also launched Project Glasswing and gave Amazon Web Services, Apple, Broadcom, Cisco, CrowdStrike, Google, … More →
The post Anthropic: Claude Mythos identified 10,000+ software flaws appeared first on Help Net Security.
CVE-2026-8376 | Perl up to 5.43.10 on 32-bit regcomp_study.c Perl_study_chunk integer overflow (EUVD-2026-31772 / Nessus ID 316506)
CVE-2026-46597 | x-crypto up to 0.51.x integer underflow (Nessus ID 316556 / WID-SEC-2026-1653)
CVE-2026-8997 | vifm up to 0.14.3 vifminfo.json heap-based overflow (EUVD-2026-31439 / Nessus ID 316555)
Lithuania investigates theft of 600,000 state registry records by foreign actor
Chinese phishing gangs grow into a force to be reckoned with
Chinese-language phishing-as-a-service (PhaaS) communities are expanding in an area historically dominated by Russian-speaking cybercriminal groups. The Google Threat Intelligence Group (GTIG) analyzed a dozen active PhaaS offerings operating in Chinese-language underground communities and found mature services, with several likely linked to broader criminal activity in the region. Nearly all legitimate organizations mimicked by these phishing services were non-Chinese entities, suggesting that activity rarely targets China itself. Researchers noted that Telegram serves as a common channel … More →
The post Chinese phishing gangs grow into a force to be reckoned with appeared first on Help Net Security.