Aggregator
SECUROTROP
1 week 2 days ago
You must login to view this content
cohenido
Знакомьтесь, Cuddle-Fish: парящий робот-кит станет вашим самым ласковым и безопасным домашним призраком
1 week 2 days ago
Он будто вышел из мультиков Миядзаки…
AI used to help plan the break-in, now it’s doing the break-in
1 week 2 days ago
Over the past twelve months, researchers documented intrusions in which AI ran exploitation workflows autonomously, generating thousands of commands across dozens of sessions with minimal human direction, according to Check Point’s AI Security Report 2026. AI-powered cyber attacks The attackers posing the greatest risk are those orchestrating AI across multiple stages of the attack chain without requiring human intervention. They achieve this by obtaining capable AI models and removing their safety controls. Attackers gain AI … More →
The post AI used to help plan the break-in, now it’s doing the break-in appeared first on Help Net Security.
Anamarija Pogorelec
一句假验证码,一条真命令:ClickFix 如何取代钓鱼邮件成为今年最暴利的渗透手段
1 week 2 days ago
传统的钓鱼邮件附件不再是攻击者最爱的敲门砖。取而代之的,是一种几乎不需要任何技术门槛、却能在用户眼皮底下"自愿"执行恶意代码的手法——ClickFix。KnowBe4 最新发布的威胁报告将其列为当前头号恶意软件分发方式。
CVE-2026-47478 | NVIDIA Triton Inference Server up to 26.04 on Linux Expired File expired file descriptor
1 week 2 days ago
A vulnerability was found in NVIDIA Triton Inference Server up to 26.04 on Linux and classified as critical. This affects an unknown part of the component Expired File Handler. The manipulation results in use of expired file descriptor.
This vulnerability is cataloged as CVE-2026-47478. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-48274 | Adobe After Effects out-of-bounds write (apsb26-78)
1 week 2 days ago
A vulnerability has been found in Adobe After Effects and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to out-of-bounds write.
This vulnerability is listed as CVE-2026-48274. The attack must be carried out locally. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-48350 | Adobe Animate path traversal (apsb26-83)
1 week 2 days ago
A vulnerability, which was classified as critical, was found in Adobe Animate. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to path traversal.
This vulnerability is tracked as CVE-2026-48350. The attack is restricted to local execution. No exploit exists.
You should upgrade the affected component.
vuldb.com
Учился пользоваться Nmap — случайно уронил рабочую сеть. История одного любопытного инженера
1 week 2 days ago
Обычный сетевой сканер навредил компании сильнее любой внешней атаки.
CVE-2026-48354 | Adobe Content Credentials Rust SDK integer overflow (apsb26-80)
1 week 2 days ago
A vulnerability, which was classified as problematic, has been found in Adobe Content Credentials Rust SDK, Content Credentials Command-Line Tool and Content Credentials JS SDK. Affected is an unknown function. Performing a manipulation results in integer overflow.
This vulnerability is identified as CVE-2026-48354. The attack is only possible with local access. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
7 月补天战神榜开启!赏金发放,荣誉就位!
1 week 2 days ago
实打实激励!月度冠军现金¥2000!月度亚军现金¥1000!
JVN: HYPER SBI 2のインストーラにおけるDLL読み込みに関する脆弱性
1 week 2 days ago
株式会社SBI証券が提供するHYPER SBI 2のインストーラには、DLL読み込みに関する脆弱性が存在します。
CVE-2026-15029 | ASUS System Control Interface/Business Manager IOCTL null pointer dereference
1 week 2 days ago
A vulnerability classified as problematic was found in ASUS System Control Interface and Business Manager. This impacts an unknown function of the component IOCTL Handler. Such manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2026-15029. The attack can only be performed from a local environment. No exploit is available.
vuldb.com
Prinz Eugen
1 week 2 days ago
You must login to view this content
cohenido
CVE-2026-15030 | ASUS System Control Interface/Business Manager IOCTL out-of-bounds
1 week 2 days ago
A vulnerability classified as problematic has been found in ASUS System Control Interface and Business Manager. This affects an unknown function of the component IOCTL Handler. This manipulation causes out-of-bounds read.
The identification of this vulnerability is CVE-2026-15030. The attack can only be executed locally. There is no exploit available.
vuldb.com
CVE-2026-8920 | ASUS Aura Wallpaper Service up to 2.1.15.0 file path file inclusion
1 week 2 days ago
A vulnerability described as problematic has been identified in ASUS Aura Wallpaper Service up to 2.1.15.0. The impacted element is an unknown function of the component Wallpaper Service. The manipulation of the argument file path results in file inclusion.
This vulnerability was named CVE-2026-8920. The attack needs to be approached locally. There is no available exploit.
vuldb.com
CVE-2026-8919 | ASUS GameSDK up to 1.0.5 Web cross-domain policy
1 week 2 days ago
A vulnerability marked as problematic has been reported in ASUS GameSDK up to 1.0.5. The affected element is an unknown function of the component Web Handler. The manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is uniquely identified as CVE-2026-8919. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-13585 | ASUS System Control Interface/Business Manager Driver allocation of resources
1 week 2 days ago
A vulnerability labeled as problematic has been found in ASUS System Control Interface and Business Manager. Impacted is an unknown function of the component Driver. Executing a manipulation can lead to allocation of resources.
This vulnerability is handled as CVE-2026-13585. It is possible to launch the attack on the local host. There is not any exploit available.
vuldb.com
CVE-2026-13385 | ASUS Router channel accessible
1 week 2 days ago
A vulnerability identified as very critical has been detected in ASUS Router 3.0.0.4_386 series/3.0.0.4_388 series/3.0.0.6_102 series. This issue affects some unknown processing. Performing a manipulation results in channel accessible by non-endpoint.
This vulnerability is known as CVE-2026-13385. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-11851 | ASUS Router Web Management Interface sql injection
1 week 2 days ago
A vulnerability categorized as critical has been discovered in ASUS Router. This vulnerability affects unknown code of the component Web Management Interface. Such manipulation leads to sql injection.
This vulnerability is traded as CVE-2026-11851. The attack may be launched remotely. There is no exploit available.
vuldb.com