CVE-2026-73653:Vitest Browser Mode 权限绕过漏洞原理与代码分析
`CVE-2026-73653` 的核心不是单个路径遍历点,而是 Vitest Browser Mode 里多条 `browser -> RPC -> provider -> filesystem` 链路同时缺失统一的权限检查。
The Republican lawmaker called OpenAI’s leadership decisions “reckless,” and used recent warnings about the existential risk of AI to bolster his inquiry.
The post Hawley probes OpenAI over Hugging Face breach appeared first on CyberScoop.
The report details a Russian-aligned espionage campaign against more than 20 organizations, an exploit foundry run by Chinese undergraduates and ShinyHunters-affiliated breaches, among other disrupted operations.
The post AI lets small actors run state-level hacking campaigns, Anthropic report finds appeared first on CyberScoop.