A vulnerability was found in RabbitMQ up to 4.2.5. It has been classified as problematic. This affects an unknown function of the component Stream Listener. The manipulation leads to resource consumption.
This vulnerability is uniquely identified as CVE-2026-57220. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability was found in RabbitMQ up to 3.13.14/4.0.19/4.1.10/4.2.5. It has been declared as problematic. This impacts an unknown function of the component Authentication Handler. The manipulation results in infinite loop.
This vulnerability was named CVE-2026-57216. The attack may be performed from remote. There is no available exploit.
A vulnerability labeled as problematic has been found in Samsung Open Source rlottie. This issue affects some unknown processing of the file src/lottie_parser.cpp of the component Lottie Renderer. The manipulation results in integer overflow.
This vulnerability was named CVE-2026-15551. The attack needs to be approached locally. There is no available exploit.
New macOS infostealer CrashStealer uses a signed app to bypass Gatekeeper, steals credentials and wallets, then AES-encrypts stolen data. Jamf Threat Labs first spotted CrashStealer in early May 2026 as a suspicious macOS sample uploaded to VirusTotal. By early July, in-the-wild detections confirmed the malware had moved from development into active deployment. The malware is […]
欧盟考虑限制青少年使用社交媒体,包括年龄限制、分阶段开放访问以及彻底禁止。社交媒体平台可能还需在青少年获准使用其服务前,证明自身服务无害。欧洲委员会主席 Ursula von der Leyen 表示,在审查了专家小组建议后,欧盟委员会可能会在数月内提出新立法提案。专家小组建议采用分阶段的方法,包括 3 岁以下儿童“完全不接触屏幕”、13 岁以下儿童需在监督下使用互联网,以及对年龄更大的青少年设置一些限制。专家小组还表示,社交媒体平台应证明其服务对年轻用户是安全的,von der Leye 表示她支持这一做法。欧盟委员会将研究这份报告,在“夏季之后”提出相关提案。任何立法需获得欧洲议会及欧盟 27 个成员国的批准,才能在整个欧盟范围内生效。
A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog.
The packages did not go after the developers who might install them. The operators used the registry as free hosting for a booby-trapped proxy site and let the students who came to dodge
A vulnerability labeled as critical has been found in D-link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is an unknown functionality of the file /etc/boa/boa.conf of the component Web Interface. Executing a manipulation can lead to least privilege violation.
This vulnerability is tracked as CVE-2026-15270. The attack can be launched remotely. Moreover, an exploit is present.