A vulnerability described as critical has been identified in css_parser 1.22.0/2.0/2.1.0 on Ruby. The affected element is the function CssParser::Parser#read_remote_file. Such manipulation leads to server-side request forgery.
This vulnerability is listed as CVE-2026-53727. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability marked as problematic has been reported in enchant97 note-mark. Impacted is an unknown function of the component Backend. This manipulation causes information disclosure.
This vulnerability is tracked as CVE-2026-50554. The attack is possible to be carried out remotely. No exploit exists.
Applying a patch is the recommended action to fix this issue.
A vulnerability labeled as critical has been found in enchant97 note-mark. This issue affects some unknown processing of the component Backend. The manipulation results in path traversal.
This vulnerability is identified as CVE-2026-50553. The attack can be executed remotely. There is not any exploit available.
It is advisable to implement a patch to correct this issue.
A vulnerability identified as critical has been detected in pyLoad. This vulnerability affects unknown code of the component IPv6 NAT Handler. The manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-48737. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability categorized as critical has been discovered in keeva decompress up to 4.2.1. This affects an unknown part. Executing a manipulation can lead to path traversal.
The identification of this vulnerability is CVE-2026-39245. The attack needs to be done within the local network. There is no exploit available.
It is advisable to upgrade the affected component.
AI 检测平台 Pangram 的研究显示,LinkedIn 和 X 等平台上四分之一的长文完全是 AI 撰写的。Pangram 对长文定义是包含至少 250 个字符,对 LinkedIn、Medium、Substack、X 和 Reddit 等平台帖子的分析显示,长文受 AI slop 影响最大,这些平台四分之一长文完全是 AI 生成,这里的“完全”并不包含用 AI 润色文字。研究显示,LinkedIn 的长文 AI 生成比例最高,达到了 41%,该平台包含 50-250 字的帖子 AI 生成比例也高达 30%。LinkedIn 上 55.2% 的长文是人类撰写的,4.3% 是在 AI 帮助下撰写的。X 上四分之一的推文完全由 AI 撰写,23.2% 的推文是在 AI 辅助下完成的,52.7% 的推文则是由人类撰写。Medium 上约三分之一的文章是 AI 撰写或 AI 辅助撰写,Substack 上有 21.9% 的文章是 AI 撰写或 AI 辅助撰写。Reddit 上 11.6% 的帖子是 AI 撰写或 AI 辅助撰写,98.1% 的评论是人类撰写的。
Microsoft uncovered GigaWiper, a modular Go backdoor combining three malware families with espionage, remote control, and destructive wiping features. In October 2025, Microsoft’s threat intelligence team identified destructive wiping activity inside compromised environments and traced it to a previously unknown piece of malware they’re now calling GigaWiper. The malicious code is written in Go, it […]
A vulnerability was found in Apache IoTDB C++ client up to 1.3.7/2.0.9. It has been rated as critical. Affected by this issue is some unknown functionality of the component TsBlock Deserializer. Performing a manipulation results in out-of-bounds read.
This vulnerability was named CVE-2026-40454. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Apache IoTDB up to 1.3.7/2.0.9. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /rest/v2/fastLastQuery of the component FastLastQuery Handler. Such manipulation leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2026-40452. The attack can be launched remotely. No exploit exists.
A vulnerability was found in Apache IoTDB up to 2.0.9. It has been classified as problematic. Affected is an unknown function of the component Privilege Management. This manipulation causes improper access controls.
This vulnerability is handled as CVE-2026-40009. The attack can be initiated remotely. There is not any exploit available.
A former employee of cybersecurity incident response company DigitalMint was sentenced to 70 months in prison for targeting U.S. companies in BlackCat (ALPHV) ransomware attacks. [...]
A vulnerability was found in Apache IoTDB up to 2.0.9 and classified as critical. This impacts the function Class.forName of the component Pipe Processor. The manipulation results in use of externally-controlled input to select classes or code.
This vulnerability is known as CVE-2026-40008. It is possible to launch the attack remotely. No exploit is available.