Aggregator
BeyondTrust security advisory (AV26-660)
US Army websites defaced with pro-Kurdish sentiments, insults to Trump
At least two websites appear to be victim to 404 hijacking attacks. Army officials took the sites down after being contacted by CyberScoop.
The post US Army websites defaced with pro-Kurdish sentiments, insults to Trump appeared first on CyberScoop.
16-Year-Old Linux KVM Flaw Lets Guest VMs Escape to Host on Intel and AMD x86 Systems
A Long-Lived KVM Bug Resurfaces: Shadow Paging Use-After-Free in the Linux Kernel (CVE-2026-53359)
Учёные проверили мРНК-вакцины «от и до» — и развеяли главный миф о них
Microsoft Device Code Phishing Attack Steals Tokens Through Legitimate Login Page
A new phishing technique is tricking users into handing over their Microsoft account tokens without a fake website in sight. Attackers are exploiting a legitimate Microsoft authentication feature to steal access to email, files, and chat messages. The method works well because victims never leave the real Microsoft login page during the attack. The technique […]
The post Microsoft Device Code Phishing Attack Steals Tokens Through Legitimate Login Page appeared first on Cyber Security News.
Airbus набрал заказов на 10 лет вперёд, но производство буксует. Спасать ситуацию будут композитом с секретным составом
Japanese teen arrested over cyberattack that disrupted anime streaming service
Gemini Live Voice Session Flaw Enables Tool Injection Through Misconfigured Ephemeral Tokens
A security flaw in how developers implement Google’s Gemini Live API allows attackers to hijack browser-based AI voice sessions, override system prompts, and trigger unauthorized code execution all through a token misconfiguration that traces back to Google’s own reference implementation. Security Researcher Alvin Ferdiansyah observed that Gemini Live API powers real-time voice assistants through persistent […]
The post Gemini Live Voice Session Flaw Enables Tool Injection Through Misconfigured Ephemeral Tokens appeared first on Cyber Security News.
JadePuffer: The First Complete LLM-Driven Ransomware Attack
ИИ смог то, что не смог другой ИИ: как Claude Fable 5 портировал Generals Zero Hour на iPad
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
Morpheus
You must login to view this content
Хоббиты с Флореса оказались не теми, кем казались. Новый анализ костей лишил их главного титула — бесстрашных охотников
New Iran-Nexus Hacking Group Targets Israel Government and IT Sectors
SecWiki News 2026-07-06 Review
更多最新文章,请访问SecWiki
物理隔离也能传数据?揭秘苹果Find My网络的隐蔽数据通道
The Gentlemen Ransomware Uses 21 Remote Execution Techniques to Encrypt Entire Networks
A new ransomware strain called The Gentlemen has emerged as one of the more aggressive threats tracked this year, combining strong encryption with a self-spreading worm engine that can take down an entire corporate network from a single infected machine. Written in the Go programming language and disguised using a tool called Garble, the malware […]
The post The Gentlemen Ransomware Uses 21 Remote Execution Techniques to Encrypt Entire Networks appeared first on Cyber Security News.