Aggregator
Please support the site operations by clicking ads.
Your Critical Vulnerabilities Might Not Be Your Biggest Risk
cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw
A recently disclosed vulnerability in ConfigServer Security & Firewall (CSF) could allow unauthenticated remote attackers to execute arbitrary commands through the product’s MESSENGER service. This vulnerability, tracked as CVE-2026-65638, affects CSF versions 14.00 through 16.29 and has been addressed in version 16.30 and later. CSF is widely used on Linux servers and in cPanel/WHM environments […]
The post cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
GitLab urges users to patch max severity path traversal flaw
【安全圈】JFrog制品库曝组合漏洞:免密换取Admin凭据篡改依赖
【安全圈】思科防火墙FMC曝满分漏洞:免密直取Root遭勒索攻陷
【安全圈】你天天打字的搜狗输入法,点个链接电脑就归黑客了
Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners
Threat actors are adapting malware not only for conventional endpoint defenses and sandboxes, but also for large language model-powered tools increasingly used to triage suspicious code. ESET researchers linked the activity to Russia-aligned threat actor UAC-0099, which used the method during an attack against an organization in Ukraine. The group inserted a safety-sensitive, weapon-related request […]
The post Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
评论 | 当AI“善解人意”,请多一分清醒
蚂蚁大安全CTO陈亮:安全可信是AI规模化应用的前提
关注 | 新一批“银狐”木马相关恶意域名及恶意IP公布!
CNNVD | 关于微软多个安全漏洞的通报
CNNVD | 关于Palo Alto Networks PAN-OS缓冲区错误漏洞的通报
专题·原创 | 人工智能赋能的安全漏洞研究与防治
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code
GitLab has issued an emergency security update to address two critical vulnerabilities that could lead to unauthenticated file disclosure and authenticated credential theft, as well as a high-severity flaw that may enable remote code execution. The company released updated versions of GitLab Community Edition and Enterprise Edition, specifically versions 19.3.2, 19.2.6, and 19.1.8, on September […]
The post Critical GitLab Flaws Let Attackers Read Arbitrary Files, Steal Credentials and Execute Code appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
近八成中招设备防护缺位,360发布8月勒索软件态势报告
倒计时3天|以AI对抗AI!360亮相2026国家网络安全宣传周
AI agents exploited PaperCut flaws to breach 395 organizations
A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the work on their own, according to GreyNoise. The result was at least 440 compromised PaperCut instances across 395 identified organizations in 48 countries. Attacker, believed to be Russian-speaking, first built a private lab environment with a vulnerable copy of PaperCut NG/MF and an Active Directory … More →
The post AI agents exploited PaperCut flaws to breach 395 organizations appeared first on Help Net Security.
Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access
Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to bypass authentication, escalate privileges, and gain administrative control of exposed instances. Wiz Research reports that multiple attackers are targeting self-hosted Artifactory deployments in the wild, using both a two-bug token escalation chain and a separate critical authentication-bypass flaw. A successful […]
The post Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.