Posts of last 24 hours
A vulnerability labeled as critical has been found in RRWO Catalyst View Wkhtmltopdf up to 0.6.0. Impacted is an unknown function. Such manipulation of the argument page_size/orientation/margins leads to os command injection.
This vulnerability is documented as CVE-2026-16766. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/383037
这几天在社交媒体上刷到了几个财务自由主题相关的内容。
https://mp.weixin.qq.com/s?__biz=Mzg5NDY4ODM1MA==&mid=2247486144&idx=1&sn=cdcc0c1d2657594ac0bab57e03c42c46
Vulnerability / Application SecuritySecurity researchers depthfirst published working exploit code
https://buaq.net/go-430843.html
Новый червь в npm крадёт ключи разработчиков и распространяется через ИИ-помощников для написания кода.
https://www.securitylab.ru/news/575268.php
为在情报学领域深入落实国家人才培养战略,激发大学生对开源情报分析的热情,提升学生在数据采集、深度分析及情报应用等方面的综合能力,特举办“第四届全国大学生开源情报数据采集与分析挑战专项”活动。
https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651156703&idx=2&sn=9af36fc6aec4d851db5bcde2d93f84f7
网络国家任务部队(Cyber National Mission Force, CNMF)是美国网络司令部下属的次级统一司令部,成立于 2014 年,并于 2022 年 12 月 19 日正式升格为次级统一司令部地位。CNMF 总部位于马里兰州 Fort George G. Meade,与国家安全局同址办公。
https://mp.weixin.qq.com/s?__biz=MzI2MTE0NTE3Mw==&mid=2651156703&idx=1&sn=9fa056e2cde8a21819ce02e98657ee56
Infostealer malware has now become the invisible thread linking petty credential theft to full-blown ransomware campaigns. Attackers no longer bother forcing their way through firewalls when infostealers have already unlocked the front door for them. Documented by DarkOwl, a stealer log archive generated by infostealer malware that silently harvests browser-saved passwords, session cookies, cryptocurrency wallet data, […]
The post Hackers Use Stealer Logs to Bypass MFA and Launch Ransomware Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
https://gbhackers.com/hackers-stealer-logs-launch-ransomware-attacks/
A vulnerability identified as problematic has been detected in Yoast SEO Plugin up to 28.0 on WordPress. This issue affects the function get_permalink. This manipulation of the argument post_name causes cross site scripting.
This vulnerability is registered as CVE-2026-15425. Remote exploitation of the attack is possible. No exploit is available.
https://vuldb.com/vuln/383036