Aggregator
Secure Your Spot at RSAC 2026 Conference
1 month 3 weeks hence
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
1 hour 42 minutes ago
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
Some ChatGPT browser extensions are stealing your data
3 hours 11 minutes ago
A threat actor is seeding the internet with AI browser extensions that can intercept a user’s authenticated session tokens and hijack accounts.
The post Some ChatGPT browser extensions are stealing your data appeared first on CyberScoop.
djohnson
Devman
3 hours 58 minutes ago
You must login to view this content
cohenido
Supreme Court to hear Facebook pixel tracking case
4 hours 1 minute ago
The Supreme Court said Monday that it will hear a case stemming from the use of a Facebook tracking pixel to monitor the streaming habits of the user of a sports website.
CVE-2026-21509: Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally
4 hours 6 minutes ago
CVE-2026-21509: Reliance on untrusted inputs in a security decision in Microsoft Office allows an unauthorized attacker to bypass a security feature locally
Dark Web Informer
Fake Microsoft Teams Billing Phishing Alerts Reach 6,135 Users via 12,866 Emails
4 hours 29 minutes ago
Scammers are abusing Microsoft Teams invitations to send fake billing notices, with 12,866 emails reaching around 6,135 users in a phone-based phishing campaign.
Deeba Ahmed
Play
4 hours 31 minutes ago
You must login to view this content
cohenido
Play
4 hours 32 minutes ago
You must login to view this content
cohenido
Play
4 hours 32 minutes ago
You must login to view this content
cohenido
Play
4 hours 32 minutes ago
You must login to view this content
cohenido
INC
4 hours 34 minutes ago
You must login to view this content
cohenido
绕过 AI 检测:用迭代器构建“合法”恶意代码
4 hours 50 minutes ago
前言在现代 Web 应用安全攻防中,攻击者不断演化其技术手段,以规避日益智能的检测机制。传统的基于关键词匹配或简单语法分析的安全防护(如 WAF、SAST 工具甚至部分 AI 驱动的代码扫描系统)正面临严峻挑战,恶意代码不再以明文形式暴露危险函数或命令,而是通过逻辑拆分、数据混淆、运行时重构等高级技巧,将攻击载荷(payload)伪装成合法的业务逻辑。AI检测的思路AI 检测 WebShell 的
从 Chatbot 到 Autonomous Agents-新型LLM攻击漏洞总结
4 hours 50 minutes ago
随着 AI 从单一的 Chatbot 进化为拥有工具调用权限的 Autonomous Agents(自主智能体),安全边界已彻底瓦解。
本文不再局限于简单的 Prompt Injection,而是深入剖析了 GCG 自动化对抗、AI-CSRF 跨插件攻击、RAG 逻辑炸弹 等前沿威胁,并提供了基于 Zero-Trust AI 的防御架构设计与 DevSecOps 落地代码。
CVE-2025-61686-React Router 任意文件写入漏洞——从代码层面分析漏洞成因
4 hours 51 minutes ago
该漏洞成因是使用createFileSessionStorage()函数存储用户凭证,并且在会话存储配置中未提供secrets参数,导致攻击者可以利用这一特性写入/覆盖任意文件
newbee-mall开源电商项目代码审计:水平越权、支付逻辑缺陷与文件上传漏洞
4 hours 51 minutes ago
本文着重分析开源项目newbee-mall的未修复漏洞以及对CVE-2024-48178的思考。
自定义MCP&skill技能分析漏洞利用链
4 hours 51 minutes ago
本文提出 Tabby + Neo4j + LLM 的 Java 漏洞利用链分析方案:先用 Tabby 生成函数调用图,Cypher 查询恶意调用链;再通过自定义 MCP/Skill 上传源码片段至 LLM 分析参数可控性。
PyTorch 最新版本反序列化漏洞分析
4 hours 52 minutes ago
PyTorch因torch.load硬编码weights_only=False,导致加载恶意.pt2文件可触发pickle任意代码执行。
Submit #737032: Hisense TransTech Hisense Smart Bus Management System 1.0 SQL Injection [Accepted]
4 hours 59 minutes ago
Submit #737032 / VDB-342881
jiefengliang