Aggregator
官方预警 | “银狐”木马病毒出现专门针对我国用户的新变种,真实受害案例触目惊心
Действительно ли мы «выключаемся» под общей анестезией? Нейроны говорят, что нет
科学家破解烟草合成尼古丁之谜
【直播预告】新一代反钓鱼系统上线,AI 高仿真四步实战演练
AI带来的影响初现:互联网漏洞赏金大幅下降
自动化供应链攻击6小时内攻陷5561个 GitHub 仓库
趋势科技提醒注意已遭利用的 Apex One 0day 漏洞
CVE-2026-2651 | MLflow up to 3.9.x Multipart Upload /mlflow-artifacts/mpu/ authorization (EUVD-2026-31642)
Дарёному значку в чип смотрят: Песков призвал не доверять электронным сувенирам
日本声优起诉要求 TikTok 删除 AI 模仿其声音的视频
气候变化威胁全球植物物种
补天端午活动第一弹 | “粽”测有礼
通用 | 端午第三弹,粽享万元奖励金
FBI director Kash Patel’s brand website taken offline after malware reports
Слепая зона AppSec: почему проверки зависимостей не должны заканчиваться на CVE
CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks
CISA has issued an urgent alert regarding a critical SQL injection vulnerability in Drupal Core, tracked as CVE-2026-9082, which is now being actively exploited in real-world attacks. The flaw, classified under CWE-89, affects Drupal’s database abstraction API and could allow attackers to execute malicious SQL queries through specially crafted requests. According to the Cybersecurity and […]
The post CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks appeared first on Cyber Security News.
GitHub Adds Staged Publishing to npm to Block Automated Supply Chain Attacks
GitHub has introduced a major security upgrade to the npm ecosystem with the general availability of staged publishing and new install-time controls, aimed at reducing automated supply chain attacks targeting open-source packages. The newly released staged publishing feature changes how npm packages are published and distributed. Instead of immediately making a package available after publishing, […]
The post GitHub Adds Staged Publishing to npm to Block Automated Supply Chain Attacks appeared first on Cyber Security News.
Hackers Use Browser-Locking CypherLoc Kit to Push Fake Microsoft Support Calls
A newly identified scareware kit called CypherLoc is locking victims’ browsers and tricking them into calling fake Microsoft support lines. The kit has been linked to roughly 2.8 million attacks since the start of 2026, making it one of the more aggressive browser-based threats observed this year. Unlike traditional malware that requires a file to […]
The post Hackers Use Browser-Locking CypherLoc Kit to Push Fake Microsoft Support Calls appeared first on Cyber Security News.