Aggregator
CVE-2026-48831 | WineHQ Wine up to 11.0 MIME resource transfer (EUVD-2026-31599 / Nessus ID 316603)
CVE-2026-4372 | huggingface transformers up to 5.2.x config.json AutoModelForCausalLM.from_pretrained _attn_implementation_internal missing serialization control element (EUVD-2026-31598)
用开源情报读懂美情报总监加巴德辞职,一封辞职信背后的权力退场学
《星际公民(Star Citizen)》筹款突破十亿美元
荷兰扣押了一家支持网络攻击的托管服务商的 800 台服务器
10 лет медвуза vs 10 секунд ChatGPT. Угадайте, кто ставит диагноз, пока вы ждёте в кабинете
npm 新增 2FA 门控发布与包安装控制,防范供应链攻击
任意用户密码重置
网安传承
API公益中转站建议还是先了解后再用
Drupal 漏洞在披露后不久即成为黑客攻击目标
“Underminr”漏洞允许攻击者将恶意连接隐藏在受信任域名之后
Pentest Agent Suite – Bug Bounty Framework for Claude Code and 6 AI Coding Tools
A fully autonomous bug-bounty framework called Pentest Agent Suite has been open-sourced, delivering 50 specialized security agents, 26 slash commands, 19 CLI tools, and a cross-IDE installer across seven major AI coding platforms — Claude Code, OpenAI Codex, Google Gemini, Cursor, Windsurf, VS Code Copilot, and OpenClaw. The project, published on GitHub by researcher H-mmer, […]
The post Pentest Agent Suite – Bug Bounty Framework for Claude Code and 6 AI Coding Tools appeared first on Cyber Security News.
Wireshark 4.6.6 Released With Fix for Dissector Crash via Malformed Packet Injection
The Wireshark Foundation has released Wireshark 4.6.6, addressing a critical security vulnerability in the ROHC (Robust Header Compression) protocol dissector that could allow an attacker to crash the application by injecting a specially crafted, malformed packet. The update also resolves over a dozen stability and compatibility bugs affecting Windows users. The primary security fix targets […]
The post Wireshark 4.6.6 Released With Fix for Dissector Crash via Malformed Packet Injection appeared first on Cyber Security News.
Laravel Lang 软件包遭劫持,被用于部署凭证窃取恶意软件
攻守之间,亿万信任|腾讯七线联合众测,四倍奖金+超百万奖池等你来!
【公益译文】2026年AI指数报告(一)
Hacker Selling 340 Million OnlyFans User Records Built From Old Breaches
Hackers Compromised 34 Packages in npm, PyPI, and Crates in New Supply Chain Attack
New TrapDoor supply chain campaign, an active attack deploying 34 malicious packages and over 384 related versions across npm, PyPI, and Crates.io to steal developer credentials and cryptocurrency wallets. The operation explicitly targets developers in the crypto, DeFi, Solana, and AI communities by disguising malware as generic developer tools and security scanners. The campaign’s earliest […]
The post Hackers Compromised 34 Packages in npm, PyPI, and Crates in New Supply Chain Attack appeared first on Cyber Security News.