Aggregator
【AI自动逆向算法】Binary Analysis Agent:构建AI驱动的二进制分析系统
CVE-2026-7798 | techjewel FluentCRM Plugin up to 2.9.87 on WordPress _fc_bounce_key SubscribeURL server-side request forgery
北京经信局发布《关于做好工业领域网络和数据安全工作的提示》
CVE-2026-8684 | jetmonsters MotoPress Hotel Booking Plugin up to 6.0.1 on WordPress authorization
Splunk Patches Multiple Vulnerabilities that Enable DOS Attacks and Expose Sensitive Data
Splunk has released security updates addressing multiple vulnerabilities across Splunk Enterprise, Splunk Cloud Platform, and the Splunk AI Toolkit that could lead to denial-of-service (DoS) conditions and exposure of sensitive data. The issues, disclosed on May 20, 2026, include three tracked vulnerabilities: CVE-2026-20238, CVE-2026-20239, and CVE-2026-20240. Splunk AI Toolkit Access Flaw (CVE-2026-20238) A medium-severity flaw […]
The post Splunk Patches Multiple Vulnerabilities that Enable DOS Attacks and Expose Sensitive Data appeared first on Cyber Security News.
CVE-2026-8381 | TeamViewer DEX up to 9.1 Backend API Endpoint authorization (WID-SEC-2026-1651)
CVE-2026-9011 | metaphorcreations Ditty Plugin up to 3.1.65 on WordPress AJAX Endpoint init authorization
CVE-2026-8679 | cssigniterteam AudioIgniter Music Player Plugin up to 2.0.2 on WordPress /audioigniter/playlist/ handle_playlist_endpoint authorization
CVE-2026-7636 | smub Slider by Soliloquy Plugin up to 2.8.1 on WordPress Configuration map_meta_cap information disclosure
CVE-2026-8692 | registrationformbuilder Vedrixa Forms Plugin up to 1.1.1 on WordPress Shortcode wp_localize_script authorization (EUVD-2026-31414)
CVE-2026-7615 | kasparsd Widget Context Plugin up to 1.3.3 on WordPress /wp-admin/widgets.php save_widget_context_settings cross-site request forgery
脱离人体的大脑被用于药物测试
把 Yaklang 脚本编译成原生二进制:SSA2LLVM 现在走到哪了
CISA Warns of Trend Micro Apex One Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, warning organizations of active exploitation risks. The flaw, tracked as CVE-2026-34926, affects on-premise deployments of Trend Micro Apex One and could allow attackers to tamper with endpoint security systems. CVE-2026-34926 […]
The post CISA Warns of Trend Micro Apex One Vulnerability Exploited in Attacks appeared first on Cyber Security News.
CISA’s new KEV nomination form opens reporting to vendors and researchers
The Cybersecurity and Infrastructure Security Agency launched a new nomination form that lets researchers, vendors, and industry partners report known exploited vulnerabilities for possible inclusion in its KEV catalog. The form gives outside contributors a direct way to submit vulnerabilities to CISA. Email submissions remain available at [email protected] for organizations and individuals who prefer that route. “Every day, CISA collaborates with security researchers and industry partners that identify and report exploited vulnerabilities. This new reporting … More →
The post CISA’s new KEV nomination form opens reporting to vendors and researchers appeared first on Help Net Security.
Спешка перед рабочим созвоном = пустой кошелёк. Разбираем новую волну атак на пользователей Microsoft Teams
FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA
The FBI has issued a new cybersecurity warning about a rapidly emerging phishing-as-a-service (PhaaS) platform named Kali365, which is actively targeting Microsoft 365 users to steal access tokens and bypass multi-factor authentication (MFA). Kali365 is being distributed primarily through Telegram channels, where threat actors can subscribe to the service and launch phishing campaigns with minimal […]
The post FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA appeared first on Cyber Security News.