Aggregator
CVE-2026-5433 | Honeywell International Control Network Module up to 110.2 Web Interface command injection
NASA 预计中国将在 2027 年执行载人绕月飞行任务
When Identity is the Attack Path
GitHub Internal Repositories Breached Via Weaponized VS Code Extension
GitHub confirmed a significant security breach on May 18, 2026, after attackers leveraged a weaponized Visual Studio Code extension to compromise an employee’s device and exfiltrate data from the company’s internal source code repositories. The attack was detected and contained on Monday, May 18, when GitHub’s security team identified suspicious activity on an employee endpoint. […]
The post GitHub Internal Repositories Breached Via Weaponized VS Code Extension appeared first on Cyber Security News.
CVE-2026-9082: Mitigating a Critical SQL Injection Vulnerability in Drupal
Банки обязали следить за счетами клиентов каждый день. Список признаков, по которым вас признают подозрительным
Microsoft’s Retired IE Tool MSHTA Now Being Used in Fileless Malware Attacks
GitHub 被黑,3800个内部仓库外泄:从一枚恶意VS Code扩展说起
Конец эпохи «введите код из сообщения». Microsoft переходит на вход без паролей и SMS
上架麒麟软件、统信应用商店,360安全卫士(信创版)加快融入信创生态
“银狐”木马新变种爆发!伪装人事文件定向攻击国内用户
第二届软件系统安全赛 robo_admin 题解
上海急缺的“人工智能训练师”到底是个什么职业?
The readiness paradox: Why a false sense of cyber confidence is becoming a liability
As AI expands the attack surface and alert fatigue grows, cyber exposure management offers a clearer path to understanding where risk truly concentrates and how to reduce it before a crisis hits.
The post The readiness paradox: Why a false sense of cyber confidence is becoming a liability appeared first on CyberScoop.
终端是AI安全唯一的"战场"
七岁的剪映,长大成人
Nine-year-old Linux Kernel Vulnerability Let Attackers Exfiltrate SSH Private Keys
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-46333, exposes a serious local privilege escalation flaw that has remained undetected for nearly nine years. Security researchers at the Qualys Threat Research Unit (TRU) revealed that the issue allows attackers to exfiltrate sensitive data, including SSH private keys, and execute arbitrary commands as root on affected […]
The post Nine-year-old Linux Kernel Vulnerability Let Attackers Exfiltrate SSH Private Keys appeared first on Cyber Security News.