Aggregator
Critical ChromaDB Flaw Exposes AI Vector Databases to Remote Code Execution
双重认可!绿盟科技入选《通信产业报》电信日两大榜单
Webworm: New burrowing techniques
Verizon DBIR: Vulnerability Exploits Overtake Credentials as Top Access Vector
GitHub 证实黑客窃取了其内部代码库
GitHub 证实黑客窃取了其内部代码库
When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax
Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585)
Microsoft is working on a fix for CVE-2026-45585 (aka “Yellowkey”), a vulnerability that can be used by attackers to bypass protections offered by BitLocker, the full-disk encryption feature built into Windows, and access users’ data. In the meantime, the company has provided step-by-step mitigation advice to protect affected Windows devices from exploitation. CVE-2026-45585 and the YellowKey exploit CVE-2026-45585 is a security feature bypass vulnerability that can only be exploited if the attacker has physical access … More →
The post Microsoft provides mitigation for “YellowKey” BitLocker bypass flaw (CVE-2026-45585) appeared first on Help Net Security.
Один 0day — и страна без связи. Неизвестная уязвимость в Huawei затронула телеком Люксембурга
Postgres Extensions Cheat Sheet: Replace 7 Databases With SQL
FBI warns students and staff that ShinyHunters may come knocking after Canvas breach
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit
Залить данные проекта в нейросеть — самый быстрый способ получить проблему
GitHub confirms breach of 3,800 repos via malicious VSCode extension
GitHub confirms breach of 3,800 repos via malicious VSCode extension
4000 закрытых репозиториев и ценник в 50 тысяч долларов. TeamPCP утверждает, что украла внутренний код GitHub
Shai-Hulud Malware Hits @antv Ecosystem, Poisoning Hundreds of npm Packages
The npm ecosystem has been subjected to a massive, highly coordinated supply-chain assault. Within a compressed one-hour envelope,
The post Shai-Hulud Malware Hits @antv Ecosystem, Poisoning Hundreds of npm Packages appeared first on Information Security News.
Bypassing the Guardrails: New “DirtyDecrypt” Linux Flaw Overwrites Root Files in Memory
The Linux ecosystem has been destabilized by successive operational waves for several weeks; scarcely had the industry turbulence
The post Bypassing the Guardrails: New “DirtyDecrypt” Linux Flaw Overwrites Root Files in Memory appeared first on Information Security News.