Aggregator
Actively exploited Apache ActiveMQ flaw impacts 6,400 servers
RALord
You must login to view this content
Думали, блокчейн защитит ваш сайт? Взлом eth.limo доказал: человеческий фактор сильнее
AI-Powered Exploitation May Collapse the Patch Window for Defenders
Artificial intelligence is reshaping cybercrime in ways that defenders can no longer treat as distant or theoretical. New frontier AI models are showing a growing ability to find software flaws, understand attack paths, and help move an intrusion from one stage to the next with far less human effort than before. This change matters because […]
The post AI-Powered Exploitation May Collapse the Patch Window for Defenders appeared first on Cyber Security News.
CVE-2026-40496 | freescout-help-desk freescout up to 1.8.212 Attachments random values (GHSA-2783-wxmm-wmwr / EUVD-2026-24049)
清华姚班到全球 3D AI 第一:胡渊鸣的 Meshy ARR 已超 4000 万美元
因第三方AI工具受陷,Vercel 内部系统遭未授权访问
Anthropic MCP 设计漏洞可导致 RCE,威胁 AI 供应链安全
3555 дыр за год. В банковских приложениях из App Store и Google Play нашли рекордное число уязвимостей
The US NSA is using Anthropic’s Claude Mythos despite supply chain risk
12 Browser Extensions Mimic as TikTok Video Downloaders Compromised 130k Users
A massive malware campaign known as “StealTok” involves at least 12 interrelated browser extensions. These extensions masquerade as TikTok video downloaders but secretly track user activity and harvest sensitive data. The campaign uncovered by LayerX security has affected over 130,000 users worldwide, with approximately 12,500 installations still active across the Google Chrome and Microsoft Edge […]
The post 12 Browser Extensions Mimic as TikTok Video Downloaders Compromised 130k Users appeared first on Cyber Security News.
英国计划学校期间禁止使用手机
Google Patches Antigravity IDE Flaw Enabling Prompt Injection Code Execution
科技云报到:当AI闯入特教行业,一场颠覆变革正在发生!
Hackers Could Weaponize GGUF Models to Achieve RCE on SGLang Inference Servers
A critical vulnerability in the SGLang inference server that allows threat actors to execute arbitrary code. Tracked as CVE-2026-5760, this flaw allows hackers to weaponize standard GGUF machine learning models to compromise the underlying servers that host them. As enterprise artificial intelligence deployments grow, this discovery highlights the severe infrastructure risks posed by loading untrusted […]
The post Hackers Could Weaponize GGUF Models to Achieve RCE on SGLang Inference Servers appeared first on Cyber Security News.
CISA Warns Axios npm Package Was Compromised in Major Supply Chain Attack
The Cybersecurity and Infrastructure Security Agency (CISA) has released a critical alert regarding a severe software supply chain compromise. The attack targets Axios, a massively popular HTTP client for JavaScript that developers worldwide rely on for Node.js and browser environments. Supply chain attacks have become a top priority for security teams, as compromising a single […]
The post CISA Warns Axios npm Package Was Compromised in Major Supply Chain Attack appeared first on Cyber Security News.