Aggregator
【已复现】PostgreSQL pgcrypto 堆缓冲区溢出漏洞(CVE-2026-2005)安全风险通告
【已复现】Next.js 服务器端请求伪造漏洞(CVE-2026-44578)安全风险通告
CVE-2026-44001 | vm2 up to 3.10.5 denial of service
CVE-2026-44866 | HPE Aruba Networking Wireless Operating System up to 10.8.0.0 Web-based Management Interface command injection
CVE-2026-8202 | MongoDB Server up to 7.0.33/8.0.22/8.2.8/8.3.1 Aggregation allocation of resources
CVE-2026-8336 | MongoDB Server up to 7.0.33/8.0.22/8.2.8/8.3.1 _internalJsEmit use after free
CVE-2026-8200 | MongoDB Server up to 7.0.33/8.0.22/8.2.8/8.3.1 Log Message log file
CVE-2026-44572 | vercel next.js up to 15.5.15/16.2.4 acceptance of extraneous untrusted data with trusted data (WID-SEC-2026-1401)
CVE-2026-42578 | Netty up to 4.1.133.Final/4.2.13.Final newInitialMessage response splitting (Nessus ID 314888)
CVE-2026-42031 | CKAN up to 2.10.9/2.11.4 datastore_search_sql sql injection (GHSA-h7j7-3rx6-xvcg)
CVE-2026-42032 | CKAN up to 2.10.9/2.11.4 datastore_search_sql authorization (GHSA-cg4x-64p3-x59h)
CVE-2026-41132 | CKAN up to 2.10.9/2.11.4 certificate validation (GHSA-mpfm-fpgx-647q)
微软将停止向个人账户提供短信验证码服务 未来登录时主要靠通行密钥或邮箱验证码
7-Eleven Confirms Hack After Appearing on ShinyHunters Leak List
The SNEK Initiative Drops “Eris”: New Post-Exploit Framework Abuses Windows Fax Service for SYSTEM Root
A novel exploitation framework designed to escalate execution privileges within the Windows environment, designated as Eris, has emerged
The post The SNEK Initiative Drops “Eris”: New Post-Exploit Framework Abuses Windows Fax Service for SYSTEM Root appeared first on Penetration Testing Tools.
Shai-Hulud worm copycats emerge after source code leak
Shai-Hulud worm copycats emerge after source code leak
Egnyte unveils Email Capture and AI features to unify fragmented data
Egnyte has announced a new set of capabilities designed to consolidate fragmented knowledge. Email Capture centralizes critical communications and attachments from siloed inboxes into the Egnyte folder structure, assisting users to make more informed data-driven decisions based on their entire knowledge base. Egnyte is also launching a set of AI-driven integrations and capabilities specifically designed for the architecture, engineering, and construction (AEC) industry. Data fragmentation is a pervasive problem for organizations that can contribute to … More →
The post Egnyte unveils Email Capture and AI features to unify fragmented data appeared first on Help Net Security.