Aggregator
阿联酋核电站遭到无人机袭击 无人员伤亡
Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026
Lyrie: Open-source autonomous pentesting agent
Penetration testing has usually required weeks of manual work, specialized tooling, and teams with narrow skill sets. Lyrie, an open-source autonomous security agent built by OTT Cybersecurity, compresses that process into a command line tool and publishes the entire codebase. The project reached version 3.1.0 this month. The release adds XChaCha20-Poly1305 memory encryption for sensitive threat data, seven new proof-of-concept generators covering prompt injection, auth bypass, CSRF, open redirect, race conditions, secret exposure, and cross-site … More →
The post Lyrie: Open-source autonomous pentesting agent appeared first on Help Net Security.
[无需删除] Windows 11安装更新后会新增SecureBoot文件夹 用于更新启动证书
CVE-2026-43349 | Linux Kernel up to 6.18.24/7.0.1 f2fs f2fs_finish_read_bio uninitialized resource (EUVD-2026-28633 / Nessus ID 313395)
CVE-2026-43340 | Linux Kernel up to 6.19.11 comedi_device comedi.comedi_num_legacy_minors initialization
CVE-2026-43346 | Linux Kernel up to 6.18.23/6.19.13 ice_get_ctrl_ptp initialization (Nessus ID 313401)
CVE-2026-43347 | Linux Kernel up to 6.18.23/6.19.13 arm64 qhee_hyp_assign_remove_memory denial of service
CVE-2026-43339 | Linux Kernel up to 6.19.11 addrconf_permanent_addr use after free (Nessus ID 313396)
CVE-2026-43341 | Linux Kernel up to 6.19.11 ioam6_fill_trace_data buffer overflow
CVE-2026-43348 | Linux Kernel up to 7.0.1 mshv_vtl privilege escalation (EUVD-2026-28632)
CVE-2026-43350 | Linux Kernel up to 6.6.135/6.12.83/6.18.24/7.0.1 parse_dacl sub_auth[] comparison (EUVD-2026-28634)
CVE-2026-43345 | Linux Kernel up to 6.6.135/6.12.82/6.18.23/6.19.13 net gsi_channel_trans_quiesce privilege escalation (Nessus ID 313453)
CVE-2026-43351 | Linux Kernel up to 6.18.18/6.19.8 KVM vgic_allocate_private_irqs_locked allocation of resources (Nessus ID 313446)
Microsoft не заплатила — Microsoft получила пять эксплойтов. Хронология двухмесячной мести исследователя Chaotic Eclipse
AI shrinks vulnerability exploitation window to hours
Time has become organizations’ biggest vulnerability because the gap between vulnerability discovery and exploitation has narrowed to hours, according to Synack’s 2026 State of Vulnerabilities Report. Total vulnerabilities by severity (2022-2025) (Source: Synack) AI expands the attack surface Agentic AI systems that act autonomously across systems introduce new risks that require human expertise to identify and understand. Automated scanning detects known signatures but can miss logic flaws, misconfigurations, and unexpected behavior. In 2025, mean time … More →
The post AI shrinks vulnerability exploitation window to hours appeared first on Help Net Security.