Aggregator
网络安全信息与动态周报2026年第11期(3月9日-3月15日)
【漏洞通告】Langflow 任意文件创建漏洞 CVE-2026-33309
关于《网络空间安全科学学报》网站变更公告
NCA Boss Warns That Teens Are Being “Radicalized” Into Cybercrime Online
码力·智能开发与安全一体化平台
《码力·智能开发与安全一体化平台》由长亭科技推出,以"AI+安全"双引擎破解企业AI编码困局:IDE智能辅助实现代码生成-审计-修复闭环,AI员工全自动完成需求到提交;内置SAST/SCA/AI审计三层防护,误报率<5%,支持DeepSeek等主流模型私有化部署。独创第四代自主规划Agent架构,1400倍上下文压缩、环境驱动执行与动态任务分解,让80万行代码审计从"被动扫描"升级为"主动探索";配套安全/质量/合规/业务逻辑四维模板与Skill热插拔体系,已服务蔚来、贝壳等企业,AI代码占比超30%,实现"代码生而安全"的新型开发范式。
Unpatched ScreenConnect servers open to attack (CVE-2026-3564)
ConnectWise has patched a critical vulnerability (CVE-2026-3564) that could enable attackers to hijack ScreenConnect sessions by abusing ASP.NET machine keys to forge trusted authentication. About CVE-2026-3564 The ScreenConnect remote access platform is popular with managed service providers, IT departments, and technology solution providers. They can opt for the cloud-hosted version or can deploy it on their own servers or in their private cloud. CVE-2026-3564 stems from improper verification of cryptographic signature, can be exploited remotely … More →
The post Unpatched ScreenConnect servers open to attack (CVE-2026-3564) appeared first on Help Net Security.
ИИ посоветовал — инженер сделал. История о том, как одна рекомендация нейросети чуть не обрушила защиту Meta
Musician admits to $10M streaming royalty fraud using AI bots
Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover
Задача 2026 года: поймать неуловимого злоумышленника в эпоху ИИ
CVE-2026-4497 | Totolink WA300 5.2cu.7112_B20190227 /cgi-bin/cstecgi.cgi recvUpgradeNewFw os command injection
Reunifying the Cloud: Introducing Aurelian for Multi-Cloud Security Testing
You are one week into a cloud penetration test. The client handed you an AWS access key, pointed you at three Azure subscriptions, and mentioned a GCP project that “someone on the platform team set up last year.” Your objective: find everything that is exposed, misconfigured, or one IAM policy away from a full compromise. […]
The post Reunifying the Cloud: Introducing Aurelian for Multi-Cloud Security Testing appeared first on Praetorian.
The post Reunifying the Cloud: Introducing Aurelian for Multi-Cloud Security Testing appeared first on Security Boulevard.
Securing Third-Party Procurement Platforms with Enterprise SSO
Protect third-party procurement platforms with enterprise SSO, SCIM, and MFA to reduce access risks, improve compliance, and secure vendor data.
The post Securing Third-Party Procurement Platforms with Enterprise SSO appeared first on Security Boulevard.
How to Block Bots and Stop Bot Attacks on Your Website, Apps, & APIs
Learn how to block bots and stop bot attacks on your website, app, and APIs. From basic techniques to advanced AI-powered bot management, we cover what works, what doesn’t, and why.
The post How to Block Bots and Stop Bot Attacks on Your Website, Apps, & APIs appeared first on Security Boulevard.