Aggregator
CVE-2026-2415 | pretix prior 2025.9.0/2025.10.0/2026.1.0/2026.1.1 Placeholder dynamic variable evaluation
Зачем ломать код, если можно просто попросить? Итог – 6 миллионов человек «под колпаком»
Crypto Payments to Human Traffickers Surges 85%
CVE-2026-2001 | WowRevenue Plugin up to 2.1.3 on WordPress Plugin Installation install_activate_plugin authorization
CVE-2025-59905 | Kubysoft Endpoint procedure cross site scripting
CVE-2025-59904 | Kubysoft /kForms/app cross site scripting
CVE-2025-59903 | Kubysoft SVG Image cross site scripting
CVE-2026-0998 | Mattermost up to 10.11.9/11.1.2/11.2.1 Zoom /api/v1/askPMI authorization
CVE-2026-0997 | Mattermost up to 10.11.9/11.1.2/11.2.1 Zoom channel-preference authorization
CVE-2026-0999 | Mattermost up to 10.11.9/11.1.2/11.2.1 Login incorrect implementation of authentication algorithm
CVE-2026-2577 | HKUDS nanobot up to 0.1.3.Post6 WhatsApp Bridge missing authentication
白帽一百祝各位 新春快乐万事胜意
New ZeroDayRAT Mobile Spyware Enables Real-Time Surveillance and Data Theft
ChatGPT gets new security feature to fight prompt injection attacks
OpenAI has introduced Lockdown Mode and Elevated Risk labels in ChatGPT to help users and organizations reduce the risk of prompt injection attacks and other advanced security threats, particularly when using features that interact with external systems. Limiting tool access to prevent data exfiltration Lockdown Mode in ChatGPT is an optional, advanced security setting for highly security-conscious users who require protection against advanced threats. To reduce the risk of prompt injection–based data exfiltration, it constrains … More →
The post ChatGPT gets new security feature to fight prompt injection attacks appeared first on Help Net Security.
Google fixes first actively exploited Chrome zero-day of 2026
Lotus Blossom Hackers Compromised Official Hosting Infrastructure of Notepad++
The state-sponsored threat group Lotus Blossom successfully breached the official hosting infrastructure of Notepad++ between June and December 2025, targeting users across government agencies, telecommunications companies and critical infrastructure sectors. The attackers gained access by compromising the shared hosting provider’s environment, which allowed them to intercept traffic headed to the Notepad++ update server and redirect […]
The post Lotus Blossom Hackers Compromised Official Hosting Infrastructure of Notepad++ appeared first on Cyber Security News.
CISA Warns of ZLAN ICS Devices Vulnerabilities Allows Complete Device Takeover
An alert regarding two critical vulnerabilities found in ZLAN Information Technology Co.’s ZLAN5143D industrial communication device. According to the advisory (ICSA-26-041-02), successful exploitation could allow attackers to gain complete control of affected systems by bypassing authentication mechanisms or resetting device passwords remotely. The vulnerabilities impact ZLAN5143D version 1.600, a device commonly used across global critical […]
The post CISA Warns of ZLAN ICS Devices Vulnerabilities Allows Complete Device Takeover appeared first on Cyber Security News.