Aggregator
CVE-2023-5414 | Icegram Express Plugin up to 5.6.23 on WordPress path traversal
CVE-2023-5576 | WPvivid Plugin up to 0.9.91 on WordPress Google Drive Client Secret information disclosure (ID 2977863)
CVE-2023-5071 | Sitekit Plugin up to 1.4 on WordPress Shortcode sitekit_iframe cross site scripting (ID 2970788)
CVE-2020-36751 | Coupon Creator Plugin up to 3.1 on WordPress save_meta cross-site request forgery (ID 2368658)
500 Tbps of capacity: 16 years of scaling our global network
EngageSDK Vulnerability Exposes Millions of Crypto Wallet Users to Cyberattacks
A serious security flaw found inside a widely used Android library called EngageSDK has put over 30 million cryptocurrency wallet users at risk of financial theft and personal data exposure. The vulnerability, described as an intent redirection flaw, allowed malicious apps on the same device to break through Android’s built-in security sandbox and gain unauthorized […]
The post EngageSDK Vulnerability Exposes Millions of Crypto Wallet Users to Cyberattacks appeared first on Cyber Security News.
CVE-2026-3865
从发现 33 个 0day 漏洞,看安全攻防的下半场 | 朱雀实验室
Hackers Use AiTM Session Hijacking to Redirect Employee Salaries in New Storm-2755 Campaign
A financially motivated threat group called Storm-2755 has launched a campaign that quietly reroutes employee salary payments to attacker-controlled bank accounts. Targeting Canadian workers, the group uses adversary-in-the-middle (AiTM) techniques to hijack authenticated sessions and bypass multi-factor authentication (MFA), in what researchers have labeled “payroll pirate” attacks. The campaign starts with SEO poisoning and malvertising. […]
The post Hackers Use AiTM Session Hijacking to Redirect Employee Salaries in New Storm-2755 Campaign appeared first on Cyber Security News.
Мощные нейросети теперь только для своих. ИТ-гиганты строят закрытый клуб для избранных
UK government threatens tech bosses with jail time if they do not adequately fight nudification tools
‘It reads like a spy novel’: $280 million theft from Drift involved North Korean fake companies, cutouts
Google Extends Gmail Encryption to Mobile, but Limits Access to Enterprise Tier
Google has expanded its encryption capabilities in Gmail to mobile devices, enabling enterprise customers to transmit encrypted emails directly within the app on both Android and iOS. The update removes a limitation that previously restricted native encrypted email use on mobile devices. The rollout allows eligible users to compose and read encrypted messages natively, without..
The post Google Extends Gmail Encryption to Mobile, but Limits Access to Enterprise Tier appeared first on Security Boulevard.
France to Replace Windows with Linux on Government Desktops
France has taken a decisive step toward digital sovereignty, announcing plans to migrate government workstations from Microsoft Windows to Linux. The move was formally declared during an interministerial seminar held on April 8, 2026, organized by the Interministerial Directorate for Digital Affairs (DINUM), the National Cybersecurity Agency of France (ANSSI), the Directorate General for Enterprises […]
The post France to Replace Windows with Linux on Government Desktops appeared first on Cyber Security News.
Два криптографа поспорили на $5000: что сломается первым — старая защита интернета или новая. Ставки сделаны, выиграет лишь один
Randall Munroe’s XKCD ‘Electric Vehicles’
via the comic artistry and dry wit of Randall Munroe, creator of XKCD
The post Randall Munroe’s XKCD ‘Electric Vehicles’ appeared first on Security Boulevard.