Aggregator
美国政府去年有逾万名 STEM 博士离职
HoneyMyte Hacker Group Updates CoolClient Malware to Deploy Browser Login Data Stealer
The HoneyMyte threat group, also known as Mustang Panda or Bronze President, continues to pose a significant risk to government organizations across Asia and Europe. Recent security research has revealed that this advanced hacker collective is actively upgrading its digital arsenal with enhanced versions of malware designed to steal sensitive information from targeted systems. The […]
The post HoneyMyte Hacker Group Updates CoolClient Malware to Deploy Browser Login Data Stealer appeared first on Cyber Security News.
Ваша мышь двигается сама. Это троян добавляет себя в исключения антивируса
CVE-2026-24747 | PyTorch up to 2.9.x Checkpoint File deserialization (ID 163105)
CVE-2026-24836 | dnnsoftware Dnn.Platform up to 9.13.9/10.1.x Persona Bar cross site scripting (GHSA-2g5g-hcgh-q3rp)
CVE-2026-24833 | dnnsoftware Dnn.Platform up to 9.13.9/10.1.x Persona Bar Description cross site scripting (GHSA-9r3h-mpf8-25gj)
CVE-2026-24784 | dnnsoftware Dnn.Platform up to 9.13.9/10.1.x Headers/Footers cross site scripting (GHSA-jjwg-4948-6wxp)
CVE-2026-24838 | dnnsoftware Dnn.Platform up to 9.13.9/10.1.x cross site scripting (GHSA-w9pf-h6m6-v89h)
CVE-2026-1504 | Google Chrome up to 144.0.7559.96 Background Fetch API cross-domain policy (ID 474435)
CVE-2026-24765 | sebastianbergmann phpunit up to 8.5.51/9.6.32/10.5.61/11.5.49/12.5.7 cleanupForCoverage deserialization (GHSA-vvj3-c3rp-c85p)
CVE-2026-24837 | dnnsoftware Dnn.Platform up to 9.13.9/10.1.x Persona Bar cross site scripting (GHSA-vm5q-8qww-h238)
CERT UEFI Parser: Open-source tool exposes UEFI architecture to uncover vulnerabilities
CERT UEFI Parser, a new open-source security analysis tool from the CERT Coordination Center has been released to help researchers and defenders examine the structure of Unified Extensible Firmware Interface (UEFI) software and identify classes of vulnerabilities that are often difficult to study. UEFI software The tool is published by the Software Engineering Institute (SEI) at Carnegie Mellon University and applies program analysis techniques to UEFI firmware code to extract architectural details that are typically … More →
The post CERT UEFI Parser: Open-source tool exposes UEFI architecture to uncover vulnerabilities appeared first on Help Net Security.
16 Malicious Chrome Extensions as ChatGPT Enhancements Steals ChatGPT Logins
Researchers have uncovered a significant security threat targeting ChatGPT users through deceptive browser extensions. A coordinated campaign involving 16 malicious Chrome extensions has been discovered, all designed to appear as legitimate productivity tools and ChatGPT enhancement applications. These malware extensions are actively stealing ChatGPT session authentication tokens, granting attackers complete access to victims’ accounts and […]
The post 16 Malicious Chrome Extensions as ChatGPT Enhancements Steals ChatGPT Logins appeared first on Cyber Security News.
信息安全漏洞周报(2026年第4期)
CNNVD关于Microsoft Office安全漏洞的通报
Fortinet Disables FortiCloud SSO Following 0-day Vulnerability Exploited in the Wild
Fortinet temporarily disabled its FortiCloud Single Sign-On (SSO) service after confirming active exploitation of a zero-day authentication bypass vulnerability in multiple products. The issue, tracked as FG-IR-26-060, allows attackers with a malicious FortiCloud account to log into devices registered to other accounts. The flaw stems from an Authentication Bypass Using an Alternate Path or Channel […]
The post Fortinet Disables FortiCloud SSO Following 0-day Vulnerability Exploited in the Wild appeared first on Cyber Security News.