Aggregator
CVE-2026-23888 | pnpm up to 10.28.0 Prefix path traversal (GHSA-6pfh-p556-v868 / EUVD-2026-4655)
CVE-2026-24428 | Tenda W30E V2 up to 16.01.0.19(5037) User Management API authorization
CVE-2025-14756 | TP-Link Systems Archer MR600 5.0 Admin Interface command injection
CVE-2026-24435 | Tenda W30E V2 up to 16.01.0.19(5037) Administrative Endpoint cross-domain policy
CVE-2026-24131 | pnpm up to 10.28.1 path.join directories.bin path traversal (GHSA-v253-rj99-jwpq / EUVD-2026-4653)
CVE-2025-59471 | vercel next.js up to 16.1.4 Image Optimization Endpoint /_next/image denial of service (GHSA-9g9p-9gw9-jx7f)
CVE-2026-24436 | Tenda W30E V2 up to 16.01.0.19(5037) excessive authentication
CVE-2026-24430 | Tenda W30E V2 up to 16.01.0.19(5037) Maintenance Interface insertion of sensitive information into sent data
CVE-2026-24408 | sigstore sigstore-python up to 4.1.x OAuth Authentication _OAuthSession cross-site request forgery (GHSA-hm8f-75xx-w2vr)
CVE-2026-22696 | Phala-Network dcap-qvl up to 0.3.8 signature verification (GHSA-796p-j2gh-9m2q)
CVE-2026-24123 | BentoML up to 1.4.33 bentofile.yaml path traversal (GHSA-6r62-w2q3-48hf)
CVE-2026-24478 | mintplex-labs anything-llm up to 1.9.x path traversal (GHSA-jp2f-99h9-7vjv)
银狐黑产组织新型注入型攻击样本与威胁情报
CISA publishes a post-quantum shopping list for agencies. Security professionals aren’t sold
A guide aims to help tech buyers navigate their switch to post-quantum encryption, but experts cautioned that most products and backend internet protocols have yet to be updated.
The post CISA publishes a post-quantum shopping list for agencies. Security professionals aren’t sold appeared first on CyberScoop.
光网铺路·云脑赋能·安全护航 三步构建智慧校园
安全考核跨部门落地与编码规范执行:机制设计与技术实践|总第306周
A new wave of ‘vishing’ attacks is breaking into SSO accounts in real time
Cybercrime groups, including one that identifies as ShinyHunters, are targeting single sign-on services to gain access to victim networks and steal data.
The post A new wave of ‘vishing’ attacks is breaking into SSO accounts in real time appeared first on CyberScoop.
New malware service guarantees phishing extensions on Chrome web store
Claude expands tool connections using MCP
Anthropic has added interactive tool support to its Claude AI platform, a change powered by the open Model Context Protocol (MCP). The update lets users work directly with external applications inside Claude’s interface rather than relying solely on text interactions with connected services. Interactive tools arrive in Claude With the update launched January 26, users can open tools such as project management boards, analytics dashboards, design canvases, and messaging platforms inside Claude’s chat interface. Users … More →
The post Claude expands tool connections using MCP appeared first on Help Net Security.