Aggregator
如何基于开源情报(OSINT) 识别军事AI技术部署节点
Phishers Abuse LiveChat Support Tools to Steal Sensitive Data in New SaaS-Based Attack Tactic
A newly identified phishing campaign is turning legitimate customer service software into a weapon for stealing sensitive user data. Attackers have been found abusing LiveChat, a widely used Software-as-a-Service (SaaS) platform that businesses rely on for real-time customer support, to carry out convincing phishing operations against unsuspecting victims. The campaign marks a clear shift from […]
The post Phishers Abuse LiveChat Support Tools to Steal Sensitive Data in New SaaS-Based Attack Tactic appeared first on Cyber Security News.
Защита облака: почему старые подходы не работают?
年度征文 | 冬游九寨,或许这个季节更适合叙述她的美
CVE-2026-32141 | WebReflection flatted up to 3.3.x JSON Parser parse recursion (GHSA-25h7-pfq9-p65f / Nessus ID 302061)
CVE-2026-31900 | psf black up to 26.2.x input validation (Nessus ID 302062)
CVE-2026-1526 | undici up to 6.23.0 WebSocket decompress data amplification (Nessus ID 302064)
CVE-2026-2581 | undici up to 6.23.0 when interceptors.deduplicate allocation of resources (Nessus ID 302065)
CVE-2026-1528 | undici up to 6.23.x/7.23.x WebSocket Frame uncaught exception (EUVD-2026-11703 / Nessus ID 302066)
CVE-2026-3644 | Python CPython up to 3.14.x http.cookies.Morsel input validation (EUVD-2026-12484)
CVE-2026-4224 | Python CPython up to 3.14.x Expat Parser ElementDeclHandler stack-based overflow (EUVD-2026-12486)
CVE-2026-4254 | Tenda AC8 up to 16.03.50.11 HTTP Endpoint /goform/SysToolChangePwd doSystemCmd local_2c stack-based overflow (EUVD-2026-12488)
CVE-2026-32267 | Craft CMS up to 4.17.5/5.9.11 authorization (EUVD-2026-12508)
CVE-2026-30875 | Chamilo LMS up to 1.11.35 H5P Import Feature h5p.json code injection (EUVD-2026-12496)
CVE-2026-28430 | Chamilo LMS up to 1.11.33 Legacy Password Reset custom_dates sql injection (EUVD-2026-12492)
CVE-2026-30876 | Chamilo LMS up to 1.11.35 response discrepancy (EUVD-2026-12498)
Список жертв зачитывали два часа. Суд огласил имена людей, потерявших деньги из-за онлайн-мошенников
Traefik Triple Gate gains parallel safety pipelines, failover routing, and AI runtime controls
Traefik Labs has announced new capabilities that extend Traefik Hub’s Triple Gate architecture (API Gateway, AI Gateway, and MCP Gateway) with deeper runtime governance across the full AI workflow, including a composable multi-vendor safety pipeline with parallel guard execution, multi-provider failover routing, token-level cost controls, graceful error handling for agent-aware enforcement, IBM Granite Guardian integration, and a new Regex Guard capability that enables organizations to create custom guards. These capabilities address a growing gap. Enterprises … More →
The post Traefik Triple Gate gains parallel safety pipelines, failover routing, and AI runtime controls appeared first on Help Net Security.