Aggregator
SecWiki News 2026-01-22 Review
更多最新文章,请访问SecWiki
«Ваш аккаунт удалят через 10 минут!» Ага, конечно. Учимся игнорировать истерику мошенников
mRNA 癌症疫苗展现了抗癌潜力
泄密者的致命疏忽:打印机监控存档涉密截图
Researchers Detailed r1z Initial Access Broker OPSEC Failures
U.S. authorities have pulled back the curtain on “r1z,” an initial access broker who quietly sold gateways into corporate networks around the world. Operating across popular cybercrime forums, he offered stolen VPN credentials, remote access to enterprise environments, and custom tools designed to bypass security controls. His activity fed the ransomware supply chain by giving […]
The post Researchers Detailed r1z Initial Access Broker OPSEC Failures appeared first on Cyber Security News.
Хотел посчитать интегралы, а получил майнер. Будни Python-разработчика в 2026 году
大模型智能知识库WeKnora命令注入漏洞(CVE-2026-22688)
Hackers Earned $516,500 for 37 Unique 0-day Vulnerabilities – Pwn2Own Automotive 2026
Day One of Pwn2Own Automotive 2026, which delivered $516,500 USD for 37 zero-days, the event has now accumulated $955,750 USD across 66 unique vulnerabilities, demonstrating the automotive sector’s substantial attack surface. The competition showcased exploits targeting multiple vehicle subsystems, including in-vehicle infotainment (IVI) systems, EV charging stations, and embedded Linux environments. Researchers successfully demonstrated command […]
The post Hackers Earned $516,500 for 37 Unique 0-day Vulnerabilities – Pwn2Own Automotive 2026 appeared first on Cyber Security News.
国外某RTS域渗透靶场通关实战
Eric Schmidt 认为欧洲必须投资自己的开源 AI 模型
Attackers Reverse‑Engineer Patch to Exploit SmarterMail Admin Bypass in the Wild
A critical authentication bypass vulnerability in SmarterTools SmarterMail is actively being exploited in the wild by attackers, according to security researchers at watchTowr Labs. The vulnerability, tracked as WT-2026-0001, allows unauthenticated attackers to reset the system administrator password without any validation, leading to complete system takeover. The flaw exists in the ForceResetPassword API endpoint, which is designed […]
The post Attackers Reverse‑Engineer Patch to Exploit SmarterMail Admin Bypass in the Wild appeared first on Cyber Security News.
Critical SmarterMail vulnerability under attack, no CVE yet
RealHomes CRM Plugin Flaw Affected 30,000 WordPress Sites
«Рекрутер из Одессы» с северокорейским акцентом. Как PurpleBravo обманывает айтишников со всего света
逆天漏洞:《明日方舟:终末地》海外首日公测上线就遭遇T0级事故
Why Active Directory password resets are surging in hybrid work
The Blame Game! Is it the Network or Gaps in Observability?
Obsidian Security unveils end-to-end SaaS supply chain security to stop integration-led breaches
Obsidian Security announced end-to-end SaaS supply chain security solution, empowering organizations to monitor, control and contain the security risk hiding inside interconnected SaaS ecosystems. Companies depend on hundreds of SaaS applications to operate their business. The security threat posed by these interconnected SaaS applications is growing exponentially with major breaches like the Salesloft-Drift Supply Chain attack that impacted over 700 organizations last year. Obsidian Security is launching a new solution that secures the SaaS supply … More →
The post Obsidian Security unveils end-to-end SaaS supply chain security to stop integration-led breaches appeared first on Help Net Security.