Aggregator
iPhone Air 暴降 2500 开卖;特斯拉停用 AP,全力推 FSD;网友用 2 吨 SIM 卡练出 191 克黄金 | 极客早知道
2 months 3 weeks ago
· OpenAI 靠 API 业务月增超 10 亿美元年化收入
ISMG Editors: How Deepfakes Are Breaking Digital Trust
2 months 3 weeks ago
Also: How Non-Human Identities Redefine Security; the Delinea-StrongDM Deal
In this week's panel, four editors discussed how deepfakes are reshaping digital Know Your Customer practices, what the rise of non-human identities means for CISOs and what Delinea's acquisition of StrongDM tells us about where the privileged access market is heading.
In this week's panel, four editors discussed how deepfakes are reshaping digital Know Your Customer practices, what the rise of non-human identities means for CISOs and what Delinea's acquisition of StrongDM tells us about where the privileged access market is heading.
Microsoft Confirms Court-Ordered BitLocker Key Releases
2 months 3 weeks ago
FBI Accessed Encrypted Windows Devices Via BitLocker Keys, Microsoft Says
Microsoft confirmed it handed over BitLocker recovery keys to the FBI in 2025 under court order, raising concerns over cloud-stored encryption keys and whether default designs that prioritize recovery convenience and efficiency weaken user control and security.
Microsoft confirmed it handed over BitLocker recovery keys to the FBI in 2025 under court order, raising concerns over cloud-stored encryption keys and whether default designs that prioritize recovery convenience and efficiency weaken user control and security.
ISMG, CyCube Join Forces to Better Train AI-Era Defenders
2 months 3 weeks ago
Partnership With Israeli Startup Brings Real-World Threat Labs to Security Training
ISMG has teamed with CyCube to strengthen CyberEd.io's hands-on cyber training platform. The strategic investment aims to deliver personalized, adaptive labs and assessments that help security teams respond to evolving threats fueled by generative and agentic AI.
ISMG has teamed with CyCube to strengthen CyberEd.io's hands-on cyber training platform. The strategic investment aims to deliver personalized, adaptive labs and assessments that help security teams respond to evolving threats fueled by generative and agentic AI.
Audio Accessory Flaw Converts Headphones Into Spy Tool
2 months 3 weeks ago
'WhisperPair' Flaw Likely to Endure for Years
A hacker could secretly record phone conversations, track users' locations and blast music through headphones due to a flaw in implementations of a Google-developed low-energy technology for discovering nearby Bluetooth devices.
A hacker could secretly record phone conversations, track users' locations and blast music through headphones due to a flaw in implementations of a Google-developed low-energy technology for discovering nearby Bluetooth devices.
2025 Was a Wake-up Call to Protect Human Decisions, Not Just Systems
2 months 3 weeks ago
Cybersecurity must shift from solely protecting systems to safeguarding human decision-making under uncertainty and system failures.
Rashmi Tallapragada
AI如何重塑情报工作
2 months 3 weeks ago
从冷战时期的人海战术,到数字时代的信息海洋,情报工作正迎来新一轮范式转变。人工智能(AI)的崛起既为情报分析赋能,也带来前所未有的挑战。
CVE-2026-24399 | chattermate chat up to 1.0.8 LocalStorage cross site scripting (EUVD-2026-4613)
2 months 3 weeks ago
A vulnerability labeled as problematic has been found in chattermate chat up to 1.0.8. Affected by this issue is some unknown functionality of the component LocalStorage Handler. Executing a manipulation can lead to cross site scripting.
This vulnerability is tracked as CVE-2026-24399. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-22586 | Salesforce Marketing Cloud Engagement hard-coded key (EUVD-2026-4597)
2 months 3 weeks ago
A vulnerability identified as problematic has been detected in Salesforce Marketing Cloud Engagement. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in use of hard-coded cryptographic key
.
This vulnerability is identified as CVE-2026-22586. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-22585 | Salesforce Marketing Cloud Engagement risky encryption (EUVD-2026-4595)
2 months 3 weeks ago
A vulnerability categorized as problematic has been discovered in Salesforce Marketing Cloud Engagement. Affected is an unknown function. Such manipulation leads to risky cryptographic algorithm.
This vulnerability is referenced as CVE-2026-22585. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-22583 | Salesforce Marketing Cloud Engagement CloudPagesUrl argument injection (EUVD-2026-4596)
2 months 3 weeks ago
A vulnerability was found in Salesforce Marketing Cloud Engagement. It has been rated as critical. This impacts an unknown function of the component CloudPagesUrl. This manipulation causes argument injection.
The identification of this vulnerability is CVE-2026-22583. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-22582 | Salesforce Marketing Cloud Engagement MicrositeUrl argument injection (EUVD-2026-4594)
2 months 3 weeks ago
A vulnerability was found in Salesforce Marketing Cloud Engagement. It has been declared as critical. This affects an unknown function of the component MicrositeUrl. The manipulation results in argument injection.
This vulnerability was named CVE-2026-22582. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
11-Year-Old critical telnetd flaw found in GNU InetUtils (CVE-2026-24061)
2 months 3 weeks ago
Critical telnetd flaw CVE-2026-24061 (CVSS 9.8) affects all GNU InetUtils versions 1.9.3–2.7 and went unnoticed for nearly 11 years. A critical vulnerability, tracked as CVE-2026-24061 (CVSS score of 9.8), in the GNU InetUtils telnet daemon (telnetd) impacts all versions from 1.9.3 to 2.7. The vulnerability can be exploited to gain root access on affected systems. […]
Pierluigi Paganini
CVE-2026-24474 | DioxusLabs components use_animated_open eval injection (GHSA-34pj-292j-xr69)
2 months 3 weeks ago
A vulnerability was found in DioxusLabs components. It has been classified as critical. The impacted element is the function use_animated_open. The manipulation leads to improper neutralization of directives in dynamically evaluated code.
This vulnerability is uniquely identified as CVE-2026-24474. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2026-24139 | franklioxygen MyTube up to 1.7.78 Database Export Endpoint authorization (GHSA-hhc3-8q8c-89q7)
2 months 3 weeks ago
A vulnerability was found in franklioxygen MyTube up to 1.7.78 and classified as critical. The affected element is an unknown function of the component Database Export Endpoint. Executing a manipulation can lead to missing authorization.
This vulnerability is handled as CVE-2026-24139. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-24140 | franklioxygen MyTube up to 1.7.78 Setting saveSettings dynamically-determined object attributes (GHSA-c938-x24g-fxcx)
2 months 3 weeks ago
A vulnerability has been found in franklioxygen MyTube up to 1.7.78 and classified as problematic. Impacted is the function saveSettings of the component Setting Handler. Performing a manipulation results in dynamically-determined object attributes.
This vulnerability is known as CVE-2026-24140. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2026-24136 | Saleor up to 3.20.109/3.21.44/3.22.28 order authorization (GHSA-r6fj-f4r9-36gr)
2 months 3 weeks ago
A vulnerability, which was classified as problematic, was found in Saleor up to 3.20.109/3.21.44/3.22.28. This issue affects the function order. Such manipulation leads to authorization bypass.
This vulnerability is traded as CVE-2026-24136. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2025-27821 | Apache HDFS Native Client up to 3.4.1 URI Parser out-of-bounds write
2 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Apache HDFS Native Client up to 3.4.1. This vulnerability affects unknown code of the component URI Parser. This manipulation causes out-of-bounds write.
This vulnerability appears as CVE-2025-27821. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-13205 | SurveyJS Plugin up to 1.12.20 on WordPress SurveyJS_CloneSurvey cross-site request forgery (EUVD-2026-4559)
2 months 3 weeks ago
A vulnerability classified as problematic was found in SurveyJS Plugin up to 1.12.20 on WordPress. This affects the function SurveyJS_CloneSurvey. The manipulation results in cross-site request forgery.
This vulnerability is reported as CVE-2025-13205. The attack can be launched remotely. No exploit exists.
vuldb.com