Aggregator
CVE-2026-22401 | Freshio Plugin up to 2.4.2 on WordPress file inclusion
CVE-2025-13454 | Lenovo ThinkPlus TSD303 Configuration Software cleartext transmission
CVE-2025-13453 | Lenovo ThinkPlus TSD303 USB Drive missing encryption
CVE-2025-13455 | Lenovo ThinkPlus TSD303 Configuration Software authentication spoofing
CVE-2025-13154 | Lenovo Vantage SmartPerformanceAddin link following
CVE-2025-14058 | Lenovo Tab M11 TB330FU TB330XU Control Center Settings missing authentication
CVE-2026-0601 | Sonatype Nexus Repository up to 3.87.1 Request cross site scripting
CVE-2026-0600 | Sonatype Nexus Repository up to 3.0.0/3.88.0 Proxy Configuration server-side request forgery
CVE-2026-0421 | Lenovo ThinkPad L13 Gen 6 BIOS Secure Boot return value
CVE-2026-0861 | GNU glibc up to 2.42 integer overflow
JumpCloud introduces AI features to govern shadow AI and autonomous agents
JumpCloud is unveiling new AI capabilities to fuel safe innovation. Organizations can leverage JumpCloud’s platform to accelerate AI adoption. They can ensure compliance and control for all types of identity, human, non-human, and autonomous agents. Generative and agentic AI workflows present vast new opportunities. JumpCloud empowers organizations with intelligent, secure IT to meet them. JumpCloud’s new features allow you to see, secure, and automate AI management in your organization. Organizations can focus on proactive IT … More →
The post JumpCloud introduces AI features to govern shadow AI and autonomous agents appeared first on Help Net Security.
【漏洞通告】Fortinet FortiSIEM phMonitor服务命令注入漏洞(CVE-2025-64155)
Asimily extends Cisco ISE integration to turn device risk into segmentation policy
Asimily announced enhanced microsegmentation capabilities, including new support for Security Group Access Control Lists (SGACL) within Cisco Identity Services Engine (ISE). The release builds on Asimily’s longstanding ISE integration, enabling organizations to translate device intelligence and risk context into enforceable segmentation policies that move beyond visibility to actionable risk reduction. The SGACL integration allows Cisco ISE customers to automatically apply security group policies based on Asimily’s device classification, behavioral analysis, and risk prioritization. By providing … More →
The post Asimily extends Cisco ISE integration to turn device risk into segmentation policy appeared first on Help Net Security.
The Silent Listener: How “Reprompt” Hijacks Microsoft Copilot with One Click
Security analysts at Varonis have unveiled a sophisticated offensive targeting Microsoft’s AI assistant, designated as Reprompt. This maneuver
The post The Silent Listener: How “Reprompt” Hijacks Microsoft Copilot with One Click appeared first on Penetration Testing Tools.
Смерть RedVDS. Microsoft хладнокровно вырезала главную опухоль даркнета
Guarding the Guardian: Horizon3 Unmasks Root RCE in Fortinet FortiSIEM
Security researchers at Horizon3 have disseminated a meticulous deconstruction of a burgeoning critical vulnerability within Fortinet FortiSIEM—a widely
The post Guarding the Guardian: Horizon3 Unmasks Root RCE in Fortinet FortiSIEM appeared first on Penetration Testing Tools.
Critical Code Red: Ransomware Paralyses Belgian Hospital AZ Monica
In the early hours of January 13, a prominent Belgian medical institution was abruptly rendered near-paralyzed. AZ Monica,
The post Critical Code Red: Ransomware Paralyses Belgian Hospital AZ Monica appeared first on Penetration Testing Tools.
Unmasking Gbyte: How One Hacker Exposed the Masters of 2FA-Bypassing Stalkerware
Investigative journalist Maia Arson Crimew disclosed in a recent blog post that in February 2024, she received a
The post Unmasking Gbyte: How One Hacker Exposed the Masters of 2FA-Bypassing Stalkerware appeared first on Penetration Testing Tools.
Microsoft’s 2026 Kickoff: 110+ Patches Fix Active Zero-Days and Office Flaws
Microsoft has inaugurated its first Patch Tuesday of 2026, disseminating a comprehensive suite of mandatory security remediations for
The post Microsoft’s 2026 Kickoff: 110+ Patches Fix Active Zero-Days and Office Flaws appeared first on Penetration Testing Tools.