Aggregator
CVE-2026-2550 | EFM iptime A6004MX 14.18.2 /cgi/timepro.cgi commit_vpncli_file_upload unrestricted upload (EUVD-2026-6098)
Нейросети выходят на «большую дорогу» Ethereum. OpenAI проверила, как ИИ грабит смарт-контракты
CVE-2026-26993 | FlintSH Flare 1.7.1 SVG cross site scripting (GHSA-q8fp-w6m5-4gjm)
CVE-2026-2739 | bn.js up to 5.2.2 toString/divmod infinite loop (ID 186)
CVE-2026-27017 | refraction-networking utls up to 1.8.0 a cryptographic primitive with a risky implementation (GHSA-7m29-f4hw-g2vx)
CVE-2026-26980 | TryGhost up to 6.19.0 sql injection (GHSA-w52v-v783-gw97)
CVE-2026-26977 | Frappe LMS up to 2.44.0 API Endpoint authorization (GHSA-26vf-p39q-frx3)
CVE-2026-26065 | kovidgoyal calibre up to 9.2.x path traversal (GHSA-vmfh-7mr7-pp2w)
CVE-2026-26994 | refraction-networking utls up to 1.6.x RFC 8446 protection mechanism (ID 181)
CVE-2026-26974 | Tygo-van-den-Hurk Slyde up to 0.0.4 node_modules inclusion of functionality from untrusted control sphere (GHSA-w7h5-55jg-cq2f)
CVE-2026-26996 | isaacs minimatch up to 10.2.0 Pattern redos (GHSA-3ppc-4f35-3m26)
CVE-2026-26064 | kovidgoyal calibre up to 9.2.x utils/zipfile.py ZipFile.extractall path traversal (GHSA-72ch-3hqc-pgmp)
CVE-2026-26967 | pjsip up to 2.16 heap-based overflow
CVE-2025-30416 | Acronis Cyber Protect 15/Cyber Protect 16 authorization
Why AISPM Isn’t Enough for the Agentic Era
AI agents have moved from novelty to operational reality, acting autonomously across business systems in ways traditional AI security posture management (AISPM) and IAM can’t fully govern. Learn why risk now emerges at runtime, where existing posture tools fall short, and how Agentic SPM enables continuous discovery, runtime decision control, and auditability for autonomous agents.
The post Why AISPM Isn’t Enough for the Agentic Era appeared first on Security Boulevard.
CVE-2025-30412 | Acronis Cyber Protect 15/Cyber Protect 16 weak authentication
CVE-2025-30411 | Acronis Cyber Protect 15/Cyber Protect 16 weak authentication
The CISO view of fraud risk across the retail payment ecosystem
In this Help Net Security interview, Paul Suarez, VP and CISO at Casey’s, explains how his team manages patching and upgrades for fuel payment systems with long hardware lifecycles. He also discusses risks tied to QR code payments and outlines why loyalty abuse can be hard to spot. Suarez shares how Casey’s monitors payment systems across stores, corporate networks, and third-party processors. How do you manage patching and modernization for fuel-related payment infrastructure that may … More →
The post The CISO view of fraud risk across the retail payment ecosystem appeared first on Help Net Security.