Aggregator
CVE-2017-3273 | Oracle MySQL Server 5.6.34/5.7.16 DDL input validation (Nessus ID 96618 / ID 20029)
CVE-2017-3265 | Oracle MySQL Server 5.5.53/5.6.34/5.7.16 Packaging access control (Nessus ID 96732 / ID 175942)
В Германии задержали предполагаемого главу наркоплощадки Dream Market. Следствие считает, что он менял крипту на золото и отправлял слитки себе домой
Akamai to acquire LayerX for $205 million
Akamai has entered into a definitive agreement to acquire LayerX, a provider of browser-based AI usage control and secure enterprise browser (SEB) technology. LayerX’s solutions will extend Akamai’s protection into the browser, where the majority of enterprise tasks now occur and where today’s workforce engages with generative AI applications, SaaS AI solutions, and AI agents. With this acquisition, Akamai is taking a critical step in the evolution of its zero trust security portfolio and addressing … More →
The post Akamai to acquire LayerX for $205 million appeared first on Help Net Security.
PraisonAI Vulnerability Exploited Within Hours of Public Disclosure
As artificial intelligence frameworks become central to enterprise operations, a critical flaw in a popular AI platform has exposed organizations to serious security risks from threat actors. Within hours of public disclosure, a severe vulnerability in PraisonAI’s legacy API server, tracked as CVE-2026-44338, is already sending shockwaves through the developer community. By shipping with authentication […]
The post PraisonAI Vulnerability Exploited Within Hours of Public Disclosure appeared first on Cyber Security News.
Amazon Redshift JDBC Driver Vulnerabilities Enables Remote Code Execution Attacks
A critical vulnerability in the Amazon Redshift JDBC driver has put enterprise applications at severe risk of Remote Code Execution (RCE). Threat actors can exploit this newly disclosed flaw simply by manipulating database connection URLs. This hidden vulnerability allows attackers to hijack the application process from within, potentially exposing sensitive enterprise data to unauthorized access […]
The post Amazon Redshift JDBC Driver Vulnerabilities Enables Remote Code Execution Attacks appeared first on Cyber Security News.
Shai-Hulud в открытом доступе. Теперь любой желающий может похищать токены GitHub, SSH-ключи и криптокошельки — инструкция прилагается
【安全圈】OpenAI 确认在 TanStack 供应链攻击中出现安全漏洞
【安全圈】Pwn2Own Berlin 2026 首日发放 52.3 万美元奖金,Win11 被攻破 3 次
【安全圈】新型远程控制木马被披露,黑客伪造苹果与雅虎 CDN 域名攻击
Weekly Threat Landscape Digest – Week 20
Privilege Escalation Vulnerability in VMware Fusion Overview: A Time-of-Check to Time-of-Use (TOCTOU) vulnerability exists in a SETUID binary operation within […]
The post Weekly Threat Landscape Digest – Week 20 appeared first on HawkEye.
What 45 Days of Watching Your Own Tools Will Tell You About Your Real Attack Surface
TanStack Supply Chain Attack Hits Two OpenAI Employee Devices, Forces macOS Updates
Thieves unlock stolen iPhones using cheap tools sold on Telegram
Helping a friend recover a stolen phone, Infoblox researchers uncovered a thriving Telegram-based underground marketplace selling unlocking tools and phishing infrastructure used to monetize stolen iPhones. Activation Lock can remotely disable a stolen iPhone and prevent normal resale, with owners also able to lock individual components. Even with those protections, more than 7.35 million iPhones are reportedly stolen each year in the United States alone. “A locked device is almost worthless on the black market, … More →
The post Thieves unlock stolen iPhones using cheap tools sold on Telegram appeared first on Help Net Security.