欧盟委员会主席 Ursula von der Leyen 周二表示欧盟将在今年晚些时候对 TikTok 和 Instagram 等平台上的成瘾性设计功能采取行动。此类功能包括了无限滚动、自动播放和推送通知。欧盟委员会最早将在今年夏天公布一项法律提议,目前正在等待 Special Panel of experts on Child Safety Online 的调查报告。
As part of Dark Reading's 20th anniversary special coverage, we profile the CISOs, founders, researchers, criminals, and policymakers who rewrote the enterprise risk playbook.
Why do the Riskiest SOC Alerts Go Unanswered?
Security operations teams are drowning in alerts. But the real problem isn't always alert volume; it's the blind spots. The most dangerous alerts are the ones no one is investigating.
A recent report from The Hacker News examined why certain high-risk alert categories - WAF, DLP, OT/IoT, dark web intelligence, and supply chain signals- consistently
TeamPCP, the threat actor behind the recentsupply chain attack spree, has been linked to the compromise of the npm and PyPI packages from TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI as part of a fresh Mini Shai-Hulud campaign.
The affected npm packages have been modified to include an obfuscated JavaScript file ("router_init.js") that's designed to profile the execution
A vulnerability categorized as critical has been discovered in WP Travel Plugin up to 11.4.0 on WordPress. This vulnerability affects unknown code. Such manipulation leads to sql injection.
This vulnerability is traded as CVE-2026-45218. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Saad Iqbal WP EasyPay Plugin up to 4.3.0 on WordPress. It has been rated as problematic. This affects an unknown part. This manipulation causes insertion of sensitive information into sent data.
This vulnerability appears as CVE-2026-45215. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Xpro Elementor Addons Plugin up to 1.5.1 on WordPress. It has been declared as critical. Affected by this issue is some unknown functionality. The manipulation results in sql injection.
This vulnerability is reported as CVE-2026-45214. The attack can be launched remotely. No exploit exists.