Aggregator
Six new dnsmasq vulnerabilities open the door to DNS cache poisoning, local root
Recent disclosures have revealed that open-source networking tool dnsmasq is grappling with a serious set of vulnerabilities. The problems span memory safety and input validation, with researchers identifying heap buffer overflows, heap corruption, and code execution bugs among the issues. Taken together, the security flaws open the door to various attacks: poisoning cached DNS entries, slipping past security controls, crashing the dnsmasq process, and in certain scenarios, escalating privileges locally. To address all of this, … More →
The post Six new dnsmasq vulnerabilities open the door to DNS cache poisoning, local root appeared first on Help Net Security.
从日入$10到不以物喜的修行:阿小信的自由职业周记(2026W18-19)
英特尔或将获得特斯拉AI6芯片生产订单
安全与发展:《智能体规范应用与创新发展实施意见》与《审慎采用指南CAAS》的理解和比较
Claude’s Chrome Extension Vulnerability Allows Malicious Extensions to Steal Gmail and Drive Data
Researchers have exposed a catastrophic vulnerability hiding inside the “Claude in Chrome” extension. By weaponizing an otherwise harmless, zero-permission extension, invisible attackers can completely hijack the trusted AI assistant. Transform it into a malicious puppet that silently pillages private Gmail messages, restricted Google Drive documents, and secret GitHub repositories. This terrifying blind spot exposes the […]
The post Claude’s Chrome Extension Vulnerability Allows Malicious Extensions to Steal Gmail and Drive Data appeared first on Cyber Security News.
信息安全漏洞周报(2026年第19期)
50+ дыр в iPhone, 70 в Mac — крупнейшая волна патчей Apple в эпоху iOS 26
Why Agentic AI Is Security's Next Blind Spot
Why Agentic AI Is Security's Next Blind Spot
中国附条件批准腾讯收购喜马拉雅股权案
Digg 再次尝试重启,将转向 AI 新闻聚合
告别静态标签:DarkAtlas发布“六维六层”网络威胁归因模型
首次发现!AI生成零日漏洞利用工具并实施网络攻击
告别静态标签:DarkAtlas发布“六维六层”网络威胁归因模型
首次发现!AI生成零日漏洞利用工具并实施网络攻击
Škoda confirms unauthorized access to its online shop
Car manufacturer Škoda discovered that attackers had exploited a vulnerability in its online shop software and gained temporary unauthorized access to the system. What happened? After discovering the incident, the company took the shop offline as a precautionary measure, fixed the vulnerability, referred the incident to a specialized IT forensics team for technical analysis, and reported it to the data protection supervisory authority. “Technical analysis has revealed that access to data stored in the shop … More →
The post Škoda confirms unauthorized access to its online shop appeared first on Help Net Security.