Aggregator
PicoADSB: An Ultra-Compact All-in-One ADS-B Receiver Now on Kickstarter
1 month 1 week ago
May 15, 2026Over on Kic
美财长贝森特称中美将启动AI安全对话
1 month 1 week ago
美财长贝森特称中美将启动AI安全对话美国财政部长贝森特14日表示,中美两国政府将就AI安全措施启动对话。双方将推进规则制定,防止恐怖组织等 “非国家行为体” 滥用中美先进AI模型。贝森特在接受采访时表
OpenAI Confirms Security Breach Via TanStack npm Supply Chain Attack
1 month 1 week ago
Two employee devices at OpenAI were compromised in a sweeping software supply chain attack targeting TanStack npm, but the AI company confirmed no user data, production systems, or intellectual property were affected. On May 11, 2026 UTC, threat actors launched a campaign dubbed “Mini Shai-Hulud” a coordinated supply chain offensive orchestrated by the TeamPCP extortion […]
The post OpenAI Confirms Security Breach Via TanStack npm Supply Chain Attack appeared first on Cyber Security News.
Guru Baran
Астронавты Apollo могли сгореть заживо в 1972-м — и мы узнали об этом из дневника японского поэта 1204 года
1 month 1 week ago
Солнечные протоны убивают — а мы ищем их следы в кольцах 800-летних деревьев.
npm热门依赖包遭投毒,维护者账号被接管
1 month 1 week ago
2026年5月14日,npm生态中的热门依赖包node-ipc遭受供应链攻击
你真的需要墨水屏设备吗?
1 month 1 week ago
Matrix 首页推荐Matrix 是少数派的写作社区,我们主张分享真实的产品体验,有实用价值的经验与思考。我们会不定期挑选 Matrix 最优质的文章,展示来自用户的最真实的体验和观点。文章代表作者
xAI被指运行着近50台未受监管的燃气轮机
1 month 1 week ago
马斯克旗下 xAI 在其密西西比数据中心运行着近五十台天然气轮机,这些发电厂由于一个漏洞目前不受该州监管。这些发电厂被密西西比州视为 “移动式”,因为它们位于平板拖车上,从而允许它们规避空气污染法规一
速报!GitHub错误率正在快速增加 不过目前状态页还未显示原因
1 month 1 week ago
Хотели обновиться — получили бэкдор. Как так вышло, что node-ipc теперь охотится за паролями разработчиков
1 month 1 week ago
История началась с тихой публикации трёх версий, но быстро превратилась в тревожный сигнал для всей экосистемы.
OpenAI受TanStack供应链攻击影响被窃取数据 基于安全考虑OpenAI再次轮换证书
1 month 1 week ago
Self directed learning
1 month 1 week ago
抢先加入AI时代顶尖安全团队!阿里云2027届实习生招聘来了!
1 month 1 week ago
欢迎投递简历!
缓存投毒导致的 XSS 接管账号
1 month 1 week ago
缓存投毒导致的 XSS 接管账号正文通过缓存投毒导致的 XSS 接管账号。
JVN: Musetheque V4 情報公開 for IPKNOWLEDGEにおける複数の脆弱性
1 month 1 week ago
富士通Japan株式会社が提供するMusetheque V4 情報公開 for IPKNOWLEDGEには、複数の脆弱性が存在します。
Linux的最新漏洞允许非特权用户读取Root拥有的文件
1 month 1 week ago
继Dirty Frag、Fragnesia以及其他最近几天暴露出来的Linux内核漏洞之后,现在最新的漏洞是ssh-keysign-pwn。通过 ssh-keysign-pwn,非特权用户能够读取Ro
CVE-2026-44541 | Ethyca Fides fides.js fides_description cross site scripting
1 month 1 week ago
A vulnerability classified as problematic has been found in Ethyca Fides. Affected by this vulnerability is an unknown functionality of the file fides.js. This manipulation of the argument fides_description causes cross site scripting.
This vulnerability is handled as CVE-2026-44541. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-0432 | AMD Ryzen 4000 Mobile Processors with Radeon Graphics AMD Chipset Driver default permission (EUVD-2026-30497)
1 month 1 week ago
A vulnerability described as critical has been identified in AMD Ryzen 4000 Mobile Processors with Radeon Graphics, Ryzen 7035 Processors with Radeon Graphics, Athlon 3000 Mobile Processors with Radeon Graphics, Ryzen 7040 Mobile Processors with Radeon Graphics, Ryzen 7020 Processors with Radeon Graphics, Ryzen 7045 Mobile Processors with Radeon Graphics, Ryzen 7000 Desktop Processors, Ryzen 3000 Desktop Processors, Ryzen Threadripper PRO 3000 WX-Series Processors, Ryzen 7030 Mobile Processors with Radeon Graphics, Ryzen Threadripper 3000 Processors, Ryzen 9000HX Processors, Ryzen AI 300 Processors, Athlon 3000 Desktop Processors with Radeon Graphics, Ryzen Threadripper PRO 5000 WX-Series Processors, Ryzen Threadripper 7000 Processors, Ryzen Threadripper PRO 7000 WX-Series Processors, Ryzen 8000 Desktop Processors, Ryzen 9000 Desktop Processors, Ryzen 5000 Mobile Processors with Radeon Graphics, Ryzen 4000 Desktop Processors, Ryzen 5000 Desktop Processors, Ryzen 5000 Desktop Processors with Radeon Graphics, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen 6000 Processors with Radeon Graphics, Ryzen AI Max 300 Processors, Ryzen AI 400 Processors, Ryzen Embedded R1000 Processors, Ryzen Embedded R2000 Processors, Ryzen Embedded V1000 Processors, Ryzen Embedded V2000 Processors, EPYC Embedded 8004 Processors, Ryzen Embedded 8000 Processors, Ryzen Embedded 7000 Processors, EPYC Embedded 9005 Processors, Ryzen Embedded 9000 Processors, EPYC 9004 Processors, EPYC 7003 Processors, EPYC 7002 Processors, EPYC 7001 Processors, EPYC 4004 Processors, EPYC 9005 Processors, Instinct MI300A Processors, EPYC 9V64H Processor, EPYC 8004 Processors and EPYC 4005 Processors. Affected is an unknown function of the component AMD Chipset Driver. The manipulation results in incorrect default permissions.
This vulnerability is known as CVE-2026-0432. Attacking locally is a requirement. No exploit is available.
vuldb.com
CVE-2026-8612 | OALDERS WWW::Mechanize::Cached up to 1.x on Perl HTTP Response /tmp/FileCache get permission assignment
1 month 1 week ago
A vulnerability marked as problematic has been reported in OALDERS WWW::Mechanize::Cached up to 1.x on Perl. This impacts the function get of the file /tmp/FileCache of the component HTTP Response Handler. The manipulation leads to incorrect permission assignment.
This vulnerability is traded as CVE-2026-8612. An attack has to be approached locally. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-52540 | AMD Ryzen 7035 Processors with Radeon Graphics Management Frame out-of-bounds write (EUVD-2025-209864)
1 month 1 week ago
A vulnerability labeled as critical has been found in AMD Ryzen 7035 Processors with Radeon Graphics, Ryzen 7040 Mobile Processors with Radeon Graphics, Ryzen 8040 Mobile Processors with Radeon Graphics, Ryzen 6000 Processors with Radeon Graphics and Ryzen Embedded 8000 Processors. This affects an unknown function of the component Management Frame Handler. Executing a manipulation can lead to out-of-bounds write.
This vulnerability appears as CVE-2025-52540. The attack requires local access. There is no available exploit.
The affected component should be upgraded.
vuldb.com