Aggregator
2026软件安全赛半决赛PWN Robo_admin WP fix&break
2025ciscn决赛ez_orw
2025ccb决赛interpreter
«Мул» как услуга. Мошенники открыли «банк» со службой поддержки — и он работает лучше, чем настоящий
Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security
Designing secure access with ZTNA
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code Vulnerability
- CVE-2026-45321 TanStack Unspecified Vulnerability
- CVE-2026-48027 Nx Console Embedded Malicious Code Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
FBI warns of in-person data theft attacks from extortion gang
Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware
Attackers are hosting counterfeit installers and plugins on GitHub and SourceForge that pose as widely used software, including ChatGPT, Claude, AutoTune, Kontakt, Ableton Live, and ZENOLOGY. The downloads deliver a backdoor called DinDoor, which then loads a remote access Trojan built on the Deno JavaScript runtime, according to Malwarebytes. Compromised YouTube channels push victims toward the malicious repositories. The videos promoting the fake tools have accumulated more than 50,000 views. The attackers rotate through GitHub … More →
The post Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware appeared first on Help Net Security.
GlassWorm Malware Takedown Disrupts Developer Supply Chain Attack Infrastructure
3 SOC Steps that Shut Down Incident Risks Early
How cybersecurity firms took down Glassworm botnet in one shot
Криптоинвестор купил биткоин по $442. Продавать не стал — уничтожил по $77 000
Thousands of Fake FIFA Domains Target World Cup Fans
Inside ANY.RUN’s 10-Year Evolution: An Interview with CEO Aleksey Lapshin
What happens when a malware analyst decides to build a product he always wished he had? The case of ANY.RUN tells us that ten years later it may turn into an industry-standard solution, adopted by 74 Fortune 100 companies. Celebrating a decade of ANY.RUN, CEO Aleksey Lapshin shared his perspective on the evolution of the company, […]
The post Inside ANY.RUN’s 10-Year Evolution: An Interview with CEO Aleksey Lapshin appeared first on ANY.RUN's Cybersecurity Blog.
Apple makes its quantum-resistant encryption open source
Apple has published its post-quantum cryptography implementations in corecrypto, together with mathematical proofs and verification tools for independent expert evaluation, allowing external researchers to review the work and reproduce the company’s analysis. Post-quantum cryptography is designed to protect encrypted data from future quantum computers that could break widely used public-key encryption algorithms. A new approach to formal verification of Apple corecrypto (Source: Apple) Corecrypto, the cryptography library used throughout Apple operating systems and services, provides … More →
The post Apple makes its quantum-resistant encryption open source appeared first on Help Net Security.