Aggregator
CVE-2026-1528 | undici up to 6.23.x/7.23.x WebSocket Frame uncaught exception (EUVD-2026-11703 / Nessus ID 302066)
CVE-2026-2229 | undici up to 6.24.0 isValidClientWindowBits uncaught exception (EUVD-2026-11704 / Nessus ID 302068)
CVE-2026-1526 | undici up to 6.23.0 WebSocket decompress data amplification (Nessus ID 302064 / WID-SEC-2026-0933)
CVE-2026-1525 | undici 1.1 Strict HTTP Parser request smuggling (GHSA-2mjp-6q6p-2qxm / EUVD-2026-11685)
CVE-2026-2123 | OpenText Operations Agent up to 12.29 on Windows insufficient permissions or privileges (EUVD-2026-17534)
CVE-2026-30278 | Aviation Navigation 35.33 privilege escalation (EUVD-2026-17538)
CVE-2026-30277 | TA UTAX Mobile Print App 3.7.2.251001 privilege escalation (EUVD-2026-17536)
CVE-2026-5206 | code-projects Simple Gym Management System 1.0 Payment sql injection (EUVD-2026-17577)
CVE-2026-30282 | UXGROUP Cast to TV Screen Mirroring 2.2.77 privilege escalation (EUVD-2026-17542)
CVE-2026-30283 | PEAKSEL NIS Animal Sounds and Ringtones 1.3.0 File Import privilege escalation (EUVD-2026-17544)
CVE-2026-30279 | Squareapps My Location Travel Timeline 11.80 privilege escalation (EUVD-2026-17540)
Technical Advisory: Axios npm Supply Chain Attack – Cross-Platform RAT Deployed via Compromised Maintainer Account
[CRITICAL] | Active RAT | Malicious npm versions removed | Assess all systems that ran npm install during exposure window
The post Technical Advisory: Axios npm Supply Chain Attack – Cross-Platform RAT Deployed via Compromised Maintainer Account appeared first on Security Boulevard.
Axios Compromise on npm Introduces Hidden Malicious Package
A newly discovered software supply chain attack targeting the npm ecosystem briefly compromised one of the most widely used JavaScript libraries in the world.
The post Axios Compromise on npm Introduces Hidden Malicious Package appeared first on Security Boulevard.
Flipping the Script: The Premiere of ‘The Women in Security’ Documentary at RSAC
The cybersecurity industry has long grappled with a significant representation gap, but a new documentary premiering at RSAC 2026 is working to change the conversation. In this interview from Broadcast Alley, Techstrong Group’s Jon Swartz speaks with Aarti Gadhia and Kristen Rank about The Women in Security, a film five years in the making and..
The post Flipping the Script: The Premiere of ‘The Women in Security’ Documentary at RSAC appeared first on Security Boulevard.
保姆级讲解CC1-7(跟踪代码调试+讲解)
ciscn及长城杯半决赛回顾
Google's Vertex AI Has an Over-Privileged Problem
Cursor 代码审计 Skill 编写指南
Synthetic data is all you need for Reinforcement Learning
We used Tonic Fabricate to generate a fully synthetic email corpus, then RL fine-tuned an open-source model against it. The result: it beat o3 on real Enron emails — without ever seeing a real email.
The post Synthetic data is all you need for Reinforcement Learning appeared first on Security Boulevard.