Aggregator
Doctor Lobby Urges Congress to Set AI Chatbot Safeguards
1 month 3 weeks ago
AMA Wants Privacy, Security AI Tool Protections, Especially in Mental Health
The American Medical Association says using artificial intelligence chatbots carries risks - including data privacy and security breaches - and the largest U.S. professional association for physicians and medical students is urging Congress to take action to protect patients from potential harm.
The American Medical Association says using artificial intelligence chatbots carries risks - including data privacy and security breaches - and the largest U.S. professional association for physicians and medical students is urging Congress to take action to protect patients from potential harm.
Germany Tries, Tries Again With ISP Data Retention Mandate
1 month 3 weeks ago
Berlin Proposes 3 Month Requirement to Store IP Addresses
The German government says it's unlocked the secret to passing a law that would require internet service providers to keep customer data without running afoul of privacy and security concerns that sunk earlier attempts. Critics say that's impossible
The German government says it's unlocked the secret to passing a law that would require internet service providers to keep customer data without running afoul of privacy and security concerns that sunk earlier attempts. Critics say that's impossible
Cloudsmith Raises $72M for Software Supply-Chain Security
1 month 3 weeks ago
Recent Package Compromises Pushed Software Component Trust to the Security Agenda
Cloudsmith raised a $72 million Series C led by TCV to expand policy enforcement, auditability and real-time package risk analysis as CISOs focus more closely on software supply-chain threats tied to open-source dependencies, AI-assisted development and compromised artifacts.
Cloudsmith raised a $72 million Series C led by TCV to expand policy enforcement, auditability and real-time package risk analysis as CISOs focus more closely on software supply-chain threats tied to open-source dependencies, AI-assisted development and compromised artifacts.
Breach Roundup: Myanmar Scam Compound Managers Charged
1 month 3 weeks ago
Also, Europol Cracks DDoS Networks, Mythos Finds Bugs, France Portal Hit
This week, scam compounds. Attackers exploit flaws pre-disclosure. A crackdown on DDoS-for-hire. No Mythos for CISA, yes for Mozilla. France ID portal breach. Israeli and Venezuelan critical infrastructure targeted. Russian hacking in Ukraine. An Apache flaw. A ransomware negotiator aided BlackCat.
This week, scam compounds. Attackers exploit flaws pre-disclosure. A crackdown on DDoS-for-hire. No Mythos for CISA, yes for Mozilla. France ID portal breach. Israeli and Venezuelan critical infrastructure targeted. Russian hacking in Ukraine. An Apache flaw. A ransomware negotiator aided BlackCat.
«Кошмар для приватности 2.0». OpenAI выпустила Chronicle — функцию, которая делает снимки экрана, как печально известный Microsoft Recall
1 month 3 weeks ago
Снимки экрана хранятся локально шесть часов, затем удаляются — но извлеченный текст может остаться надолго.
CVE-2026-41339 | OpenClaw up to 2026.4.1 exposure of sensitive system information to an unauthorized control sphere (GHSA-2f7j-rp58-mr42)
1 month 3 weeks ago
A vulnerability identified as problematic has been detected in OpenClaw up to 2026.4.1. Affected by this issue is some unknown functionality. This manipulation causes exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is registered as CVE-2026-41339. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-41337 | OpenClaw up to 2026.3.30 toctou (GHSA-89r3-6x4j-v7wf)
1 month 3 weeks ago
A vulnerability categorized as problematic has been discovered in OpenClaw up to 2026.3.30. Affected by this vulnerability is an unknown functionality. The manipulation results in time-of-check time-of-use.
This vulnerability is cataloged as CVE-2026-41337. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-41354 | OpenClaw up to 2026.4.1 Silent Message name resolution (GHSA-rxmx-g7hr-8mx4)
1 month 3 weeks ago
A vulnerability was found in OpenClaw up to 2026.4.1. It has been rated as problematic. Affected is an unknown function of the component Silent Message Handler. The manipulation leads to incorrectly-resolved name.
This vulnerability is listed as CVE-2026-41354. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-41351 | OpenClaw up to 2026.3.30 Signature Verification authentication replay (GHSA-37v6-fxx8-xjmx)
1 month 3 weeks ago
A vulnerability was found in OpenClaw up to 2026.3.30. It has been declared as critical. This impacts an unknown function of the component Signature Verification. Executing a manipulation can lead to authentication bypass by capture-replay.
This vulnerability is tracked as CVE-2026-41351. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-41340 | OpenClaw up to 2026.3.30 Telegram Legacy state distinction (GHSA-f693-58pc-2gfr)
1 month 3 weeks ago
A vulnerability was found in OpenClaw up to 2026.3.30. It has been classified as critical. This affects an unknown function of the component Telegram Legacy Handler. Performing a manipulation results in incomplete internal state distinction.
This vulnerability is identified as CVE-2026-41340. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-41347 | OpenClaw up to 2026.3.30 validationHTTP Operator Endpoint cross-site request forgery (GHSA-mhr7-2xmv-4c4q)
1 month 3 weeks ago
A vulnerability was found in OpenClaw up to 2026.3.30 and classified as problematic. The impacted element is an unknown function of the component validationHTTP Operator Endpoint. Such manipulation leads to cross-site request forgery.
This vulnerability is referenced as CVE-2026-41347. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-41344 | OpenClaw up to 2026.3.27 Gateway Call /verbose authorization (GHSA-5h2w-qmfp-ggp6)
1 month 3 weeks ago
A vulnerability has been found in OpenClaw up to 2026.3.27 and classified as critical. The affected element is an unknown function of the file /verbose of the component Gateway Call Handler. This manipulation causes incorrect authorization.
The identification of this vulnerability is CVE-2026-41344. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-41350 | OpenClaw up to 2026.3.30 session_status authorization (GHSA-fwjq-xwfj-gv75)
1 month 3 weeks ago
A vulnerability, which was classified as problematic, was found in OpenClaw up to 2026.3.30. Impacted is the function session_status. The manipulation results in incorrect authorization.
This vulnerability was named CVE-2026-41350. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-41336 | OpenClaw up to 2026.3.30 Environment Variable OPENCLAW_BUNDLED_HOOKS_DIR inclusion of functionality from untrusted control sphere (GHSA-3qpv-xf3v-mm45)
1 month 3 weeks ago
A vulnerability, which was classified as problematic, has been found in OpenClaw up to 2026.3.30. This issue affects some unknown processing of the component Environment Variable Handler. The manipulation of the argument OPENCLAW_BUNDLED_HOOKS_DIR leads to inclusion of functionality from untrusted control sphere.
This vulnerability is uniquely identified as CVE-2026-41336. Local access is required to approach this attack. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-41353 | OpenClaw up to 2026.3.21 external control of assumed-immutable web parameter (GHSA-h5hg-h7rr-gpf3)
1 month 3 weeks ago
A vulnerability classified as critical was found in OpenClaw up to 2026.3.21. This vulnerability affects unknown code. Executing a manipulation can lead to external control of assumed-immutable web parameter.
This vulnerability is handled as CVE-2026-41353. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
Ubuntu 26.04 LTS 释出
1 month 3 weeks ago
Canonical 释出了代号为 Resolute Raccoon 的 Ubuntu 26.04 LTS。同时释出的还有衍生版本 Edubuntu、Kubuntu、Lubuntu、Ubuntu Budgie、Ubuntu Cinnamon、Ubuntu Kylin、Ubuntu Studio、Ubuntu Unity 和 Xubuntu。Ubuntu Desktop、Ubuntu Server、Ubuntu Cloud、Ubuntu WSL 和 Ubuntu Core 将获得五年的支持,其余版本获得三年的支持,付费扩展支持 ESM (Expanded Security Maintenance)为十年 。Ubuntu 26.04 采用最新的 Linux 7.0 kernel,GNOME 50 桌面环境,引入了基于 TPM 的全盘加密,GStreamer 1.28,沙盒图形加载,Chrony 4.8,等等。
CVE-2026-41345 | OpenClaw up to 2026.3.30 Header Authorization insufficiently protected credentials (GHSA-68v4-hmwv-f43h)
1 month 3 weeks ago
A vulnerability classified as problematic has been found in OpenClaw up to 2026.3.30. This affects an unknown part of the component Header Handler. Performing a manipulation of the argument Authorization results in insufficiently protected credentials.
This vulnerability is known as CVE-2026-41345. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-41338 | OpenClaw up to 2026.3.30 apply_patch/remove/mkdir toctou (GHSA-rm5c-4rmf-vvhw)
1 month 3 weeks ago
A vulnerability described as problematic has been identified in OpenClaw up to 2026.3.30. Affected by this issue is the function apply_patch/remove/mkdir. Such manipulation leads to time-of-check time-of-use.
This vulnerability is traded as CVE-2026-41338. An attack has to be approached locally. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-41335 | OpenClaw up to 2026.3.30 Control Interface exposure of sensitive system information to an unauthorized control sphere (GHSA-hr8g-2q7x-3f4w)
1 month 3 weeks ago
A vulnerability marked as problematic has been reported in OpenClaw up to 2026.3.30. Affected by this vulnerability is an unknown functionality of the component Control Interface. This manipulation causes exposure of sensitive system information to an unauthorized control sphere.
This vulnerability appears as CVE-2026-41335. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com