Aggregator
CVE-2026-3960 | h2oai h2o-3 up to 3.46.0.9/3.46.0.10 REST API Endpoint /99/ImportSQLTable jdbc:postgresql code injection (EUVD-2026-25205)
Держите крипту? У нас плохие новости. Преступники поняли: выбить пароль силой гораздо проще, чем ломать код
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-39987 Marimo Remote Code Execution Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
International cyber agencies share fresh advice to defend against China-linked covert networks
Defending against China-nexus covert networks of compromised devices
Supporting AI adoption for UK cyber defence
Executive Summary: Defending against China-nexus covert networks of compromised devices
Google Introduces Unique AI Agent Identities in New Gemini Enterprise Platform
Passkeys are more secure than traditional ways to log in
NCSC: Leave passwords in the past - passkeys are the future
TSRC关于AI辅助漏洞挖掘报告的提交规范:每一份漏洞报告,都值得被认真对待
360漏洞云关于AI生成漏洞报告的处置公告
盖茨基金会准备裁员,正在审查与爱泼斯坦的关联
Смартфоны, планшеты и даже машины. В чипах Qualcomm нашли уязвимость, которую почти невозможно устранить
Project Glasswing Proved AI Can Find the Bugs. Who's Going to Fix Them?
小米安全中心关于AI生成漏洞报告的处置公告
马来西亚企业代表团到访360 共探智能经济时代AI安全新路径!
CISA orders feds to patch BlueHammer flaw exploited as zero-day
Lockbit
You must login to view this content