Aggregator
CVE-2026-35630 | OpenClaw up to 2026.5.17 authorization (GHSA-mgq6-vr84-7m2j)
CVE-2026-45663 | dokploy up to 0.29.1 destinationPath command injection (GHSA-9m66-74x3-5mwr)
CVE-2026-45662 | dokploy up to 0.29.0 registry.ts shEscape os command injection (GHSA-827c-7x62-29jq)
CVE-2026-35673 | OpenClaw up to 2026.4.28 authorization (GHSA-hcm3-8f6r-6xwg)
CVE-2026-34507 | OpenClaw up to 2026.4.28 QQBot Admin Command authorization (GHSA-w4v6-g3wm-w36c)
英伟达税
Ransomware Uses SYSTEM Scheduled Task to Encrypt Local Drives With Elevated Privileges
A newly analyzed ransomware strain called The Gentlemen is raising serious alarms across the cybersecurity community. Built in the Go programming language and obfuscated with a tool called Garble, it combines powerful per-file encryption with an aggressive ability to spread itself silently across entire networks without any human intervention. Organizations in education, healthcare, transportation, and […]
The post Ransomware Uses SYSTEM Scheduled Task to Encrypt Local Drives With Elevated Privileges appeared first on Cyber Security News.
SecWiki News 2026-05-29 Review
将遏制网络犯罪的关口前移 by ourren
AI 渗透测试 Agent 的 Harness 工程演进、防御与我的思考 by ourren
更多最新文章,请访问SecWiki
Flathub 禁止 AI 生成的应用
JINX-0164 Threat Actor Using LinkedIn Social Engineering to Deploy Custom macOS Malware
A new threat actor tracked as JINX-0164 has been running calculated attacks against cryptocurrency organizations, using LinkedIn profiles to lure developers into downloading custom macOS malware. Active since at least mid-2025, the group has combined social engineering, credential theft, and supply chain sabotage into a seamless operation that puts the entire software development pipeline at […]
The post JINX-0164 Threat Actor Using LinkedIn Social Engineering to Deploy Custom macOS Malware appeared first on Cyber Security News.
Google 恨你和我
Attackers Abuse Trusted Developer Tooling to Exfiltrate Source Code and Secrets
A wave of sophisticated supply chain attacks has put millions of software developers on high alert, with threat actors turning everyday developer tools into weapons for stealing credentials, cloud tokens, and source code. What makes these campaigns especially alarming is how they exploit the very systems developers trust most: their editors, automated pipelines, and version […]
The post Attackers Abuse Trusted Developer Tooling to Exfiltrate Source Code and Secrets appeared first on Cyber Security News.
Frontier artificial intelligence (ITSAP.10.050)
Argentine Healthcare Provider Swiss Medical Listed in Alleged 458K-Record Member Data Sale
French Real-Estate Co-op Platform Amepi Hit by Alleged 6K-Record Leak
From 200 CVEs to Actionable Fixes – DockSec Brings AI to Container Security
Ask any developer who has run a container image scan what happens next, and you will hear the same story. The scanner returns 200 CVEs. Most are noise. A handful are real. The report gets closed, the image ships, and the vulnerabilities go with it. That gap between finding a problem and fixing it is […]
The post From 200 CVEs to Actionable Fixes – DockSec Brings AI to Container Security appeared first on Cyber Security News.
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
The Good, the Bad and the Ugly in Cybersecurity – Week 22
Malicious NuGet Package as Sicoob SDK Exfiltrates Banking Passwords
A newly discovered malicious NuGet package masquerading as an official Sicoob software development kit (SDK) has been caught exfiltrating highly sensitive banking credentials, raising serious concerns about software supply chain security in financial ecosystems. The package, published under the name “Sicoob. Sdk,” targeted developers building integrations with Brazil’s Sicoob banking APIs and silently harvested authentication […]
The post Malicious NuGet Package as Sicoob SDK Exfiltrates Banking Passwords appeared first on Cyber Security News.