Aggregator
火绒安全解决方案|御险于未然 互联网企业勒索防护解决方案
2 months 1 week ago
火绒安全解决方案|御险于未然 互联网企业勒索防护解决方案
Хотели обмануть систему, а получили кирпич. Tesla жестко наказала 100000 автовладельцев за взлом электроники
2 months 1 week ago
Как удаленно превратить современный электрокар в обычную машину.
上周关注度较高的产品安全漏洞(20260406-20260412)
2 months 1 week ago
上周关注度较高的产品安全漏洞(20260406-20260412)
CNVD漏洞周报2026年第14期
2 months 1 week ago
国家信息安全漏洞共享平台(以下简称CNVD)本周共收集、整理信息安全漏洞583个,其中高危漏洞300个、中危漏洞238个、低危漏洞45个。
CVE-2026-35628 | OpenClaw up to 2026.3.24 excessive authentication (GHSA-vcx4-4qxg-mfp4 / WID-SEC-2026-0884)
2 months 1 week ago
A vulnerability was found in OpenClaw up to 2026.3.24. It has been classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper restriction of excessive authentication attempts.
This vulnerability is listed as CVE-2026-35628. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-35625 | OpenClaw up to 2026.3.24 operator.admin incorrect privileged apis (GHSA-fqw4-mph7-2vr8 / WID-SEC-2026-0884)
2 months 1 week ago
A vulnerability marked as problematic has been reported in OpenClaw up to 2026.3.24. Affected is the function operator.admin. This manipulation causes incorrect use of privileged apis.
This vulnerability appears as CVE-2026-35625. The attack requires local access. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-35617 | OpenClaw up to 2026.3.24 Policy Enforcement reliance on untrusted inputs in a security decision (GHSA-52q4-3xjc-6778 / WID-SEC-2026-0884)
2 months 1 week ago
A vulnerability marked as problematic has been reported in OpenClaw up to 2026.3.24. This issue affects some unknown processing of the component Policy Enforcement Handler. Performing a manipulation results in reliance on untrusted inputs in a security decision.
This vulnerability is known as CVE-2026-35617. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-34512 | OpenClaw up to 2026.3.24 kill killSubagentRunAdmin authorization (GHSA-9p93-7j67-5pc2 / WID-SEC-2026-0884)
2 months 1 week ago
A vulnerability, which was classified as problematic, has been found in OpenClaw up to 2026.3.24. Affected by this vulnerability is the function killSubagentRunAdmin of the file /sessions/:sessionKey/kill. Performing a manipulation results in incorrect authorization.
This vulnerability was named CVE-2026-34512. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-35670 | OpenClaw up to 2026.3.21 reliance on untrusted inputs in a security decision (GHSA-wv46-v6xc-2qhf / WID-SEC-2026-0856)
2 months 1 week ago
A vulnerability marked as problematic has been reported in OpenClaw up to 2026.3.21. This issue affects some unknown processing. This manipulation causes reliance on untrusted inputs in a security decision.
The identification of this vulnerability is CVE-2026-35670. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-35660 | OpenClaw up to 2026.3.22 New Message /reset authorization (GHSA-wq58-2pvg-5h4f / WID-SEC-2026-0856)
2 months 1 week ago
A vulnerability, which was classified as problematic, was found in OpenClaw up to 2026.3.22. This vulnerability affects unknown code of the file /reset of the component New Message Handler. Such manipulation leads to missing authorization.
This vulnerability is documented as CVE-2026-35660. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-35666 | OpenClaw up to 2026.3.21 /usr/bin/time name resolution (GHSA-qm9x-v7cx-7rq4 / WID-SEC-2026-0856)
2 months 1 week ago
A vulnerability labeled as critical has been found in OpenClaw up to 2026.3.21. This vulnerability affects unknown code of the file /usr/bin/time. The manipulation results in incorrectly-resolved name.
This vulnerability was named CVE-2026-35666. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-35656 | OpenClaw up to 2026.3.21 Header X-Forwarded-For authentication spoofing (GHSA-844j-xrrq-wgh4 / WID-SEC-2026-0856)
2 months 1 week ago
A vulnerability labeled as critical has been found in OpenClaw up to 2026.3.21. Impacted is an unknown function of the component Header Handler. The manipulation of the argument X-Forwarded-For results in authentication bypass by spoofing.
This vulnerability is identified as CVE-2026-35656. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-35659 | OpenClaw up to 2026.3.21 data authenticity (GHSA-rvqr-hrcc-j9vv / WID-SEC-2026-0856)
2 months 1 week ago
A vulnerability classified as problematic was found in OpenClaw up to 2026.3.21. Affected by this issue is some unknown functionality. The manipulation results in insufficient verification of data authenticity.
This vulnerability is cataloged as CVE-2026-35659. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-35658 | OpenClaw up to 2026.3.1 Image Parser exposure of resource (GHSA-cfp9-w5v9-3q4h / WID-SEC-2026-0856)
2 months 1 week ago
A vulnerability has been found in OpenClaw up to 2026.3.1 and classified as problematic. The impacted element is an unknown function of the component Image Parser. The manipulation leads to exposure of resource.
This vulnerability is documented as CVE-2026-35658. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-35652 | OpenClaw up to 2026.3.21 Interactive Call incorrect behavior order (GHSA-8883-9w57-vwv6 / WID-SEC-2026-0856)
2 months 1 week ago
A vulnerability classified as critical was found in OpenClaw up to 2026.3.21. This issue affects some unknown processing of the component Interactive Call Handler. Such manipulation leads to incorrect behavior order.
This vulnerability is listed as CVE-2026-35652. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-35655 | OpenClaw up to 2026.3.21 rawInput reliance on untrusted inputs in a security decision (GHSA-74wf-h43j-vvmj / WID-SEC-2026-0856)
2 months 1 week ago
A vulnerability, which was classified as problematic, was found in OpenClaw up to 2026.3.21. The affected element is an unknown function. Executing a manipulation of the argument rawInput can lead to reliance on untrusted inputs in a security decision.
This vulnerability is registered as CVE-2026-35655. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
vuldb.com
CVE-2026-35649 | OpenClaw up to 2026.3.21 Setting permissive list of allowed inputs (GHSA-pw7h-9g6p-c378 / WID-SEC-2026-0856)
2 months 1 week ago
A vulnerability described as critical has been identified in OpenClaw up to 2026.3.21. This affects an unknown part of the component Setting Handler. The manipulation results in permissive list of allowed inputs.
This vulnerability is identified as CVE-2026-35649. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
【漏洞通告】Nginx 缓冲区溢出漏洞 CVE-2026-27654
2 months 1 week ago
2026年4月11日,深瞳漏洞实验室监测到一则Nginx组件存在缓冲区溢出漏洞的信息,漏洞编号:CVE-2026-27654,漏洞威胁等级:高危。
North Korea's APT37 Uses Facebook Social Engineering to Deliver RokRAT Malware
2 months 1 week ago
The North Korean hacking group tracked as APT37 (aka ScarCruft) has been attributed to a fresh multi-stage, social engineering campaign in which threat actors approached targets on Facebook and added them as friends on the social media platform, turning the trust-building exercise into a delivery channel for a remote access trojan called RokRAT.
"The threat actor used two Facebook
The Hacker News