Aggregator
FBI director Kash Patel’s brand website taken offline after malware reports
Слепая зона AppSec: почему проверки зависимостей не должны заканчиваться на CVE
CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks
CISA has issued an urgent alert regarding a critical SQL injection vulnerability in Drupal Core, tracked as CVE-2026-9082, which is now being actively exploited in real-world attacks. The flaw, classified under CWE-89, affects Drupal’s database abstraction API and could allow attackers to execute malicious SQL queries through specially crafted requests. According to the Cybersecurity and […]
The post CISA Warns of Drupal Core SQL Injection Vulnerability Exploited in Attacks appeared first on Cyber Security News.
GitHub Adds Staged Publishing to npm to Block Automated Supply Chain Attacks
GitHub has introduced a major security upgrade to the npm ecosystem with the general availability of staged publishing and new install-time controls, aimed at reducing automated supply chain attacks targeting open-source packages. The newly released staged publishing feature changes how npm packages are published and distributed. Instead of immediately making a package available after publishing, […]
The post GitHub Adds Staged Publishing to npm to Block Automated Supply Chain Attacks appeared first on Cyber Security News.
Hackers Use Browser-Locking CypherLoc Kit to Push Fake Microsoft Support Calls
A newly identified scareware kit called CypherLoc is locking victims’ browsers and tricking them into calling fake Microsoft support lines. The kit has been linked to roughly 2.8 million attacks since the start of 2026, making it one of the more aggressive browser-based threats observed this year. Unlike traditional malware that requires a file to […]
The post Hackers Use Browser-Locking CypherLoc Kit to Push Fake Microsoft Support Calls appeared first on Cyber Security News.
Firefox 加入对 Web Serial API 的支持,与 Adafruit 合作
TrapDoor Supply Chain Attack Spreads Credential-Stealing Malware via npm, PyPI, and CratesIO
Ученые создали миниатюрный ядерный огненный шар в лаборатории
Бесшовное покрытие, дроны и лазеры вместо проводов. Китай представил прототип беспроводного интернета будущего
Lessons for organizations from the Verizon 2026 Data Breach Investigations Report
This is my favourite time of the year, not just because spring is here and the promise of summer is on the way. But also, because one of my must reads each year gets published. There are a few must read reports that I have on my reading list for each year and the Verizon Data Breach Investigations Report is on top of that list. The latest Verizon 2026 Data Breach Investigations Report (DBIR) once … More →
The post Lessons for organizations from the Verizon 2026 Data Breach Investigations Report appeared first on Help Net Security.
四月全球风能太阳能发电量超过天然气发电量
AI 定向注入攻击:加密货币窃取供应链攻击新邪招
OpenHack: Open-source AI-powered vulnerability research
Source-guided vulnerability research increasingly leans on coding harnesses such as Claude Code, Codex, and Cursor to drive agent-based reviews of application code. A new MIT-licensed project from the Dutch security firm Hadrian, called OpenHack, packages that approach into a file-based workspace that any of those harnesses can run. OpenHack is a set of agents and tools that mimics how Hadrian’s research team performs automated vulnerability research. The workflow runs inside a coding harness or a … More →
The post OpenHack: Open-source AI-powered vulnerability research appeared first on Help Net Security.
JVN: NEC AtermシリーズにおけるOSコマンドインジェクションの脆弱性(NV26-003)
ZDI-CAN-30890: Anysphere
JVN: NEC Atermシリーズにおけるクロスサイトスクリプティングの脆弱性(NV26-002)
Скачали PDF-редактор? Готовьтесь прощаться с паролями от всех ваших аккаунтов
Boards want cyber risk in dollars, not CVE counts
In this Help Net Security video, Ziv Levi, SVP of Technology at CYE, explains why translating cyber risk into dollars is one of the most pressing tasks for security leaders. Boards and executives want cyber exposure described in business terms, not technical jargon. Levi walks through a three-step financial translation framework. First, identify business exposure by mapping attack paths to the assets that matter most, such as intellectual property and customer data. Second, focus on … More →
The post Boards want cyber risk in dollars, not CVE counts appeared first on Help Net Security.