Aggregator
JVN: M-Audio製M-Track Duo HDインストーラにおける任意のDLL読み込みの脆弱性
4 months 1 week ago
M-Audioが提供するM-Track Duo HDのインストーラには、DLL読み込みに関する脆弱性が存在します。
Apple 0-Day Vulnerability Actively Exploited in Sophisticated Attack to Target Individuals
4 months 1 week ago
Apple released iOS 26.3 and iPadOS 26.3 on February 11, 2026, patching over 40 vulnerabilities, including a critical zero-day in the dyld component actively exploited in targeted attacks. The update addresses CVE-2026-20700, a memory-corruption flaw discovered by Google’s Threat Analysis Group, which enables arbitrary code execution for attackers with memory-write access. Dyld, Apple’s Dynamic Link […]
The post Apple 0-Day Vulnerability Actively Exploited in Sophisticated Attack to Target Individuals appeared first on Cyber Security News.
Guru Baran
一款让网络安全分析效率翻倍的开源神器,Flowsint图谱调查工具上线!
4 months 1 week ago
在网络攻击如潮水、社工手段不断进化的今天,情报分析师最头疼的不是“没数据”,而是“数据太碎”。
注意喚起: 2026年2月マイクロソフトセキュリティ更新プログラムに関する注意喚起 (公開)
4 months 1 week ago
MingJing (明镜):基于混合架构的智能中文敏感信息识别
4 months 1 week ago
MingJing (明镜):基于混合架构的智能中文敏感信息识别
Should CISOs Plan for Government as an Adversary?
4 months 1 week ago
Why Modern Threat Modeling Must Account for State Control of Infrastructure
CISOs for decades viewed governments as partners. That assumption is weakening. Today, state control over infrastructure needs be part of threat modeling and business continuity planning for global security leaders - and it's time for CISOs to reassess dependencies and trust boundaries.
CISOs for decades viewed governments as partners. That assumption is weakening. Today, state control over infrastructure needs be part of threat modeling and business continuity planning for global security leaders - and it's time for CISOs to reassess dependencies and trust boundaries.
Webinar | Industrialized Deception: The Crisis of Point-in-Time Trust
4 months 1 week ago
Singapore Mounts Largest-Ever Coordinated Cyber Defense
4 months 1 week ago
Singapore Signals Heightened Vigilance Against State-Linked Threat Actors
Singapore conducted a yearlong, multi-agency cyber defense operation to expel UNC3886 from all four major telecom providers after the advanced threat actor accessed segments of critical communications infrastructure and extracted limited technical data without disrupting services.
Singapore conducted a yearlong, multi-agency cyber defense operation to expel UNC3886 from all four major telecom providers after the advanced threat actor accessed segments of critical communications infrastructure and extracted limited technical data without disrupting services.
How CIOs Are Navigating the AI-Driven Software Market Crash
4 months 1 week ago
AI Is Transforming Economics But Enterprise IT Architecture Issues Are Still Here
While AI systems such as Claude lower the marginal cost of writing code and automating discrete tasks, especially when it comes to early-stage work including prototyping and front-end design, the idea that AI will lay waste to the industry is overblown, analysts say.
While AI systems such as Claude lower the marginal cost of writing code and automating discrete tasks, especially when it comes to early-stage work including prototyping and front-end design, the idea that AI will lay waste to the industry is overblown, analysts say.
Vega Raises $125M Series B for AI-Native Security Operations
4 months 1 week ago
Accel-Led Funding Round Fuels AI-Native Detection and Response
Vega raised $125 million led by Accel to expand its AI-native security operations platform. The funding will boost product development and global go-to-market efforts as enterprises seek faster threat detection, broader analytics and support for complex multi-cloud and on-premises environments.
Vega raised $125 million led by Accel to expand its AI-native security operations platform. The funding will boost product development and global go-to-market efforts as enterprises seek faster threat detection, broader analytics and support for complex multi-cloud and on-premises environments.
CISA: DHS Funding Lapse Would Sideline Federal Cyber Staff
4 months 1 week ago
Acting Chief Tells Lawmakers Most Staff Would Be Furloughed Amid Partial Shutdown
More than half of the U.S. cyber defense agency's workforce would be furloughed under a DHS funding lapse, the agency's acting chief warned Wednesday, pausing incident reporting rulemaking, security assessments and proactive cyber programs while significantly limiting operations.
More than half of the U.S. cyber defense agency's workforce would be furloughed under a DHS funding lapse, the agency's acting chief warned Wednesday, pausing incident reporting rulemaking, security assessments and proactive cyber programs while significantly limiting operations.
AI +电商反欺诈情报平台:威胁猎人DarkSphere暗域全新发布
4 months 1 week ago
DarkSphere(暗域),以 AI + 情报的方式,助力电商企业构建更主动、更智能的风险防御体系。
CVE-2021-47918 | Simplephpscripts Simple CMS 2.1 Users admin.php sql injection (EUVD-2021-34753)
4 months 1 week ago
A vulnerability classified as critical was found in Simplephpscripts Simple CMS 2.1. This issue affects some unknown processing of the file admin.php of the component Users Module. The manipulation results in sql injection.
This vulnerability is cataloged as CVE-2021-47918. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-25128 | NaturalIntelligence fast-xml-parser up to 5.3.3 denial of service (Nessus ID 297652)
4 months 1 week ago
A vulnerability has been found in NaturalIntelligence fast-xml-parser up to 5.3.3 and classified as problematic. Affected is an unknown function. This manipulation causes denial of service.
This vulnerability is tracked as CVE-2026-25128. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-24070 | Native Instruments Native Access com.native-instruments.NativeAccess.Helper2 untrusted search path (EUVD-2026-5108)
4 months 1 week ago
A vulnerability classified as problematic was found in Native Instruments Native Access. Affected by this vulnerability is an unknown functionality of the component com.native-instruments.NativeAccess.Helper2. The manipulation results in untrusted search path.
This vulnerability was named CVE-2026-24070. The attack needs to be approached locally. There is no available exploit.
vuldb.com
CVE-2026-24071 | Native Instruments Native Access XPC Service hasValidSignature toctou (EUVD-2026-5109)
4 months 1 week ago
A vulnerability, which was classified as critical, was found in Native Instruments Native Access. This affects the function hasValidSignature of the component XPC Service. Such manipulation leads to time-of-check time-of-use.
This vulnerability is referenced as CVE-2026-24071. The attack needs to be initiated within the local network. No exploit is available.
vuldb.com
CVE-2025-15395 | IBM Jazz Foundation up to 7.0.3 iFix019/7.1.0 iFix005 authorization (EUVD-2025-206601)
4 months 1 week ago
A vulnerability was found in IBM Jazz Foundation up to 7.0.3 iFix019/7.1.0 iFix005. It has been rated as problematic. The impacted element is an unknown function. This manipulation causes incorrect authorization.
This vulnerability is registered as CVE-2025-15395. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2024-4147 | lunary-ai lunary up to 1.2.24 Organization insufficient granularity of access control (EUVD-2024-32706)
4 months 1 week ago
A vulnerability categorized as problematic has been discovered in lunary-ai lunary up to 1.2.24. Impacted is an unknown function of the component Organization Handler. The manipulation results in insufficient granularity of access control.
This vulnerability is reported as CVE-2024-4147. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2024-5386 | lunary-ai lunary up to 1.2.13 Password Reset Token recoveryToken excessive attack surface (EUVD-2024-55392)
4 months 1 week ago
A vulnerability identified as critical has been detected in lunary-ai lunary up to 1.2.13. The affected element is an unknown function of the component Password Reset Token Handler. This manipulation of the argument recoveryToken causes excessive attack surface.
This vulnerability appears as CVE-2024-5386. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
vuldb.com