Aggregator
CVE-2025-5192 | Soar Cloud System HRD Human Resource Management System up to 7.3.2025.0408 missing authentication
CVE-2025-48781 | Soar Cloud System HRD Human Resource Management System up to 7.3.2025.0408 file inclusion (EUVD-2025-17101)
CVE-2024-35280 | Fortinet FortiDeceptor up to 5.3.0 cross site scripting (FG-IR-24-010)
CVE-2024-45326 | Fortinet FortiDeceptor up to 5.0.0/5.1.0/5.2.1/5.3.3/6.0.0 Request access control (FG-IR-24-285)
ConnectSecure introduces Linux patching capability to simplify cross-distro updates
ConnectSecure announced the launch of a new cross-platform Linux operating system patching capability. The update eliminates the complexity of managing fragmented Linux environments by delivering a single, unified interface for deploying critical security updates across the four most widely used Linux distributions: Red Hat, Ubuntu, Debian, and CentOS. The new capability helps MSPs and security teams automate the identification and deployment of kernel and OS patches without requiring distribution-specific tools. As a result, organizations can … More →
The post ConnectSecure introduces Linux patching capability to simplify cross-distro updates appeared first on Help Net Security.
The Double-Edged Sword of Non-Human Identities
Nederlandse troepen in Litouwen onder Duits bevel
Supply Chain Attack Abused Notepad++ Update Infrastructure to Deliver Targeted Malware
The developers of Notepad++ disclosed a critical security breach on February 2, 2026, affecting their update infrastructure. The popular text editor, widely used by developers worldwide, became the target of a sophisticated supply chain attack that remained undetected for several months. According to the official statement, attackers gained unauthorized access through a hosting provider-level incident […]
The post Supply Chain Attack Abused Notepad++ Update Infrastructure to Deliver Targeted Malware appeared first on Cyber Security News.
New Technical Markers Reveal Expanding ShadowSyndicate Cybercriminal Infrastructure
Chinese Mustang Panda Used Fake Diplomatic Briefings to Spy on Officials
GreyNoise tracks massive Citrix Gateway recon using 63K+ residential proxies and AWS
分析 Notepad++ 的供应链攻击
Submit #742676: Wekan <8.21 Missing authorization on admin function (CWE-284) [Accepted]
Submit #742671: Wekan <8.21 Missing authorization checks leading to information disclosure a [Accepted]
Submit #742670: Wekan <8.21 Improper access control on administrative migration methods (CWE [Accepted]
Submit #742666: Wekan <8.21 Improper access control (CWE-284) [Accepted]
Submit #742663: Wekan <8.21 IDOR via REST API / improper object relationship validation [Accepted]
Submit #742662: Wekan <8.21 IDOR via REST API / improper object relationship validation [Accepted]
Beyond the Chatbot: Why NIST is Rewriting the Rules for Autonomous AI
The chatbot era has ended. For two years, we’ve interacted with digital assistants that summarize emails and suggest recipes, but the National Institute of Standards and Technology (NIST) now draws a definitive line between machines that talk and machines that act. Their newly released Request for Information (RFI) signals a fundamental paradigm shift in how..
The post Beyond the Chatbot: Why NIST is Rewriting the Rules for Autonomous AI appeared first on Security Boulevard.