Aggregator
LibreOffice 26.2 释出
4 months 2 weeks ago
开源办公软件 LibreOffice 项目释出了最新的 v26.2 版本。一大变化是取消了社区版品牌。LibreOffice 26.2 主要变化包括:Writer 改进拼写检查对话框和文档更改跟踪,优化段落首尾对齐等;Calc 支持连接器,支持 xmlMaps.xml,改进排序对话框选项,支持 Excel 2007+ 的 Biff12 贴板格式,性能改进;Base 支持多用户,改进 Chart 的 3D 图表性能,更快的 SVG 图形渲染速度,等等。
Why Moltbook Changes the Enterprise Security Conversation
4 months 2 weeks ago
For several years, enterprise security teams have concentrated on a well-established range of risks, including users clicking potentially harmful links, employees uploading data to SaaS applications, developers inadvertently disclosing credentials on platforms like GitHub, and chatbots revealing sensitive information. However, a notable shift is emerging—one that operates independently of user actions. Artificial intelligence agents are...
The post Why Moltbook Changes the Enterprise Security Conversation appeared first on Aryaka.
The post Why Moltbook Changes the Enterprise Security Conversation appeared first on Security Boulevard.
Srini Addepalli
У Microsoft вышла «дыра», а у хакеров — праздник. APT28 обновила рекорды скорости
4 months 2 weeks ago
Новое вредоносное ПО MiniDoor крадет почтовую переписку из всех папок пользователя.
CVE-2026-1802 | Ziroom ZHOME A0101 1.0.1.0 zrMacClone.lua macAddrClone macType command injection
4 months 2 weeks ago
A vulnerability categorized as critical has been discovered in Ziroom ZHOME A0101 1.0.1.0. This issue affects the function macAddrClone of the file luci\controller\api\zrMacClone.lua. The manipulation of the argument macType results in command injection.
This vulnerability is cataloged as CVE-2026-1802. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-1803 | Ziroom ZHOME A0101 1.0.1.0 Dropbear SSH Service default credentials
4 months 2 weeks ago
A vulnerability identified as critical has been detected in Ziroom ZHOME A0101 1.0.1.0. Impacted is an unknown function of the component Dropbear SSH Service. This manipulation causes use of default credentials.
This vulnerability is registered as CVE-2026-1803. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2025-62603 | eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0 message_data out-of-bounds
4 months 2 weeks ago
A vulnerability classified as problematic was found in eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0. The affected element is an unknown function. The manipulation of the argument message_data results in out-of-bounds read.
This vulnerability is cataloged as CVE-2025-62603. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-62599 | eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0 PID_IDENTITY_TOKEN/PID_PERMISSION_TOKEN integer overflow
4 months 2 weeks ago
A vulnerability labeled as problematic has been found in eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0. Impacted is an unknown function. Executing a manipulation of the argument PID_IDENTITY_TOKEN/PID_PERMISSION_TOKEN can lead to integer overflow.
The identification of this vulnerability is CVE-2025-62599. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-62600 | eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0 PID_IDENTITY_TOKEN/PID_PERMISSION_TOKEN integer overflow
4 months 2 weeks ago
A vulnerability described as problematic has been identified in eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0. The impacted element is an unknown function. The manipulation of the argument PID_IDENTITY_TOKEN/PID_PERMISSION_TOKEN results in integer overflow.
This vulnerability is identified as CVE-2025-62600. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-62799 | eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0 RTPS DATA_FRAG Packet heap-based overflow
4 months 2 weeks ago
A vulnerability classified as critical was found in eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0. This impacts an unknown function of the component RTPS DATA_FRAG Packet Handler. Such manipulation leads to heap-based buffer overflow.
This vulnerability is listed as CVE-2025-62799. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-64438 | eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0 processGapMsg infinite loop
4 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0. Affected is the function StatefulReader::processGapMsg. Performing a manipulation results in infinite loop.
This vulnerability is cataloged as CVE-2025-64438. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-62601 | eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0 PID_IDENTITY_TOKEN/PID_PERMISSIONS_TOKEN heap-based overflow (EUVD-2025-206631)
4 months 2 weeks ago
A vulnerability was found in eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0. It has been declared as critical. This issue affects some unknown processing. Such manipulation of the argument PID_IDENTITY_TOKEN/PID_PERMISSIONS_TOKEN leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2025-62601. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-64098 | eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0 readOctetVector vecsize out-of-bounds
4 months 2 weeks ago
A vulnerability categorized as problematic has been discovered in eProsima Fast-DDS up to 2.6.10/3.3.0/3.4.0. The affected element is the function readOctetVector. Executing a manipulation of the argument vecsize can lead to out-of-bounds read.
This vulnerability is handled as CVE-2025-64098. The attack can be executed remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-25241 | pear pearweb up to 1.32.x /get// sql injection (GHSA-63fv-vpq5-gv8p)
4 months 2 weeks ago
A vulnerability described as critical has been identified in pear pearweb up to 1.32.x. Affected is an unknown function of the file /get//. Such manipulation leads to sql injection.
This vulnerability is referenced as CVE-2026-25241. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
维也纳工业大学 | 基于大语言模型的自动化安全评估
4 months 2 weeks ago
本文探索了LLM在渗透测试领域的应用潜力,并提出了两个核心用例:高层任务规划(如为攻击Active Directory制定策略)与低层攻击执行(如在已获得初始权限的Linux系统上进行自动化漏洞发现与提权)。
Extra Extra! Announcing DR Global Latin America
4 months 2 weeks ago
Dark Reading has something new hitting the newsstand: a content section purpose-built for Latin American readers, featuring news, analysis, features, and multimedia.
Tara Seals
ИИ-термины без боли: 20 слов, которые нужно знать всем
4 months 2 weeks ago
Больше вы никогда не спутаете ML с LLM и запросто отличите «галлюцинации» от «предвзятости».
CVE-2026-21964 | Oracle MySQL Server up to 8.0.44/8.4.7/9.5.0 Thread Pooling denial of service (EUVD-2026-3548 / Nessus ID 297724)
4 months 2 weeks ago
A vulnerability identified as problematic has been detected in Oracle MySQL Server up to 8.0.44/8.4.7/9.5.0. This issue affects some unknown processing of the component Thread Pooling. The manipulation leads to denial of service.
This vulnerability is documented as CVE-2026-21964. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-21985 | Oracle VM VirtualBox 7.1.14/7.2.4 Core information disclosure (EUVD-2026-3527 / Nessus ID 297733)
4 months 2 weeks ago
A vulnerability was found in Oracle VM VirtualBox 7.1.14/7.2.4. It has been declared as problematic. The impacted element is an unknown function of the component Core. The manipulation results in information disclosure.
This vulnerability is identified as CVE-2026-21985. The attack is only possible with local access. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-1035 | Red Hat Keycloak Refresh Token TokenManager toctou (Nessus ID 297730 / WID-SEC-2026-0197)
4 months 2 weeks ago
A vulnerability described as problematic has been identified in Red Hat Keycloak. Affected by this vulnerability is the function TokenManager of the component Refresh Token Handler. The manipulation results in time-of-check time-of-use.
This vulnerability is cataloged as CVE-2026-1035. The attack may be launched remotely. There is no exploit available.
vuldb.com