Aggregator
Canadian man gets 33 years for using social media to coerce US children into sending sexual content
ThreatsDay Bulletin: Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More
CVE-2025-38619 | Linux Kernel up to 6.12.41/6.15.9/6.16.0 ti_csi2rx_start_dma denial of service (Nessus ID 276629 / WID-SEC-2025-1898)
CVE-2025-38620 | Linux Kernel up to 6.16.0 blk_mq_free_tag_set use after free (WID-SEC-2025-1898)
CVE-2025-38617 | Linux Kernel up to 6.16.0 packet_set_ring/packet_notifier race condition (Nessus ID 264665 / WID-SEC-2025-1898)
CVE-2025-38618 | Linux Kernel up to 6.17-rc1 vsock accept use after free (Nessus ID 260273 / WID-SEC-2025-1898)
CVE-2025-38616 | Linux Kernel up to 6.12.42/6.15.10/6.16.1/6.17-rc1 tls out-of-bounds (Nessus ID 266176 / WID-SEC-2025-1898)
CVE-2024-58239 | Linux Kernel up to 6.7.6 tls recv infinite loop (Nessus ID 265792 / WID-SEC-2025-1898)
Не смогли взломать удалённо — приехали лично. Спецслужбы описали самую наглую группировку года
Chinese-speaking fraud gang could be stealing millions from 2026 World Cup fans
Russia conducting daily attacks on UK 'from seabed to cyberspace,' spy chief warns
Social Engineering in the AI Age: How Offense Has Evolved and How to Defend
Social engineering has always worked because it targets the one component no firewall can patch, human judgment. What has changed […]
The post Social Engineering in the AI Age: How Offense Has Evolved and How to Defend appeared first on HawkEye.
U.S. CISA adds Daemon Tools, TanStack, and Nx Console flaws to its Known Exploited Vulnerabilities catalog
Grading on a curve: How to assess a pentest
Конвейер гуманоидов запущен: каждые 15 минут здесь рождается робот, который претендует на вашу работу
Zapier exploit chain shows how known anti-patterns compose into critical risk
A five-stage exploit chain disclosed by Token Security researchers turned a free Zapier account into write access on Zapier’s public developer SDK packages and on internal packages that load in every authenticated zapier.com session. Each link in the chain was a known anti-pattern. The composition across five systems was the finding. Zapier triaged the report within four days of submission on February 12, 2026, revoked the leaked NPM token, and tightened the underlying AWS role … More →
The post Zapier exploit chain shows how known anti-patterns compose into critical risk appeared first on Help Net Security.
How we built Cloudflare's data platform and an AI agent on top of it
Zapier fixes bug chain that researchers say risked widespread account takeover
A five-step flaw chain in the popular automation service, now patched, could have let a single attacker act as any signed-in user across thousands of connected apps.
The post Zapier fixes bug chain that researchers say risked widespread account takeover appeared first on CyberScoop.