Aggregator
SecWiki News 2026-05-15 Review
更多最新文章,请访问SecWiki
Avada Builder WordPress plugin flaws allow site credential theft
中欧合作揭示地球磁场的形状
Gunra Ransomware Expands RaaS Operations After Shifting From Conti-Based Locker
Gunra ransomware has quickly grown from a new threat into a serious global problem, hitting dozens of organizations in less than a year. The group behind it is not just encrypting data, but also running a business-like operation that sells access, leaks stolen files, and recruits partners to spread its malware. For defenders, this is […]
The post Gunra Ransomware Expands RaaS Operations After Shifting From Conti-Based Locker appeared first on Cyber Security News.
Думаете, ваши голосовые в WhatsApp защищены? Вот список расширений, которые перехватывают аудио перед отправкой
OpenClaw Chain Vulnerabilities Expose 245,000 Public AI Agent Servers to Attack
A chain of four critical vulnerabilities discovered in OpenClaw, one of the fastest-growing open-source platforms for autonomous AI agents, has left an estimated 245,000 publicly accessible server instances exposed to remote exploitation, credential theft, and persistent backdoor installation. Originally launched as “Clawdbot” in late 2025, OpenClaw connects large language models directly to filesystems, SaaS applications, […]
The post OpenClaw Chain Vulnerabilities Expose 245,000 Public AI Agent Servers to Attack appeared first on Cyber Security News.
CVE-2017-3315 | Oracle PeopleSoft 9.2 HCM ePerformance information disclosure (BID-95510 / ID 1037634)
CVE-2017-3324 | Oracle Primavera P6 Enterprise Project Portfolio Management Web Access access control (BID-95528)
CVE-2017-3316 | Oracle VM VirtualBox up to 5.0.31/5.1.13 GUI input validation (EDB-41196 / Nessus ID 96609)
CVE-2017-3317 | Oracle MySQL Server 5.5.53/5.6.34/5.7.16 Logging denial of service (Nessus ID 96732 / ID 175942)
CVE-2017-3318 | Oracle MySQL Server 5.5.53/5.6.34/5.7.16 Error Handling access control (Nessus ID 96732 / ID 175942)
CVE-2017-3321 | Oracle MySQL Cluster 7.2.19/7.3.8/7.4.5 input validation (Nessus ID 96727 / BID-95562)
CVE-2017-3323 | Oracle MySQL Cluster 7.2.25/7.3.14/7.4.12 input validation (Nessus ID 96726 / BID-95575)
CVE-2017-3322 | Oracle MySQL Cluster 7.2.25/7.3.14/7.4.12 Cluster NDBAPI denial of service (Nessus ID 96726 / BID-95574)
CVE-2017-3319 | Oracle MySQL Server up to 5.7.16 X Plugin information disclosure (Nessus ID 96618 / ID 20029)
CVE-2017-3320 | Oracle MySQL Server up to 5.7.16 Encryption access control (Nessus ID 96618 / ID 20029)
KRYBIT
You must login to view this content
Shai-Hulud Worm Steals npm, GitHub, AWS, and Kubernetes Secrets From Developers
A dangerous new piece of malware called Shai-Hulud has emerged as one of the most alarming supply chain threats of 2026. It is a self-propagating worm that quietly tunnels through developer environments, stealing credentials from npm, GitHub, AWS, and Kubernetes all at once. Hundreds of malicious packages have already been tied to this campaign, making […]
The post Shai-Hulud Worm Steals npm, GitHub, AWS, and Kubernetes Secrets From Developers appeared first on Cyber Security News.