Posts of last few hours
Please support the site operations by clicking ads.
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14.
On such servers, many customers' sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself,
https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html
NVIDIA 宣布将于 2026 年 10 月 15—16 日在苏州举办中国开发者日。日程分为两日:首日为动手实践日,包含 2026 黑客松总决赛路演、全天实战培训及实训营,同时开放四门 Associate 级别认证现场考试;次日为主论坛,设 LLM、AI 模型与运行时、物理AI/机器人、AI基础设施四个分论坛,并举行黑客松颁奖典礼。
值得注意的细节:认证考试可在现场完成,对希望获得 NVIDIA 官方技术背书但不愿单独约考的开发者有一定吸引力。活动偏向实战而非产品宣讲,适合关注推理优化、训练基础设施和机器人方向的工程师。注册已开放,名额限制未公布,建议提早。 https://www.nvidia.cn/developer-day/?ncid=partn-270555
值得注意的细节:认证考试可在现场完成,对希望获得 NVIDIA 官方技术背书但不愿单独约考的开发者有一定吸引力。活动偏向实战而非产品宣讲,适合关注推理优化、训练基础设施和机器人方向的工程师。注册已开放,名额限制未公布,建议提早。 https://www.nvidia.cn/developer-day/?ncid=partn-270555
https://www.solidot.org/story?sid=85379
https://www.jpcert.or.jp/at/2026/at260027.html
ИИ породил вайбпентестинг и резко снизил порог для атакующих.
https://www.securitylab.ru/news/577387.php
微软上周推送了 9 月份的例行安全更新,修复了近千个 bug。一周后,微软证实这次更新又给用户带来了一系列新 bug:Windows 11 26H1 和 Windows Server 2012 等多个 Windows 版本的远程桌面服务(RDS)出现问题; Windows 11 26H1、25H2 和 24H2 版本对 USB Audio Class 1.0 设备的支持出现问题,受影响的用户可能会遇到无音频输出、声音设置和音量控制失效,多声道音频问题;对电子表格 Excel 的 bug 修正导致粘贴功能失效。
微软表示它正在着手修复新 bug,但没有给出修复时间。
https://www.solidot.org/story?sid=85378
在重新上线一周时间后,基于 Nitter 开源项目的实例 XCancel 再次下线,运营者表示“由于正在进行的法律诉讼有了新进展,我们不得不再次暂停此项服务,直至另行通知。我们无法透露更多详情”。8 月 24 日, X/Twitter 向 Nitter 及其实例发出停止侵权通知 ,指控 Nitter 抓取数据并要求永久关闭 Nitter 实例和项目代码库。8 月 25 日,Nitter 的 GitHub 项目归档。9 月 6 日,Nitter 项目宣布在听取法律建议之后决定恢复服务,一天后 XCancel 成为第一个重新上线的 Nitter 实例。9 月 14 日,XCancel 再次下线。
https://www.solidot.org/story?sid=85377
https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247508693&idx=1&sn=00cc38b00ff11dd37ac384f361e99ea1
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker
https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html
近日,vivo正式通过全球权威认证机构挪威船级社(DNV)的审核,获得ISO漏洞管理体系认证,覆盖ISO/IE
https://mp.weixin.qq.com/s?__biz=MzI0Njg4NzE3MQ==&mid=2247492424&idx=1&sn=ddf6fff159e06459eeb6f3daf07d5d3d
Работодатель видит одного человека, документы принадлежат другому, а работу через VPN выполняет третий участник схемы.
https://www.securitylab.ru/news/577390.php
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.
Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026.
"The
https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html
Верите в тайну электронного голосования? Доступный ИИ за несколько часов взломал анонимность выборов
Для эксперимента не понадобились взлом, закрытые базы или доступ к избирательным машинам.
https://www.securitylab.ru/news/577353.php
За цифровой сбой теперь может расплачиваться тот, кто вообще не участвовал в инциденте.
https://www.securitylab.ru/news/577343.php
小宇宙想要「强而久」。
https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653113576&idx=1&sn=eb6fa0af13ee2ed5bc1057ce88b202c8
A CVSS score 7.8 AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'parkjunhyun' was reported to the affected vendor on: 2026-09-15, 5 days ago. The vendor is given until 2027-01-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
http://www.zerodayinitiative.com/advisories/upcoming/
A CVSS score 8.8 AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H severity vulnerability discovered by 'parkjunhyun' was reported to the affected vendor on: 2026-09-15, 5 days ago. The vendor is given until 2027-01-13 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
http://www.zerodayinitiative.com/advisories/upcoming/
NTTドコモビジネス株式会社が提供するAndroidアプリ「【保護者専用】まなびポケット」には、アクセス制限不備の脆弱性が存在します。
https://jvn.jp/jp/JVN72918755/
Триллионная инфраструктурная гонка всё сильнее зависит от денег, которых пока нет.
https://www.securitylab.ru/news/577345.php
Спутники научились замечать то, что постоянно ускользает из сводок.
https://www.securitylab.ru/news/577351.php
Электроника сделала ещё один шаг в сторону биологических систем.
https://www.securitylab.ru/news/577349.php
Latest Blog Posts
- 4 weeks ago
- 2 months 4 weeks ago
- 2 months 4 weeks ago
- 2 months 4 weeks ago
- 3 months ago
- 7 months 3 weeks ago
- 1 year 1 month ago
- 1 year 1 month ago
- 1 year 2 months ago
- 1 year 6 months ago