Aggregator
GLP-1 减肥药与脱发相关
GLP-1 减肥药与脱发相关
CVE-2026-15821 | brainstormforce SureDash Plugin up to 1.10.0 on WordPress cross site scripting
CVE-2026-15346 | e4jvikwp VikBooking Hotel Booking Engine & PMS Plugin up to 1.8.13 on WordPress category_id cross site scripting
How Infostealer Logs Became the Fuel Behind Massive Cloud Data Breaches
Infostealer malware has quietly become the single most important initial-access commodity in the cybercrime economy, replacing traditional phishing and exploit-driven intrusions as the leading precursor to enterprise breaches and ransomware. Rather than breaking into networks, modern threat actors buy their way in by purchasing “stealer logs” containing valid usernames, passwords, session cookies, and SSO tokens […]
The post How Infostealer Logs Became the Fuel Behind Massive Cloud Data Breaches appeared first on Cyber Security News.
CVE-2026-15739 | widgetpack Rich Showcase for Google Reviews Plugin up to 6.9.9 on WordPress Shortcode pagination cross site scripting
CVE-2026-15704 | Eclipse BaSyx Go Components up to 1.0.0 Trailing Slash middleware.StripSlashes authorization
CVE-2026-63317 | Apache OpenNLP up to 2.5.10/3.0.0-M3 GeneratorFactory Class.forName opennlp.interner.class/-format input validation
CVE-2026-56392 | GNU coreutils integer overflow
CVE-2026-56391 | GNU coreutils up to 9.11 Multibyte Input find_field out-of-bounds
Google’s newest sign-in method asks you to look at the camera
Google’s selfie video sign-in option verifies that an account owner is a real person and that the account wasn’t created or used by computer programs or bots for the purpose of abuse, such as spamming. It is not available for all regions, accounts, or devices. Source: Google A selfie video is recorded and securely stored with the account owner’s consent, and it can be deleted at any time in the Google Account. Users may take … More →
The post Google’s newest sign-in method asks you to look at the camera appeared first on Help Net Security.
У Oracle случился свой собственный «баг-апокалипсис»
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
Google Rolls Out Emergency Chrome Update for Four High-Severity Security Flaws
Google has released an emergency security update for its Chrome browser, addressing four high-severity vulnerabilities that could expose users to serious risks if left unpatched. The update, now rolling out globally, upgrades Chrome to version 150.0.7871.186/.187 for Windows and macOS, and 150.0.7871.186 for Linux systems. The latest release focuses primarily on security fixes, with Google […]
The post Google Rolls Out Emergency Chrome Update for Four High-Severity Security Flaws appeared first on Cyber Security News.
Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails
Hackers are using fake payment receipt emails to deliver a 750MB Lampion remote access trojan to targets in Portugal. The campaign relies on familiar financial language, convincing business details, and oversized files designed to slow down analysis and evade security checks. The attack begins with phishing emails that pose as routine financial or administrative messages. […]
The post Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails appeared first on Cyber Security News.