Aggregator
【安全圈】挥刀“斩”Sora!OpenAI在下什么棋
Microsoft Authenticator’s Unclaimed Deep Link: A Full Account Takeover Story (CVE-2026–26123)
Microsoft Authenticator’s Unclaimed Deep Link: A Full Account Takeover Story (CVE-2026–26123)
Finding XSS Through HTML Injection — Without Fuzzing Tools
Finding XSS Through HTML Injection — Without Fuzzing Tools
The End of “Just Buy an iPhone” as Security Advice
We Are At War
We Are At War
RSAC 2026:AI SOC从“辅助驾驶”迈入“智能体驱动”时代
Hackers Use USB Malware, RATs, and Stealers in Espionage Attacks on Southeast Asian Government
A highly coordinated cyberespionage campaign has been uncovered targeting a government organization in Southeast Asia, with threat actors deploying a mix of USB-propagated malware, remote access trojans (RATs), and data stealers to secure long-term access to sensitive government systems. The operation, active between June and August 2025, involved three separate clusters of activity running simultaneously […]
The post Hackers Use USB Malware, RATs, and Stealers in Espionage Attacks on Southeast Asian Government appeared first on Cyber Security News.
Bogus Avast website fakes virus scan, installs Venom Stealer instead
Anti-piracy coalition takes down AnimePlay app with 5 million users
科技云报到:“龙虾”入笼:为何金融行业不敢“养”?
CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation
The US Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-33017, a recently disclosed code injection vulnerability in Langflow, an open-source framework for building AI agents and workflows, and CVE-2026-33634, an embedded malicious code vulnerability in Aqua Security’s Trivy security scanner. Their addition to the catalog means that US federal civilian agencies are required to address the flaws within their networks by April 8 and 9, … More →
The post CISA sounds alarm on Langflow RCE, Trivy supply chain compromise after rapid exploitation appeared first on Help Net Security.
Anti-piracy coalition takes down AnimePlay app with 5 million users
苹果向 FBI 提供用马甲邮箱发出匿名威胁的用户名字
苹果向 FBI 提供用马甲邮箱发出匿名威胁的用户名字
RSAC 2026 wrap-up – Week in security with Tony Anscombe
Hackers Use Phishing ZIP Files to Deploy PXA Stealer Against Financial Firms
A new wave of cyberattacks is putting financial institutions on high alert, as threat actors ramp up the use of PXA Stealer — a powerful information-stealing malware — against organizations worldwide. The surge follows law enforcement’s successful dismantling of major infostealer operations, including Lumma, Rhadamanthys, and RedLine, throughout 2025. With those platforms gone, PXA Stealer […]
The post Hackers Use Phishing ZIP Files to Deploy PXA Stealer Against Financial Firms appeared first on Cyber Security News.