Aggregator
CVE-2026-41006 | Vmware Spring HATEOAS up to 3.0.3 Collection+JSON/UBER access control
CVE-2026-44751 | SAP NetWeaver and ABAP Platform up to 816 authorization
Сотни каналов в «Макс» опубликовали чужой пост из-за уязвимости стороннего сервиса
CVE-2026-41850 | Vmware Spring Framework up to 5.3.48/6.1.27/6.2.18/7.0.7 Spring Expression Language algorithmic complexity
CVE-2026-41849 | Vmware Spring Framework up to 5.3.48 SpEL integer overflow
CVE-2026-41843 | Vmware Spring Framework up to 5.3.48/6.1.27/6.2.18/7.0.7 Versioned Static Resource path traversal
CVE-2026-41842 | Vmware Spring Framework up to 5.3.48/6.1.27/6.2.18/7.0.7 resource consumption
Treating AI agents like service accounts for federated query security
In this interview with Help Net Security, Paras Malhotra, CISO at Starburst, explains how the company handles data governance across federated query environments. Topics include layering Starburst’s access controls above native source permissions, tiering vendor risk across more than 200 partners and connectors, and building audit trails for autonomous agents. The conversation covers how AIDA turns natural language into SQL while guarding against prompt injection, and how the company treats AI agents querying through MCP … More →
The post Treating AI agents like service accounts for federated query security appeared first on Help Net Security.
Идеальный DDoS-вербовщик. Новый ботнет C0XMO пачками подчиняет роутеры и видеорегистраторы
Malware ships with bugs that defenders could use against it
Static analysis tools have spent years scanning legitimate software for security bugs before it goes out the door. The same scanners work on malware, and malware carries a steady supply of its own bugs. Researchers ran four of these tools across 658 leaked malware projects and found that close to 90 percent contained at least one recognized software weakness. The malware code came from VX-Underground, a public repository of leaked samples. The scanners were Cppcheck, … More →
The post Malware ships with bugs that defenders could use against it appeared first on Help Net Security.
Получили SMS о «сгорающих бонусах»? Значит вас только что попытались ограбить. Новая мошенническая схема Smishing Error524
The security questions around Chinese AI coding models in U.S. software
Software developers across the United States are using AI models built in China to write, debug, and review code, drawn by prices below those of American alternatives. These models carry risks for the security of American software, according to a report from Booz Allen Hamilton, which tested how the models respond when the user appears to work for the U.S. government. What the testing covered In May 2026, Booz Allen ran more than 2,800 trials … More →
The post The security questions around Chinese AI coding models in U.S. software appeared first on Help Net Security.
Идеальные лица и выдуманные жизни. Соцсети наводнили синтетические блогеры, которых невозможно отличить от живых людей
OpenAI 申请 IPO
Cybersecurity jobs available right now: June 9, 2026
Application Security Architect INTENSITY Global Group | Israel | Hybrid – View job details As an Application Security Architect, you will design secure application architectures, perform threat modeling and security assessments, define security standards and controls, integrate security into the SDLC and CI/CD pipelines, support application security tooling and incident response, and guide engineering teams on secure development practices. Application Security Engineer HealthHero | United Kingdom | Hybrid – View job details As an Application … More →
The post Cybersecurity jobs available right now: June 9, 2026 appeared first on Help Net Security.