Aggregator
Please support the site operations by clicking ads.
CVE-2026-9076 | OpenSSL up to 4.0.0 kek_unwrap_key out-of-bounds (Nessus ID 320351 / WID-SEC-2026-1852)
CVE-2026-43491 | Linux Kernel up to 6.6.139/6.12.85/6.18.26/7.0.3 SERVER Message qrtr_ns_worker resource consumption (Nessus ID 315312 / WID-SEC-2026-1587)
CVE-2026-45447 | OpenSSL up to 4.0.0 PKCS7_verify digestAlgorithms use after free (Nessus ID 320333 / WID-SEC-2026-1852)
我还挺会想的,香港国际机场
CVE-2026-45445 | OpenSSL up to 4.0.0 EVP_Cipher missing cryptographic step (Nessus ID 320335 / WID-SEC-2026-1852)
CVE-2026-45446 | OpenSSL up to 4.0.0 EVP Interface /CMS/PKCS7/HPKE/QUIC EVP_DecryptFinal_ex missing cryptographic step (Nessus ID 320634 / WID-SEC-2026-1852)
CVE-2026-42771 | OpenSSL up to 4.0.0 X509_VERIFY_PARAM_set1_email out-of-bounds (Nessus ID 320328 / WID-SEC-2026-1852)
CVE-2026-42770 | OpenSSL up to 4.0.0 EVP_PKEY_derive_set_peer missing cryptographic step (Nessus ID 320323 / WID-SEC-2026-1852)
CVE-2026-42769 | OpenSSL up to 3.4.5/3.5.6/3.6.2/4.0.0 OSSL_CMP_get1_rootCaKeyUpdate certificate validation (Nessus ID 320330 / WID-SEC-2026-1852)
CVE-2026-42768 | OpenSSL up to 3.4.5/3.5.6/3.6.2/4.0.0 Decryption API CMS_decrypt/PKCS7_decrypt Bleichenbacher covert channel (Nessus ID 320343 / WID-SEC-2026-1852)
CVE-2026-42767 | OpenSSL up to 4.0.0 symmAlg null pointer dereference (Nessus ID 320340 / WID-SEC-2026-1852)
CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw. The issue affects GitLab Community Edition and Enterprise Edition deployments and carries a maximum CVSS severity score of 10.0. CVE-2026-85706 is a path traversal […]
The post CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks appeared first on Cyber Security News.
CVE-2026-42766 | OpenSSL up to 4.0.0 null pointer dereference (Nessus ID 320350 / WID-SEC-2026-1852)
CVE-2026-42765 | OpenSSL up to 3.6.2/4.0.0 null pointer dereference (Nessus ID 320332 / WID-SEC-2026-1852)
CVE-2026-42764 | OpenSSL up to 3.5.6/3.6.2/4.0.0 SSL_new_listener null pointer dereference (Nessus ID 320634 / WID-SEC-2026-1852)
CVE-2026-35188 | OpenSSL up to 3.6.2/4.0.0 TLS OCSP Stapling double free (Nessus ID 320349 / WID-SEC-2026-1852)
Вредоносное ПО начали продавать как рекламу. Unit 42 нашла сеть из 10000 загрузчиков
OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE
A swarm of AI agents attributed by researchers to OpenAI flooded RubyGems with more than 2,000 packages in May 2026, abused RubyDoc.info’s documentation builder for remote code execution (RCE), and attempted to harvest developers’ API keys through a then-undisclosed caching flaw. The episode, initially tracked as the GemStuffer campaign, demonstrates how autonomous agents can turn […]
The post OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE appeared first on Cyber Security News.