Aggregator
CVE-2026-2370 | GitLab Community Edition/Enterprise Edition up to 18.8.6/18.9.2/18.10.0 parameters (EUVD-2026-17046 / Nessus ID 304265)
CVE-2026-3124 | wpchill Download Monitor Plugin up to 5.1.7 on WordPress executePayment authorization (EUVD-2026-17052)
CVE-2025-15036 | MLflow up to 3.8.x dbconnect_artifact_cache.py extract_archive_to_dir path traversal (EUVD-2025-209119)
CVE-2026-4946 | NSA Ghidra up to 12.0.2 Binary os command injection (GHSA-mc3p-mq2p-xw6v / EUVD-2026-17042)
Why risk alone doesn’t get you to yes
I have been in security rooms for years, from military operations centers to corporate boardrooms. In all those years I can tell you that the hardest mission that most security leaders will face is not identifying a threat, but getting someone to act on it. We’re trained to see exposure before they are identified by others. We continually assess likely threats, evaluate impact, and design controls to prevent disruption long before it reaches operations or … More →
The post Why risk alone doesn’t get you to yes appeared first on Help Net Security.
CVE-2026-0562 | parisneo lollms up to 2.1.x respond_request authorization (EUVD-2026-17039)
CVE-2026-0560 | parisneo lollms up to 2.1.x export-content _download_image_to_temp server-side request forgery (EUVD-2026-17037)
CVE-2026-4176 | SHAY perl up to 5.43.8 Compress Compress::Raw vulnerable third-party component (EUVD-2026-17044)
CVE-2026-0558 | parisneo lollms up to 2.1.x Endpoint /api/files/extract-text get_current_active_user improper authentication (EUVD-2026-17035)
CVE-2025-7741 | Yokogawa Electric CENTUM VP up to R5.04.20/R6.12.00/R7.01.00 hard-coded password (EUVD-2025-209116)
奥地利政府计划禁止儿童使用社交媒体
Telegram 9.8 分零日漏洞警示:富媒体时代,即时通讯的安全红线在哪?
Is Poor Risk Management Causing More Businesses to Fail Amid 2026 Uncertainty?
《AI模型安全评估及围栏技术应用指南》 调研正式启动,诚邀厂商共筑AI安全生态!
警惕 OpenClaw:AI 主权代理时代,网络安全迎来致命第四维
お知らせ:JPCERT/CC Eyes「TSUBAMEレポート Overflow(2025年7~9月)」
ShipSec Studio brings open-source workflow orchestration to security operations
Security teams have long relied on a mix of shell scripts, cron jobs, and loosely connected tools to chain reconnaissance and vulnerability scanning work together. ShipSec Studio, an open-source security workflow automation platform from ShipSec AI, aims to replace that arrangement with a dedicated orchestration layer built specifically for security operations. What the platform does ShipSec Studio provides a visual, no-code workflow builder that lets operators connect security tools into automated pipelines without writing glue … More →
The post ShipSec Studio brings open-source workflow orchestration to security operations appeared first on Help Net Security.