Aggregator
CVE-2026-20968 | Samsung Devices DualDAR use after free
CVE-2025-69194 GNU Wget2路径遍历漏洞
通用 | 春节第三趴,提交几个漏洞能拿万元奖励金/大疆运动相机?(文末抽奖)
CVE-2026-20973 | Samsung Devices libimagecodec.quram.so out-of-bounds
CVE-2026-20969 | Samsung SecSettings access control
电视价格为何如此廉价?
电视价格为何如此廉价?
【0day预警】ComfyUI-Manager CRLF注入导致远程代码执行漏洞
CVE-2025-14803 | NEX-Forms Plugin up to 9.1.7 on WordPress Setting cross site scripting
CVE-2025-66315 | ZTE MF258K Setting privileges management
CVE-2025-70974 | Alibaba Fastjson up to 1.2.47 inclusion of functionality from untrusted control sphere
CVE-2025-55182 (React2Shell) 安全研究报告
Защита от взлома или новая уязвимость? В США впервые разрешили полностью оцифровать систему безопасности реактора
Hackers Actively Exploiting AI Deployments – 91,000+ Attack Sessions Observed
Security researchers have identified over 91,000 attack sessions targeting AI infrastructure between October 2025 and January 2026, exposing systematic campaigns against large language model deployments. GreyNoise’s Ollama honeypot infrastructure captured 91,403 attack sessions during this period, revealing two distinct threat campaigns. The findings corroborate and extend previous research from Defused on AI system targeting. The […]
The post Hackers Actively Exploiting AI Deployments – 91,000+ Attack Sessions Observed appeared first on Cyber Security News.
New Ghost Tapped Attack Uses Your Android Device to Drain Your Bank Account
Chinese threat actors have developed a dangerous new way to steal money directly from bank accounts using specially crafted Android applications. Known as Ghost Tapped, these malicious apps exploit Near Field Communication (NFC) technology, the same wireless technology that powers contactless payments. Instead of needing your physical bank card, criminals can complete transactions from anywhere […]
The post New Ghost Tapped Attack Uses Your Android Device to Drain Your Bank Account appeared first on Cyber Security News.
动态磁贴消亡史
How AI agents are turning security inside-out
AppSec teams have spent the last decade hardening externally facing applications, API security, software supply chain risk, CI/CD controls, and cloud-native attack paths. But a growing class of security threats is emerging from a largely underestimated and undefended source: internally built no-code assets. What started out as a few business user created no-code apps is evolving into thousands of automations and AI agents operating across enterprise systems. They pull external data, call internal APIs, reason … More →
The post How AI agents are turning security inside-out appeared first on Help Net Security.