Aggregator
CVE-2020-21995 | Inim Electronics SmartLiving SmartLAN up to 6.x Telnet/SSH/FTP hard-coded credentials (Duplicate CVE-2019-25291 / ZSL-2019-5546)
CVE-2020-21992 | Inim Electronics SmartLiving SmartLAN up to 6.x testemail web.cgi system par format string (Duplicate CVE-2019-25289 / ZSL-2019-5544)
CVE-2019-25278 | iWT FaceSentry Access Control System 6.4.8 cleartext transmission (ID 153498 / XFDB-163192)
海量岗位招聘|阿里云安全保障团队期待你的加入
CVE-2019-25277 | iWT FaceSentry Access Control System 5.7.0/5.7.2/6.4.8 pluginInstall.php msg cross site scripting (ID 153494 / XFDB-163191)
CVE-2026-21858 | n8n-io n8n up to 1.120.x Form-based Workflow improper authentication (GHSA-v4pr-fm98-w9pg)
CVE-2026-21877 | n8n-io n8n up to 1.121.2 code injection (GHSA-v364-rw7m-3263)
MSI微星的新款电源将能够监测GPU每路电压变化 电压异常时将发出警报防止GPU熔毁
PayPal email scam: How it worked before the fix
Cybercriminals are scaling phishing attacks with ready-made kits
Phishing-as-a-Service (PhaaS) kits lower the barrier to entry, enabling less-skilled attackers to run large-scale, targeted phishing campaigns that impersonate legitimate services and institutions, according to Barracuda Networks. Phishing kits grow more sophisticated and scalable Barracuda threat analysts found that in 2025 the most common phishing themes were designed to trick users into clicking links, scanning QR codes, opening attachments, or sharing personal information with attackers. These techniques remain successful despite years of security controls and … More →
The post Cybercriminals are scaling phishing attacks with ready-made kits appeared first on Help Net Security.
陈天桥入局小模型,用 30B 跑赢万亿
扫地机器人的「物种爆发」时刻:从困于平面,到征服三维
浏览器扩展合集:派友近期推荐的 7 款浏览器扩展
Three Malicious NPM Packages Attacking Developers to Steal Login Credentials
Three malicious npm packages are targeting JavaScript developers to steal browser logins, API keys, and cryptocurrency wallet data. The packages, named bitcoin-main-lib, bitcoin-lib-js, and bip40, were uploaded to the public npm registry and posed as tools linked to the popular bitcoinjs project. Any developer who added them as dependencies could silently install a new remote […]
The post Three Malicious NPM Packages Attacking Developers to Steal Login Credentials appeared first on Cyber Security News.