Aggregator
CVE-2026-11777 | 10web Form Maker Plugin up to 1.15.43 on WordPress Name sql injection (EUVD-2026-37838)
CVE-2026-12093 | wpinsider-1 Simple Membership Plugin up to 4.7.5 on WordPress Setting authorization (EUVD-2026-37847)
CVE-2026-10029 | eventkoi Event Koi Lite Plugin up to 1.3.13.1 on WordPress Configuration authorization
CVE-2026-11776 | 10web Form Maker Plugin up to 1.15.43 on WordPress groupids sql injection (EUVD-2026-37842)
CVE-2026-10736 | themeum Tutor LMS Plugin up to 3.9.11 on WordPress data sql injection
CVE-2026-12120 | fireplugins FireBox Popups Plugin up to 3.1.7 on WordPress Form Submission form_id information disclosure (EUVD-2026-37839)
CVE-2026-9199 | equalizedigital Equalize Digital Accessibility Checker Plugin up to 1.42.1 on WordPress Authorization Token authorization
CVE-2026-10623 | pressprimer PressPrimer Quiz Plugin up to 2.3.0 on WordPress rule_id authorization
CVE-2026-55740 | Nur-Alam39 bus-ticket bus_info.php mysqli_query busid sql injection (EUVD-2026-37851)
CVE-2026-11357 | stellarwp Kadence Blocks Plugin up to 3.7.5 on WordPress License Key information disclosure (EUVD-2026-37843)
CVE-2026-11360 | algolplus Advanced Order Export for WooCommerce Plugin up to 4.0.10 on WordPress Endpoint stripslashes_deep sort_direction sql injection (EUVD-2026-37844)
CVE-2026-9860 | vanyukov Offload, AI & Optimize with Cloudflare Images cf-images Plugin wp-config.php sanitize_text_field unrestricted upload (EUVD-2026-37840)
美国暂缓将 DeepSeek 加入黑名单
Lynx
You must login to view this content
Чипы будущего толщиной в 3 атома — и одна ошибка плазмы может всё испортить. Теперь есть способ это исправить
Securing digital keys when your phone unlocks the car
In this interview with Help Net Security, Alysia Johnson, President of the Car Connectivity Consortium (CCC), explains how the CCC Digital Key has grown from a single-brand feature into a standard meant to work across phones, automakers, and suppliers. She talks through what changed with Version 4, why the team focused on interoperability and testing instead of one new threat, and how NFC fallback access stays protected. She also covers fast credential revocation when a … More →
The post Securing digital keys when your phone unlocks the car appeared first on Help Net Security.
Google’s open standard for AI agents to discover and verify tools
AI agents depend on tools, skills, and other agents spread across many teams, organizations, and platforms. These capabilities live in separate systems with their own registries, and an agent working in one environment has limited means to locate and connect to a resource hosted somewhere else. Google addressed this gap with Agentic Resource Discovery, an open specification for publishing, discovering, and verifying AI capabilities across the web. It allows tools and services to be shared … More →
The post Google’s open standard for AI agents to discover and verify tools appeared first on Help Net Security.
CVE-2026-8049 | SignalRGB kernel driver up to 1.3.7.0 access control
How security teams are getting credential visibility into developer endpoints
As we noted in our earlier analysis, attackers already know secrets are on your developers’ machines, the only question is whether security teams do. The supply chain attack calendar of 2026 has been relentless. Megalodon backdoored 5,500 GitHub repositories in six hours. TrapDoor spread across npm, PyPI, and Crates.io simultaneously, planting persistence inside AI coding assistant config files. Miasma compromised 32 official Red Hat packages by abusing GitHub’s trusted publishing. Each campaign shared the same … More →
The post How security teams are getting credential visibility into developer endpoints appeared first on Help Net Security.