Aggregator
CVE-2016-10101 | Hitek Automize 10.x/11.x passManager.jsd inadequate encryption (BID-96840)
CVE-2016-10102 | Hitek Automize up to 10.25/11.14 Profile Password hitek.jar inadequate encryption (BID-96848)
CVE-2016-10103 | Hitek Automize up to 10.25/11.14 GPG Encryption Profile encryptionProfiles.jsd inadequate encryption (BID-96850)
CVE-2016-10104 | Hitek Automize up to 10.25/11.14 sshProfiles.jsd Password inadequate encryption (BID-96845)
CVE-2016-10156 | systemd v228 Timer /src/basic/fs-util.c access control (EDB-41171 / Nessus ID 96793)
CVE-2016-10157 | Akamai NetSession 1.9.3.1 CSUNSAPI.dll code injection (ID 140366 / BID-95995)
Simple bypass of the link preview function in Outlook Junk folder, (Thu, May 14th)
Ваш мозг уже разрушается от хронического недосыпа — есть способ это остановить
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
Critical MongoDB Vulnerability Allow Attackers to Execute Arbitrary Code
A newly disclosed critical vulnerability in MongoDB could allow threat actors to execute arbitrary code, potentially handing them complete control over affected servers and exposing millions of records to theft. The vulnerability, officially tracked as CVE-2026-8053, directly impacts MongoDB Server deployments. Arbitrary code execution is one of the most severe types of security flaws in […]
The post Critical MongoDB Vulnerability Allow Attackers to Execute Arbitrary Code appeared first on Cyber Security News.
CVE-2026-7912 | Google Chrome up to 147.0.7727.138 on Android GPU integer overflow (Nessus ID 314292 / WID-SEC-2026-1394)
CVE-2026-7913 | Google Chrome up to 147.0.7727.138 on Android DevTools Local Privilege Escalation (Nessus ID 314292 / WID-SEC-2026-1394)
CVE-2026-7909 | Google Chrome up to 147.0.7727.138 ServiceWorker sandbox (Nessus ID 314292 / WID-SEC-2026-1394)
CVE-2026-7910 | Google Chrome up to 147.0.7727.138 Views use after free (Nessus ID 314292 / WID-SEC-2026-1394)
CVE-2026-7911 | Google Chrome up to 147.0.7727.138 on Windows Aura use after free (Nessus ID 314292 / WID-SEC-2026-1394)
社交平台X宣布推出一个新的“历史”标签页
The Gentlemen RaaS Leverages Fortinet and Cisco Edge Devices for Initial Access
A ransomware group that only surfaced in mid-2025 has already made a significant mark on the threat landscape. The Gentlemen, a ransomware-as-a-service (RaaS) operation, has quickly risen to become one of the most active ransomware programs in the world, with around 332 published victims in just the first five months of 2026 alone. The group […]
The post The Gentlemen RaaS Leverages Fortinet and Cisco Edge Devices for Initial Access appeared first on Cyber Security News.
Vector embedding security gap exposes enterprise AI pipelines
Enterprise adoption of retrieval-augmented generation has moved sensitive corporate content into a new storage format that existing security tools cannot inspect. Companies deploying internal AI assistants convert documents into high-dimensional numerical vectors and ship them to embedding services and vector databases over ordinary HTTPS connections. Data loss prevention products scan documents and network traffic, and they read none of it. A research framework called VectorSmuggle, released by Jascha Wanger of ThirdKey under the Apache 2.0 … More →
The post Vector embedding security gap exposes enterprise AI pipelines appeared first on Help Net Security.