Aggregator
Simple bypass of the link preview function in Outlook Junk folder, (Thu, May 14th)
Ваш мозг уже разрушается от хронического недосыпа — есть способ это остановить
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE
Critical MongoDB Vulnerability Allow Attackers to Execute Arbitrary Code
A newly disclosed critical vulnerability in MongoDB could allow threat actors to execute arbitrary code, potentially handing them complete control over affected servers and exposing millions of records to theft. The vulnerability, officially tracked as CVE-2026-8053, directly impacts MongoDB Server deployments. Arbitrary code execution is one of the most severe types of security flaws in […]
The post Critical MongoDB Vulnerability Allow Attackers to Execute Arbitrary Code appeared first on Cyber Security News.
CVE-2026-7912 | Google Chrome up to 147.0.7727.138 on Android GPU integer overflow (Nessus ID 314292 / WID-SEC-2026-1394)
CVE-2026-7913 | Google Chrome up to 147.0.7727.138 on Android DevTools Local Privilege Escalation (Nessus ID 314292 / WID-SEC-2026-1394)
CVE-2026-7909 | Google Chrome up to 147.0.7727.138 ServiceWorker sandbox (Nessus ID 314292 / WID-SEC-2026-1394)
CVE-2026-7910 | Google Chrome up to 147.0.7727.138 Views use after free (Nessus ID 314292 / WID-SEC-2026-1394)
CVE-2026-7911 | Google Chrome up to 147.0.7727.138 on Windows Aura use after free (Nessus ID 314292 / WID-SEC-2026-1394)
社交平台X宣布推出一个新的“历史”标签页
The Gentlemen RaaS Leverages Fortinet and Cisco Edge Devices for Initial Access
A ransomware group that only surfaced in mid-2025 has already made a significant mark on the threat landscape. The Gentlemen, a ransomware-as-a-service (RaaS) operation, has quickly risen to become one of the most active ransomware programs in the world, with around 332 published victims in just the first five months of 2026 alone. The group […]
The post The Gentlemen RaaS Leverages Fortinet and Cisco Edge Devices for Initial Access appeared first on Cyber Security News.
Vector embedding security gap exposes enterprise AI pipelines
Enterprise adoption of retrieval-augmented generation has moved sensitive corporate content into a new storage format that existing security tools cannot inspect. Companies deploying internal AI assistants convert documents into high-dimensional numerical vectors and ship them to embedding services and vector databases over ordinary HTTPS connections. Data loss prevention products scan documents and network traffic, and they read none of it. A research framework called VectorSmuggle, released by Jascha Wanger of ThirdKey under the Apache 2.0 … More →
The post Vector embedding security gap exposes enterprise AI pipelines appeared first on Help Net Security.
Q-Day близко. Современную криптографию вскроют куда раньше любых прогнозов
营收1965亿,市值创近一年新低,马化腾:一年前上了AI的船,结果发现船漏水了
法官拒绝立即批准马斯克与SEC的和解协议
Closing the AI governance gap in your enterprise
In this Help Net Security video, Casey Bleeker, CEO at SurePath AI, talks about the AI governance gap that exists in almost every organization. Drawing from three years of conversations with IT, business, and security leaders, Casey explains why AI adoption is outpacing governance maturity by a wide margin, creating friction between security teams pushing for responsible use and business leaders worried about falling behind competitors. Casey walks through what a typical audit reveals at … More →
The post Closing the AI governance gap in your enterprise appeared first on Help Net Security.