Posts of last few hours
Please support the site operations by clicking ads.
2026 年 8 月多台被入侵的 Cisco Firewall Management Center(思科防火墙
https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451188758&idx=1&sn=925fa614b706046fb8a5fb51f635ba9d
Три голоса появились там, где железо умеет только включать и выключать звук.
https://www.securitylab.ru/news/577362.php
表面上是个 debug 接口问题,顺着调用链跟下去会发现,真正失守的是 `authentik` 在 detail `GET` 上依赖的对象级授权边界。只要目标实例配置过 LDAP Source,攻击者又能访问 API 并知道或猜到某个 `slug`,就可以在未登录状态下请求
https://xz.aliyun.com/news/92667
RAGFlow v0.24.0 用户裸奔了 2.5 个月——SSTI 沙箱补丁 3 月才合入、4 月才发版。三个 CVE(SSTI/Zip Slip/API key 推导)都是普通账号起步直接 root,核心问题是"用户输入没边界检查就进了危险函数"。配套开源了 ragflow-audit.py,ssti/zipslip/apikey 三子命令实测复现。
https://xz.aliyun.com/news/92668
本文详细梳理了ret2dlresolve的核心底层原理,从延迟绑定、PLT/GOT表结构到_dl_fixup查表流程进行了深度剖析,并针对No RELRO、Partial RELRO等不同保护机制,给出了32 位/64位的攻击利用思路与经典例题实战
https://xz.aliyun.com/news/92670
A forum actor posting as BogotaLeaks is offering what they claim are databases from Argentina's SIPA, Sistema Integrado Previsional Argentino, the national pension system.
https://darkwebinformer.com/argentina-sipa-pension-dataset-claim-covers-38m-records-and-9-5m-citizens/
https://cyber.gc.ca/en/alerts-advisories/samsung-mobile-security-advisory-av26-919
9月12日晚香港iPhone 18预购刚开,一堆人突然收到银行短信——信用卡被刷了10499、11499、13299港元,正好是一部新机的钱。
最离谱的是,卡明明在手里,连验证码都没收到。有人压根没买手机,卡片却被连刷好几笔,最高一笔干进去11.4万。到13日凌晨,报案超700人,涉款约1470万,恒生、汇丰、渣打全中招。
为啥没验证码也能刷?因为网上支付只要卡号、有效期和背面的CVV码。碰上大促订单暴增,风控系统觉得风险低就直接放行,验证码这关直接省了。黑产专挑新款iPhone下手,单价高还好脱手。
目前苹果说正排查取消可疑订单,银行也表态:确认非本人授权且你没犯傻,不用你赔。但前提是得自己及时发现并申报。
真遇上这事,赶紧按这几步走:先冻结卡片,再联系银行退单,截图留证,顺手报警。
https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078922&idx=1&sn=a0091fb8176b4b0b034d42ccf6d49b75
Socket has discovered a Twitch browser extension forwarding users' OAuth tokens to a Russian bot service
https://www.infosecurity-magazine.com/news/malicious-twitch-extension-oauth/
Защитные команды столкнулись с противником, который не делает пауз.
https://www.securitylab.ru/news/577337.php
Kinryū Labs 发现了一个因错误配置而能被访问的数据库,该数据库 Advance Passenger Information 记录了过去九年进出越南的几乎所有旅客和机组人员的信息。在接到通知之后该数据库的访问于 2026 年 6 月关闭。Kinryu Labs 是在 6 月 3 日发现了名为 pax-info 的 Elasticsearch 集群,该数据库可使用默认凭证登陆,运营者没有改变默认的用户名和密码,它包含了 29 个索引和约 107 GB 的数据。其中两个主要索引分别存储了 210,318,069 条乘客记录和 10,465,631 条机组人员记录,总计 220,783,700 条记录,时间是从 2017 年 1 月 7 日至 2026 年 4 月 30 日。泄露的信息包括乘客和机组人员的姓名、出生日期、性别、国籍、护照或旅行证件号码、证件有效期及签发国。相关的旅行数据则包括航班号与日期、航空公司、出发地、目的地及中转机场、座位信息、行李编号,以及计划、预计和实际飞行时间。涉及的旅客国籍包括韩国、中国、加拿大、新西兰等。
https://www.solidot.org/story?sid=85375
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination.
The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of
https://thehackernews.com/2026/09/weekly-recap-rogue-ai-agents-wechat.html
Марсианское жильё прошло первый лабораторный тест.
https://www.securitylab.ru/news/577315.php
https://cyber.gc.ca/en/alerts-advisories/mongodb-security-advisory-av26-918
A human attacker exploited a Marimo RCE and reached an SSH bastion in eight seconds
https://www.infosecurity-magazine.com/news/human-attacker-machine-speed/
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Two of the above vulnerabilities affect JFrog Artifactory. CVE-2026-42016 can allow attackers to bypass authorization checks and […]
https://securityaffairs.com/199032/security/u-s-cisa-adds-gitlab-jfrog-artifactory-and-connectwise-screenconnect-flaws-to-its-known-exploited-vulnerabilities-catalog.html
Будущее ПВО взлетает с грузовика, CARI в действии.
https://www.securitylab.ru/news/577318.php
Patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster. Action1 explains how update rings, predefined success criteria, and human oversight can make automated patching faster without sacrificing control. [...]
https://www.bleepingcomputer.com/news/security/why-patch-automation-needs-brakes-not-just-an-accelerator/
https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497150&idx=1&sn=cc60d411fd7fc7217878b774d67e63e9
Entrust has unveiled new capabilities for its Cryptographic Security Platform (CSP) that help organizations turn Cryptographic Bill of Materials (CBOMs) data into action. Government agencies, financial institutions, healthcare organizations, and other critical infrastructure operators are navigating increased cyber threats, shorter certificate lifecycles, the rapid growth of machine and AI identities, evolving compliance requirements, and the transition to post-quantum cryptography. Managing these changes depends on a comprehensive view of where cryptography resides and how assets and … More →
The post Entrust turns cryptographic inventory data into security action appeared first on Help Net Security.
https://www.helpnetsecurity.com/2026/09/14/entrust-cbom-capabilities/
Latest Blog Posts
- 1 month ago
- 3 months ago
- 3 months ago
- 3 months ago
- 3 months ago
- 7 months 3 weeks ago
- 1 year 1 month ago
- 1 year 1 month ago
- 1 year 2 months ago
- 1 year 6 months ago