Aggregator
Шесть запросов до полного взлома. Ошибка в коде популярной CRM ставит под удар малый бизнес
4 days 10 hours ago
Разработчики EspoCRM закрыли критическую уязвимость в механизме обработки файлов.
Apple adds macOS Terminal warning to block ClickFix attacks
4 days 10 hours ago
Apple has introduced a security feature in macOS Tahoe 26.4 that blocks pasting and executing potentially harmful commands in Terminal and alerts users to possible risks. [...]
Bill Toulas
New macOS security feature will alert users about possible ClickFix attacks
4 days 10 hours ago
Apple introduced an extra layer of protection against ClickFix attacks, only for macOS Tahoe 26.4 and later
The post New macOS security feature will alert users about possible ClickFix attacks appeared first on Security Boulevard.
Malwarebytes
Akira
4 days 10 hours ago
You must login to view this content
cohenido
It’s a mystery … alleged unpatched Telegram zero-day allows device takeover, but Telegram denies
4 days 10 hours ago
A critical Telegram flaw could allow zero-click remote code execution on devices, but Telegram denies it. Researcher Michael DePlante (@izobashi) of TrendAI Zero Day disclosed a new Telegram vulnerability through Zero Day Initiative (ZDI). The vulnerability, tracked as ZDI-CAN-30207 (CVSS score of 9.8) allows attackers to execute code on targeted devices without any user interaction. […]
Pierluigi Paganini
Плати за VPN: Минцифры вводит лимиты на международный трафик с 1 мая
4 days 10 hours ago
Ozon, Wildberries и «Яндекс» начнут ограничивать доступ пользователям с VPN.
Qilin
4 days 10 hours ago
You must login to view this content
cohenido
Qilin
4 days 10 hours ago
You must login to view this content
cohenido
Qilin
4 days 10 hours ago
You must login to view this content
cohenido
How to Evaluate AI SOC Agents: 7 Questions Gartner Says You Should Be Asking
4 days 10 hours ago
AI SOC agents can reduce alert fatigue, but most teams fail to measure real outcomes. Prophet Security breaks down Gartner's questions for evaluating AI SOC agents and separating real impact from hype. [...]
Sponsored by Prophet Security
Lloyds IT Glitch Exposed Data of Nearly 500,000 Banking Customers
4 days 10 hours ago
Lloyds app glitch exposed up to 447,936 customers’ transactions and personal data during update
Как сделать из одной мухи пять слонов. Инструкция от составителей базы CVE
4 days 10 hours ago
Как эксперты пугают нас дутыми цифрами
European Commission downplays ShinyHunters cyberattack impact
4 days 11 hours ago
In a statement issued Friday, the Commission said it had detected an incident affecting the Europa.eu web portal, the European Union’s central online platform hosting websites and services for its institutions.
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
4 days 11 hours ago
Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention.
There's a bit of everything this week. Persistence plays, legal wins, influence ops, and at least one thing that looks boring
The Hacker News
沧桑十年_马识途
4 days 11 hours ago
百科上的介绍偏重他的作家身份,对他的革命者、建设者身份着墨不多。我则对他的另两重身份很有兴趣。
Fortinet security advisory (AV26-096) – Update 1
4 days 11 hours ago
Canadian Centre for Cyber Security
ALP001
4 days 11 hours ago
You must login to view this content
cohenido
CVE-2026-3321 | ON24 Q&A Chat History answer authorization (EUVD-2026-17084)
4 days 11 hours ago
A vulnerability has been found in ON24 Q&A Chat and classified as problematic. Affected by this vulnerability is an unknown functionality of the file console-survey/api/v1/answer/ of the component History Handler. Performing a manipulation results in authorization bypass.
This vulnerability is cataloged as CVE-2026-3321. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com
CVE-2026-5157 | code-projects Online Food Ordering System 1.0 Order /form/order.php cust_id cross site scripting
4 days 11 hours ago
A vulnerability, which was classified as problematic, was found in code-projects Online Food Ordering System 1.0. Affected is an unknown function of the file /form/order.php of the component Order Module. Such manipulation of the argument cust_id leads to cross site scripting.
This vulnerability is listed as CVE-2026-5157. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com