Aggregator
Tamnoon introduces skill-based AI orchestration for autonomous cloud defense
Tamnoon has expanded its AI engine, Tami, into a skill-based orchestrator that generates customer-specific remediation skills tailored to each enterprise environment. Trained on more than 6 million real cloud fixes across 800+ accounts, Tami coordinates specialized AI skills to safely and autonomously address every class of cloud risk. Two new skills are available, Remediation Confidence Score and Safe Vulnerability Patching Simulator. Frontier AI is reshaping the cloud attack surface exponentially. AI ships vulnerable code 24/7, … More →
The post Tamnoon introduces skill-based AI orchestration for autonomous cloud defense appeared first on Help Net Security.
Malware Found in Laravel-Lang Composer Packages After Git Tag Poisoning Attack
Hackers Use SEO Poisoning to Impersonate Gemini CLI and Claude Code Installers
Hackers are targeting software developers by creating fake installation pages for two popular AI coding tools, Gemini CLI and Claude Code. The attackers are using a technique called SEO poisoning to push their malicious websites above real ones in search results, tricking developers into running dangerous commands on their own machines. The campaign began surfacing […]
The post Hackers Use SEO Poisoning to Impersonate Gemini CLI and Claude Code Installers appeared first on Cyber Security News.
CVE-2026-42627 | Arm ArmNN up to 2026-03-27 TFLite armnn/Tensor.cpp GetNumElements integer overflow (Nessus ID 316557)
CVE-2026-40295 | heartcombo devise up to 5.0.3 Timeoutable FailureApp#redirect_url (GHSA-jp94-3292-c3xv / Nessus ID 316558)
CVE-2026-39834 | x-crypto up to 0.51.x integer overflow (EUVD-2026-31400 / Nessus ID 316559)
56 моделей AMD, 7,1 балла по CVSS. Чем опасна CVE-2025-54502 и нужно ли срочно обновлять BIOS
CVE-2026-9568 | ThingsBoard up to 4.3.1.1 YAML /api/v1/provision getGatewayDockerComposeFile code injection (ID 15550)
【安全圈】“神奇小子”乔治 · 霍茨警告称 AI 编程智能体将成软件最大隐患
【安全圈】用户反馈摩托罗拉手机预装 App 劫持电商应用,植入电商联盟代码
【安全圈】微软 Copilot Cowork 智能体 AI 曝安全风险,机密文件恐外泄
Submit #817064: ThingsBoard ThingsBoard Community Edition 3.6.2 through 4.3.1.1 Code Injection [Accepted]
CVE-2026-9567 | GPAC up to 2.4.0 MP4Box isom_intern.c MergeFragment null pointer dereference (Issue 3549)
CVE-2026-9566 | teableio teable up to 1.9.x Sign-up LoginPage.tsx redirect cross site scripting
Submit #816075: GPAC MP4Box <= 2.4.0 (master commit 7508ccc and earlier) Null pointer dereference (Denial of Service) [Accepted]
Submit #815798: Teable < release.2026-04-21T08-57-20Z.1513 DOM-Based XSS, Open Redirect [Accepted]
Critical Memcached SASL Vulnerability Let Attackers Infer Valid Usernames
A newly disclosed security issue in Memcached has raised concerns after developers confirmed a timing side-channel vulnerability in its SASL authentication mechanism that could allow attackers to infer valid usernames, now tracked as CVE‑2026‑47783. The flaw was addressed in the recently released Memcached version 1.6.42, a security-focused update that fixes multiple critical bugs affecting stability […]
The post Critical Memcached SASL Vulnerability Let Attackers Infer Valid Usernames appeared first on Cyber Security News.
共研智能体岗位标准 360牵头推进AI人才规范化发展!
High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659)
Microsoft has released patches for a high-severity remote code execution vulnerability (CVE-2026-45659) in SharePoint that may be exploited in low-complexity attacks. It affects the SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. About CVE-2026-45659 CVE-2026-45659 stems from Shareoint deserializing untrusted data, and may be exploited by an authenticated attacker to execute code remotely on a vulnerable SharePoint Server instance – no user interaction required. “The attack complexity is Low (AC:L) because … More →
The post High-severity SharePoint RCE bug patched by Microsoft (CVE-2026-45659) appeared first on Help Net Security.