Aggregator
python免杀工具学习记录
2 months ago
最近学习了一下免杀相关的知识,参考了互联网几个公开项目的思路,尝试自己开发了一个小工具,本文主要用来记录一下主要思路。
【从这里 向世界出发】2025 BSRC年度盛典圆满落幕!
2 months ago
2026 年 4 月 21 日,「从这里 向世界出发」百度安全 2025 BSRC 年度盛典在印度尼西亚-巴厘岛圆满举办。近30 位白帽精英齐聚一堂,围绕AI 安全攻防实践、高危漏洞挖掘等核心议题深度交流,共探数字时代安全挑战与防御之道。
先知平台关于AI生成漏洞报告的处置公告
2 months ago
感谢您一直以来对先知平台的支持与信任!
GopherWhisper: A burrow full of malware
2 months ago
ESET Research has discovered a new China-aligned APT group that we’ve named GopherWhisper, which targets Mongolian governmental institutions
CVE-2026-41228 | Froxlor up to 2.3.5 API Endpoint Language::loadLanguage def_language filename control (GHSA-w59f-67xm-rxx7 / EUVD-2026-25176)
2 months ago
A vulnerability was found in Froxlor up to 2.3.5. It has been declared as critical. This affects the function Language::loadLanguage of the component API Endpoint. The manipulation of the argument def_language results in improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is cataloged as CVE-2026-41228. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-41229 | Froxlor up to 2.3.5 Setting lib/userdata.inc.php parseArrayToString privileged_user code injection (GHSA-gc9w-cc93-rjv8 / EUVD-2026-25178)
2 months ago
A vulnerability was found in Froxlor up to 2.3.5. It has been rated as critical. This vulnerability affects the function PhpHelper::parseArrayToString in the library lib/userdata.inc.php of the component Setting Handler. This manipulation of the argument privileged_user causes code injection.
This vulnerability is registered as CVE-2026-41229. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-41230 | Froxlor up to 2.3.5 DomainZones::add crlf injection (GHSA-47hf-23pw-3m8c / EUVD-2026-25180)
2 months ago
A vulnerability has been found in Froxlor up to 2.3.5 and classified as problematic. This affects the function DomainZones::add. Performing a manipulation results in crlf injection.
This vulnerability was named CVE-2026-41230. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-41231 | Froxlor up to 2.3.5 Destination DataDump.add fixed_homedir link following (GHSA-75h4-c557-j89r / EUVD-2026-25182)
2 months ago
A vulnerability marked as critical has been reported in Froxlor up to 2.3.5. This affects the function DataDump.add of the component Destination Handler. Performing a manipulation of the argument fixed_homedir results in link following.
This vulnerability is reported as CVE-2026-41231. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-41232 | Froxlor up to 2.3.5 Email Address EmailSender::add authorization (EUVD-2026-25186)
2 months ago
A vulnerability classified as problematic was found in Froxlor up to 2.3.5. This affects the function EmailSender::add of the component Email Address Handler. Such manipulation leads to incorrect authorization.
This vulnerability is traded as CVE-2026-41232. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-41233 | Froxlor up to 2.3.5 Domains.add adminid authorization (EUVD-2026-25188)
2 months ago
A vulnerability categorized as problematic has been discovered in Froxlor up to 2.3.5. This affects the function Domains.add. Such manipulation of the argument adminid leads to incorrect authorization.
This vulnerability is listed as CVE-2026-41233. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-2951 | Gutentor Plugin up to 3.5.5 on WordPress Gutenberg Block cross site scripting (EUVD-2026-25168)
2 months ago
A vulnerability categorized as problematic has been discovered in Gutentor Plugin up to 3.5.5 on WordPress. Affected is an unknown function of the component Gutenberg Block Handler. The manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-2951. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-1923 | socialrocket Social Rocket Plugin up to 1.3.4.2 on WordPress cross site scripting (EUVD-2026-25148)
2 months ago
A vulnerability identified as problematic has been detected in socialrocket Social Rocket Plugin up to 1.3.4.2 on WordPress. Affected by this vulnerability is an unknown functionality. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2026-1923. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-3844 | cloudways Breeze Cache Plugin up to 2.4.4 on WordPress fetch_gravatar_from_remote unrestricted upload (EUVD-2026-25174)
2 months ago
A vulnerability has been found in cloudways Breeze Cache Plugin up to 2.4.4 on WordPress and classified as critical. Impacted is the function fetch_gravatar_from_remote. This manipulation causes unrestricted upload.
The identification of this vulnerability is CVE-2026-3844. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-4106 | HT Mega Addons for Elementor Plugin up to 3.0.6 on WordPress Ajax Action information disclosure (EUVD-2026-25196)
2 months ago
A vulnerability was found in HT Mega Addons for Elementor Plugin up to 3.0.6 on WordPress. It has been declared as problematic. This vulnerability affects unknown code of the component Ajax Action Handler. Such manipulation leads to information disclosure.
This vulnerability is referenced as CVE-2026-4106. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-4512 | WebDesignBy reCaptcha Plugin up to 1.x on WordPress Setting grecaptcha_js cross site scripting (EUVD-2026-25197)
2 months ago
A vulnerability was found in WebDesignBy reCaptcha Plugin up to 1.x on WordPress. It has been rated as problematic. This issue affects the function grecaptcha_js of the component Setting Handler. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2026-4512. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-34488 | i-PRO IP Setting Software up to 5.19 uncontrolled search path (EUVD-2026-25194)
2 months ago
A vulnerability categorized as problematic has been discovered in i-PRO IP Setting Software up to 5.19. Impacted is an unknown function. Executing a manipulation can lead to uncontrolled search path.
This vulnerability is tracked as CVE-2026-34488. The attack is restricted to local execution. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
深度分析 | 在官方 KICS Docker 中发现恶意 Checkmarx 构件
2 months ago
TeamPCP组织对Checkmarx KICS发起供应链投毒攻击,Docker镜像劫持+Git历史操纵+Bun运行时执行+凭证收割+Canister Worm蠕虫传播
NCSC Backs Passkeys, Hailing a New Era of Sign-in
2 months ago
The UK’s NCSC has fully backed passkeys as consumers’ first choice for login, citing progress with FIDO and successful use across the NHS
Vercel Finds More Compromised Accounts in Context.ai-Linked Breach
2 months ago
Vercel on Wednesday revealed that it has identified an additional set of customer accounts that were compromised as part of a security incident that enabled unauthorized access to its internal systems.
The company said it made the discovery after expanding its investigation to include an extra set of compromise indicators, alongside a review of requests to the Vercel network and environment
The Hacker News