Aggregator
打破光刻工艺束缚,华为提出「韬定律」;宇树科技将于 6 月 1 日接受科创板上市审核;追觅官宣 C 罗出任全球代言人 | 极客早知道
5 days 20 hours ago
谷歌 CEO:Gemini 在 AI 编程赛道已落后;法拉利首款纯电动车 Ferrari Luce 发布;曝小红书已获 2026 世界杯分销版权。
INC
5 days 20 hours ago
You must login to view this content
cohenido
Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th)
5 days 20 hours ago
IntroductionIn recent weeks, I've searched for pages impersonating Claude that distribute malware
欧盟将对谷歌开出近10亿欧元反垄断罚单
5 days 20 hours ago
德国《商报》周一援引欧盟委员会知情人士的消息称,欧盟正计划在一项反垄断调查中对谷歌处以数亿欧元、接近10亿欧元级别的罚款。报道称,该决定已接近完成,预计将在欧盟夏季休会前公布。这将是欧盟因违反《数字市
[local] Linux Kernel 6.8 - Local Privilege Escalation
5 days 20 hours ago
Linux Kernel 6.8 - Local Privilege Escalation
[webapps] cPanel - CRLF Injection
5 days 20 hours ago
cPanel - CRLF Injection
[webapps] Wordpress Temporary Login Plugin 1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover
5 days 20 hours ago
Wordpress Temporary Login Plugin 1.0.0 - 'temp-login-token' Authentication Bypass to Account Takeover
[hardware] D-Link DSL2600U - 'rom-0' Admin Password Disclosure
5 days 20 hours ago
D-Link DSL2600U - 'rom-0' Admin Password Disclosure
[webapps] Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service
5 days 20 hours ago
Apache HTTP Server 2.4.66 - 'mod_http2' Double-Free Denial of Service
[webapps] Grav CMS 2.0.0-beta.2 - Remote Code Execution
5 days 20 hours ago
Grav CMS 2.0.0-beta.2 - Remote Code Execution
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
5 days 20 hours ago
TrendAI™ Research analyzed an intrusion where threat actors used the EtherHiding technique to route ClearFake payload delivery through smart contracts on the BNB Smart Chain testnet. The attack chain ended with two simultaneously deployed stealers, SectopRAT and ACRStealer alongside an on-chain execution tracker that confirmed each victim compromise in real time.
Ryan Soliven
筑牢工控安全屏障,威努特为药企生产保驾护航
5 days 20 hours ago
守护药企生产安全。
筑牢工控安全屏障,威努特为药企生产保驾护航
5 days 20 hours ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
Kremlin appoints cyber executive with alleged GRU ties to Security Council role
5 days 21 hours ago
Andrei Kozlov, the former head of a cybersecurity center within Russia’s state-owned defense conglomerate Rostec, was named an aide to Security Council Secretary Sergei Shoigu on Friday.
Dutch authorities arrest men suspected of providing infrastructure for Russian cyber operations
5 days 21 hours ago
Investigators seized more than 800 servers as they arrested two men suspected of violating European sanctions and assisting pro-Russian cyberattacks and disinformation campaigns.
Welcoming the Bhutanese Government to Have I Been Pwned
5 days 21 hours ago
Today, we welcome the 45th government onboarded to Have I Been Pwned’s free gov service: Bhutan. The Bhutan Computer Incident Response Team, BtCIRT, now has access to monitor Bhutanese government domains against the data in HIBP. As Bhutan’s national CIRT, BtCIRT is responsible for consuming threat
Troy Hunt
【工具】开源情报“侦察兵”:SnScrape 多平台社交媒体爬取工具全解析
5 days 22 hours ago
Snscrape是一款功能强大的免费工具,无需API密钥即可从 Twitter、TikTok、YouTube、Reddit等平台抓取公开的社交媒体数据。它非常适合研究人员、营销人员、开发人员和Python初学者,让您能够快速轻松地收集、导出和分析数据。
CVE-2026-48848 | Roundcube Webmail up to 1.6.15/1.7.0 SVG Document attributeName cross site scripting (EUVD-2026-31727)
5 days 22 hours ago
A vulnerability described as problematic has been identified in Roundcube Webmail up to 1.6.15/1.7.0. Affected by this vulnerability is an unknown functionality of the component SVG Document Handler. Such manipulation of the argument attributeName leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2026-48848. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-9486 | SourceCodester Student Grades Management System 1.0 cross-site request forgery (EUVD-2026-31726)
5 days 22 hours ago
A vulnerability labeled as problematic has been found in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery.
This vulnerability is identified as CVE-2026-9486. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com