Aggregator
联邦调查局警告:假冒国际足联网站借世界杯实施诈骗
19 hours 52 minutes ago
联邦调查局(FBI)发出警告,在 2026 年世界杯前夕,出现了一些假冒国际足联(FIFA)的网站,这些网站旨在窃取个人和财务信息、售卖假门票与贵宾套餐,以及实施与赛事相关的其他诈骗活动。 这届国际足球锦标赛将于 6 月 11 日至 7 月 19 日在美国、加拿大和墨西哥举行,威胁行为者已准备了数百个钓鱼网站。 根据 FBI 发布的公共服务公告,这些假冒域名模仿官方的fifa.com,但利用一些不...
hackernews
Charter Communications data breach affects 4.9 million accounts
19 hours 53 minutes ago
The ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking the U.S. telecom giant Charter Communications in early April, according to data breach notification service Have I Been Pwned. [...]
Sergiu Gatlan
CVE-2026-10064 | TRENDnet TEW-432BRP 3.10B20 /goform/formSetPortTr special_name stack-based overflow
19 hours 56 minutes ago
A vulnerability classified as critical has been found in TRENDnet TEW-432BRP 3.10B20. This affects the function formSetPortTr of the file /goform/formSetPortTr. Performing a manipulation of the argument special_name results in stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is cataloged as CVE-2026-10064. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."
vuldb.com
CVE-2026-10063 | TRENDnet TEW-432BRP 3.10B20 /goform/formWPS peerPin stack-based overflow
19 hours 56 minutes ago
A vulnerability described as critical has been identified in TRENDnet TEW-432BRP 3.10B20. Affected by this issue is the function formWPS of the file /goform/formWPS. Such manipulation of the argument peerPin leads to stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is listed as CVE-2026-10063. The attack may be performed from remote. In addition, an exploit is available.
The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."
vuldb.com
CVE-2026-10062 | TRENDnet TEW-432BRP 3.10B20 /goform/formSetRoute ip/mask/gateway stack-based overflow
19 hours 57 minutes ago
A vulnerability marked as critical has been reported in TRENDnet TEW-432BRP 3.10B20. Affected by this vulnerability is the function formSetRoute of the file /goform/formSetRoute. This manipulation of the argument ip/mask/gateway causes stack-based buffer overflow. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is tracked as CVE-2026-10062. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."
vuldb.com
CVE-2026-10061 | TRENDnet TEW-432BRP 3.10B20 /goform/formWPS peerPin command injection
19 hours 57 minutes ago
A vulnerability labeled as critical has been found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is identified as CVE-2026-10061. The attack can be executed remotely. Additionally, an exploit exists.
The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."
vuldb.com
CVE-2026-10060 | TRENDnet TEW-432BRP 3.10B20 /goform/formSetRoute ip/mask/gateway command injection
19 hours 57 minutes ago
A vulnerability identified as critical has been detected in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads to command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is referenced as CVE-2026-10060. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
The vendor explains: "This product has been EOL for 15 years (since 2009). As the item has been EOL for such a long time, we are not able to replicate or fix any vulnerabilities."
vuldb.com
新型 BTMOB 安卓恶意软件可实现设备完全接管
19 hours 57 minutes ago
ESET 警告称,BTMOB 远程访问木马(RAT)因其具备数据窃取和设备接管能力,正对安卓用户构成日益严重的威胁。 据信,BTMOB 基于 SpySolr 恶意软件开发,通过网络钓鱼攻击传播,利用诸如流媒体、加密货币挖矿及其他常见服务作为诱饵。 然而,其开发者将它与 APK 构建器界面捆绑销售,使得威胁行为者无需编写代码,就能根据目标地域定制诱饵并创建新的有效载荷。 ...
hackernews
BTMOB RAT Gives Criminals a Point-and-Click Kit to Take Over Your Android Phone
20 hours ago
BTMOB sells Android full-device takeover as a kit, no coding needed. It steals data, records screens, and hands attackers remote control for $5,000 lifetime. Most Android malware requires at least some technical competence to deploy, but the BTMOB doesn’t. The developers sell it with a built-in APK builder that lets buyers generate new malicious apps, […]
Pierluigi Paganini
Submit #814760: TRENDnet TEW-432BRP 3.10B20 Stack-based Buffer Overflow [Accepted]
20 hours 1 minute ago
Submit #814760 / VDB-367150
pjqwudi_Buoy
Submit #814759: TRENDnet TEW-432BRP 3.10B20 Stack-based Buffer Overflow [Accepted]
20 hours 1 minute ago
Submit #814759 / VDB-367149
pjqwudi_Buoy
Submit #814758: TRENDnet TEW-432BRP 3.10B20 Stack-based Buffer Overflow [Accepted]
20 hours 2 minutes ago
Submit #814758 / VDB-367148
pjqwudi_Buoy
Anthropic 估值首次超过 OpenAI
20 hours 2 minutes ago
Anthropic 周四宣布以 9650 亿美元估值融资 650 亿美元。此次 H 轮融资后 Anthropic 估值首次超过竞争对手 OpenAI。OpenAI 在今年 3 月的融资后估值为 8520 亿美元,而今年 2 月 Anthropic 的估值还只有 3800 亿美元。Anthropic 和 OpenAI 都在筹备上市,最快发生在今年。Anthropic 称它根据最近一个月的营收估计全年营收有望突破 470 亿美元。
Submit #814757: TRENDnet TEW-432BRP 3.10B20 Command Injection [Accepted]
20 hours 2 minutes ago
Submit #814757 / VDB-367147
pjqwudi_Buoy
Submit #814756: TRENDnet TEW-432BRP 3.10B20 Command Injection [Accepted]
20 hours 2 minutes ago
Submit #814756 / VDB-367146
pjqwudi_Buoy
CVE-2026-45343 | Kovah LinkAce up to 2.5.5 SSO/OAuth cross site scripting (GHSA-jx4g-ph82-x9mm)
20 hours 4 minutes ago
A vulnerability categorized as problematic has been discovered in Kovah LinkAce up to 2.5.5. This affects an unknown function of the component SSO/OAuth. Executing a manipulation can lead to cross site scripting.
The identification of this vulnerability is CVE-2026-45343. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-8070 | ASUS Armoury Crate up to 6.4.12 permission assignment
20 hours 4 minutes ago
A vulnerability was found in ASUS Armoury Crate up to 6.4.12. It has been rated as problematic. The impacted element is an unknown function. Performing a manipulation results in incorrect permission assignment.
This vulnerability was named CVE-2026-8070. The attack needs to be approached locally. There is no available exploit.
vuldb.com
CVE-2026-48116 | Mintplex-Labs anything-llm up to 1.12.x command injection (GHSA-6hrp-7mw6-8v59)
20 hours 5 minutes ago
A vulnerability was found in Mintplex-Labs anything-llm up to 1.12.x. It has been declared as critical. The affected element is an unknown function. Such manipulation leads to command injection.
This vulnerability is uniquely identified as CVE-2026-48116. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-6892 | Canon PIXUS iX6800 CUPS Printer Driver up to 16.91.0.0 on macOS link following
20 hours 5 minutes ago
A vulnerability was found in Canon PIXUS iX6800 CUPS Printer Driver, PIXMA MG2500 CUPS Printer Driver and PIXMA iX6800 CUPS Printer Driver up to 16.91.0.0 on macOS. It has been classified as critical. Impacted is an unknown function. This manipulation causes link following.
This vulnerability is handled as CVE-2026-6892. It is possible to launch the attack on the local host. There is not any exploit available.
vuldb.com