Aggregator
CVE-2026-39968 | baptisteArno typebot.io up to 3.15.x Preview Chat Endpoint getCredentials access control (GHSA-cq66-9cwr-x8jr)
CVE-2026-39966 | baptisteArno typebot.io up to 3.15.x getLinkedTypebots API Endpoint Array.filter authorization (GHSA-3fr5-999r-84qj)
CVE-2026-9291 | AWS Amazon Braket Python SDK up to 1.116.x Job Results Processing deserialization (GHSA-g697-2xrc-gc46)
Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos
A highly sophisticated supply chain attack has compromised the Laravel-Lang ecosystem, injecting credential-stealing remote code execution backdoors into 233 package versions across 700 GitHub repositories. Discovered in May 2026 by Socket and Aikido, threat actors manipulated GitHub tags to distribute malware through Composer’s autoloader, granting complete remote access to developer environments. The attackers bypassed direct […]
The post Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos appeared first on Cyber Security News.
Карпову 75: чемпион, после партий с которым соперники не сразу понимали, где проиграли
CVE-2026-9284 | WooCommerce PayPal Payments Plugin up to 4.0.1 on WordPress ppc-create-order/ppc-get-order authorization (EUVD-2026-31524)
Запуск посреди эскалации, но "не про политику". США испытали ядерную ракету, которой уже 55 лет
Frigate NVR 0.16.3 Remote Code Execution
Linux nf_tables 6.19.3 Local Privilege Escalation
ThingsBoard IoT Platform 4.2.0 Server-Side Request Forgery (SSRF)
Linux Kernel Local Privilege Escalation (CVE-2026-43284 / CVE-2026-43500 / CVE-2026-46300)
SUSE Manager 4.3.15 Code Execution
Sub2Api Codex登录出现严重问题 账号无法认证且可能必须手机号验证
The War for Your Documents: Why The Document Foundation is Challenging Microsoft’s OOXML Monopoly
The Document Foundation (TDF), the steward of the open-source office suite LibreOffice, has long been embroiled in an irreconcilable conflict with Microsoft regarding document interoperability. The heart of this contention lies in the divergence...
The post The War for Your Documents: Why The Document Foundation is Challenging Microsoft’s OOXML Monopoly appeared first on Information Security News.
Urgent Patch: Microsoft Defender Update Fixes Critical SYSTEM-Level Privilege Escalation Flaw
Microsoft has formally disseminated a security advisory detailing the successful remediation of critical vulnerabilities identified within the Microsoft Defender anti-virus architecture. These security flaws have been neutralized via the most recent platform and intelligence...
The post Urgent Patch: Microsoft Defender Update Fixes Critical SYSTEM-Level Privilege Escalation Flaw appeared first on Information Security News.
Заряжается за три минуты, держит 700 циклов. Что не так с новой китайской батареей — и почему до электрокаров ей еще далеко
谷歌宣布将反重力每周配额也增加3倍同时重置本周额度试图平息开发者怒火
The Pre-Boot Breach: Microsoft Releases Critical Emergency Script to Defend Against “YellowKey” BitLocker Bypass
Historically, independent security researchers bypassed standard coordinate disclosure protocols to directly publish an unhedged vulnerability residing within the Microsoft BitLocker cryptographic sub-system. The underlying defect facilitates the subversion of conventional encryption barriers natively inside...
The post The Pre-Boot Breach: Microsoft Releases Critical Emergency Script to Defend Against “YellowKey” BitLocker Bypass appeared first on Information Security News.
Anthropic’s Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing
Anthropic has revealed the staggering initial results of Project Glasswing, a collaborative cybersecurity initiative designed to secure critical infrastructure using advanced AI before malicious actors can exploit it. In its first month, the project leveraged the unreleased Claude Mythos Preview model to autonomously discover over 10,000 high- and critical-severity zero-day vulnerabilities across the world’s most […]
The post Anthropic’s Claude Mythos Preview Uncovers 10,000+ 0-Days in Project Glasswing appeared first on Cyber Security News.