Aggregator
Впервые за 50 лет: Россия снова строит сверхзвуковой пассажирский самолёт — и это уже не чертежи
1 week 6 days ago
Он должен летать на скорости 1,7 Маха и быть тише своих предшественников.
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
1 week 6 days ago
Microsoft has announced that Visual Studio Code (VS Code) will apply a two-hour delay before extensions for the integrated development environment (IDE) are updated automatically to a newer version in an attempt to tackle software supply chain threats.
"When automatic updates are enabled, new versions are auto-updated two hours after they are published, adding an extra layer of protection
The Hacker News
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
1 week 6 days ago
Software Supply Chain / MalwareMicrosoft has announced that Visual Studio Code (VS Code) will appl
CVE-2026-11559 | CodeAstro Payroll System 1.0 /view_account.php ID sql injection
1 week 6 days ago
A vulnerability, which was classified as critical, was found in CodeAstro Payroll System 1.0. This affects an unknown function of the file /view_account.php. The manipulation of the argument ID results in sql injection.
This vulnerability was named CVE-2026-11559. The attack may be performed from remote. In addition, an exploit is available.
vuldb.com
CVE-2026-11558 | CodeAstro Payroll System 1.0 /home_salary.php rate/salary_rate sql injection
1 week 6 days ago
A vulnerability, which was classified as critical, has been found in CodeAstro Payroll System 1.0. The impacted element is an unknown function of the file /home_salary.php. The manipulation of the argument rate/salary_rate leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-11558. The attack is possible to be carried out remotely. Moreover, an exploit is present.
vuldb.com
全球核弹头数量在中朝拉动下连续4年增长
1 week 6 days ago
全球核弹头数量在中朝拉动下连续4年增长瑞典斯德哥尔摩国际和平研究所6月8日发布报告称,截至今年1月,全球可投入使用的核弹头数量为9745枚,较上年增加131枚。可用弹头总数是2005年有完整统计以来首
Over 20,000 Instagram accounts stolen in Meta AI support hack
1 week 6 days ago
Meta has revealed that over 20,000 Instagram users had their accounts hijacked in a recent
Why do people with kids seem to get preference everywhere? Is it some subtle nudge to have children?
1 week 6 days ago
CVE-2026-11557 | Tenda F451 1.0.0.7/1.0.0.9 Web Management Interface /goform/Natlimit fromNatlimit page stack-based overflow
1 week 6 days ago
A vulnerability classified as critical was found in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the file /goform/Natlimit of the component Web Management Interface. Executing a manipulation of the argument page can lead to stack-based buffer overflow.
This vulnerability is handled as CVE-2026-11557. The attack can be executed remotely. Additionally, an exploit exists.
vuldb.com
CVE-2026-11556 | Tenda F451 1.0.0.7/1.0.0.9 Web Management Interface /goform/WriteFacMac formWriteFacMac mac os command injection
1 week 6 days ago
A vulnerability classified as critical has been found in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the component Web Management Interface. Performing a manipulation of the argument mac results in os command injection.
This vulnerability is known as CVE-2026-11556. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
vuldb.com
谷歌Gemini API再BUG 有开发者每小时被收取200美元缓存费且无法删除缓存
1 week 6 days ago
Over 20,000 Instagram accounts stolen in Meta AI support hack
1 week 6 days ago
Meta has revealed that 20,225 Instagram users had their accounts hijacked in a recent incident where attackers used Meta's AI-powered support system to reset passwords. [...]
Sergiu Gatlan
Submit #836791: codeastro Payroll System V1.0 SQL Injection [Accepted]
1 week 6 days ago
Submit #836791 / VDB-369169
SchneiderGrace
Submit #836787: codeastro Payroll System V1.0 SQL Injection [Duplicate]
1 week 6 days ago
Submit #836787 / VDB-367579
SchneiderGrace
Submit #836790: codeastro Payroll System V1.0 SQL Injection [Duplicate]
1 week 6 days ago
Submit #836790 / VDB-369168
SchneiderGrace
Submit #836785: codeastro Payroll System V1.0 SQL Injection [Accepted]
1 week 6 days ago
Submit #836785 / VDB-369168
cshwswwsshd99
CVE-2026-11555 | D-Link DGS-1100-08PD 1.00.006 Web Interface /etc/boa.conf least privilege violation
1 week 6 days ago
A vulnerability described as critical has been identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least privilege violation.
This vulnerability is traded as CVE-2026-11555. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
Submit #836477: Tenda Tenda F451 Wireless Router V1.0.0.7, V1.0.0.9 Stack-based Buffer Overflow [Accepted]
1 week 6 days ago
Submit #836477 / VDB-369167
hacker128
Submit #836476: Tenda Tenda F451 Wireless Router V1.0.0.7, V1.0.0.9 OS Command Injection [Accepted]
1 week 6 days ago
Submit #836476 / VDB-369166
hacker128