Aggregator
火绒小问答--「个人版」近期top问题解答
抽奖啦 | “绒”意相伴 金榜题名
The AI Proxy: Meta’s Virtual Assistant Exploited in Instagram Takeovers
The New Frontier of Account Hijacking Account hijacking on Instagram is conventionally synonymous with stolen credentials or breached electronic mail. In a recent anomaly, however, adversaries successfully navigated an alternate vector. They manipulated Meta’s...
The post The AI Proxy: Meta’s Virtual Assistant Exploited in Instagram Takeovers appeared first on Information Security News.
The Vulnerability Rift: Microsoft Realigns Posture Toward Security Researchers
A Fractured Consensus The escalating friction between Microsoft and the independent security research community has taken an unexpected turn. Following a wave of intense criticism, the technology titan was compelled to publicly clarify its...
The post The Vulnerability Rift: Microsoft Realigns Posture Toward Security Researchers appeared first on Information Security News.
CVE-2026-10693 | SourceCodester Online Boat Reservation System 1.0 Administrative Endpoint improper authorization (EUVD-2026-34058)
CVE-2026-10694 | SourceCodester Online Food Ordering System 2.0 /index.php include page file inclusion (EUVD-2026-34059)
The Netlogon Imperative: Critical Windows Server Exploitation Intensifies
Emerging Perimeter Vulnerabilities Malicious actors have aggressively initiated exploitation of a critical vulnerability within a foundational Windows Server subsystem. Crucially, this activity manifested a mere few weeks following the deployment of the official patch....
The post The Netlogon Imperative: Critical Windows Server Exploitation Intensifies appeared first on Information Security News.
CISA 预警:一款两年前已修复的 Oracle 漏洞正被黑客实战利用
The Cybercrime Continuum: Infrastructure Destruction Squad and the Blacknet Ecosystem
An Overview of the Digital Syndicate A novel threat actor has emerged within the digital underground. Remarkably, this collective commercializes dangerous cyber weapons much like standard enterprise software. The group operates under the moniker...
The post The Cybercrime Continuum: Infrastructure Destruction Squad and the Blacknet Ecosystem appeared first on Information Security News.
ssrf绕过
JVN: WordPress用プラグインZoho Mail for WordPressにおけるクロスサイトリクエストフォージェリの脆弱性
CVE-2026-0039 | Google Android 14/15/16/16-qpr2 ubsan_throwing_runtime.cpp integer overflow (WID-SEC-2026-1772)
CVE-2026-0040 | Google Android 14/15/16/16-qpr2 ubsan_throwing_runtime.cpp integer overflow (WID-SEC-2026-1772)
CVE-2026-0018 | Google Android 15/16/16-qpr2 AccessibilityManagerService.java denial of service (WID-SEC-2026-1772)
CVE-2026-0036 | Google Android 14/15/16/16-qpr2 StageCoordinator.java startAnimation Local Privilege Escalation (WID-SEC-2026-1772)
CVE-2026-0016 | Google Android 16/16-qpr2 CredentialManagerService.java updateProvidersWhenServiceRemoved permission (WID-SEC-2026-1772)
一行代码致使数十亿次微软安卓应用下载面临安全风险
WeedHack 恶意软件攻击已侵染超 11.6 万台 Mincraft 设备
The Dashlane Lockout: Security Countermeasures and User Disruption
The Brute-Force Wave and Vault Compromise The password manager Dashlane recently dispatched urgent security notifications to numerous subscribers. The electronic correspondence stated that the platform temporarily deactivated their accounts to bolster defensive metrics. Specifically,...
The post The Dashlane Lockout: Security Countermeasures and User Disruption appeared first on Information Security News.