Aggregator
Please support the site operations by clicking ads.
Submit #912535: TDuckCloud tduck-platform 5.3 Cross Site Scripting [Accepted]
Containing Machine Speed Cyber Attacks Inside AI Infrastructure
A critical flaw in current security operations is assuming time is on our side. Historically, attacks progressed slowly, allowing analysts and response teams time to detect, discuss, and respond. Even severe incidents operated at a human pace. Our defenses have relied on human error, human speed, and human limitations. That era is over. AI-driven adversaries […]
The post Containing Machine Speed Cyber Attacks Inside AI Infrastructure appeared first on Cyber Security News.
Submit #912534: quequnlong shiyi-blog 1.0.0 through 1.2.1; source through 4db96f9 Cross Site Scripting [Accepted]
CVE-2026-90524 | jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09 Update Endpoint missing authentication
CVE-2026-90523 | jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09 User Register Endpoint UsersController.java UsersEntity privileges management
CVE-2026-90522 | jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d Password Recovery UsersController.java resetPass password recovery
CVE-2026-90521 | jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132 CRUD MenpiaodingdanController.java ID authorization
CVE-2026-90520 | jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64 Authorization Interceptor AuthorizationInterceptor.java improper authorization
【安全圈】GitLab曝CVSS 10满分漏洞:免密盗源码,数小时遭在野狂扫
【安全圈】黑客把Claude玩疯了:全自动扒光180万安卓App密钥机密
【安全圈】黑客操纵数百个AI Agent:26秒破11家企业,夜袭440台服务器
Submit #912528: SourceCodester School Registration and Fee System using PHP with Source Code /bilal/save_class.php 1.0 SQL Injection [Accepted]
Submit #912526: itsourcecode Sales and Inventory System V1.0 SQL Injection [Accepted]
Submit #912245: jaychouchannel Tourism_Management_System 8122bf020d91199eddfff3ee02d1632a70a9a132 Missing Authentication [Accepted]
Submit #912244: **Vendor:** jaychouchannel Tourism_Management_System 8122bf020d91199eddfff3ee02d1632a70a9a132 Incorrect Privilege Assignment [Accepted]
Submit #912236: jaychouchannel Tourism_Management_System 8122bf020d91199eddfff3ee02d1632a70a9a132 Weak Password Recovery [Accepted]
Submit #912235: jaychouchannel Tourism_Management_System 8122bf020d91199eddfff3ee02d1632a70a9a132 Authorization Bypass Through User-Controlled SQL Primary Key [Accepted]
Submit #912234: jaychouchannel Tourism_Management_System 8122bf020d91199eddfff3ee02d1632a70a9a132 Improper Authorization [Accepted]
Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks
A critical zero-day vulnerability in Oracle PeopleSoft exposed the Council of Europe and scores of other organizations to data theft and extortion in May and early June 2026. The ShinyHunters hacking group exploited the flaw across about 100 organizations and 300 instances worldwide, according to reports cited by The Register. The attackers targeted the management and configuration layers of enterprise resource-planning systems, stealing sensitive records. […]
The post Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks appeared first on Cyber Security News.