Aggregator
CVE-2026-1526 | undici up to 6.23.0 WebSocket decompress data amplification (Nessus ID 302064 / WID-SEC-2026-0933)
CVE-2026-1525 | undici 1.1 Strict HTTP Parser request smuggling (GHSA-2mjp-6q6p-2qxm / EUVD-2026-11685)
CVE-2026-2123 | OpenText Operations Agent up to 12.29 on Windows insufficient permissions or privileges (EUVD-2026-17534)
CVE-2026-30278 | Aviation Navigation 35.33 privilege escalation (EUVD-2026-17538)
CVE-2026-30277 | TA UTAX Mobile Print App 3.7.2.251001 privilege escalation (EUVD-2026-17536)
CVE-2026-5206 | code-projects Simple Gym Management System 1.0 Payment sql injection (EUVD-2026-17577)
CVE-2026-30282 | UXGROUP Cast to TV Screen Mirroring 2.2.77 privilege escalation (EUVD-2026-17542)
CVE-2026-30283 | PEAKSEL NIS Animal Sounds and Ringtones 1.3.0 File Import privilege escalation (EUVD-2026-17544)
CVE-2026-30279 | Squareapps My Location Travel Timeline 11.80 privilege escalation (EUVD-2026-17540)
Technical Advisory: Axios npm Supply Chain Attack – Cross-Platform RAT Deployed via Compromised Maintainer Account
[CRITICAL] | Active RAT | Malicious npm versions removed | Assess all systems that ran npm install during exposure window
The post Technical Advisory: Axios npm Supply Chain Attack – Cross-Platform RAT Deployed via Compromised Maintainer Account appeared first on Security Boulevard.
Повестки в военкомат и отзыв аккредитации. Чем грозит персоналу ИТ компаний работа приложений через VPN
Axios Compromise on npm Introduces Hidden Malicious Package
A newly discovered software supply chain attack targeting the npm ecosystem briefly compromised one of the most widely used JavaScript libraries in the world.
The post Axios Compromise on npm Introduces Hidden Malicious Package appeared first on Security Boulevard.
Flipping the Script: The Premiere of ‘The Women in Security’ Documentary at RSAC
The cybersecurity industry has long grappled with a significant representation gap, but a new documentary premiering at RSAC 2026 is working to change the conversation. In this interview from Broadcast Alley, Techstrong Group’s Jon Swartz speaks with Aarti Gadhia and Kristen Rank about The Women in Security, a film five years in the making and..
The post Flipping the Script: The Premiere of ‘The Women in Security’ Documentary at RSAC appeared first on Security Boulevard.
Google links axios supply chain attack to North Korean group
保姆级讲解CC1-7(跟踪代码调试+讲解)
Google's Vertex AI Is Over-Privileged. That's a Problem
Cursor 代码审计 Skill 编写指南
Synthetic data is all you need for Reinforcement Learning
We used Tonic Fabricate to generate a fully synthetic email corpus, then RL fine-tuned an open-source model against it. The result: it beat o3 on real Enron emails — without ever seeing a real email.
The post Synthetic data is all you need for Reinforcement Learning appeared first on Security Boulevard.
Bridging the Gap: CSA’s AI Security Initiatives at RSAC
Alan Shimel sits down with longtime friend and cybersecurity veteran Rich Mogull to discuss his new role as chief analyst at the Cloud Security Alliance. The conversation covers a lot of ground, from the rapid rise of agentic AI to how CSA is working to bridge the gap between high-level security frameworks and the practitioners..
The post Bridging the Gap: CSA’s AI Security Initiatives at RSAC appeared first on Security Boulevard.