Aggregator
Please support the site operations by clicking ads.
尼泊尔用大疆无人机运送遗体和食物
3 days 19 hours ago
在毁灭性的泥石流之后,尼泊尔正利用大疆无人机运送遇难者遗体,向幸存者运送食物。尼泊尔军方正使用中国捐赠的四架大疆 FlyCart 100 无人机,每天执行 10-16 次物资运送任务。FlyCart 100 配备了约 30 米长的绳索和绞盘系统,可用于吊装和投放重物。根据电池配置的不同,无人机载重能力在 85-100 公斤之间。尼泊尔军方使用无人机每趟运送约 60 公斤的物资,它也能将遇难者遗体从部分受灾严重的地区运送出来。截至 9 月 9 日,尼泊尔官方确认的死亡人数升至 1369 人,仍有逾 5000 人失踪,其中包括 587 名外国公民。协助珠峰登山者的夏尔巴人从 2024 年起就开始使用 Flycart 100 及较小型号的 Flycart 30 无人机向登山营地运送氧气瓶等物资,将排泄物袋等垃圾运送下山。
CVE-2026-3869 | Schneider Electric Modicon M580/Modicon M580 Safety incorrect implementation of authentication algorithm
3 days 19 hours ago
A vulnerability marked as very critical has been reported in Schneider Electric Modicon M580 and Modicon M580 Safety. This impacts an unknown function. The manipulation leads to incorrect implementation of authentication algorithm.
This vulnerability is referenced as CVE-2026-3869. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-81861 | Schneider Electric SCADAPack 32 insufficiently protected credentials
3 days 19 hours ago
A vulnerability labeled as very critical has been found in Schneider Electric SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R, SCADAPack 57x, SCADAPack 3xx and SCADAPack 32. This affects an unknown function. Executing a manipulation can lead to insufficiently protected credentials.
The identification of this vulnerability is CVE-2026-81861. The attack may be launched remotely. There is no exploit available.
vuldb.com
Metropolis Technologies Source Code Allegedly Stolen and Leaked
3 days 19 hours ago
A forum moderator posting as 888 claims to have breached Metropolis Technologies and uploaded stolen company source code for other forum members to download.
Dark Web Informer
Кристалл против невидимой Вселенной. Новый детектор ищет сигнал тёмной материи
3 days 20 hours ago
TiSe₂ и Sr₂RuO₄ могут реагировать на частицы, которые остаются недоступными для традиционных экспериментов.
G.O.S.S.I.P 阅读推荐 2026-09-11 波音737安全须知
3 days 20 hours ago
祝您旅途愉快,一路顺利~
CVE-2026-85083 | CareCam ANJIA AJL33PC0801 Bootloader hard-coded credentials
3 days 20 hours ago
A vulnerability identified as very critical has been detected in CareCam ANJIA AJL33PC0801. The impacted element is an unknown function of the component Bootloader. Performing a manipulation results in hard-coded credentials.
This vulnerability was named CVE-2026-85083. The attack needs to be approached locally. There is no available exploit.
vuldb.com
CVE-2026-89010 | WAVLINK WN535M1/WN535M3 up to M35M1_V210223 sync_server system filenames os command injection
3 days 20 hours ago
A vulnerability categorized as very critical has been discovered in WAVLINK WN535M1 and WN535M3 up to M35M1_V210223. The affected element is the function system of the component sync_server. Such manipulation of the argument filenames leads to os command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2026-89010. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-89009 | WAVLINK WN535M1/WN535M3 up to M35M1_V250922 sync_server daemon filename path traversal
3 days 20 hours ago
A vulnerability was found in WAVLINK WN535M1 and WN535M3 up to M35M1_V250922. It has been rated as critical. Impacted is an unknown function of the component sync_server daemon. This manipulation of the argument filename causes path traversal. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2026-89009. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
远程办公增加了睡眠时间但减少了身体活动
3 days 20 hours ago
根据 Turku 大学的一项研究,远程办公增加了睡眠时间但减少了身体活动。研究人员分析了混合办公者在远程办公和去办公室办公之间的睡眠、久坐行为及身体活动差异。结果显示,相比去办公室办公,远程办公日的平均睡眠时间多了 15分钟,但坐姿或卧姿时间增加了 45 分钟。站立、轻度身体活动以及中高强度身体活动的时间都有所减少。研究还显示,办公室办公日的步行和骑行活动,在远程办公日部分被坐姿、卧姿和睡眠所取代,因为远程办公不需要通勤。
[Control systems] Schneider Electric security advisory (AV26-912)
3 days 20 hours ago
Canadian Centre for Cyber Security
CVE-2026-38056 | ST Engineering iDirect Evolution iQ-Series terminals up to 4.5.2.1 privileges management
3 days 20 hours ago
A vulnerability was found in ST Engineering iDirect Evolution iQ-Series terminals, 3315-Series terminals and 9-Series Terminals up to 4.5.2.1. It has been declared as very critical. This issue affects some unknown processing. The manipulation results in improper privilege management.
This vulnerability is known as CVE-2026-38056. Attacking locally is a requirement. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-8301 | Pardus Boot Repair up to 1.0.7 os command injection
3 days 20 hours ago
A vulnerability was found in TUBITAK BILGEM Software Technologies Research Institute Pardus Boot Repair up to 1.0.7. It has been classified as very critical. This vulnerability affects unknown code. The manipulation leads to os command injection.
This vulnerability is traded as CVE-2026-8301. An attack has to be approached locally. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-38058 | ST Engineering iDirect Evolution iQ-Series terminals up to 4.5.2.1 Web Administration weak password hash
3 days 20 hours ago
A vulnerability was found in ST Engineering iDirect Evolution iQ-Series terminals, 3315-Series terminals and 9-Series Terminals up to 4.5.2.1 and classified as problematic. This affects an unknown part of the component Web Administration. Executing a manipulation can lead to password hash with insufficient computational effort.
This vulnerability appears as CVE-2026-38058. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
当智能体开始替人花钱,如何证明「它是谁」?
3 days 20 hours ago
智能体商业的 ChatGPT 时刻正在到来,但要让 AI 真正替人办成事,必须先补上代码自主交易的信任基石。
Один человек вместо разведотдела. ИИ резко удешевляет государственную слежку
3 days 20 hours ago
Claude уже помогает властям превращать огромные массивы данных в готовые списки целей.
CVE-2026-78224 | NextGen Healthcare Mirth Connect up to 4.7.1 XSLT Transformer Step xml external entity reference
3 days 20 hours ago
A vulnerability has been found in NextGen Healthcare Mirth Connect up to 4.7.1 and classified as critical. Affected by this issue is some unknown functionality of the component XSLT Transformer Step. Performing a manipulation results in xml external entity reference.
This vulnerability is reported as CVE-2026-78224. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-82578 | NextGen Healthcare Mirth Connect up to 4.7.1 XML Batch Processing xml external entity reference
3 days 20 hours ago
A vulnerability, which was classified as critical, was found in NextGen Healthcare Mirth Connect up to 4.7.1. Affected by this vulnerability is an unknown functionality of the component XML Batch Processing. Such manipulation leads to xml external entity reference.
This vulnerability is documented as CVE-2026-82578. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-87983 | Mistral AI Mistral Vibe up to 2.6.0 information disclosure
3 days 20 hours ago
A vulnerability, which was classified as problematic, has been found in Mistral AI Mistral Vibe up to 2.6.0. Affected is an unknown function. This manipulation causes information disclosure.
This vulnerability is registered as CVE-2026-87983. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com