Aggregator
【安全事件】axios前端库npm供应链投毒预警通告
How we made Trail of Bits AI-native (so far)
WordPress Plugin Vulnerability Exposes Sensitive Data From 800,000+ Sites
A high-severity security flaw has been disclosed in Smart Slider 3, one of the most widely used WordPress slider builder plugins. With over 800,000 active installations, this vulnerability leaves a massive number of websites exposed to severe data theft. Tracked as CVE-2026-3098, this medium-severity flaw allows attackers with minimal permissions to access and download highly sensitive […]
The post WordPress Plugin Vulnerability Exposes Sensitive Data From 800,000+ Sites appeared first on Cyber Security News.
EvilTokens Emerges as New Phishing-as-a-Service Platform for Microsoft Account Takeover
A new and dangerous phishing toolkit has entered the cybercrime scene. In early 2026, a Phishing-as-a-Service platform called EvilTokens began circulating in underground cybercrime communities, offering criminals a ready-to-use kit built to steal Microsoft 365 accounts. Unlike most phishing tools that mimic Microsoft login pages, EvilTokens takes a different approach — it abuses the legitimate […]
The post EvilTokens Emerges as New Phishing-as-a-Service Platform for Microsoft Account Takeover appeared first on Cyber Security News.
WorldLeaks
You must login to view this content
Payload
You must login to view this content
Attacker
You must login to view this content
ChatGPT Vulnerability Let Attackers Silently Exfiltrate User Prompts and Other Sensitive Data
Users routinely trust AI assistants with highly sensitive information, including medical records, financial documents, and proprietary business code. Check Point Research recently disclosed a critical vulnerability in ChatGPT’s architecture that allowed attackers to extract this exact type of user data silently. By abusing a covert outbound channel in ChatGPT’s isolated code execution environment, attackers could […]
The post ChatGPT Vulnerability Let Attackers Silently Exfiltrate User Prompts and Other Sensitive Data appeared first on Cyber Security News.
Attacker
You must login to view this content
Attacker
You must login to view this content
Attacker
You must login to view this content
Attacker
You must login to view this content
Attacker New Threat Actor
You must login to view this content
绕过正则表达式+抽象语法树(AST)实现Python代码执行
CareCloud Data Breach – Hackers Accessed IT Infrastructure and Stole Patient Data
A prominent healthcare technology provider has formally disclosed a significant cybersecurity incident involving unauthorized access to its IT infrastructure. An unauthorized actor compromised one of the company’s electronic health record (EHR) systems, raising concerns over possible exposure of sensitive patient data. The security breach initially unfolded on March 16, 2026. The intrusion caused a temporary […]
The post CareCloud Data Breach – Hackers Accessed IT Infrastructure and Stole Patient Data appeared first on Cyber Security News.
Attacker
You must login to view this content
Attacker
You must login to view this content
Claude Code源码泄露!可直接build
Attacker
You must login to view this content