Aggregator
AI 安全攻防实战:从对抗攻击到隐私泄露
利用Linux io_uring子系统绕过安全监控机制
b01lers CTF 2026 wp
CVE-2026-1207: Django raster lookups on PostGIS SQL注入漏洞
PWN核心利用手法归纳总结
软件系统安全赛2026分区赛 Web NodeJs
2026软件安全赛半决赛PWN Robo_admin WP fix&break
2025ciscn决赛ez_orw
2025ccb决赛interpreter
«Мул» как услуга. Мошенники открыли «банк» со службой поддержки — и он работает лучше, чем настоящий
Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security
Designing secure access with ZTNA
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-8398 Daemon Tools Lite Embedded Malicious Code Vulnerability
- CVE-2026-45321 TanStack Unspecified Vulnerability
- CVE-2026-48027 Nx Console Embedded Malicious Code Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
FBI warns of in-person data theft attacks from extortion gang
Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware
Attackers are hosting counterfeit installers and plugins on GitHub and SourceForge that pose as widely used software, including ChatGPT, Claude, AutoTune, Kontakt, Ableton Live, and ZENOLOGY. The downloads deliver a backdoor called DinDoor, which then loads a remote access Trojan built on the Deno JavaScript runtime, according to Malwarebytes. Compromised YouTube channels push victims toward the malicious repositories. The videos promoting the fake tools have accumulated more than 50,000 views. The attackers rotate through GitHub … More →
The post Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware appeared first on Help Net Security.