Aggregator
CVE-2026-8605 | ScadaBR 1.2.0 hard-coded credentials (icsa-26-139-03)
每周高级威胁情报解读(2026.07.17~07.23)
每周高级威胁情报解读(2026.07.17~07.23)
Workshop map for MECCHA CHAMELEON is a malware dropper (full breakdown)
CVE-2023-4874 | Mutt up to 2.2.11 Email null pointer dereference (EUVD-2023-54713 / Nessus ID 235543)
CVE-2023-4875 | Mutt up to 2.2.11 Draft input behavior (EUVD-2023-54714 / Nessus ID 235543)
CVE-2026-47670 | DbGate up to 7.1.8 /runners/load-reader functionName os command injection (EUVD-2026-48376)
CVE-2026-47669 | DbGate up to 7.1.8 ZIP unzipDirectory.js unzipDirectory path traversal (EUVD-2026-48377)
CVE-2026-66141 | Exim up to 4.99.4 pipe transport force_command privileges management (EUVD-2026-48479)
CVE-2026-66139 | OpenStack Zaqar up to 22.0.0 improper authentication (EUVD-2026-48477)
CVE-2026-66140 | Exim up to 4.99.4 queue-name path traversal (EUVD-2026-48478)
一加手机国行调整 Bootloader 解锁方式
Один агент строит модель возможных атак, другой ищет уязвимости, третий независимо всё перепроверяет. Именно так спроектирован новый плагин Anthropic.
古代语言的多样性远超今日
古代语言的多样性远超今日
美国对80多个国家加征10%至12.5%关税
Malicious RubyGems Turn Developer Machines Into Monero Miners and Spread Through SSH
A malicious RubyGems campaign has turned seemingly useful developer packages into tools for hidden cryptocurrency mining. The poisoned packages can consume a machine’s computing power, slow down development work, and quietly generate Monero for the attackers. The campaign also goes beyond a typical package-based infection. One set of malicious gems can examine a compromised developer […]
The post Malicious RubyGems Turn Developer Machines Into Monero Miners and Spread Through SSH appeared first on Cyber Security News.
Governing Al agents at scale: Lessons from the leaders who’ve done it
Enterprise AI leaders from ZoomInfo, Docusign and AppViewX share what it took to build AI Centers of Excellence and govern agent identities inside two companies operating at scale. What you’ll take away: What an AI Center of Excellence looks like day to day at ZoomInfo and Docusign How to govern agent identities without standing up a parallel identity stack The traps both leaders worked hard to avoid, and what they’d do differently now What Venkat … More →
The post Governing Al agents at scale: Lessons from the leaders who’ve done it appeared first on Help Net Security.