Aggregator
Claude Cowork 漏洞可导致虚拟机逃逸,访问Mac 文件
1 week 2 days ago
速修复
Exim 目录遍历漏洞可导致提权攻击
1 week 2 days ago
速修复
Exim 目录遍历漏洞可导致提权攻击
1 week 2 days ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
Claude Cowork 漏洞可导致虚拟机逃逸,访问Mac 文件
1 week 2 days ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
CVE-2026-16870 | Snowflake libsnowflakeclient up to 2.9.1 redirect
1 week 2 days ago
A vulnerability classified as problematic was found in Snowflake libsnowflakeclient up to 2.9.1. This vulnerability affects unknown code. Executing a manipulation can lead to open redirect.
This vulnerability appears as CVE-2026-16870. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331
1 week 2 days ago
躺着也能搞安全?Memfit / Yakit AI支持接入飞书钉钉了!
1 week 2 days ago
办公 IM 联动 Yakit/Memfit,远程驱动 AI 安全任务
CVE-2026-15768 | Google Chrome up to 150.0.7871.124 HTML-in-Canvas cross-domain policy (Nessus ID 327759 / WID-SEC-2026-2347)
1 week 2 days ago
A vulnerability was found in Google Chrome up to 150.0.7871.124. It has been declared as problematic. This impacts an unknown function of the component HTML-in-Canvas. The manipulation results in permissive cross-domain policy with untrusted domains.
This vulnerability is cataloged as CVE-2026-15768. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-15769 | Google Chrome up to 150.0.7871.115 Linux Toolkit Theming escape output (Nessus ID 327759 / WID-SEC-2026-2347)
1 week 2 days ago
A vulnerability labeled as critical has been found in Google Chrome. This affects an unknown part of the component Linux Toolkit Theming. Executing a manipulation can lead to escaping of output.
This vulnerability appears as CVE-2026-15769. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-15770 | Google Chrome up to 150.0.7871.115 V8 uninitialized pointer (Nessus ID 327181 / WID-SEC-2026-2347)
1 week 2 days ago
A vulnerability, which was classified as problematic, was found in Google Chrome. This affects an unknown function of the component V8. Executing a manipulation can lead to uninitialized pointer.
The identification of this vulnerability is CVE-2026-15770. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2026-15765 | Google Chrome up to 150.0.7871.115 Ozone use after free (EUVD-2026-44472 / Nessus ID 327759)
1 week 2 days ago
A vulnerability identified as critical has been detected in Google Chrome. Affected by this issue is some unknown functionality of the component Ozone. Performing a manipulation results in use after free.
This vulnerability is reported as CVE-2026-15765. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-15766 | Google Chrome up to 150.0.7871.115 Skia uninitialized pointer (Nessus ID 327759 / WID-SEC-2026-2347)
1 week 2 days ago
A vulnerability described as problematic has been identified in Google Chrome. This issue affects some unknown processing of the component Skia. The manipulation results in uninitialized pointer.
This vulnerability is known as CVE-2026-15766. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-15767 | Google Chrome up to 150.0.7871.115 Libyuv heap-based overflow (EUVD-2026-44474 / Nessus ID 327182)
1 week 2 days ago
A vulnerability classified as critical has been found in Google Chrome. Impacted is an unknown function of the component Libyuv. This manipulation causes heap-based buffer overflow.
This vulnerability is handled as CVE-2026-15767. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-27960 | OpenCTI up to 6.9.12 improper authentication (GHSA-6vvv-vmfr-xhrx / WID-SEC-2026-1357)
1 week 2 days ago
A vulnerability labeled as critical has been found in OpenCTI up to 6.9.12. The affected element is an unknown function. The manipulation results in improper authentication.
This vulnerability is cataloged as CVE-2026-27960. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-15764 | Google Chrome up to 150.0.7871.115 Ozone use after free (EUVD-2026-44471 / Nessus ID 327172)
1 week 2 days ago
A vulnerability was found in Google Chrome. It has been classified as critical. This affects an unknown function of the component Ozone. The manipulation leads to use after free.
This vulnerability is listed as CVE-2026-15764. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
RTX 4060 внезапно заработала на Windows для ARM. Нужно было всего лишь подсунуть правильный драйвер
1 week 2 days ago
Всегда мечтали подключить мощную дискретку к ультрабуку? Это ваш шанс.
中国打造新型软实力:开放、低成本的AI
1 week 2 days ago
中国打造新型软实力:开放、低成本的AI冷战时期,“软实力” 意味着在海外赢得人心的美国电影和音乐。如今在数字时代,中国正在推行一种截然不同的软实力:开放、低成本的人工智能技术。在上周的一次讲话中,中国
Ransomware gangs go after EMEA healthcare’s supply chain
1 week 2 days ago
A ransomware attack against a hospital makes headlines, while attacks on the rest of the ecosystem around it tend to stay quiet despite doing damage that can be just as bad. Flare researcher Assaf Morag analyzed ransomware leak-site activity tied to healthcare organizations in the EMEA region between 2024 and 2026, and found that ransomware groups are going after the entire healthcare supply chain. The dataset covers hospitals and clinics, telemedicine providers, diagnostic laboratories, pharmacies, … More →
The post Ransomware gangs go after EMEA healthcare’s supply chain appeared first on Help Net Security.
Sinisa Markovic
CVE-2026-53185 | Linux Kernel up to 6.6.142/6.12.93/6.18.35/7.0.12 zram zram_bvec_write_partial use after free (WID-SEC-2026-2077)
1 week 2 days ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.6.142/6.12.93/6.18.35/7.0.12. This issue affects the function zram_bvec_write_partial of the component zram. Such manipulation leads to use after free.
This vulnerability is listed as CVE-2026-53185. The attack must be carried out from within the local network. There is no available exploit.
You should upgrade the affected component.
vuldb.com