Aggregator
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers
Google Rolls Out Emergency Chrome Update for Four High-Severity Security Flaws
Google has released an emergency security update for its Chrome browser, addressing four high-severity vulnerabilities that could expose users to serious risks if left unpatched. The update, now rolling out globally, upgrades Chrome to version 150.0.7871.186/.187 for Windows and macOS, and 150.0.7871.186 for Linux systems. The latest release focuses primarily on security fixes, with Google […]
The post Google Rolls Out Emergency Chrome Update for Four High-Severity Security Flaws appeared first on Cyber Security News.
Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails
Hackers are using fake payment receipt emails to deliver a 750MB Lampion remote access trojan to targets in Portugal. The campaign relies on familiar financial language, convincing business details, and oversized files designed to slow down analysis and evade security checks. The attack begins with phishing emails that pose as routine financial or administrative messages. […]
The post Hackers Hide 750MB Lampion RAT Inside Fake Payment Receipt Emails appeared first on Cyber Security News.
GeekBench 7发布 测试更贴近真实场景
人类预期寿命增长,但不健康寿命更长
人类预期寿命增长,但不健康寿命更长
Help!!
Cross-Border Payments on Crypto Infrastructure: The $857 Billion Opportunity
Wordpress wp2shell 未授权RCE(CVE-2026-63030 / CVE-2026-60137)
2026年了,在AI时代下总感觉什么都有可能,但是看到Wordpress居然能有原生未授权RCE还是感觉不可思议。Wordpress算是我曾经深度研究过的php源码之一,虽然wp架构复杂但是开发习惯很好,封装也比较严格,尤其是对权限的分割都做得很好,在5.0之后我一直认为wp不太可能出未授权的大漏洞了。
但很快,这个漏洞的挖掘者通过两个漏洞的组合就实现了这不可思议的一幕。
据说作者用AI完成了这个漏洞挖掘,并获得了50w刀的赏金(我没有求证,听说)。
- https://bugbunny.ai/blog/wordpress-7-0-2-rce-deep-dive#three-fixes-for-three-broken-assumptions
- 影响版本:WordPress 6.9.0-6.9.4、7.0.0-7.0.1
接下来我们就古法分析一下这个漏洞具体是怎么回事。