Aggregator
Cross-Border Payments on Crypto Infrastructure: The $857 Billion Opportunity
1 week 5 days ago
Cross-Border Payments on Crypto Infrastructure: The $857 Billion Opportunity Behind the Financial Su
Wordpress wp2shell 未授权RCE(CVE-2026-63030 / CVE-2026-60137)
1 week 5 days ago
2026年了,在AI时代下总感觉什么都有可能,但是看到Wordpress居然能有原生未授权RCE还是感觉不可思议。Wordpress算是我曾经深度研究过的php源码之一,虽然wp架构复杂但是开发习惯很好,封装也比较严格,尤其是对权限的分割都做得很好,在5.0之后我一直认为wp不太可能出未授权的大漏洞了。
但很快,这个漏洞的挖掘者通过两个漏洞的组合就实现了这不可思议的一幕。
据说作者用AI完成了这个漏洞挖掘,并获得了50w刀的赏金(我没有求证,听说)。
- https://bugbunny.ai/blog/wordpress-7-0-2-rce-deep-dive#three-fixes-for-three-broken-assumptions
- 影响版本:WordPress 6.9.0-6.9.4、7.0.0-7.0.1
接下来我们就古法分析一下这个漏洞具体是怎么回事。
LoRexxar
Why Digital Forensic Reports Don’t Survive Cross-Examination
1 week 5 days ago
A forensic report is not a summary of finished work. It’s a
自托管 AI 智能体的自状态攻击:操作系统防御能走多远?
1 week 5 days ago
error code: 521
南鸟岛附近海底淤泥中检出多种中重稀土
1 week 5 days ago
南鸟岛附近海底淤泥中检出多种中重稀土日本海洋研究开发机构24日宣布,深海探测船 “地球” 号在南鸟岛附近深海海底实施的稀土采掘试验中,从采集到的淤泥中检测出多种更珍贵且高科技产品不可或缺的“中重稀土元
补丁没死,但不再是核心防御手段
1 week 5 days ago
当一台机器能在 20 小时内仅凭漏洞描述写出可用的利用代码时,你没法靠打补丁跑赢它。
诚邀渠道合作伙伴共启新征程
1 week 5 days ago
【火绒安全周报】AI失控后入侵知名企业/韩国外交系统遭黑客攻击
1 week 5 days ago
【火绒安全周报】AI失控后入侵知名企业/韩国外交系统遭黑客攻击
火绒小问答——「企业版」Syslog数据导出
1 week 5 days ago
火绒小问答——「企业版」Syslog数据导出
防窃密可溯源 火绒构建终端数据安全审计完整防线
1 week 5 days ago
防窃密可溯源 火绒构建终端数据安全审计完整防线
补丁没死,但不再是核心防御手段
1 week 5 days ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
Wordpress7.0 wp2shell 未授权RCE(CVE-2026-63030 / CVE-2026-60137)
1 week 5 days ago
2026年了,在AI时代下总感觉什么都有可能,但是看到Wordpress居然能有原生未授权RCE还是感觉不可思议
CVE-2026-16519 | GeoVision GV-IP Device Utility up to 9.0.7.0 uncontrolled search path
1 week 5 days ago
A vulnerability was found in GeoVision GV-IP Device Utility up to 9.0.7.0 and classified as critical. Affected is an unknown function. Executing a manipulation can lead to uncontrolled search path.
This vulnerability is handled as CVE-2026-16519. It is possible to launch the attack on the local host. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-15665 | wpmanageninja Fluent Support Plugin up to 2.3.0 on WordPress Shortcode redirect-to cross site scripting
1 week 5 days ago
A vulnerability has been found in wpmanageninja Fluent Support Plugin up to 2.3.0 on WordPress and classified as problematic. This impacts an unknown function of the component Shortcode Handler. Performing a manipulation of the argument redirect-to results in cross site scripting.
This vulnerability is known as CVE-2026-15665. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-15653 | meIsle Visualizer Plugin up to 4.0.5 on WordPress backend-title cross site scripting
1 week 5 days ago
A vulnerability, which was classified as problematic, was found in meIsle Visualizer Plugin up to 4.0.5 on WordPress. This affects an unknown function. Such manipulation of the argument backend-title leads to cross site scripting.
This vulnerability is traded as CVE-2026-15653. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-15464 | ThimPress WP Hotel Booking Plugin up to 2.3.2 on WordPress Shortcode widget_search cross site scripting
1 week 5 days ago
A vulnerability, which was classified as problematic, has been found in ThimPress WP Hotel Booking Plugin up to 2.3.2 on WordPress. The impacted element is an unknown function of the component Shortcode Handler. This manipulation of the argument widget_search causes cross site scripting.
This vulnerability appears as CVE-2026-15464. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-15334 | cozythemes Cozy Blocks Plugin up to 2.2.11 on WordPress cross site scripting
1 week 5 days ago
A vulnerability classified as problematic was found in cozythemes Cozy Blocks Plugin up to 2.2.11 on WordPress. The affected element is an unknown function. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-15334. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-15333 | cozythemes Cozy Blocks Plugin up to 2.2.11 on WordPress cozyCustomFont cross site scripting
1 week 5 days ago
A vulnerability classified as problematic has been found in cozythemes Cozy Blocks Plugin up to 2.2.11 on WordPress. Impacted is an unknown function. The manipulation of the argument cozyCustomFont leads to cross site scripting.
This vulnerability is documented as CVE-2026-15333. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
当游戏越来越漂亮,外挂却越来越丑:作弊技术摸底(2026)
1 week 5 days ago
游戏越做越漂亮。贴图、光追、动效、剧情、过场动画——每一帧都在向"电影感"靠拢。然后某天,看到熟悉的主播,屏幕角落里冒出一行字:「[√] 连接成功」还多了绿色的火柴人……