Aggregator
安全热点周报:Cisco FMC 零日漏洞已被积极利用,静态凭证可能泄露敏感数据
【已复现】KindaRails2Shell——Ruby on Rails 远程代码执行漏洞(CVE-2026-66066)安全风险通告
CVE-2026-65313 | ANDRITZ HIPASE-250/250 SCALA up to 7.20/8.14 hard-coded credentials
CVE-2026-65310 | ANDRITZ HIPASE-250/250 SCALA up to 7.20/7.39 improper authentication
CVE-2026-65311 | ANDRITZ HIPASE-250 up to 7.20 HTTP Server privileges management
没想到吧,Windows 剪贴板复制图片后,体积可能暴涨数百倍|解决方案:SlimPaste
Traefik Labs introduces Distro Zero secure runtime for API and AI gateways
Traefik Labs has introduced the Distro Zero image, a hardened, vendor-supported secure runtime delivered as Traefik Hub in proxy mode. It gives platform and security teams a container whose entire executable content is a single memory-safe binary, with validated cryptography built inside it and every advanced capability, from API gateway to AI and MCP gateway to full API management, unlocked by license on that same binary. No binary swap, no migration, no re-validation as needs … More →
The post Traefik Labs introduces Distro Zero secure runtime for API and AI gateways appeared first on Help Net Security.
Patch In, Exploit Out: How deepsec Reconstructed the Pwn2Own Microsoft Edge Sandbox Escape
Horizon3.ai expands NodeZero with automated web application attack path testing
Horizon3.ai has expanded its NodeZero platform with AI-powered web application pentesting. The platform can now autonomously test web applications and identify attack paths that chain application vulnerabilities, credential theft, lateral movement, cloud access, and data exposure. Web applications have never been more exposed or more critical to secure. The rapid deployment of “vibe-coded” applications built with generative AI has introduced a wave of systems riddled with exploitable flaws. At the same time, threat actors are … More →
The post Horizon3.ai expands NodeZero with automated web application attack path testing appeared first on Help Net Security.
从现有证据来看,AI漏洞挖掘被过度炒作
AttackIQ targets CTEM execution with AVA Agentic OS
AttackIQ has announced AVA Agentic OS, an agentic operating system designed to operationalize Continuous Threat Exposure Management. CTEM has emerged as the strategic framework for managing cyber risk, yet many organizations continue to struggle to operationalize CTEM across fragmented security technologies, disconnected workflows, and manual processes. Security teams have invested heavily in tools that identify risk, but they lack an intelligent operational layer that continuously transforms intelligence into action. AVA Agentic OS fills that gap … More →
The post AttackIQ targets CTEM execution with AVA Agentic OS appeared first on Help Net Security.