Aggregator
CVE-2026-16490 | itsourcecode Hospital Management System 1.0 /prescription.php editid sql injection (EUVD-2026-47594)
CVE-2026-16492 | umijs umi up to 4.6.63 GIT File Helper getFileGitIno.ts git.getFileCreateInfo os command injection (Issue 13345 / EUVD-2026-47596)
CVE-2026-16517 | Red Hat libarchive Zip Writer archive_write_set_format_zip.c archive_write_zip_header integer overflow (EUVD-2026-47586)
CVE-2026-56844 | Veeam Software Appliance up to 13.0.1 Updater Local Privilege Escalation (EUVD-2026-47595)
CVE-2026-15802 | Chimpstudio Foodbakery Plugin up to 4.9 on WordPress delete_locations_backup_file_callback path traversal (EUVD-2026-47611)
Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform
A Russian-speaking threat actor known as “Trim” has reportedly transformed jailbroken frontier AI models into an automated penetration testing platform called AI Pentest Checker. This activity highlights how criminals can misuse legitimate AI services and common security tools to accelerate reconnaissance, validate vulnerabilities, and create reports. According to Cato reports, Trim first appeared on a […]
The post Russian Hacker Jailbreaks Claude to Turn into an AI-Powered Penetration Testing Platform appeared first on Cyber Security News.
1800 преступников. 15 тысяч кампаний в месяц. 35 стран жертв. Полиция изъяла у сети Kratos более 200 серверов
美国计算机科学专业入学人数首次下降
BDSec CTF 2026
Date: July 20, 2026, 3 p.m. — 21 July 2026, 15:00 UTC [add to calendar]
Format: Jeopardy
On-line
Offical URL: https://2026.bdsec-ctf.com/
Rating weight: 15.62
Event organizers: Knight Squad
一次关于工作的聊天
信息安全漏洞周报(2026年第29期)
Xiaomi скормила роботу 100 000 часов видео — и он раздавил всех конкурентов по показателям
欧盟法院裁决 VPN 是合法工具
Chick-fil-A discloses data breach after credential stuffing attacks
Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA
PHP Type Juggling: как нестрогое сравнение превращается в обход аутентификации
GNOME 项目禁止 AI 生成的安全报告
Разрешения не было. Команды не было. Взлом — был. ИИ от OpenAI взломал Hugging Face по собственной инициативе
Small teams are the heaviest users of AI coding agents
The pull request arrives with the tests already run and the description already written, the work of an agent that handled the whole thing on its own. Somebody still has to read it. On GitHub that somebody is usually one developer sitting alone with the diff, and the rest of the project never sees the code. Maliha Noushin Raida and Daqing Hou at Rochester Institute of Technology sorted 25,264 agentic pull requests by who reviewed … More →
The post Small teams are the heaviest users of AI coding agents appeared first on Help Net Security.