Aggregator
CVE-2026-12982 | Document Gallery Plugin up to 5.1.0 on WordPress cross site scripting
CVE-2025-15662 | Printcart Web to Print Product Designer Plugin up to 2.5.2 on WordPress server-side request forgery
AgentBaiting 与 7600 个恶意仓库背后的 AI 供应链投毒深度解读
CVE-2026-13390 | The Events Calendar Plugin up to 6.8.2.1 on WordPress Event Aggregator Import authorization
CVE-2026-12394 | MemberGlut Plugin up to 1.1.4 on WordPress privileges management
CVE-2026-12255 | MainWP Child Plugin up to 6.1.1 on WordPress improper authentication
CVE-2026-10082 | Advanced Ads Plugin up to 2.0.22 on WordPress Shortcode cross site scripting
CVE-2026-13332 | Masteriyo LMS Plugin up to 2.3.0 on WordPress improper authentication
CVE-2026-13152 | Custom Fields Account Registration for Woocommerce Plugin privileges management
CVE-2026-12493 | Zaytech Clover Payment Gateway Plugin up to 1.3.5 on WordPress improper authentication
35 名学生有 32 名在历史考试中使用 AI 生成答案
Каждые несколько недель на Земле исчезает язык. Так мы уже лишились 68 000. И счётчик не останавливается
【安全圈】你的AI对话,正在被谷歌"裸奔"
【安全圈】Steam论坛中招!你的电脑可能在给别人"挖矿"
【安全圈】苹果崩了!App Store等多项服务故障
Marathon Petroleum’s CISO on OT security automation, supply chain risk
In this interview with Help Net Security, Mary Rose Martinez, CISO at Marathon Petroleum, talks about what happens to security when automation reaches deep into refineries, pipelines, and terminals. She explains why the old idea of air-gapped operational technology has faded, how the Purdue model helps her team apply controls without stopping production, and where supply chain risk sits when vendors and their vendors hold the keys. She also covers cross-skilling the workforce and working … More →
The post Marathon Petroleum’s CISO on OT security automation, supply chain risk appeared first on Help Net Security.
LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations
华为据报道在建造内存芯片工厂
Nono: Open-source sandbox for AI agents
An AI coding agent opens a terminal, reads a config file, and finds a live cloud key sitting in plaintext. It runs with the permissions of the person who launched it. Every file that person can read, the agent reads. Every credential in the environment, the agent can use. That reach is where the damage starts. A prompt injection, a mistyped command, or a hallucinated path points that access at the company’s own credentials and … More →
The post Nono: Open-source sandbox for AI agents appeared first on Help Net Security.