Aggregator
CVE-2026-67193 | Xlight FTP Server up to 3.9.4 GetTickCount information disclosure
CVE-2026-54735 | Prebid Server up to 4.3.x Bidder Adapters server-side request forgery
CVE-2026-16543 | Kong Kubernetes Ingress Controller up to 2.0.10/2.1.8/2.2.2 input validation
CVE-2026-67192 | Xlight FTP Server up to 3.9.4 GCM Decrypt GCM decrypt function stack-based overflow
CVE-2026-67191 | Xlight FTP Server up to 3.9.4 heap-based overflow
Broadcom Patches Critical VMware Flaws Enabling vCenter Authentication Bypass and ESXi VM Escape
CVE-2026-15228 | Kong Kubernetes Ingress Controller up to 3.4.17/3.5.10 certificate validation
Huntress warns about attack spree that hit 30 SonicWall customers in 2 days
Unknown attackers broke into 92 unique SonicWall user accounts with legitimate credentials, researchers said.
The post Huntress warns about attack spree that hit 30 SonicWall customers in 2 days appeared first on CyberScoop.
OpenAI agent used exposed credentials at 4 services in Hugging Face breach
电子证据的现场处置:风险与机遇并存
【欧盟刑事案件电子证据条例的主要内容】
LogoKit Phishing Kit Screenshots Victim Sites in Real Time
SecWiki News 2026-07-29 Review
HuggingFace遭大模型自主攻击事件复盘 by ourren
更多最新文章,请访问SecWiki
NVIDIA BlueField Vulnerability Enables Code Execution Attacks
NVIDIA has disclosed a serious vulnerability affecting its BlueField DPUs and ConnectX networking platforms that could allow attackers to execute code on affected systems if successfully exploited. This vulnerability, tracked as CVE-2026-65094, impacts the VIRTIO-Net component and has a CVSS v3.1 score of 9.0, indicating a high-risk issue for enterprise and cloud deployments. According to […]
The post NVIDIA BlueField Vulnerability Enables Code Execution Attacks appeared first on Cyber Security News.
CVE-2026-54078 | veraPDF validation up to 1.30.1/1.31.70 DictionaryKeysHelper DictionaryKeysHelper.java xml external entity reference
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
CVE-2026-54079 | veraPDF validation up to 1.30.1/1.31.70 AcroForm GFPDAcroForm.java getdynamicRender xml external entity reference
CVE-2026-54082 | veraPDF veraPDF-validation up to 1.30.1/1.31.70 DocumentBuilderFactory xml external entity reference
macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets
Mac users are being targeted by a ClickFix campaign that turns a fake verification prompt into a path for malware installation. Victims are persuaded to copy a command from a web page, open Terminal, paste it, and run it, believing they are completing a routine CAPTCHA check. The attack does not rely on a software […]
The post macOS ClickFix Attack Deploys Atomic Stealer to Steal Passwords and Crypto Wallets appeared first on Cyber Security News.