Aggregator
CVE-2026-54080 | veraPDF up to 1.30.1/1.31.22 PDF Parser PSOperator.java denial of service
CVE-2026-16463 | Autodesk AutoCAD/AutoCAD LT/DWG TrueView prior 2027.1.0 DXF file heap-based overflow
CVE-2026-17550 | Autodesk AutoCAD/AutoCAD LT/DWG TrueView prior 2027.1.0 out-of-bounds
CVE-2026-16465 | Autodesk AutoCAD/AutoCAD LT/DWG TrueView prior 2027.1.0 DWG/DXF File out-of-bounds
VPN в госсетях США — не защита, а входная дверь для хакеров. Сенатор требует снести всё за два года
Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape
Joint guidance on minimum elements for a software bill of materials
CVE-2026-65947 | Balbooa Gridbox Extension up to 2.20.1 Admin Interface cross-site request forgery
Critical Ruflo MCP Bridge Flaw Lets Attackers Execute Commands and Hijack AI Agents
A critical security flaw in the open-source AI orchestration platform Ruflo has been disclosed, allowing unauthenticated attackers to execute arbitrary commands and fully compromise AI agent environments. Assigned a maximum CVSS base score of 10.0, the vulnerability (tracked as CVE-2026-59726) was discovered by Noma Labs and affects Ruflo’s Model Context Protocol (MCP) Bridge, a core […]
The post Critical Ruflo MCP Bridge Flaw Lets Attackers Execute Commands and Hijack AI Agents appeared first on Cyber Security News.
CVE-2026-65888 | Balbooa Gridbox Extension up to 2.20.1 socialLogin improper authentication
CVE-2026-66724 | CERT.PL MWDB Core up to 2.18.x Config/Blob Upload Endpoints improper authorization
Google 研究未发现有证据显示 AI 将导致大规模自动化以及能取代白领
听键盘声就能还原你打的字?无需标注的自监督窃听,正在变成真实隐私威胁
Russian-Alligned TA488 Returns With Persistent Outlook Web Access Attack
9,8 CVSS и обход аутентификации. Уязвимость серверов TeamCity позволяет подменить код перед самым релизом
Человек в контуре — только на бумаге: ИИ управляет уже четырьмя из шести этапов военного удара
OpenAI 开源 Codex Security CLI:用于发现、验证和修复安全漏洞
Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts and Messages
Russian intelligence-linked hackers are trying to seize Signal accounts by posing as support staff and asking targets for backup recovery keys. The campaign targets people with access to sensitive conversations, including officials, military personnel, political figures, journalists, and Ukrainian leaders. It relies on deception, not a break in Signal’s end-to-end encryption, but the possible loss […]
The post Russian Intelligence Hackers Phish Signal Backup Keys to Hijack Accounts and Messages appeared first on Cyber Security News.