Aggregator
CVE-2016-9304 | Autodesk FBX-SDK prior 2017.1 DFX File Converter memory corruption (BID-95799)
CVE-2016-9305 | Autodesk FBX-SDK prior 2017.1 FBX File Converter uninitialized Pointer data processing (BID-95803)
CVE-2016-9306 | Autodesk FBX-SDK prior 2017.1 DAE File Converter memory corruption (BID-95807)
CVE-2016-9307 | Autodesk FBX-SDK prior 2017.1 3DS File Converter memory corruption (BID-95802)
CVE-2017-5594 | Pagekit CMS up to 1.0.10 Debug Toolbar Password password recovery (EDB-41143 / BID-95806)
CVE-2016-10160 | Apple macOS up to 10.12.3 apache_mod_php memory corruption (HT207615 / Nessus ID 97052)
CVE-2016-10161 | Apple macOS up to 10.12.3 apache_mod_php out-of-bounds (HT207615 / Nessus ID 97052)
Critical Canon MailSuite Vulnerability Enables Remote Code Execution Attacks
Enterprise email infrastructure remains one of the most critical and vulnerable targets for cybercriminals. A highly severe security flaw has just been discovered in Canon’s GUARDIANWALL MailSuite, exposing corporate networks to devastating Remote Code Execution (RCE) attacks. Threat actors can easily exploit this newly disclosed vulnerability to seize complete control over affected web services, making […]
The post Critical Canon MailSuite Vulnerability Enables Remote Code Execution Attacks appeared first on Cyber Security News.
TeamPCP and BreachForums Hackers Running $1,000 Contest for Supply Chain Attacks
The cybercrime underworld is turning open-source supply chain attacks into a twisted competition. After months of infiltrating security tools and CI/CD pipelines, the notorious hacking group TeamPCP has partnered with BreachForums to launch a disturbing new contest. The objective is to compile as many open-source packages as possible. The prize, however, is a surprisingly small […]
The post TeamPCP and BreachForums Hackers Running $1,000 Contest for Supply Chain Attacks appeared first on Cyber Security News.
CVE-2026-6654 | Mozilla thin-vec up to 0.2.15 clear use after free (GHSA-xphw-cqx3-667j / EUVD-2026-23832)
CVE-2026-4367 | X.org libXpm up to 3.5.4 xpmNextWord out-of-bounds (5448e1bd / Nessus ID 314592)
CVE-2026-41316 | ruby erb up to 4.0.4/6.0.3 eval protection mechanism (GHSA-q339-8rmv-2mhv / EUVD-2026-25385)
CVE-2026-42215 | gitpython-developers GitPython up to 3.1.46 os command injection (Nessus ID 314600)
'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine
科学家首次从直立人化石中提取出遗传信息
Дроны научились возвращаться домой без GPS благодаря пчёлам
AI渗透工具 Kali & HexStrike 大量RCE 0day漏洞
在尝试将该MCP集成到的Agent测试其行为时,我发现它用的是SSE方式,看一眼代码就感觉它存在漏洞,于是尝试看AI智能体是否能发现并构造EXP,测试后发现了大量远程命令执行(RCE)漏洞,风险极高。本文以演示 7 个 RCE 漏洞利用(EXP)为主