Aggregator
eBay拒绝GameStop 560亿美元的收购提议
1 month 2 weeks ago
当地时间周二,eBay公司表示,其董事会拒绝了GameStop主动提出的560亿美元收购提议。在致GameStop首席执行官瑞恩·科恩的信中,eBay写道:“我们得出的结论是,你们的提议既不可信,也没
欧盟准备对 TikTok 和 Instagram 的成瘾性设计采取行动
1 month 2 weeks ago
欧盟委员会主席 Ursula von der Leyen 周二表示欧盟将在今年晚些时候对 TikTok 和 Instagram 等平台上的成瘾性设计功能采取行动。此类功能包括了无限滚动、自动播放和推送通知。欧盟委员会最早将在今年夏天公布一项法律提议,目前正在等待 Special Panel of experts on Child Safety Online 的调查报告。
30 тысяч заражений в месяц и никакой пощады: троян Mamont охотится на бабушек с дешёвыми Android
1 month 2 weeks ago
Почему троян Mamont до сих пор остаётся грозой подъездов.
20 Leaders Who Built the CISO Era: 2 Decades of Change
1 month 2 weeks ago
As part of Dark Reading's 20th anniversary special coverage, we profile the CISOs, founders, researchers, criminals, and policymakers who rewrote the enterprise risk playbook.
Dark Reading Editorial Team
Attackers Combine ClickFix With PySoxy Proxying to Maintain Persistence
1 month 2 weeks ago
Exploitation of open-source tools allows attackers to maintain persistent access after initial social engineering, warn ReliaQuest researchers
Webinar: What the Riskiest SOC Alerts Go Unanswered - and How Radiant Security Can Help
1 month 2 weeks ago
Why do the Riskiest SOC Alerts Go Unanswered?
Security operations teams are drowning in alerts. But the real problem isn't always alert volume; it's the blind spots. The most dangerous alerts are the ones no one is investigating.
A recent report from The Hacker News examined why certain high-risk alert categories - WAF, DLP, OT/IoT, dark web intelligence, and supply chain signals- consistently
The Hacker News
Webinar: What the Riskiest SOC Alerts Go Unanswered - and How Radiant Security Can Help
1 month 2 weeks ago
Threat Detection / AI SecurityWhy do the Riskiest SOC Alerts Go Unanswered?Security operations te
Aur0ra
1 month 2 weeks ago
You must login to view this content
cohenido
Operation HumanitarianBait Uses Fake Aid Documents to Deploy Python Spyware
1 month 2 weeks ago
Operation HumanitarianBait uses fake aid documents, GitHub-hosted payloads, and Python spyware to target Russian-speaking victims.
Deeba Ahmed
Fulcrum
1 month 2 weeks ago
You must login to view this content
cohenido
研究发现工作时间减少与肥胖率下降相关
1 month 2 weeks ago
欧洲肥胖大会公布的一项研究比较了 1990-2022 年间 33 个经合组织国家的工作模式和肥胖率。结果发现,美国、墨西哥和哥伦比亚等年工作时间较长的国家肥胖率也更高,即使北欧国家的平均能量和脂肪摄入量高于拉美国家。年工作时间减少 1% 与肥胖率下降 0.16% 相关。研究人员认为,工作压力和缺乏锻炼时间可能是工作时长更多的人容易发胖的原因。研究主要作者、澳大利亚昆士兰大学的 Pradeepa Korale-Gedara 博士表示,压力增加会提高皮质醇激素水平,导致人们在无法消耗能量的工作中储存更多脂肪。研究人员强调这一发现是相关性的,并不代表因果关系。但它促使专家再次呼吁推行四天工作制,四天工作制有助于人们在饮食、运动和睡眠方面做出更健康的选择,有助于促进整个社会的健康。
【恶意文件通告】Linux多功能病毒分析
1 month 2 weeks ago
近期,深信服千里目安全技术中心监测到一起Linux后门事件、经过深度分析排查发现该事件与UTG-Q-008团伙存在关联,该家族是针对Linux平台的威胁行为者,主要针对中国政府机构和企业实体,利用庞大的僵尸网络进行间谍活动。
【恶意文件通告】关于Hugging Face平台仿冒OpenAI仓库的供应链投毒事件
1 month 2 weeks ago
近期,深信服千里目安全技术中心监测到一起围绕Hugging Face平台的开源AI供应链投毒事件。
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
1 month 2 weeks ago
TeamPCP, the threat actor behind the recentsupply chain attack spree, has been linked to the compromise of the npm and PyPI packages from TanStack, UiPath, Mistral AI, OpenSearch, and Guardrails AI as part of a fresh Mini Shai-Hulud campaign.
The affected npm packages have been modified to include an obfuscated JavaScript file ("router_init.js") that's designed to profile the execution
The Hacker News
CVE-2026-45218 | WP Travel Plugin up to 11.4.0 on WordPress sql injection
1 month 2 weeks ago
A vulnerability categorized as critical has been discovered in WP Travel Plugin up to 11.4.0 on WordPress. This vulnerability affects unknown code. Such manipulation leads to sql injection.
This vulnerability is traded as CVE-2026-45218. The attack may be launched remotely. There is no exploit available.
vuldb.com
AI 为什么一定会成为这代人的全新购物入口
1 month 2 weeks ago
买对东西,是个有门槛的技术活儿。
CVE-2026-45215 | Saad Iqbal WP EasyPay Plugin up to 4.3.0 on WordPress insertion of sensitive information into sent data
1 month 2 weeks ago
A vulnerability was found in Saad Iqbal WP EasyPay Plugin up to 4.3.0 on WordPress. It has been rated as problematic. This affects an unknown part. This manipulation causes insertion of sensitive information into sent data.
This vulnerability appears as CVE-2026-45215. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-45214 | Xpro Elementor Addons Plugin up to 1.5.1 on WordPress sql injection
1 month 2 weeks ago
A vulnerability was found in Xpro Elementor Addons Plugin up to 1.5.1 on WordPress. It has been declared as critical. Affected by this issue is some unknown functionality. The manipulation results in sql injection.
This vulnerability is reported as CVE-2026-45214. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-41712 | Vmware Spring AI up to 1.0.6/1.1.5 Chat Memory information disclosure
1 month 2 weeks ago
A vulnerability was found in Vmware Spring AI up to 1.0.6/1.1.5. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Chat Memory. The manipulation leads to information disclosure.
This vulnerability is documented as CVE-2026-41712. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com