Aggregator
我们是否需要一部《小型个人信息处理者个人信息保护简化措施规定》?
AI提效供应商被黑,至少十余家客户遭数据泄露及勒索攻击
CVE-2026-33455 | Checkmk up to 2.5.0b3 Monitoring Quicksearch delimiter (WID-SEC-2026-1050)
CVE-2026-33457 | Checkmk up to 2.3.0p46/2.4.0p25/2.5.0b3 Livestatus Command service name delimiter (WID-SEC-2026-1050)
CVE-2026-33456 | Checkmk up to 2.4.0p25/2.5.0b3 Notification Test Page delimiter (WID-SEC-2026-1050)
2026 CCF网络与系统安全大会专题论坛征集通知
To counter cookie theft, Chrome ships device-bound session credentials
Cookie theft follows a well-established pattern. Infostealer malware infiltrates a device, extracts authentication cookies, and exfiltrates them to an attacker-controlled server. Because cookies often have extended lifetimes, attackers can access accounts without passwords, then bundle and sell the stolen credentials. Once malware gains access to a machine, it can read the local files and memory where browsers store authentication cookies. What DBSC does Google’s Device Bound Session Credentials (DBSC) is now entering public availability for … More →
The post To counter cookie theft, Chrome ships device-bound session credentials appeared first on Help Net Security.
EFF 退出 X 平台
Multiple TP-Link Vulnerabilities Allow Attackers to Seize Control of the Device
Cybersecurity researchers have identified five distinct security flaws in the TP-Link Archer AX53 v1.0 router. Tracked under multiple CVE identifiers, these vulnerabilities impact the router’s core modules, including OpenVPN, dnsmasq, and tmpServer. When exploited, these flaws allow attackers on the same network to execute system commands, cause system crashes, and steal sensitive configuration files, ultimately […]
The post Multiple TP-Link Vulnerabilities Allow Attackers to Seize Control of the Device appeared first on Cyber Security News.