Aggregator
New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files
CVE-2026-11108 | Google Chrome up to 148.0.7778.216 on Android NFC privileges management (ID 500517)
CVE-2026-11104 | Google Chrome up to 148.0.7778.216 ANGLE uninitialized variable (ID 500501)
CVE-2026-11105 | Google Chrome up to 148.0.7778.216 WebUI cross-domain policy (ID 500505)
CVE-2026-11106 | Google Chrome up to 148.0.7778.216 Media cross-domain policy (ID 500508)
CVE-2026-11100 | Google Chrome up to 148.0.7778.216 on Mac File Input use after free (ID 500416)
CVE-2026-11101 | Google Chrome up to 148.0.7778.216 on Windows Dawn uninitialized variable (ID 500443)
CVE-2026-11109 | Google Chrome up to 148.0.7778.216 ANGLE uninitialized variable (ID 500524)
CVE-2026-11110 | Google Chrome up to 148.0.7778.216 ANGLE uninitialized variable (ID 500528)
CVE-2026-11107 | Google Chrome up to 148.0.7778.216 Downloads clickjacking (ID 500510 / Nessus ID 319284)
CVE-2026-11103 | Google Chrome up to 148.0.7778.216 on Windows Installer privileges management (ID 500483 / EUVD-2026-34564)
От метеоритов до вражеских боеголовок. В США создали систему, способную мгновенно определить, из чего состоит летящий объект
CISA Requires Federal Agencies to Patch Critical Vulnerabilities Within 3 Days
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive (BOD) 26-04, titled “Prioritizing Security Updates Based on Risk,” compelling all Federal Civilian Executive Branch (FCEB) agencies to remediate the most dangerous known exploited vulnerabilities within just three calendar days. The directive, released on June 10, 2026, represents the most aggressive federal […]
The post CISA Requires Federal Agencies to Patch Critical Vulnerabilities Within 3 Days appeared first on Cyber Security News.
OceanLotus APT Compromises FireAnt MetaKit in Supply-Chain Attack on Stock Investors
A notorious hacking group has been caught targeting stock investors in Vietnam through a supply chain attack, hijacking a popular investment software platform to deliver a powerful backdoor. The operation, carried out by OceanLotus (also known as APT32), marks a notable shift in the group’s tactics as it turns focus increasingly toward domestic targets inside […]
The post OceanLotus APT Compromises FireAnt MetaKit in Supply-Chain Attack on Stock Investors appeared first on Cyber Security News.
Russian national charged in connection with Void Blizzard espionage campaign
Denis Obrezko accused of orchestrating cyberattacks that compromised at least 11 U.S. companies as part of the Kremlin-linked group's sprawling espionage operation.\
The post Russian national charged in connection with Void Blizzard espionage campaign appeared first on CyberScoop.
GoFlateLoader Uses Massive PE Overlay to Deliver Lumma, Vidar, and StealC Infostealers
A new malware loader called GoFlateLoader has been quietly spreading across the internet, and what makes it stand out is not how complex it is but how effective a simple trick has made it. Written in the Go programming language, this loader has one job: to decode and drop dangerous information-stealing programs onto a victim’s […]
The post GoFlateLoader Uses Massive PE Overlay to Deliver Lumma, Vidar, and StealC Infostealers appeared first on Cyber Security News.