Aggregator
CVE-2023-2500 | Go Pricing Plugin up to 3.3.19 on WordPress injection
CVE-2023-2734 | MStore API Plugin up to 3.9.1 on WordPress improper authentication
CVE-2023-2733 | MStore API Plugin up to 3.9.0 on WordPress improper authentication
CVE-2023-2987 | Wordapp Plugin up to 1.5.0 on WordPress Cryptographic Signature authorization
CVE-2023-2436 | Blog-in-Blog Plugin up to 1.1.1 on WordPress Shortcode cross site scripting
CVE-2023-2435 | Blog-in-Blog Plugin up to 1.1.1 on WordPress Shortcode file inclusion
The Identity Gap Blocking Agentic AI at Scale
FBI 称 2025 年美国因网络犯罪损失 210 亿美元
The Hidden Security Risks of Shadow AI in Enterprises
Hackers Impersonate Linux Foundation Leader in Slack to Target Open Source Developers
Open source developers are facing a growing and sophisticated threat — one that does not rely on complex exploits or hidden vulnerabilities but instead uses something far simpler: trust. A social engineering campaign is actively targeting developers through Slack, where an attacker poses as a respected Linux Foundation community leader to trick victims into downloading […]
The post Hackers Impersonate Linux Foundation Leader in Slack to Target Open Source Developers appeared first on Cyber Security News.
Intruder expands cloud security with agentless container image scanning
Intruder has announced the release of Container Image Scanning, a new upgrade to its cloud security capabilities that automatically scans container images for vulnerabilities, granting customers actionable insight into container risk without deploying and maintaining scanning agents across their estates. Leveraging existing integrations with major cloud providers, Intruder supports Amazon Web Services Elastic Container Registry, Google Cloud Artifact Registry and Azure Container Registry. New images and updated versions are scanned daily for vulnerabilities, and users … More →
The post Intruder expands cloud security with agentless container image scanning appeared first on Help Net Security.
Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
Официальный статус шпионского софта. Cloudflare уничтожил репутацию Telega
【安全圈】洛杉矶市律师系统遭入侵,敏感警局文件泄露
【安全圈】AI 数据独角兽遭黑客攻击,一周内吃了 5 场官司,Meta 紧急暂停合作
【安全圈】盗用他人信息注册账号卖给未成年人,上海警方捣毁一“游戏账号工厂”黑产链
Master C and C++ with our new Testing Handbook chapter
CISA Warns of Critical Ivanti EPMM Code Injection Vulnerability Exploited in Attacks
The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical security flaw in Ivanti Endpoint Manager Mobile (EPMM). The agency recently added this flaw, tracked as CVE-2026-1340, to its Known Exploited Vulnerabilities (KEV) catalog after confirming it is being actively exploited in real-world cyberattacks. This means the software fails to […]
The post CISA Warns of Critical Ivanti EPMM Code Injection Vulnerability Exploited in Attacks appeared first on Cyber Security News.