Aggregator
CVE-2026-7636 | smub Slider by Soliloquy Plugin up to 2.8.1 on WordPress Configuration map_meta_cap information disclosure
CVE-2026-8692 | registrationformbuilder Vedrixa Forms Plugin up to 1.1.1 on WordPress Shortcode wp_localize_script authorization (EUVD-2026-31414)
CVE-2026-7615 | kasparsd Widget Context Plugin up to 1.3.3 on WordPress /wp-admin/widgets.php save_widget_context_settings cross-site request forgery
脱离人体的大脑被用于药物测试
把 Yaklang 脚本编译成原生二进制:SSA2LLVM 现在走到哪了
CISA Warns of Trend Micro Apex One Vulnerability Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, warning organizations of active exploitation risks. The flaw, tracked as CVE-2026-34926, affects on-premise deployments of Trend Micro Apex One and could allow attackers to tamper with endpoint security systems. CVE-2026-34926 […]
The post CISA Warns of Trend Micro Apex One Vulnerability Exploited in Attacks appeared first on Cyber Security News.
CISA’s new KEV nomination form opens reporting to vendors and researchers
The Cybersecurity and Infrastructure Security Agency launched a new nomination form that lets researchers, vendors, and industry partners report known exploited vulnerabilities for possible inclusion in its KEV catalog. The form gives outside contributors a direct way to submit vulnerabilities to CISA. Email submissions remain available at [email protected] for organizations and individuals who prefer that route. “Every day, CISA collaborates with security researchers and industry partners that identify and report exploited vulnerabilities. This new reporting … More →
The post CISA’s new KEV nomination form opens reporting to vendors and researchers appeared first on Help Net Security.
Спешка перед рабочим созвоном = пустой кошелёк. Разбираем новую волну атак на пользователей Microsoft Teams
FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA
The FBI has issued a new cybersecurity warning about a rapidly emerging phishing-as-a-service (PhaaS) platform named Kali365, which is actively targeting Microsoft 365 users to steal access tokens and bypass multi-factor authentication (MFA). Kali365 is being distributed primarily through Telegram channels, where threat actors can subscribe to the service and launch phishing campaigns with minimal […]
The post FBI Warns of Kali365 Attacking Microsoft 365 Users to Steal Logins and Bypass MFA appeared first on Cyber Security News.
参会提醒|“CCF-INFORSEC网络空间安全前沿创新论坛”明日(23日)召开
AI安全正重蹈端点安全覆辙:态势优先忽视行为检测
Hackers Use Hugging Face to Host Second-Stage Malware for npm Supply Chain Attack
Hackers have found a new and alarming way to weaponize one of the most trusted platforms in the AI world. A threat actor linked to North Korea has embedded second-stage malware inside Hugging Face, the widely used AI and machine learning hub, effectively turning it into a malware delivery channel and a live data exfiltration […]
The post Hackers Use Hugging Face to Host Second-Stage Malware for npm Supply Chain Attack appeared first on Cyber Security News.
Weekly Threat Landscape Digest – Week 21
1. Multiple Vulnerabilities in HP Linux Imaging and Printing Software Overview: Two vulnerabilities have been identified in HP Linux Imaging […]
The post Weekly Threat Landscape Digest – Week 21 appeared first on HawkEye.
U.S. CISA adds Trend Micro Apex One and Langflow to its Known Exploited Vulnerabilities catalog
Microsoft 365 users targeted by new phishing threat that bypasses MFA
Microsoft 365 access tokens are being targeted by an emerging Phishing-as-a-Service (PhaaS) platform called Kali365, the FBI is warning. First observed in April 2026, Kali365 has been distributed through Telegram, allowing cybercriminals to obtain Microsoft 365 access tokens and bypass MFA without stealing user credentials. “Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities,” the FBI said. … More →
The post Microsoft 365 users targeted by new phishing threat that bypasses MFA appeared first on Help Net Security.