Aggregator
CVE-2026-34927 | Trend Micro TrendAI Apex One/TrendAI Apex One as a Service origin validation
CVE-2026-34926 | Trend Micro TrendAI Apex One/TrendAI Apex One as a Service path traversal (EUVD-2026-31284)
CVE-2025-13479 | PosCube QR Menu up to 21052026 authorization
CVE-2025-13477 | Digital Operations Services WifiBurada up to 21052026 private personal information
CVE-2026-2740 | Zoho ManageEngine ADSelfService Plus command injection
1 мая, потом 1 июня, теперь осень. Плату за VPN-трафик переносят уже в третий раз
Attackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fix
Showboat Linux Malware Hits Middle East Telecom with SOCKS5 Proxy Backdoor
Authorities dismantle First VPN, used by ransomware actors
First VPN, a virtual private network service marketed to cybercriminals, promising anonymity for its users, was taken offline on May 19 and 20 as part of Operation Saffron. During the operation, French and Dutch authorities, with support from Europol and Eurojust, dismantled 33 servers linked to the service and interviewed the operator in Ukraine. The targeted domain names were shut down through international cooperation between law enforcement and judicial authorities. The seized domains included 1vpns.com, … More →
The post Authorities dismantle First VPN, used by ransomware actors appeared first on Help Net Security.
Пока вы спите, ваш Android ударно трудится на рекламных фермах. Разбор работы скрытой сети из 455 заражённых программ
Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet
Chinese APTs Share Linux Backdoor in Central Asia Telco Attacks
Chinese hackers target telcos with new Linux, Windows malware
Max severity Cisco Secure Workload flaw gives Site Admin privileges
FreeBSD security advisory (AV26-495)
GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise
GitHub CISO Alexis Wales has named the malicious VS Code extension behind the breach they suffered at the hands of the threat group TeamPCP: Nx Console, a popular developer tool with 2.2 million installs. A malicious version of the otherwise benign extension was used to steal secrets and developer credentials, which were then used to move through CI/CD pipelines and exfiltrate around 3,800 of GitHub’s private code repositories. One missed token, many victims The company … More →
The post GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise appeared first on Help Net Security.