Aggregator
AI重塑网络攻击:漏洞利用成最流行手段,利用门槛被大幅拉低
Vivaldi 8.0 释出
BadIIS Malware Turns Hijacks IIS Servers and Redirect Users to Illicit Sites
A dangerous piece of malware known as BadIIS has been actively targeting Internet Information Services (IIS) web servers, quietly hijacking them and redirecting unsuspecting visitors to illegal gambling sites, adult content platforms, and other illicit destinations. The attacks have been going on for years across the Asia-Pacific region and beyond, placing thousands of legitimate websites […]
The post BadIIS Malware Turns Hijacks IIS Servers and Redirect Users to Illicit Sites appeared first on Cyber Security News.
Звонки с консолей, смартфонов и ПК теперь в одной защищённой комнате. Discord завершил переход на сквозное шифрование
某OA密码加密方式分析
【已复现】FreeBSD setcred(2) 栈缓冲区溢出漏洞(CVE-2026-45250)安全风险通告
Critical Cisco Secure Workload Vulnerability Enables Unauthorized API Access
Cisco has disclosed a critical security vulnerability in its Secure Workload platform that could allow unauthenticated attackers to gain unauthorized access to sensitive resources via internal APIs. The flaw, tracked as CVE-2026-20223, carries a maximum CVSS score of 10.0 and is categorized under CWE-306 (Missing Authentication for Critical Function). The issue stems from improper authentication […]
The post Critical Cisco Secure Workload Vulnerability Enables Unauthorized API Access appeared first on Cyber Security News.
Critical Drupal Core Security Vulnerability Exposes Websites to Cyberattack
A highly critical security vulnerability in Drupal core is set to impact websites worldwide, with the official security release scheduled for May 20, 2026. The vulnerability has been assigned a “Highly Critical” severity rating (20/25), indicating potential risks to confidentiality and integrity across affected systems. While technical details remain undisclosed until the official release window, […]
The post Critical Drupal Core Security Vulnerability Exposes Websites to Cyberattack appeared first on Cyber Security News.
31 уязвимость и риск потери файлов. Вот, чем грозит решение отложить установку обновления Firefox
360漏洞云携安全龙虾亮相HPW白帽世界大会
黑客利用 CVE-2026-26980 攻陷 Ghost CMS,大量站点沦为 ClickFix 攻击帮凶
80 лет никто не мог сдвинуться с места. OpenAI решил геометрическую тайну Эрдёша через теорию чисел
对话 Moka CEO 李国兴:AI 不是 SaaS 公司的绝命,是改命
SpaceX 最大的收入来源是与 Anthropic 达成的数据中心交易
Virtru centers file collaboration around data-level protection
Organizations that handle sensitive data consistently face a dilemma: lock data down and lose productivity, or share it freely and lose control. Virtru unveiled Virtru Collaborate, a new offering that eliminates that tradeoff, a FedRAMP authorized space where sensitive files are encrypted and protected by the Trusted Data Format (TDF), and where that protection travels seamlessly with the data as teams work together across organizational boundaries. Virtru Collaborate is the first solution built on the … More →
The post Virtru centers file collaboration around data-level protection appeared first on Help Net Security.
CVE-2026-4055 | Mattermost up to 10.11.13/11.4.3/11.5.1 Run Creation API authorization (WID-SEC-2026-1173)
ASAPP expands adversarial testing for enterprise AI systems
ASAPP has launched Continuous Red Teaming, a new capability that integrates adversarial AI testing directly into ASAPP’s model evaluation framework. The new capability is built on Promptfoo, an AI security platform that helps enterprises detect and address vulnerabilities in AI systems during development. Promptfoo continuously runs automated tests across ASAPP’s AI systems, screening for more than 50 vulnerability types to give enterprise customers the real-time data they need to trust their AI in production. As … More →
The post ASAPP expands adversarial testing for enterprise AI systems appeared first on Help Net Security.
Право на ремонт или дыра в безопасности. В Госдуме спорят, должны ли производители отдавать техдокументацию сторонним мастерам
Tenable Hexa AI automates remediation across attack surfaces
Tenable has announced the general availability of Tenable Hexa AI, the agentic AI engine of the Tenable One Exposure Management Platform. Tenable Hexa AI is an advanced agentic AI for cybersecurity solution, equipped with advanced multi-step reasoning and Model Context Protocol (MCP) support, enabling custom agent building and workflows that accelerate risk reduction at machine speed. LLMs and AI frontier models, such as Anthropic’s Mythos Preview, are accelerating the discovery of previously unknown vulnerabilities at … More →
The post Tenable Hexa AI automates remediation across attack surfaces appeared first on Help Net Security.