Aggregator
俄副总理:俄中应继续相互转让技术
New Windows ‘MiniPlasma’ Zero-Day Let Attackers Gain SYSTEM Access – PoC Released
A critical Windows privilege escalation zero-day vulnerability dubbed “MiniPlasma” has emerged with a public proof-of-concept exploit that allows attackers to achieve SYSTEM-level privileges on fully patched Windows systems. Security researcher Nightmare-Eclipse released the weaponized exploit on GitHub on May 13, 2026, claiming that Microsoft either failed to patch or silently rolled back the fix for […]
The post New Windows ‘MiniPlasma’ Zero-Day Let Attackers Gain SYSTEM Access – PoC Released appeared first on Cyber Security News.
The AI backdoor your security stack is not built to see
Enterprises deploying LLMs have spent the past two years building defenses around a reasonable assumption: malicious behavior leaves a trace in the input. Scan for suspicious tokens, filter unusual characters, watch for prompt injection patterns. New research from Microsoft and the Institute of Science Tokyo demonstrates that this defensive posture has a blind spot, and the cost of that blind spot could be measured in leaked proprietary data and regulatory exposure. The attack, called MetaBackdoor, … More →
The post The AI backdoor your security stack is not built to see appeared first on Help Net Security.
«ИИ, нарисуй нам оккупацию» . Как нейросети помогают кубинцам мечтать о вторжении Трампа
Project Glasswing: what Mythos showed us
Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026
CVE-2026-43361 | Linux Kernel up to 6.19.8 inode_owner_or_capable privilege escalation
CVE-2026-43352 | Linux Kernel up to 6.18.18/6.19.8 missing initialization
CVE-2026-43354 | Linux Kernel up to 6.12.77/6.18.18/6.19.8 iio set_samp_freq divide by zero
CVE-2026-43355 | Linux Kernel up to 6.19.8 iio pm_runtime_put_autosuspend reference count (Nessus ID 313403)
CVE-2026-43357 | Linux Kernel up to 6.19.8 iio pm_runtime_get_sync return return value
CVE-2026-43353 | Linux Kernel up to 6.18.18/6.19.8 hci_dma_dequeue_xfer deserialization
CVE-2026-43359 | Linux Kernel up to 6.19.8 integer underflow
CVE-2026-43360 | Linux Kernel up to 6.19.8 btrfs out-of-bounds (Nessus ID 313447)
阿联酋核电站遭到无人机袭击 无人员伤亡
Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026
Lyrie: Open-source autonomous pentesting agent
Penetration testing has usually required weeks of manual work, specialized tooling, and teams with narrow skill sets. Lyrie, an open-source autonomous security agent built by OTT Cybersecurity, compresses that process into a command line tool and publishes the entire codebase. The project reached version 3.1.0 this month. The release adds XChaCha20-Poly1305 memory encryption for sensitive threat data, seven new proof-of-concept generators covering prompt injection, auth bypass, CSRF, open redirect, race conditions, secret exposure, and cross-site … More →
The post Lyrie: Open-source autonomous pentesting agent appeared first on Help Net Security.