Aggregator
CVE-2016-4056 | TYPO3 up to 6.2.18 Backend module cross site scripting (ID 850026)
CVE-2016-4338 | Zabbix up to 2.0.17/2.2.12/3.0.2 Configuration Script userparameter_mysql.conf mysql.size sql injection (EDB-39769 / Nessus ID 95816)
CVE-2016-4340 | GitLab up to 8.7.0 Impersonation access control (EDB-40236 / Nessus ID 90877)
CVE-2016-4484 | cryptsetup Package up to 2:1.7.3-2 on Debian improper authentication (Nessus ID 219567 / BID-94315)
CVE-2016-4793 | CakePHP up to 3.2.4 HTTP Header clientIp CLIENT-IP input validation (EDB-39813 / Nessus ID 97393)
CVE-2016-5091 | TYPO3 up to 8.1.1 ExtbasE 7pk security (Nessus ID 92448 / ID 100641)
CVE-2016-5119 | KeePass up to 2.33 Automatic Update input validation (FEDORA-2016-125ea34ff9 / Nessus ID 94778)
CVE-2016-4055 | Oracle Primavera Unifier 16.x/17.x/18.x Moment resource management (Nessus ID 111213 / BID-95849)
LATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean Enterprises
Editor’s note: The analysis is authored by Moises Cerqueira, malware researcher & threat hunter. You can find Moises on LinkedIn and X. Credential theft malware rarely announces itself with ransomware-level noise. Instead, it operates like a silent siphon hidden inside everyday business workflows: invoices, payroll files, purchase orders, procurement requests. Agent Tesla campaigns are especially dangerous because they target the operational […]
The post LATAM Under Siege: Agent Tesla’s 18-Month Credential Theft Campaign Against Chilean Enterprises appeared first on ANY.RUN's Cybersecurity Blog.
PraisonAI CVE-2026-44338 Auth Bypass Targeted Within Hours of Disclosure
NGINX 漏洞预警:18 年老洞可 RCE,PoC 已公开
Поссорился с боссом и создал одну из самых опасных хакерских группировок в мире. История The Gentlemen
How AI Hallucinations Are Creating Real Security Risks
Девять стран за одну кампанию. Иранцы использовали антивирус, чтобы спрятать вирус — и это сработало
【安全圈】微软警告“ Dirty Frag ” Linux 内核漏洞已遭黑客利用
【安全圈】研究人员公布概念验证,利用 Windows BitLocker 零日漏洞可访问受保护驱动器
【安全圈】安卓新增入侵日志功能,助力深度分析复杂间谍软件攻击
Microsoft’s WinUI agent plugin trims token use by over 70% during development
Microsoft published a plugin on May 13 that lets GitHub Copilot CLI and Claude Code drive the full WinUI 3 development cycle, from project scaffolding through signed MSIX packaging. The WinUI agent plugin ships one agent, eight skills, and several supporting tools targeting the loop developers run dozens of times a day: scaffold, build, run, test, iterate. Native Windows app development with WinUI 3 pulls together several moving parts that rarely sit cleanly together for … More →
The post Microsoft’s WinUI agent plugin trims token use by over 70% during development appeared first on Help Net Security.