Aggregator
人工智能重要安全漏洞的通报 - Langflow安全漏洞
CVE-2026-1321 | Membership Plugin up to 3.2.18/3.2.20 on WordPress POST Parameter rcp_setup_registration_init rcp_level authorization (EUVD-2026-9796)
CVE-2026-2893 | Page and Post Clone Plugin up to 6.3 on WordPress content_clone meta_key sql injection (EUVD-2026-9811)
Beazley Exposure Management platform identifies external exposures and prioritizes cyber risk
Beazley Security has announced its Exposure Management product, which delivers continuous, automated discovery and intelligence-driven exposure notifications to help security teams accelerate risk mitigation in an era where AI-assisted attackers have compressed the time between vulnerability disclosure, weaponization, and exploitation. The product, validated with clients over the past eight months, is the first in an expanding suite of capabilities targeting internal and external exposures, third-party supplier risks, and leaked credentials that may be available on … More →
The post Beazley Exposure Management platform identifies external exposures and prioritizes cyber risk appeared first on Help Net Security.
聚焦密码与安全 筑牢网络强国建设的安全屏障
Смертный приговор за роутер. Интернет от Илона Маска стал уликой в деле о госизмене
Cisco Secure Firewall Management Vulnerability Allow Attackers to Bypass Authentication
Cisco has released a critical security advisory warning of a severe vulnerability in its Secure Firewall Management Center (FMC) Software. This flaw allows an unauthenticated, remote attacker to bypass authentication and execute script files, thereby gaining full root access to the underlying operating system. The vulnerability, tracked as CVE-2026-20079, stems from an improper system process […]
The post Cisco Secure Firewall Management Vulnerability Allow Attackers to Bypass Authentication appeared first on Cyber Security News.
重磅众测|高德全线业务奖励翻倍!
LeakBase cybercrime forum with 142,000 users taken down in global operation
LeakBase, an open-web cybercrime forum facilitating the trade of leaked databases and “stealer logs” containing stolen credentials, has been taken down in an international law enforcement operation coordinated by Europol and involving authorities from 14 countries. Police in action (Source: Europol) Active since 2021, LeakBase hosted a large archive of breached databases and compromised credentials used to facilitate account takeover, fraud and further cyber intrusions. By December 2025, the forum had more than 142,000 registered … More →
The post LeakBase cybercrime forum with 142,000 users taken down in global operation appeared first on Help Net Security.
告别「暴力堆料」,理想汽车打破车载芯片「高算力 低智能」困局
Hackers Mimic LastPass Support Email to Steal Vault Passwords
A new and carefully crafted phishing campaign is currently targeting LastPass users, with attackers sending fake support emails designed to steal vault master passwords. The campaign, which began on or around March 1, 2026, relies on social engineering tactics to trick users into believing their accounts have been compromised, pushing them to hand over their […]
The post Hackers Mimic LastPass Support Email to Steal Vault Passwords appeared first on Cyber Security News.
Authorities pull plug on Tycoon 2FA phishing-as-a-service platform
Tycoon 2FA, a phishing-as-a-service platform that allowed cybercriminals to bypass MFA and break into online accounts, has been disrupted by law enforcement agencies and cybersecurity partners. Takedown of the Tycoon 2FA phishing-as-a-service platform (Source: Europol) Active since August 2023, Tycoon 2FA was among the largest phishing operations worldwide. At its peak, the platform accounted for about 62% of phishing attempts blocked by Microsoft, according to investigators. The service operated on a subscription model and gave … More →
The post Authorities pull plug on Tycoon 2FA phishing-as-a-service platform appeared first on Help Net Security.