Aggregator
Зачем платить за Adobe Premiere? Вышел бесплатный и мощный Shotcut 26.2
Google Chrome shifts to two-week release cycle for increased stability
CVE-2025-52365 | ccurtsinger stabilizer Command-Line Argument os.system command injection (EUVD-2025-208230)
CVE-2025-57622 | Step-Video-T2V /vae-api get_data deserialization (EUVD-2025-208231)
CVE-2026-3465 | Tuya App/SDK 24.07.11 on Android JSON Data Point cruise_time denial of service (EUVD-2026-9297)
CVE-2026-28518 | Volcengine OpenViking up to 0.2.1 path traversal (46b3e76 / EUVD-2026-9296)
Archipelo and Checkmarx Announce Partnership Connecting AppSec Detection with DevSPM
San Francisco, CA, United States, March 3rd, 2026, CyberNewswire Archipelo and Checkmarx today announced a technical partnership focused on correlating application vulnerability findings with development-origin context within modern software delivery workflows. Application security platforms identify and prioritize vulnerabilities across repositories and pipelines. These systems indicate where risk exists but typically do not capture how a […]
The post Archipelo and Checkmarx Announce Partnership Connecting AppSec Detection with DevSPM appeared first on Cyber Security News.
CVE-2026-1566 | LatePoint Plugin up to 5.2.7 on WordPress wordpress_user_id password recovery (EUVD-2026-9269 / CNNVD-202603-243)
CVE-2026-1336 | Ays Pro AI ChatBot with ChatGPT and Content Generator Plugin store_data/get_chatgpt_api_key authorization (EUVD-2026-9268 / CNNVD-202603-244)
CVE-2026-1747 | GitLab Enterprise Edition up to 18.7.4/18.8.4/18.9.0 authentication bypass (Issue 588385 / Nessus ID 300301)
CVE-2023-26132 | dottie up to 2.0.3 /dottie.js set Current prototype pollution (Nessus ID 300393)
CVE-2026-27631 | exiv2 up to 0.28.7 Command Line max_size denial of service (EUVD-2026-9263 / Nessus ID 300392)
CVE-2026-27837 | mickhansen dottie.js up to 2.0.6 set prototype pollution (GHSA-4gxf-g5gf-22h4 / Nessus ID 300393)
Ракеты в небе – хакеры в сетях. Эскалация на Ближнем Востоке перешла в интернет
Frictionless Banking Experiences Start with Observability
New ‘StegaBin’ Campaign Uses Malicious 26 npm Packages to Deploy Multi-Stage Credential Stealer
A new software supply-chain attack is abusing the npm ecosystem today, where a single mistaken dependency can quietly open a door into a developer’s machine. The activity, tracked as “StegaBin,” mixes familiar tricks like typosquatting with a staged delivery path that runs during installation and keeps the theft out of sight. In this wave, 26 […]
The post New ‘StegaBin’ Campaign Uses Malicious 26 npm Packages to Deploy Multi-Stage Credential Stealer appeared first on Cyber Security News.
DragonForce
You must login to view this content