Aggregator
CVE-2026-5444 | Orthanc DICOM Server up to 1.12.10 PAM Image Parser integer overflow (EUVD-2026-20924 / Nessus ID 305824)
CVE-2026-39856 | mtrojnar osslsigncode up to 2.12 pe_page_hash_calc PointerToRawData/SizeOfRawData out-of-bounds (GHSA-rjrx-chvw-8jw8 / Nessus ID 305825)
CVE-2026-34983 | bytecodealliance wasmtime up to 43.0.0 API Call wasmtime::Linker use after free (GHSA-hfr4-7c6c-48w2 / Nessus ID 305827)
IRify 智能化改造:AI 代码审计 + Poc 自动生成,安全效率翻倍
EngageLab SDK flaw opens door to private data on 50M Android devices
安全热点周报:Fortinet 发布紧急补丁修复 FortiClient 零日漏洞
Little Snitch for Linux shows what your apps are connecting to
Network monitoring on Linux has long been a gap for users who want per-process visibility into outbound connections. Existing tools either operate at the command line or were designed for server security rather than desktop privacy. Objective Development, the Austrian company behind the macOS firewall utility Little Snitch, released a Linux version of the tool. It is free and, according to the company, will remain so. Architecture choices The kernel component uses eBPF for traffic … More →
The post Little Snitch for Linux shows what your apps are connecting to appeared first on Help Net Security.
CVE-2022-1729 | Linux Kernel kernel/events/core.c perf_event_open race condition (EUVD-2022-25010 / Nessus ID 247421)
CVE-2022-1725 | vim up to 8.2.4956 null pointer dereference (EUVD-2022-25007)
CVE-2022-1714 | radare2 up to 5.6.x heap-based overflow (EUVD-2022-24997)
CVE-2022-1720 | vim up to 8.2.4938 vim/vim grab_file_name buffer overflow (EUVD-2022-25002)
Apiiro CLI turns AI coding assistants into full-stack security engineers
The Apiiro CLI brings the Apiiro platform to your terminal and to your AI coding assistants, giving them six native security capabilities: scanning, risk management, remediation, an AI security analyst (via Apiiro Guardian Agent), AI Threat Modeling, and prompt enrichment. It installs in seconds on macOS, Linux, and Windows via brew, direct download, or RPM. Apiiro CLI ships with agent skills, structured capability definitions that AI coding assistants like Claude Code and Cursor can read … More →
The post Apiiro CLI turns AI coding assistants into full-stack security engineers appeared first on Help Net Security.
CVE-2022-1674 | vim up to 8.2.4925 regexp.c vim_regexec_string null pointer dereference (EUVD-2022-24960)
Хватит винить смартфоны в своей бессоннице. Кажется, проблема совсем в другом
CPUID Website Compromised to Deliver Weaponized HWMonitor and CPU-Z Tools
The cpuid-dot-com website, home to widely used system utilities CPU-Z and HWMonitor, is at the center of an active supply chain security incident. Users downloading HWMonitor 1.63 or CPU-Z ZIPs since early April have reportedly received trojanized installers capable of dropping malicious DLLs, evading antivirus detection through in-memory execution, and establishing connections to attacker-controlled infrastructure. […]
The post CPUID Website Compromised to Deliver Weaponized HWMonitor and CPU-Z Tools appeared first on Cyber Security News.