Aggregator
CVE-2019-25662 | Montala ResourceSpace 8.6 watched_searches.php ref sql injection (Exploit 46308 / EDB-46308)
CVE-2019-25675 | eDirectory 1.0 Login Endpoint language_file.php key sql injection (Exploit 46423)
CVE-2019-25671 | VA MAX 8.3.4 Parameter changeip.php mtu_eth0 path traversal (Exploit 46348 / EDB-46348)
CVE-2026-5614 | Belkin F9K1015 1.00.10 /goform/formSetPassword webpage stack-based overflow (EUVD-2026-19158)
CVE-2026-5615 | givanz Vvvebjs up to 2.0.5 File Upload Endpoint upload.php uploadAllowExtensions cross site scripting (EUVD-2026-19160)
CVE-2026-5616 | JeecgBoot 3.9.0/3.9.1 AI Chat JeecgBizToolsProvider.java missing authentication (Issue 9464 / EUVD-2026-19162)
CVE-2026-5609 | Tenda i12 1.0.0.11(3862) Parameter /goform/wifiSSIDset formwrlSSIDset index/wl_radio stack-based overflow (EUVD-2026-19148)
CVE-2026-5610 | Belkin F9K1015 1.00.10 /goform/formWISP5G webpage stack-based overflow (EUVD-2026-19150)
CVE-2026-5608 | Belkin F9K1122 1.00.33 /goform/formWlanSetup webpage stack-based overflow (EUVD-2026-19146)
Residential proxies make a mockery of IP-based defenses
Attack traffic moved through ordinary home and mobile connections in ways that limited the usefulness of IP reputation on its own. GreyNoise observed 4 billion malicious sessions during a 90-day period and described activity that appeared indistinguishable from normal user traffic at the network level. Residential proxies routed traffic through consumer broadband, mobile data, and small-business connections. These same IP ranges were used by employees, customers, and partners, which made it difficult to separate malicious … More →
The post Residential proxies make a mockery of IP-based defenses appeared first on Help Net Security.
Пятый день Artemis II: коррекция курса, проверка скафандров и 40 минут тишины. Что происходит с экипажем прямо сейчас
CVE-2026-35616: Fortinet fixes actively exploited high-severity flaw
CVE-2026-35616: Fortinet fixes actively exploited high-severity flaw
Товарищ Ким пришел за вашим кодом. Новые приключения программистов на GitHub
聊天机器人现在可以开精神科药物处方了
Product showcase: Proton Authenticator is an end-to-end encrypted, open source 2FA app
Proton Authenticator is a free and open-source two-factor authentication (2FA) app that generates time-based one-time passwords (TOTP) to help secure online accounts. It is available on Windows, macOS, Linux, iOS, and Android, allowing users to access their verification codes across devices. The app is designed to work without ads or tracking. A Proton account is optional and mainly used for encrypted sync between devices. How Proton Authenticator works Setup starts with installing the app from … More →
The post Product showcase: Proton Authenticator is an end-to-end encrypted, open source 2FA app appeared first on Help Net Security.
Пять шагов к захвату ядра. Учёные доказали, что современные GPU от Nvidia уязвимы для дистанционных атак
IT talent looks the other way as wireless security incidents pile up
Enterprise wireless networks are supporting a growing mix of devices and applications, increasing operational demand and security exposure. The 2026 Cisco State of Wireless report reflects these conditions through rising incident rates, higher costs, and ongoing staffing challenges. Wireless investment continues to increase. Most organizations expanded spending over the past 5 years, and a large share expects further growth in the next several years. Expectations for returns are also rising, with more organizations anticipating stronger … More →
The post IT talent looks the other way as wireless security incidents pile up appeared first on Help Net Security.