Researchers at AllSecure have revealed how North Korean hackers from the Lazarus Group used a fake LinkedIn job interview and deepfake technology to target their CEO.
A vulnerability, which was classified as critical, has been found in hexpm hex.pm. Affected by this issue is some unknown functionality in the library lib/hexpm/accounts/password_reset.ex of the component Reset Your Password Page. This manipulation causes session expiration.
This vulnerability appears as CVE-2026-21622. The attack may be initiated remotely. There is no available exploit.
It is suggested to install a patch to address this issue.
A vulnerability was found in filebrowser up to 2.60.x. It has been rated as problematic. The impacted element is an unknown function of the file http/public.go of the component withHashFile Middleware. This manipulation causes information disclosure.
The identification of this vulnerability is CVE-2026-28492. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability categorized as critical has been discovered in IceWhaleTech ZimaOS 1.5.2-beta3. This affects an unknown function of the component Application Interface. Such manipulation of the argument path leads to file inclusion.
This vulnerability is referenced as CVE-2026-28442. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in Frappe up to 14.99.x/15.97.x. It has been classified as critical. This affects an unknown function. This manipulation causes improper access controls.
This vulnerability is handled as CVE-2026-29077. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in Frappe up to 14.100.0/15.99.x. It has been declared as critical. This impacts an unknown function. Such manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-29081. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability categorized as critical has been discovered in graphprotocol contracts up to 2.x. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to improper access controls.
The identification of this vulnerability is CVE-2026-28410. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability identified as problematic has been detected in plone Products.isurlinportal 2.0.x/3.0.x/3.x. Affected by this issue is some unknown functionality of the file /login. The manipulation of the argument came_from leads to open redirect.
This vulnerability is referenced as CVE-2026-28413. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
A vulnerability classified as critical has been found in OpenReplay up to 1.19.x. Impacted is an unknown function of the file /{projectId}/cards/search. Performing a manipulation of the argument sort.field results in sql injection.
This vulnerability is cataloged as CVE-2026-28443. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability identified as problematic has been detected in Frappe up to 15.101.x/16.10.x. The impacted element is an unknown function. Performing a manipulation results in cross site scripting.
This vulnerability was named CVE-2026-28436. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
Attackers are mass-scanning Salesforce Experience Cloud sites using a modified AuraInspector tool to exploit misconfigurations and access sensitive data. Salesforce CSOC warns that threat actors are mass-scanning publicly accessible Experience Cloud sites using a modified version of the AuraInspector tool. AuraInspector is an open‑source command‑line tool released by Google/Mandiant to audit Salesforce Aura and Experience […]
好的,用户让我总结一篇文章的内容,控制在100字以内,并且不需要特定的开头。首先,我需要仔细阅读文章,了解主要内容。
文章主要讲的是如何学习道德黑客,提到了一些资源和建议。包括网络基础知识、认证如CompTIA的三重认证、Cisco的免费课程,还有实践平台如TryHackMe、Hack The Box和OverTheWire。工具方面提到了Nmap、Metasploit和Burp Suite,还有学习Linux的重要性。此外,还有YouTube频道和PortSwigger学院等资源。
接下来,我需要将这些信息浓缩到100字以内。要抓住关键点:学习网络基础、使用推荐资源(如认证、平台)、掌握工具和Linux,并参与社区。
最后,确保语言简洁明了,直接描述内容,不使用“总结”之类的开头词。
文章介绍了学习道德黑客的有效方法和资源,包括掌握网络基础知识、利用CompTIA认证和Cisco免费课程打下基础,通过TryHackMe、Hack The Box等平台实践技能,熟悉Nmap、Metasploit等工具,并建议学习Linux系统以提升能力。
A vulnerability was found in Zoom Workplace, Workplace VDI Client and Meeting SDK 6.6.x on Windows. It has been rated as problematic. This affects an unknown function. This manipulation causes Local Privilege Escalation.
This vulnerability is handled as CVE-2026-30900. It is possible to launch the attack on the local host. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Zoom Rooms up to 6.6.4 on Windows. It has been declared as problematic. The impacted element is an unknown function. The manipulation results in improper input validation.
This vulnerability is known as CVE-2026-30901. Attacking locally is a requirement. No exploit is available.
It is recommended to upgrade the affected component.