Aggregator
CVE-2026-23983 | Apache Superset up to 5.x Tag Endpoint information disclosure
CVE-2026-23980 | Apache Superset up to 5.x sql injection
CVE-2026-23982 | Apache Superset up to 5.x authorization
CVE-2026-23984 | Apache Superset up to 5.x authorization
CVE-2026-23969 | Apache Superset up to 4.1.1 sql injection
Fake Huorong Download Site Used to Deploy ValleyRAT Backdoor in Targeted Malware Campaign
A group of attackers has built a fake version of the Huorong Security antivirus website to trick users into downloading ValleyRAT, a Remote Access Trojan (RAT) built on the Winos4.0 framework. The campaign is linked to the Silver Fox APT group, a Chinese-speaking threat actor known for distributing trojanized versions of popular Chinese software. Huorong […]
The post Fake Huorong Download Site Used to Deploy ValleyRAT Backdoor in Targeted Malware Campaign appeared first on Cyber Security News.
Docker security advisory (AV26–158)
CVE-2026-2664 | Docker Desktop up to 4.61.x on Windows Linux VM /proc/docker out-of-bounds
血液测试将阿尔茨海默病诊断正确率提高至 94.5%
Квантовую телепортацию запустили по обычным городским кабелям — вместе с котиками и YouTube. Точность 90%
Microsoft expands Sovereign Cloud security with governance, local productivity and AI
Microsoft expands Microsoft Sovereign Cloud with new disconnected and AI capabilities that help organizations run critical infrastructure, productivity services and large AI models inside sovereign boundaries while keeping governance and operational continuity across connected and disconnected environments. Sovereign Private Cloud unifies Azure Local, Microsoft 365 Local and Foundry Local, bringing infrastructure, productivity and support for large AI models to any operational boundary. (Source: Microsoft) “Customers can choose the right control posture for each workload, through … More →
The post Microsoft expands Sovereign Cloud security with governance, local productivity and AI appeared first on Help Net Security.
Self-spreading npm malware targets developers in new supply chain attack
Security researchers have uncovered another supply chain attack targeting developers: 19 typosquatting npm packages published on npmjs.com that steal credentials, infect projects, and propagate themselves across developer environments. The operation, dubbed “SANDWORM_MODE,” represents a (still) rare example of worm-like malware designed to spread through software supply chains rather than traditional end-user systems. New npm worm builds on Shai-Hulud’s playbook After last year’s bombshell appearance of the self-replicating “Shai-Hulud” worm on the official npm registry, the … More →
The post Self-spreading npm malware targets developers in new supply chain attack appeared first on Help Net Security.