Aggregator
OpenAI依托ChatGPT技术打造AI搜索引擎,正面对标谷歌搜索
2 weeks 3 days ago
安全客
Qilin
2 weeks 3 days ago
You must login to view this content
cohenido
Qilin
2 weeks 3 days ago
You must login to view this content
cohenido
Неделя на исправление или взлом: какие обновления безопасности необходимо установить до середины марта 2026 года
2 weeks 3 days ago
Установлены жесткие сроки для исправления уязвимостей в SolarWinds и Ivanti.
Qilin
2 weeks 3 days ago
You must login to view this content
cohenido
AVideo平台存在高危零点击命令注入漏洞 可被用于劫持直播流
2 weeks 3 days ago
安全客
Qilin
2 weeks 3 days ago
You must login to view this content
cohenido
恶意浏览器插件针对imToken用户窃取私钥
2 weeks 3 days ago
安全客
The New Turing Test: How Threats Use Geometry to Prove 'Humanness'
2 weeks 3 days ago
Malware is evolving to evade sandboxes by pretending to be a real human behind the keyboard. The Picus Red Report 2026 shows 80% of top attacker techniques now focus on evasion and persistence, including geometry-based cursor tests and CPU timing checks. [...]
Sponsored by Picus Security
Qilin
2 weeks 3 days ago
You must login to view this content
cohenido
Viber即时通讯软件存在TLS漏洞,Cloak代理模式失效并导致用户暴露
2 weeks 3 days ago
安全客
黑客可利用间接提示注入攻击 借助外部内容操控AI智能体
2 weeks 3 days ago
安全客
海康威视与罗克韦尔自动化高危漏洞纳入CISA已知被利用漏洞清单
2 weeks 3 days ago
安全客
OpenAI发布GPT-5.4大模型,具备更强推理、编码与计算机操作能力
2 weeks 3 days ago
安全客
黑客利用OpenClaw、GitHub与Bing传播恶意软件,攻击手段极具隐蔽性
2 weeks 3 days ago
安全客
CVE-2026-28472 | OpenClaw up to 2026.2.1 Gateway WebSocket Connect Handshake missing authentication (GHSA-rv39-79c4-7459)
2 weeks 3 days ago
A vulnerability, which was classified as critical, has been found in OpenClaw up to 2026.2.1. Affected by this vulnerability is an unknown functionality of the component Gateway WebSocket Connect Handshake. Performing a manipulation results in missing authentication.
This vulnerability is identified as CVE-2026-28472. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-28469 | OpenClaw up to 2026.2.13 authorization (GHSA-rq6g-px6m-c248)
2 weeks 3 days ago
A vulnerability has been found in OpenClaw up to 2026.2.13 and classified as critical. This affects an unknown part. The manipulation leads to authorization bypass.
This vulnerability is listed as CVE-2026-28469. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-28478 | OpenClaw up to 2026.2.12 Webhook allocation of resources (GHSA-q447-rj3r-2cgh)
2 weeks 3 days ago
A vulnerability was found in OpenClaw up to 2026.2.12. It has been rated as problematic. The affected element is an unknown function of the component Webhook Handler. Performing a manipulation results in allocation of resources.
This vulnerability is reported as CVE-2026-28478. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-28473 | OpenClaw up to 2026.2.1 RPC Call /approve authorization (GHSA-mqpw-46fh-299h)
2 weeks 3 days ago
A vulnerability described as problematic has been identified in OpenClaw up to 2026.2.1. Affected by this vulnerability is an unknown functionality of the file /approve of the component RPC Call Handler. Such manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2026-28473. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com