Aggregator
Спросили у ChatGPT - ответили хакеру. Почему не стоит доверять каждому «умному» помощнику
Google Confirms 90 Zero-Day Vulnerabilities Actively Exploited in 2025
The Google Threat Intelligence Group (GTIG) released its annual analysis, confirming that 90 zero-day vulnerabilities were actively exploited in the wild throughout 2025. While this marks a slight decrease from the record 100 zero-days in 2023, it represents a noticeable increase from 2024’s total of 78. According to Google’s researchers, attackers are shifting their focus […]
The post Google Confirms 90 Zero-Day Vulnerabilities Actively Exploited in 2025 appeared first on Cyber Security News.
FBI investigates breach of surveillance and wiretap systems
CVE-2026-28696 | Craft CMS prior 4.17.0-beta.1/5.9.0-beta.1 GraphQL Directive Elements::parseRefs authorization
CVE-2026-28783 | Craft CMS prior 5.9.0-beta.1/4.17.0-beta.1 Twig code injection (GHSA-5fvc-7894-ghp4)
CVE-2026-28782 | Craft CMS prior 4.17.0-beta.1/5.9.0-beta.1 authorization (GHSA-jxm3-pmm2-9gf6)
CVE-2026-28781 | Craft CMS prior 4.17.0-beta.1/5.9.0-beta.1 POST Request authorization (GHSA-2xfc-g69j-x2mp)
CVE-2025-70218 | D-Link DIR-513 1.10 /goform/formAdvFirewall stack-based overflow
CVE-2025-70226 | D-Link DIR-513 1.10 formEasySetupWizard curTime stack-based overflow
CVE-2026-26949 | Dell Device Management Agent up to 26.01 authorization (dsa-2026-105 / EUVD-2026-9446)
CVE-2026-28695 | Craft CMS Twig SSTI create path traversal
CVE-2025-1394 | Silabs Zigbee Stack up to 4.3.4/2024.6.2 return value (EUVD-2025-23149)
U.S. CISA adds Apple, Rockwell, and Hikvision flaws to its Known Exploited Vulnerabilities catalog
Beyond the Perimeter: Auditing Active Directory Security with ADPulse’s 35-Point Automated Scan
ADPulse — Active Directory Security Scanner ADPulse is an open-source Active Directory security auditing tool that connects to
The post Beyond the Perimeter: Auditing Active Directory Security with ADPulse’s 35-Point Automated Scan appeared first on Penetration Testing Tools.
成果分享 | [NDSS 2026] 跨设备认证研究:以三大用户权利筑牢登录安全防线
March 2026 Patch Tuesday forecast: Is AI security an oxymoron?
Developers and analysts are using more AI tools to produce code and to test both the performance and security of the finished products. They are also embedding AI functionality in their products directly. But just how secure are these AI tools and routines themselves? Recent reports show they suffer from vulnerabilities just like any other code. For example, Google recently provided an update for CVE-2026-0628, associated with Gemini AI implemented in the Chrome browser. This … More →
The post March 2026 Patch Tuesday forecast: Is AI security an oxymoron? appeared first on Help Net Security.