Posts of last few hours
Please support the site operations by clicking ads.
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]
https://www.bleepingcomputer.com/news/security/ninja-forms-plugin-flaw-exploited-to-hack-wordpress-sites/
On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days. [...]
https://www.bleepingcomputer.com/news/security/hackers-exploit-32-zero-days-on-first-day-of-pwn2own-ireland/
Atlassian is warning customers of a critical vulnerability, tracked as CVE-2026-21589, that can be exploited for arbitrary file-access in multiple self-hosted Data Center products, including Confluence, Jira, and Bitbucket. [...]
https://www.bleepingcomputer.com/news/security/atlassian-warns-of-critical-file-access-flaw-in-jira-confluence/
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. [...]
https://www.bleepingcomputer.com/news/security/asos-confirms-data-breach-after-hacked-in-app-notifications/
A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]
https://www.bleepingcomputer.com/news/security/fake-chatgpt-gemini-sites-steal-advertising-accounts-mfa-codes/
The following CIS Benchmarks were updated during the past month. We've highlighted the major updates below. Each Benchmark includes a full changelog.
https://www.cisecurity.org/insights/blog/cis-benchmarks-october-2026-update
Microsoft released emergency updates for Exchange Server to fix CVE-2026-96940, a high-severity flaw that can let attackers gain higher privileges. Microsoft has released out-of-band security updates for Exchange Server to fix a high-severity vulnerability tracked as CVE-2026-96940 (CVSS score of 8.8). The flaw is caused by weak authorization and can allow an authenticated attacker to […]
https://securityaffairs.com/200476/security/cve-2026-96940-microsoft-fixes-high-severity-exchange-server-flaw.html
RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged access to recovery and tenant isolation. [...]
https://www.bleepingcomputer.com/news/security/how-to-secure-rmm-software-8-controls-msps-should-test/
https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497246&idx=1&sn=c4c0d6bb4764198995a717bbf5bc1cef
从一句"做个网页版 Dota"开始,地图、英雄、技能、AI、渲染、联机——全是 AI 写的。这篇记录真实过程,共消耗2500积分,8个小时,全程0人工编码投入。
https://mp.weixin.qq.com/s?__biz=MzAwMzAwOTQ5Nw==&mid=2650942092&idx=1&sn=00d6ca3834148cc43f14020a86115af3
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
https://govuln.com/news/url/x8dB
Learn why vector search can rank contradictory statements as similar, and how hybrid retrieval can help RAG systems identify conflicting information.
https://www.akamai.com/blog/ai/2026/oct/vector-search-cant-tell-yes-from-no
Rust 承诺在编译期消除内存安全问题。本文把 Rust 官方漏洞公告库 RustSec advisory-db 全库拉下来数了一遍:1246 条公告中,346 条(27.8%)带内存类标签。但按年拆开,会看到一个结构性转折 —— 内存类公告里带 CVE 编号的比例,2020 年是 94%(77/82),2025–2026 年只有 6% 和 10%,同期「自称 unsound」的条数升到 35 和
https://xz.aliyun.com/news/92874
本文系统介绍了游戏逆向中查找功能 call 的基本方法,围绕“经过发包函数”和“不经过发包函数”两大类场景,分别讲解了堆栈回溯、虚函数表查找、特征对象访问断点、写入断点回溯等实用技巧,并通过背包使用物品、NPC 服务、自动寻路三个实例进行演示。
https://xz.aliyun.com/news/92875
Go 1.22 起 net/http.ServeMux 的路由匹配改用编码视图(EscapedPath)逐段比较,%2F 不再是段分隔符;匹配命中后通配捕获值按解码视图交付,.. 回退语义恢复。授权中间件按解码路径前缀放行,处理器拼接磁盘路径时越出前缀——同一请求在两份视图里各被信任一次。
https://xz.aliyun.com/news/92894
IFUNC 的强制绑定可在 constructor 安装 seccomp 前执行 resolver,规则必须由宿主在 dlopen 前落地。
https://xz.aliyun.com/news/92735
本文主要内容是:攻击者把 GEO 技术"武器化",让恶意下载站被生成式 AI 当作权威答案推荐给用户,从而完成"投毒 → 诱导下载 → 落地执行"的闭环。
https://xz.aliyun.com/news/92829
Latest Blog Posts
- 22 hours 57 minutes ago
- 22 hours 57 minutes ago
- 22 hours 57 minutes ago
- 22 hours 57 minutes ago
- 22 hours 58 minutes ago
- 22 hours 58 minutes ago
- 22 hours 58 minutes ago
- 22 hours 58 minutes ago
- 22 hours 58 minutes ago
- 22 hours 58 minutes ago