Posts of last few hours
Please support the site operations by clicking ads.
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
https://govuln.com/news/url/x8dB
These are the top threats you should know about this week.
https://www.f5.com/labs/articles/weekly-threat-bulletin-october-7th-2026
A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available.
The flaw is in LMCache's multiprocess mode, where the cache runs as a standalone server that LLM workers reach over the ZeroMQ messaging library. A single network
https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurrency miners and further expand the scale of the botnet.
The financially motivated campaign, dubbed Canto Incognito, has been found to install cryptocurrency miners, including
https://thehackernews.com/2026/10/poellm-malware-infects-3400-servers-to.html
2026年3月,伊拉克某关键基础设施行业的一位软件工程师收到一封来自“迪拜机场IT部门”的邮件。
https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451189173&idx=1&sn=920a0ccc154ccdb3445c3e3c1a3d8648
The Operational Technology Cybersecurity Coalition released a white paper urging the CISA to create a new directive centered around operational technology, which is used to monitor and control critical infrastructure.
https://therecord.media/cyber-experts-call-on-cisa-require-ot-security
https://mp.weixin.qq.com/s?__biz=MzA4ODEyODA3MQ==&mid=2247497260&idx=1&sn=64e49cc6f7f9a371f5f98ae21168679a
The Health Care Cybersecurity and Resiliency Act of 2026 was passed by unanimous consent last week, potentially expanding federal cyber requirements for healthcare organizations.
https://therecord.media/senate-passes-healthcare-cyber-bill-after-change-breach
A report by a Labour MP and an academic argues that if the British public cannot see what Russian activity costs, it cannot weigh that burden against the cost of defending against it.
https://therecord.media/russia-cyberattacks-on-britain-putin-tax-graeme-downie
https://cyber.gc.ca/en/guidance/shopping-online-safely-itsap00071
Users of two types of Fortinet hardware should take steps to limit their exposure to a now-global credential stealing campaign, U.S. federal law enforcement says.
https://therecord.media/fortibleed-warning-fbi-secret-service
The 2026 findings are not just a year-over-year shift. They mark the latest point in a five-year arc where resilience, AI governance, human risk, and board scrutiny are converging inside the systems where work actually happens.
For years, the enterprise cybersecurity story has been told as a straight line of escalation: more attacks, more data loss, more pressure, and more urgency. That
https://thehackernews.com/2026/10/the-sixth-voice-of-ciso-data-shows.html
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways.
"The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat
https://thehackernews.com/2026/10/fbi-warns-fortibleed-remains-active.html
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions.
The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software
https://thehackernews.com/2026/10/atlassian-data-center-flaw-draws.html
If you’re evaluating an agentic pentesting solution right now, you’ve probably heard the same pitch more than once: point it at a target, and it discovers, validates, and exploits attack paths autonomously, the way a real attacker would.
That promise is worth taking seriously. It’s also worth pressure testing, and three questions do the heavy lifting.
What can the assessment actually
https://thehackernews.com/2026/10/what-is-agentic-pentesting-what-it.html
NetworkMiner 3.2 parses RADIUS authentication data and extracts more details from the OT/ICS protocols UMAS and IEC-104. The release also improves several existing protocol parsers and fixes file-reassembly issues, helping analysts extract more information from captured network traffic. OT Protocol[...]
https://www.netresec.com/?page=Blog&month=2026-10&post=NetworkMiner-3-2-Released
关键词黑客💡 威胁情报:网络安全机构 Island 今日公开曝光一起针对企业营销人员的大规模“真人值守交互式
https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652079274&idx=3&sn=d6e6368a840032a5ddfe2bf7bb4cdd84
https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652079274&idx=2&sn=2ac9ed707c794a32564ec1e4c3ba5722
关键词木马💡 威胁态势:乌克兰国家计算机应急响应团队(CERT-UA)今日通报一起代号为 UAC-0277
https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652079274&idx=1&sn=15cf3e01caa2b91119ad90f970c2db20
Latest Blog Posts
- 21 hours 6 minutes ago
- 21 hours ago
- 21 hours ago
- 21 hours ago
- 21 hours ago
- 21 hours ago
- 21 hours ago
- 21 hours ago
- 21 hours ago
- 21 hours ago