Aggregator
CVE-2026-2063 | D-Link DIR-823X 250416 Web Management Interface /goform/set_ac_server os command injection (EUVD-2026-5598 / WID-SEC-2026-0340)
CVE-2026-2061 | D-Link DIR-823X 250416 /goform/set_ipv6 sub_424D20 os command injection (WID-SEC-2026-0340)
CVE-2026-25631 | n8n-io n8n up to 1.120.x Credential Domain Validation improper authentication (GHSA-2xcx-75h9-vr9h / EUVD-2026-5569)
CVE-2026-23490 | pyasn1 up to 0.6.1 RELATIVE-OID allocation of resources (GHSA-63vm-454h-vhhq / EUVD-2026-2865)
CVE-2025-54349 | esnet iperf3 up to 3.19.0 iperf_auth.c off-by-one (EUVD-2025-23456 / Nessus ID 253491)
CVE-2026-21643 | Fortinet FortiClientEMS 7.4.4 sql injection (FG-IR-25-1142 / WID-SEC-2026-0343)
CVE-2025-6176 | Scrapy up to 2.13.2 Brotli Decompression resource consumption (Nessus ID 272129 / WID-SEC-2026-0008)
EU targets Meta over WhatsApp AI access restrictions
The European Commission believes Meta breached EU competition rules by blocking other AI assistants from accessing and interacting with users on WhatsApp. The case centers on a change Meta announced on 15 October 2025 to the WhatsApp Business Solution Terms. The update effectively blocked third-party, general-purpose AI assistants from operating on WhatsApp. Since 15 January 2026, Meta AI has been the only AI assistant available on the app. The Commission plans to impose interim measures … More →
The post EU targets Meta over WhatsApp AI access restrictions appeared first on Help Net Security.
Claude Desktop Extensions 0-Click RCE Vulnerability Exposes 10,000+ Users to Remote Attacks
A new critical vulnerability discovered by security research firm LayerX has exposed a fundamental architectural flaw in how Large Language Models (LLMs) handle trust boundaries. The zero-click remote code execution (RCE) flaw in Claude Desktop Extensions (DXT) allows attackers to compromise a system using nothing more than a maliciously crafted Google Calendar event. The vulnerability, […]
The post Claude Desktop Extensions 0-Click RCE Vulnerability Exposes 10,000+ Users to Remote Attacks appeared first on Cyber Security News.
Пароль больше не нужен. В роутерах TP-Link нашли «чёрный ход» размером с грузовик
EU, Dutch government announce hacks following Ivanti zero-days
CVE-2026-1862 | Google Chrome up to 144.0.7559.110 V8 type confusion (ID 479726 / EUVD-2026-5161)
CVE-2025-45582 | GNU Tar up to 1.35 TAR Archive path traversal (EUVD-2025-21178 / Nessus ID 281751)
HGAME2026 WEEK1 解题思路
BeyondTrust warns of critical RCE flaw in remote support software
16 ИИ-агентов Claude, две недели и $20 000. Как искусственный интеллект написал компилятор C и собрал ядро Linux
⚡ Weekly Recap: AI Skill Malware, 31Tbps DDoS, Notepad++ Hack, LLM Backdoors and More
9th February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 9th February, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Romania’s national oil pipeline operator, Conpet, has suffered a cyberattack that disrupted its IT systems and took its website offline. The company said operational technology, including pipeline control and telecommunications systems, remained […]
The post 9th February – Threat Intelligence Report appeared first on Check Point Research.