Aggregator
Unpatched flaws turn Ollama’s auto-updater into a persistent RCE vector, researchers say
Researchers at Striga have disclosed two vulnerabilities (CVE-2026-42248, CVE-2026-42249) in Ollama’s Windows auto-updater that, when chained together, may allow an attacker to covertly plant a persistent executable that runs on every login. CVE-2026-42248 and CVE-2026-42249 Ollama is an open-source tool for running large language models locally. It’s is used by those who don’t want their data to leave their machine and don’t want to be constrained by API costs, usage limits, or the requirement of … More →
The post Unpatched flaws turn Ollama’s auto-updater into a persistent RCE vector, researchers say appeared first on Help Net Security.
LastPass Mobile Smart Scanner improves password security
LastPass has launched Mobile Smart Scanner, a solution that converts photographs of typed or handwritten credentials into structured, ready-to-use password entries that can be reviewed, saved, and autofilled directly from the vault. Available in early access for Free, Premium, and Family plan customers, the feature extracts the site URL, username, and password from a single scan taken with the LastPass mobile app. No manual typing, no third-party upload. Scanning occurs on-device consistent with the LastPass … More →
The post LastPass Mobile Smart Scanner improves password security appeared first on Help Net Security.
Silver Fox Uses Fake Tax Notices to Deploy ValleyRAT and New ABCDoor Backdoor
A Chinese-linked threat group known as Silver Fox has been running a calculated phishing campaign, tricking employees at organizations across multiple countries into opening what appear to be official tax authority notices. The emails, disguised as legitimate government communications, led victims to download a chain of malware that ultimately installed both the known ValleyRAT backdoor […]
The post Silver Fox Uses Fake Tax Notices to Deploy ValleyRAT and New ABCDoor Backdoor appeared first on Cyber Security News.
Icarus
You must login to view this content
CVE-2026-0073: Zero-Click RCE Flaw in Android's Wireless ADB Bypasses Authentication
8681 окаменелость из глубины, половина видов — загадка для науки. Они пережили первую катастрофу в истории планеты
全球知名虚拟光驱软件DAEMON Tools遭供应链攻击
Unlocking the Full Value of 5G with Network Slicing
North Korean APT Targets Yanbian Gamers via Trojanized Platform
Microsoft Edge Stores Passwords in Process Memory, Posing Enterprise Risk
NASA 局长认为冥王星是行星
Торт от незнакомца. Эксперты сравнили корпоративные нейросети с десертом из неизвестных ингредиентов
LuxSci Launches Enterprise-Grade HIPAA-Compliant Email Security for Mid-Sized Healthcare Organizations
Cambridge, MA, May 5th, 2026, CyberNewswire New right-sized offering brings advanced encryption, easy API integration, and HITRUST-certified compliance to the most underserved segment in healthcare email — with pricing starting at $99/month LuxSci, a leading provider of HIPAA compliant secure healthcare communications, today announced the launch of LuxSci Secure High Volume Email for mid-sized healthcare […]
The post LuxSci Launches Enterprise-Grade HIPAA-Compliant Email Security for Mid-Sized Healthcare Organizations appeared first on Cyber Security News.
FTC to ban data broker Kochava from selling Americans’ location data
Signal 开发无需手机的独立桌面应用
Google to pay up to $1.5 million for zero-click Pixel Titan M exploits
Google has revised its Android and Chrome Vulnerability Reward Programs (VRPs), which pay security researchers to report vulnerabilities in Android, Google hardware, and the Chrome browser. The update raises top bounties to $1.5 million and adjusts rewards for lower-complexity reports. The program targets vulnerability classes that automated tools struggle to detect and prioritizes researcher-driven findings. The maximum reward of $1.5 million applies to a zero-click, full-chain compromise of Pixel devices targeting the Titan M2 security … More →
The post Google to pay up to $1.5 million for zero-click Pixel Titan M exploits appeared first on Help Net Security.
China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions
Cerberus Stalkerware on Google Play Leverages Accessibility Abuse and Firebase for Remote Control
A dangerous piece of Android stalkerware called Cerberus Anti-theft has been hiding in plain sight on the Google Play Store since October 4, 2023. Sold under the package name com.ssurebrec and marketed as a legitimate anti-theft tool, the app is capable of silently photographing victims, tracking their location, recording audio, and wiping their devices, all without their […]
The post Cerberus Stalkerware on Google Play Leverages Accessibility Abuse and Firebase for Remote Control appeared first on Cyber Security News.