Aggregator
CVE-2026-8244 | Industrial Application Software IAS Canias ERP 8.03 Login RMI Interface clientVersion improper authentication (EUVD-2026-28993)
6 days 9 hours ago
A vulnerability classified as problematic has been found in Industrial Application Software IAS Canias ERP 8.03. This impacts an unknown function of the component Login RMI Interface. The manipulation of the argument clientVersion leads to improper authentication.
This vulnerability is traded as CVE-2026-8244. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-8243 | Industrial Application Software IAS Canias ERP 8.03 JNLP Deployment Endpoint hard-coded key (EUVD-2026-28992)
6 days 9 hours ago
A vulnerability described as problematic has been identified in Industrial Application Software IAS Canias ERP 8.03. This affects an unknown function of the component JNLP Deployment Endpoint. Executing a manipulation can lead to use of hard-coded cryptographic key
.
This vulnerability appears as CVE-2026-8243. The attack may be performed from remote. There is no available exploit.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-8242 | Industrial Application Software IAS Canias ERP 8.03 Login RMI Interface doAction response discrepancy (EUVD-2026-28991)
6 days 9 hours ago
A vulnerability marked as problematic has been reported in Industrial Application Software IAS Canias ERP 8.03. The impacted element is the function doAction of the component Login RMI Interface. Performing a manipulation results in observable response discrepancy.
This vulnerability is reported as CVE-2026-8242. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
CVE-2026-8241 | Industrial Application Software IAS Canias ERP 8.03 RMI Interface iasGetServerInfoEvent improper authorization (EUVD-2026-28989)
6 days 9 hours ago
A vulnerability labeled as problematic has been found in Industrial Application Software IAS Canias ERP 8.03. The affected element is the function iasGetServerInfoEvent of the component RMI Interface. Such manipulation leads to improper authorization.
This vulnerability is documented as CVE-2026-8241. The attack can be executed remotely. Additionally, an exploit exists.
The vendor was contacted early about this disclosure but did not respond in any way.
vuldb.com
Submit #808326: Industrial Application Software - IAS Canias ERP 8.03-- Improper Authentication (CWE-287), (CWE-200) [Accepted]
6 days 10 hours ago
Submit #808326 / VDB-362460
b1lal
Submit #808296: Industrial Application Software - IAS Canias ERP 8.03-- Use of Hard-coded Cryptographic Key (CWE-321) [Accepted]
6 days 10 hours ago
Submit #808296 / VDB-362459
b1lal
Submit #808295: Industrial Application Software - IAS Canias ERP 8.03-- Observable Response Discrepancy (CWE-204) [Accepted]
6 days 10 hours ago
Submit #808295 / VDB-362458
b1lal
Submit #808270: Industrial Application Software - IAS Canias ERP 8.03-- Exposure of Sensitive Information to an Unauthorized Actor [Accepted]
6 days 10 hours ago
Submit #808270 / VDB-362457
b1lal
在地下_马识途_摘录(5)
6 days 10 hours ago
我定下心来后想,这一次可算是我经历的危险中最危险的一次。
SecWiki News 2026-05-09 Review
6 days 10 hours ago
今日暂未更新资讯~
更多最新文章,请访问SecWiki
更多最新文章,请访问SecWiki
Китайский шар над США вызвал дипломатический скандал. Американский шар над Балтикой — плановые учения НАТО. Контекст решает всё
6 days 10 hours ago
Военные технологии будущего иногда выглядят как очень серьезный воздушный шарик.
VoIP号码生态系统和黑产利用现状
6 days 10 hours ago
电话导向攻击交付(Telephone-oriented attack delivery, TOAD)
CVE-2026-8198 | logtivity Activity Logs, User Activity Tracking, Multisite Activity Log Plugin REST API Endpoint options verifyAuthorization information disclosure (EUVD-2026-28914)
6 days 11 hours ago
A vulnerability identified as problematic has been detected in logtivity Activity Logs, User Activity Tracking, Multisite Activity Log Plugin up to 3.3.6 on WordPress. Impacted is the function verifyAuthorization of the file /wp-json/logtivity/v1/options of the component REST API Endpoint. This manipulation causes information disclosure.
This vulnerability is registered as CVE-2026-8198. Remote exploitation of the attack is possible. No exploit is available.
You should upgrade the affected component.
vuldb.com
韩国人形机器人皈依我佛
6 days 11 hours ago
名为 Gabi 的韩国人形机器人参加了一场修改版的皈依仪式,成为大韩佛教曹溪宗的一名僧侣。它宣誓尊重生命、服从人类、和平对待其他机器人和物体。Gabi 的韩语是 자비,意思是慈悲,它由杭州宇树科技制造,起售价 13,500 美元。在皈依仪式上 Gabi 同意了五项通常由人类僧侣诵读的誓言,誓言略微修改以适应人形机器人。机器人承诺尊重生命,以和平的方式对待其他机器人和物体,倾听人类的意见,避免做出欺骗性的言行,以及节约能源。Gabi 还参加了修改版的净化仪式。人类僧侣的净化仪式通常是手臂上用香火轻轻烧灼,象征净化身体和心灵。Gabi 则给予了莲花灯节贴纸和一串念珠。此举旨在响应曹溪宗总务院长真愚法师在新年致辞中承诺,即将 AI 融入佛教传统。真愚法师在一份声明中称,“无畏引领 AI 时代,导向心灵的安宁与觉悟。”
Cybercrime's Human Trafficking Problem
6 days 11 hours ago
Coerced Labor in Scam Compounds Is Reshaping How Enterprises Face Fraud Risks
Fraud operations in Southeast Asia increasingly rely on trafficked workers forced into scams. This reality challenges assumptions about threat actor behavior, complicates attribution and negotiation, and demands that enterprises rethink fraud prevention and disruption strategies.
Fraud operations in Southeast Asia increasingly rely on trafficked workers forced into scams. This reality challenges assumptions about threat actor behavior, complicates attribution and negotiation, and demands that enterprises rethink fraud prevention and disruption strategies.
ISMG Editors: The Battle Over Access to Frontier AI Models
6 days 11 hours ago
Also: Washington's AI Policy Divide, FDA's Push for AI-Driven Clinical Trials
In this week's panel, four ISMG editors discussed the battle over who gets to access powerful AI cybersecurity models, policy issues unfolding in Washington over AI-driven cyber defenses, and how the FDA is beginning to test AI-supported real-time clinical trials to speed up drug development.
In this week's panel, four ISMG editors discussed the battle over who gets to access powerful AI cybersecurity models, policy issues unfolding in Washington over AI-driven cyber defenses, and how the FDA is beginning to test AI-supported real-time clinical trials to speed up drug development.
Missouri Alleges Conduent is Stonewalling State on Hack
6 days 11 hours ago
State Insurance Officials Seeking Details About Service Firm's Mega Data Breach
Missouri regulators are widening their investigation into the 204 hacking incident at Conduent Business Services, alleging that the company has stonewalled the state's attempts to obtain information about the data breach, which is estimated to affect more than 25 million people nationwide.
Missouri regulators are widening their investigation into the 204 hacking incident at Conduent Business Services, alleging that the company has stonewalled the state's attempts to obtain information about the data breach, which is estimated to affect more than 25 million people nationwide.
US Senator Presses CISA on Election Security Rollbacks
6 days 11 hours ago
Top Democrat Warns States Are Losing Federal Cyber Defense Support
A top U.S, Senate Democrat decried shrinking federal support for election security ahead of the November midterms, warning that cuts to the Cybersecurity and Infrastructure Security Agency could leave states without cyber defense or threat intelligence capabilities
A top U.S, Senate Democrat decried shrinking federal support for election security ahead of the November midterms, warning that cuts to the Cybersecurity and Infrastructure Security Agency could leave states without cyber defense or threat intelligence capabilities
Water System Hack Shows Potential, And Limits, of AI Attacks
6 days 11 hours ago
AI-Developed Attack Tooling Generated 'High-Volume, Noisy Workflows'
A hacker used Claude and Chat GPT in a cyberattack against a municipal water and sewage utility's operational technology systems in Mexico in January, according to forensic analysis by OT security firm Dragos. The tools "leveraged known techniques and existing vulnerability knowledge."
A hacker used Claude and Chat GPT in a cyberattack against a municipal water and sewage utility's operational technology systems in Mexico in January, according to forensic analysis by OT security firm Dragos. The tools "leveraged known techniques and existing vulnerability knowledge."