Aggregator
Submit #805644: jdcloud 京东云无线宝ER1 太乙 有线路由 千兆路由器 JDCOS-JDC08-4.5.1.r4518 Remote code execution [Accepted]
Submit #805635: jdcloud 京东云无线宝ER1 太乙 有线路由 千兆路由器 JDCOS-JDC08-4.5.1.r4518 Remote code execution [Duplicate]
Один ион заставили сделать невозможное — создать квантовое состояние, которое не получалось 100 лет
CVE-2026-42812 | Apache Polaris up to 1.4.0 access control
CVE-2026-42811 | Apache Polaris up to 1.4.0 improper authentication
CVE-2026-42810 | Apache Polaris up to 1.4.0 Asterisk escape output
CVE-2026-42809 | Apache Polaris up to 1.4.0 Staged Table Creation information disclosure
爆火新游戏被曝疯狂消耗SSD寿命 加速硬盘报废
CVE-2026-5337 | Frontend File Manager Plugin up to 23.6 on WordPress Download Endpoint wpfm_download file_id authorization (EUVD-2026-26818)
CVE-2026-40561 | KAZUHO Starlet up to 0.31 on Perl Reverse Proxy Content-Length request smuggling (EUVD-2026-26806 / Nessus ID 311809)
CVE-2026-5063 | webaways NEX-Forms Plugin up to 9.1.11 on WordPress POST Parameter submit_nex_form cross site scripting (EUVD-2026-26815)
CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
CISA Adds Actively Exploited Linux Root Access Bug CVE-2026-31431 to KEV
1,800 Developers Hit in Mini Shai-Hulud Supply Chain Attack Across PyPI, NPM, and PHP
What happened A supply chain attack campaign attributed to TeamPCP, dubbed Mini Shai-Hulud, has compromised packages across the PyPI, NPM, and PHP ecosystems over a two-day period, affecting over 1,800 developer repositories containing stolen credentials. The campaign was first identified on April 29 when malicious versions of four SAP NPM packages were caught delivering information-stealing […]
The post 1,800 Developers Hit in Mini Shai-Hulud Supply Chain Attack Across PyPI, NPM, and PHP appeared first on CISO Whisperer.
The post 1,800 Developers Hit in Mini Shai-Hulud Supply Chain Attack Across PyPI, NPM, and PHP appeared first on Security Boulevard.
1,800 Developers Hit in Mini Shai-Hulud Supply Chain Attack Across PyPI, NPM, and PHP
ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts
What happened A third iteration of the ConsentFix attack technique has been circulating on hacker forums, introducing automation and scalability to a method that abuses Microsoft Azure’s OAuth2 authorization code flow to hijack accounts without passwords and despite multi-factor authentication being enabled. The original ConsentFix was documented by Push Security in December 2025 as an […]
The post ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts appeared first on CISO Whisperer.
The post ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts appeared first on Security Boulevard.
ConsentFix v3 Automates OAuth Abuse to Bypass MFA and Hijack Azure Accounts
FBI Links Cybercriminals to Sharp Surge in Cargo Theft Attacks
What happened The FBI issued a public service announcement on April 30, 2026, warning the US transportation and logistics industry of a sharp rise in cyber-enabled cargo theft, with estimated losses in the United States and Canada reaching nearly $725 million in 2025. That represents a 60% increase over the prior year. Confirmed cargo theft […]
The post FBI Links Cybercriminals to Sharp Surge in Cargo Theft Attacks appeared first on CISO Whisperer.
The post FBI Links Cybercriminals to Sharp Surge in Cargo Theft Attacks appeared first on Security Boulevard.