Aggregator
CVE-2025-54292 | Canonical LXD up to 5.21.3/6.4 path traversal
CVE-2025-54291 | Canonical LXD up to 5.21.3/6.4 Images API information exposure
CVE-2025-54288 | Canonical LXD up to 5.21.3/6.4 devLXD Server authentication spoofing
CVE-2025-54290 | Canonical LXD up to 5.21.3/6.4 Image Export API information disclosure
CVE-2025-54289 | Canonical LXD up to 5.21.3/6.4 Operations API missing origin validation in websockets
《进阶逆向工程实战》:解锁逆向技术的全链路实战能力
写一个简单的VMP-不造轮子,何以知轮之精髓?
Code是AI的手:姚顺雨访谈与Python-Use范式的对话
Марсоход нашел все ингредиенты для жизни на Марсе: воду, органику, минералы… но где же сама жизнь?
从 低危 到 RCE
От 15 телеканалов к 1100. Как российская спутниковая связь прошла путь от выживания до контроля 90% национального рынка
MatrixPDF Puts Gmail Users at Risk with Malicious PDF Attachments
Forrester: Agentic AI-Powered Breach Will Happen in 2026
Warning: Beware of Android Spyware Disguised as Signal Encryption Plugin and ToTok Pro
Red Hat Data Breach – Threat Actors Claim Breach of 28K Private GitHub Repositories
An extortion group known as the Crimson Collective claims to have breached Red Hat’s private GitHub repositories, making off with nearly 570GB of compressed data from 28,000 internal repositories. This data theft is being regarded as one of the most significant breaches in technology history, involving the unauthorized extraction of source code and sensitive confidential […]
The post Red Hat Data Breach – Threat Actors Claim Breach of 28K Private GitHub Repositories appeared first on Cyber Security News.
Researchers uncover spyware targeting messaging app users in the UAE
2 млн личных фото и ключ от прошивки: портативные принтеры превратили пользователей в лёгкую добычу
Insider Threat Intelligence Solutions | Trend Analysis Report
ProSpy and ToSpy: New spyware families impersonating secure messaging apps
ESET researchers have found two Android spyware campaigns aimed at people looking for secure messaging apps such as Signal and ToTok. The attackers spread the spyware through fake websites and social engineering. Researchers identified two previously unknown spyware families. Android/Spy.ProSpy poses as upgrades or add-ons for the Signal app and the discontinued ToTok app, while Android/Spy.ToSpy pretends to be the ToTok app itself. The ToSpy campaign is still active, supported by command-and-control servers that remain … More →
The post ProSpy and ToSpy: New spyware families impersonating secure messaging apps appeared first on Help Net Security.