Aggregator
The Boring Stuff is Dangerous Now
2 hours 48 minutes hence
AI agents capable of discovering and exploiting obscure vulnerabilities are emerging alongside developers producing vast amounts of potentially flawed AI-generated code, forcing defenders to adapt accordingly.
Shlomie Liberow
Windows 11 KB5089549 会导致部分 PC 安装失败
1 hour 37 minutes ago
微软证实本月释出的例行安全更新 Windows 11 KB5089549 会导致部分 PC 安装失败,原因是对系统启动至关重要的 EFI 系统分区(ESP)空间不足。如果 ESP 可用空间不足 10 MB,KB5089549 安装会失败,返回 0x800f0922 错误,用户会看到安装卡在了 35-36%,然后回滚,提示空间不足。微软提供了一个临时的修复方法:以管理员身份打开命令提示符。运行以下命令:reg add “HKLM\SYSTEM\CurrentControlSet\Control\Bfsvc /v EspPaddingPercent /t REG_DWORD /d 0 /f”。然后重启受影响的设备。
Fisker Ocean 车主将其变成一个开源汽车项目
2 hours 20 minutes ago
2024 年 6 月 Ocean SUV 制造商 Fisker 公司申请破产,它总共交付了 1.1 万辆电动汽车。斥巨资购买汽车的车主面临汽车失去维修的难题,零部件替换、电池、软件、电子钥匙等问题横在他们面前,如果无法解决他们的汽车将会沦为昂贵的垃圾。接下来发生的堪称电动汽车行业历史上最引人入胜的故事。车主们没有认命,他们组织成立了一个非盈利组织 Fisker Owners Association(FOA),对汽车的私有软件进行逆向工程,破解 CAN 总线网络,在 GitHub 上发布开源工具,最终在 Fisker 的废墟上建起一家由志愿者运营的开源汽车公司。Fisker 不是唯一一家破产的美国电动汽车公司,Nikola、Canoo 和 Arrival 的车主都面临类似的困境。
CVE-2026-8539 | Google Chrome up to 148.0.7778.96 on Android SanitizerAPI code injection (ID 496524 / Nessus ID 315114)
2 hours 33 minutes ago
A vulnerability identified as critical has been detected in Google Chrome on Android. This vulnerability affects unknown code of the component SanitizerAPI. The manipulation leads to code injection.
This vulnerability is uniquely identified as CVE-2026-8539. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-8535 | Google Chrome up to 148.0.7778.96 on Linux Media out-of-bounds (ID 495530 / Nessus ID 315114)
2 hours 33 minutes ago
A vulnerability labeled as problematic has been found in Google Chrome on Linux. This issue affects some unknown processing of the component Media. The manipulation results in out-of-bounds read.
This vulnerability was named CVE-2026-8535. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-8537 | Google Chrome up to 148.0.7778.96 ViewTransitions cross-domain policy (ID 495890 / Nessus ID 315114)
2 hours 33 minutes ago
A vulnerability marked as critical has been reported in Google Chrome. Impacted is an unknown function of the component ViewTransitions. This manipulation causes permissive cross-domain policy with untrusted domains.
The identification of this vulnerability is CVE-2026-8537. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-8536 | Google Chrome up to 148.0.7778.96 on macOS ReadingMode information disclosure (ID 495857 / Nessus ID 315114)
2 hours 33 minutes ago
A vulnerability labeled as problematic has been found in Google Chrome on macOS. The impacted element is an unknown function of the component ReadingMode. Such manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2026-8536. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-8538 | Google Chrome up to 148.0.7778.96 GPU denial of service (ID 496415 / Nessus ID 315114)
2 hours 33 minutes ago
A vulnerability marked as problematic has been reported in Google Chrome. This affects an unknown function of the component GPU. Performing a manipulation results in denial of service.
This vulnerability was named CVE-2026-8538. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-8532 | Google Chrome up to 148.0.7778.96 XML external control of assumed-immutable web parameter (ID 492812 / Nessus ID 315114)
2 hours 33 minutes ago
A vulnerability categorized as critical has been discovered in Google Chrome. Impacted is an unknown function of the component XML. The manipulation results in external control of assumed-immutable web parameter.
This vulnerability is known as CVE-2026-8532. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-8533 | Google Chrome up to 148.0.7778.96 Accessibility use after free (ID 495247 / Nessus ID 315114)
2 hours 33 minutes ago
A vulnerability identified as critical has been detected in Google Chrome. The affected element is an unknown function of the component Accessibility. This manipulation causes use after free.
This vulnerability is handled as CVE-2026-8533. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
Critical Pre-Auth Flaw CVE-2026-44338 Exploited to Hijack Autonomous AI Agents
2 hours 58 minutes ago
Adversaries initiated a targeted reconnaissance campaign against vulnerable PraisonAI nodes less than four hours following the public disclosure
The post Critical Pre-Auth Flaw CVE-2026-44338 Exploited to Hijack Autonomous AI Agents appeared first on Penetration Testing Tools.
ddos
CVE-2026-8515 | Google Chrome up to 148.0.7778.96 HID use after free (ID 495999 / Nessus ID 314874)
3 hours 1 minute ago
A vulnerability categorized as critical has been discovered in Google Chrome. This issue affects some unknown processing of the component HID. Executing a manipulation can lead to use after free.
The identification of this vulnerability is CVE-2026-8515. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-8516 | Google Chrome up to 148.0.7778.96 DataTransfer information disclosure (ID 496393 / Nessus ID 314881)
3 hours 1 minute ago
A vulnerability described as problematic has been identified in Google Chrome. This affects an unknown function of the component DataTransfer. Such manipulation leads to information disclosure.
This vulnerability is listed as CVE-2026-8516. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-8513 | Google Chrome up to 148.0.7778.96 on Android Input use after free (ID 495939 / Nessus ID 314885)
3 hours 1 minute ago
A vulnerability, which was classified as critical, was found in Google Chrome on Android. This impacts an unknown function of the component Input. Executing a manipulation can lead to use after free.
This vulnerability appears as CVE-2026-8513. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-8512 | Google Chrome up to 148.0.7778.96 Fileystem use after free (ID 495782 / Nessus ID 314979)
3 hours 1 minute ago
A vulnerability was found in Google Chrome. It has been declared as critical. This affects an unknown part of the component Fileystem. Such manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2026-8512. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-8514 | Google Chrome up to 148.0.7778.96 Aura use after free (ID 495948 / Nessus ID 314979)
3 hours 1 minute ago
A vulnerability was found in Google Chrome. It has been rated as critical. This vulnerability affects unknown code of the component Aura. Performing a manipulation results in use after free.
This vulnerability was named CVE-2026-8514. The attack may be initiated remotely. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-45351 | open-webui Open WebUI up to 0.8.8 Web Request information disclosure (GHSA-jh9g-8jqw-m2qx / WID-SEC-2026-1542)
3 hours 1 minute ago
A vulnerability has been found in open-webui Open WebUI up to 0.8.8 and classified as problematic. Affected is an unknown function of the component Web Request Handler. This manipulation causes information disclosure.
This vulnerability is tracked as CVE-2026-45351. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2026-8509 | Google Chrome up to 148.0.7778.96 WebML heap-based overflow (ID 493310 / Nessus ID 314979)
3 hours 1 minute ago
A vulnerability has been found in Google Chrome and classified as critical. Affected is an unknown function of the component WebML. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2026-8509. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-8510 | Google Chrome up to 148.0.7778.96 on Windows Skia external control of assumed-immutable web parameter (ID 502636 / EUVD-2026-30421)
3 hours 1 minute ago
A vulnerability was found in Google Chrome on Windows and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Skia. The manipulation results in external control of assumed-immutable web parameter.
This vulnerability is known as CVE-2026-8510. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com