Aggregator
[Virtual Event] Anatomy of a Data Breach: What to Do if it Happens to You
Infosecurity Europe
GitHub 被黑,3800个内部仓库外泄:从一枚恶意VS Code扩展说起
CVE-2026-1543 | themefusion Avada Builder Plugin up to 3.15.2 on WordPress Dynamic Data Feature cross site scripting
CVE-2026-2734 | MLflow up to 3.9.x REST API BEFORE_REQUEST_VALIDATORS/AFTER_REQUEST_HANDLERS access control
CVE-2026-6279 | themefusion Avada Builder Plugin up to 3.15.2 on WordPress AJAX Endpoint get_value injection
Most dark web activity revolves around a handful of topics
Dark web activity often becomes visible during marketplace seizures, major data leaks, or sudden spikes in criminal activity. Those events can create an impression of an ecosystem where attention shifts quickly and new trends regularly replace old ones. A six-year dataset covering more than 25,000 dark web sites tracked what people discussed in underground forums and marketplaces and how those discussions changed over time. The work drew from more than 11 million archived snapshots collected … More →
The post Most dark web activity revolves around a handful of topics appeared first on Help Net Security.
AI red teaming agents change how LLMs get tested
Adversarial probing of LLMs has piled up a sprawling toolkit over the past three years. Attack techniques with names like Tree of Attacks with Pruning, Crescendo, and Skeleton Key sit alongside hundreds of prompt transforms and scoring methods across open-source frameworks including Microsoft’s PyRIT, NVIDIA’s Garak, and Promptfoo. The catalog has grown faster than any operator can fluently navigate it, and that mismatch is changing how AI red teaming gets done. A wave of recent … More →
The post AI red teaming agents change how LLMs get tested appeared first on Help Net Security.
CVE-2026-47782 | Siber Systems RoboForm Password Manager App on Android URL Validation insufficient warning
CVE-2026-48172 | LiteSpeed User-End cPanel Plugin up to 2.4.4 /var/cpanel/logs cpanel_jsonapi_func privileges assignment
CVE-2026-4811 | wpbean WPB Floating Menu or Categories Plugin up to 1.0.8 on WordPress cross site scripting
CVE-2026-9149 | libsolv solv File repo_add_solv heap-based overflow
CVE-2026-47372 | RRWO Crypt::SaltedHash up to 0.09 on Perl rand weak prng
CVE-2026-9150 | libsolv Debian Metadata Parser stack-based overflow
CVE-2026-9152 | Altium 365 Legacy SOAP Endpoint missing authentication
CVE-2026-40165 | goauthentik up to 2025.12.4/2026.2.2 NameID improper authentication (GHSA-9wj8-xv4r-qwrp)
CVE-2026-40102 | makeplane up to 1.3.0 Segment saved-analytic-view data query logic injection (GHSA-93x3-ghh7-72j3)
CVE-2026-1881 | broadstreetads Broadstreet Plugin up to 1.52.2 on WordPress get_sponsored_meta authorization
Product showcase: Bitdefender Mobile Security for iOS protects privacy where scams begin
Bitdefender Mobile Security for iOS is a security and privacy application for iPhone and iPad that helps protect against phishing attempts, online scams, unsafe websites, and account exposure. I have used Bitdefender Mobile Security for iOS for the last two years. It was easy to install, easy to use, and I have not noticed any impact on device performance. The app combines web protection, scam detection, privacy tools, account monitoring, and VPN capabilities. Dashboard and … More →
The post Product showcase: Bitdefender Mobile Security for iOS protects privacy where scams begin appeared first on Help Net Security.