Aggregator
运营定义价值:安全行业的范式变换
Java 26 ships with new cryptography API and HTTP/3 support
Oracle released JDK 26, the 17th consecutive feature release delivered under the six-month cadence the project adopted in 2018. The release includes ten JDK Enhancement Proposals spanning language changes, garbage collection improvements, cryptographic tooling, and network protocol support. PEM encoding API targets cryptographic integration JEP 524 introduces a second preview of a PEM encoding API for cryptographic objects. The API converts keys, certificates, and certificate revocation lists into Privacy-Enhanced Mail format and decodes them back … More →
The post Java 26 ships with new cryptography API and HTTP/3 support appeared first on Help Net Security.
858 亿砸 AI,腾讯杀入「AI 战争」
WaterPlum Deploys New ‘StoatWaffle’ Malware in VSCode-Based Supply Chain Campaign
A North Korea-linked hacking group known as WaterPlum has introduced a dangerous new malware called StoatWaffle, deploying it through compromised Visual Studio Code (VSCode) repositories disguised as legitimate blockchain development projects to silently infiltrate developer machines. WaterPlum has been running a campaign known as “Contagious Interview” for some time, drawing victims in through fake job […]
The post WaterPlum Deploys New ‘StoatWaffle’ Malware in VSCode-Based Supply Chain Campaign appeared first on Cyber Security News.
Inside Discord’s Architecture at Scale
Inside the Week That Shook AI
Independent Podcasters, Oscar Hopefuls, and the iHeartPodcast Awards: Your Complete Guide to SXSW
Best Speech to Text APIs to Build an AI Notetaker in 2026
CVE-2026-4006 | dartiss Draft List Plugin up to 2.6.2 on WordPress Shortcode WP_Post::__get cross site scripting (EUVD-2026-13069)
CVE-2026-27091 | UiPress lite Plugin up to 3.5.09 on WordPress authorization (EUVD-2026-13067)
OpenClaw is a Security Nightmare. Here Are The Alternatives to Use Instead
CVE-2026-4068 | pattihis Add Custom Fields to Media Plugin up to 2.0.3 on WordPress update_option cross-site request forgery (EUVD-2026-13070)
CVE-2026-2571 | codename065 Download Manager Plugin up to 3.3.49 on WordPress reviewUserStatus information disclosure (EUVD-2026-13065)
CVE-2026-27093 | Ovatheme Tripgo Plugin up to 1.5.5 on WordPress filename control (EUVD-2026-13068)
CVE-2026-4120 | bplugins Info Cards Plugin up to 2.0.7 on WordPress URL Protocol render.php esc_attr btnUrl cross site scripting (EUVD-2026-13072)
CISA Warns of Microsoft SharePoint Vulnerability Exploited in Attacks
A critical security flaw in Microsoft SharePoint has been identified as actively exploited, and on March 18, 2026, the vulnerability was officially added to the Known Exploited Vulnerabilities (KEV) catalog. This addition confirms that threat actors are actively exploiting the flaw in real-world network attacks, prompting an urgent call to action for all network administrators […]
The post CISA Warns of Microsoft SharePoint Vulnerability Exploited in Attacks appeared first on Cyber Security News.