Aggregator
CVE-2013-7195 | PHPFox 3.7.3/3.7.4 access control (XFDB-92335 / BID-66672)
CVE-2013-7196 | PHPFox 3.7.3/3.7.4/3.7.5 val[item_id] access control (EDB-39139 / XFDB-92336)
CVE-2014-2014 | Gilles Lamiral imapsync up to 1.580 credentials management (ID 15 / Nessus ID 72526)
CVE-2014-2880 | Oracle Identity Manager 11.1.1.5/11.1.1.7/11.1.2.1/11.1.2.2 User Management firstlogin backUrl input validation (EDB-32670 / Nessus ID 78542)
研究显示 1% 的 Polymarket 用户获得了 76.5% 的收益
JDownloader Downloader Hacked to Infect Users With New Python RAT
JDownloader, the popular open-source download manager trusted by millions of users worldwide, was at the center of a serious supply chain attack in early May 2026. Attackers quietly compromised the official jdownloader.org website and replaced legitimate installer download links with malicious files carrying a fully functional Python-based remote access trojan. Anyone who downloaded what they […]
The post JDownloader Downloader Hacked to Infect Users With New Python RAT appeared first on Cyber Security News.
白泽成果分享:通过补丁语义分析让“依赖库漏洞传播”看得更准
PS3 模拟器项目开发者请求停止递交 AI slop 代码
macOS 27 добьёт Time Capsule: Apple готовит похороны для миллионов устаревших бэкапов
全球招聘巨头:网络安全从业人员工作量增加,薪水减少
AI不会接管SOC 它正在将分析师变为SOC指挥官核心看点
CVE-2025-69223 | aio-libs aiohttp up to 3.13.2 data amplification (GHSA-6mq8-rvhq-8wgg / EUVD-2025-206229)
CVE-2026-25990 | python-pillow Pillow up to 12.1.0 PSD Image Parser out-of-bounds write (GHSA-cfh3-3jmp-rvhc / Nessus ID 298710)
CVE-2025-69873 | ajv up to 8.17.1 RegExp data redos (Nessus ID 298757 / WID-SEC-2026-0935)
CVE-2024-27282 | Ruby up to 3.0.6/3.1.4/3.2.3/3.3.0 Regex Search heap-based overflow (Nessus ID 215915 / WID-SEC-2024-0952)
CVE-2026-33554 | FreeIPMI up to 1.16.16 buffer overflow (Nessus ID 312089 / WID-SEC-2026-1350)
CVE-2026-42239 | budibase up to 3.35.9 utils.ts budibase:auth cookie httponly flag (GHSA-4f9j-vr4p-642r / WID-SEC-2026-1412)
Rustinel: Open-source endpoint detection for Windows and Linux
Open-source endpoint detection has long been split between Windows-focused tools built around Sysmon and Linux tools built around eBPF or auditd. Defenders running mixed environments have had to stitch together separate pipelines, separate rule sets, and separate maintenance burdens. Rustinel, a Rust-based endpoint agent, is an attempt to collapse that work into a single codebase. A single agent across two operating systems Rustinel collects telemetry through ETW on Windows and eBPF on Linux, normalizes the … More →
The post Rustinel: Open-source endpoint detection for Windows and Linux appeared first on Help Net Security.