Aggregator
Socket Buys Secure Annex to Expand Supply-Chain Visibility
1 month 2 weeks ago
Combined Platform Spans Dependencies, Extensions, Developer Tools
Socket’s acquisition of Secure Annex extends software supply-chain security beyond open-source dependencies into browser and IDE extensions, addressing AI-driven development risks and fragmented visibility across modern developer workflows.
Socket’s acquisition of Secure Annex extends software supply-chain security beyond open-source dependencies into browser and IDE extensions, addressing AI-driven development risks and fragmented visibility across modern developer workflows.
DHS Shutdown Ends as CISA Faces Long Recovery
1 month 2 weeks ago
Bipartisan Deal Funds DHS Components After Record 75-Day Shutdown
The House passed a bipartisan bill funding the Department of Homeland Security, ending a 75-day shutdown that forced the Cybersecurity and Infrastructure Security Agency into a reactive posture and disrupted preventive cyber operations, even as workforce losses and proposed cuts threaten long-term resilience.
The House passed a bipartisan bill funding the Department of Homeland Security, ending a 75-day shutdown that forced the Cybersecurity and Infrastructure Security Agency into a reactive posture and disrupted preventive cyber operations, even as workforce losses and proposed cuts threaten long-term resilience.
State CISOs Are Losing Confidence as AI Threats Surge
1 month 2 weeks ago
Tightening Budgets and AI-Enabled Attacks Stretch State Cyber Defenses
State CISO confidence has collapsed, with just 22% saying their data is protected from cyberthreats. The 2026 NASCIO-Deloitte study points to AI-enabled attacks, third-party vendor risk and the worst budget picture in years as states rethink how they defend public data.
State CISO confidence has collapsed, with just 22% saying their data is protected from cyberthreats. The 2026 NASCIO-Deloitte study points to AI-enabled attacks, third-party vendor risk and the worst budget picture in years as states rethink how they defend public data.
Breach Roundup: US Cyber Command Flags Election Threats
1 month 2 weeks ago
Also, HexDex Arrest, Black Axe Crackdown, LeRobot RCE Flaw
This week, election threats resurfaced. A prolific hacker arrested. Black Axe network disrupted. China-linked disinformation targets Tibet. Exploited ScreenConnect and Windows flaws raise alarms. Minecraft gamers hit with stealer malware. A critical AI framework bug enables remote code execution.
This week, election threats resurfaced. A prolific hacker arrested. Black Axe network disrupted. China-linked disinformation targets Tibet. Exploited ScreenConnect and Windows flaws raise alarms. Minecraft gamers hit with stealer malware. A critical AI framework bug enables remote code execution.
本周看什么 | 最近值得一看的 10 部作品
1 month 2 weeks ago
☕️ TL;DR近期佳作推荐:[电影] 燃比娃、[电影] 世界的主人、[韩剧] 努力克服自卑的我们、[韩剧] 稻草人、[日剧] 月夜行路:答案在名作中、[英剧] 半个男人、[美剧] 逆转狂篮 第二季、
Submit #804336: Open5gs AMF v2.7.7 Denial of Service [Accepted]
1 month 2 weeks ago
Submit #804336 / VDB-360536
ZiyuLin
Submit #804335: Open5gs AMF v2.7.7 Denial of Service [Duplicate]
1 month 2 weeks ago
Submit #804335 / VDB-360533
ZiyuLin
SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now
1 month 2 weeks ago
SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. The company released firmware updates to block bypass attacks and unauthorized access. SonicWall released urgent firmware updates to fix three SonicOS vulnerabilities affecting Gen 6, Gen 7, and Gen 8 firewalls. The flaws could allow attackers to bypass security controls, access restricted services, […]
Pierluigi Paganini
SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now
1 month 2 weeks ago
SonicWall patches three SonicOS flaws in Gen 6, 7 and 8 firewalls. Patch them now
Handled, Not Hosted: Administrative Activity Inside a Bulletproof Hoster
1 month 2 weeks ago
How to Build a Browser-Based Voice Assistant With the AssemblyAI Voice Agent API
1 month 2 weeks ago
New StorybyAssemblyAIbyAssemblyAI@assemblyaiAssemblyAI builds advanced speech language models that
7 Things You Can Build With a Single WebSocket (Using AssemblyAI’s Voice Agent API)
1 month 2 weeks ago
New StorybyAssemblyAIbyAssemblyAI@assemblyaiAssemblyAI builds advanced speech language models that
China-Aligned Attackers Use ShadowPad, IOX Proxy, and WMIC in Multi-Stage Espionage Campaign
1 month 2 weeks ago
A China-aligned threat group has been carrying out a carefully planned espionage campaign against government agencies and critical infrastructure across Asia. The group, tracked under the temporary designation SHADOW-EARTH-053, has been active since at least December 2024, quietly targeting organizations in at least eight countries. The campaign uses a combination of malware tools and living-off-the-land […]
The post China-Aligned Attackers Use ShadowPad, IOX Proxy, and WMIC in Multi-Stage Espionage Campaign appeared first on Cyber Security News.
Tushar Subhra Dutta
Пять уязвимостей и один слишком сильный администратор. В XAPI нашли способ получить полный контроль над сервером
1 month 2 weeks ago
Уязвимости в XAPI ломают иерархию прав.
CVE-2026-7585 | Open5GS up to 2.7.7 AMF /src/amf/nudm-handler.c amf_nudm_sdm_handle_provisioned denial of service (Issue 4403)
1 month 2 weeks ago
A vulnerability was found in Open5GS up to 2.7.7 and classified as problematic. The impacted element is the function amf_nudm_sdm_handle_provisioned of the file /src/amf/nudm-handler.c of the component AMF. Executing a manipulation can lead to denial of service.
This vulnerability is tracked as CVE-2026-7585. The attack can be launched remotely. Moreover, an exploit is present.
The project was informed of the problem early through an issue report but has not responded yet.
vuldb.com
Submit #804334: Open5gs AMF v2.7.7 Denial of Service [Accepted]
1 month 2 weeks ago
Submit #804334 / VDB-360533
ZiyuLin
How to Evaluate STT for Voice Agents in Production
1 month 2 weeks ago
New StorybySpeechmaticsbySpeechmatics@speechmaticsSpeechmatics builds world-leading speech technolo
CVE-2026-42996 | JS8Call-improved up to 2.3.1 APRSISClient.cpp grid2deg stack-based overflow (GHSA-98hp-pjp7-w62x)
1 month 2 weeks ago
A vulnerability has been found in JS8Call-improved up to 2.3.1 and classified as critical. The affected element is the function grid2deg of the file APRSISClient.cpp. Performing a manipulation results in stack-based buffer overflow.
This vulnerability is identified as CVE-2026-42996. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-7584 | Zurich Instruments LabOne Q up to 26.1.1/26.4.0b5 File deserialization
1 month 2 weeks ago
A vulnerability, which was classified as critical, was found in Zurich Instruments LabOne Q up to 26.1.1/26.4.0b5. Impacted is an unknown function of the component File Handler. Such manipulation leads to deserialization.
This vulnerability is referenced as CVE-2026-7584. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
vuldb.com