Aggregator
CVE-2026-7317 | Grav CMS up to 1.7.49.5/2.0.0-beta.1 Cache Value FileCache.php FileCache::doGet deserialization (GHSA-gwfr-jfjf-92vv / c66dfeb5f)
Submit #803083: elie mcp-project 0.1.0 Path Traversal [Accepted]
Submit #798732: Trilby Media Grav CMS >= 1.7.44, <= 1.7.49.5 Deserialization [Accepted]
CVE-2026-7316 | eiliyaabedini aider-mcp up to 667b914301aada695aab0e46d1fb3a7d5e32c8af code_with_ai aider_mcp.py working_dir/editable_files command injection
Chinese Silk Typhoon Hacker Extradited to the U.S. from Italy
A Chinese national tied to one of the most damaging state-sponsored hacking campaigns in recent history has been extradited to the United States from Italy. Xu Zewei, 34, a citizen of the People’s Republic of China, landed on U.S. soil this past weekend and appeared before U.S. District Court in Houston, Texas, on April 27, […]
The post Chinese Silk Typhoon Hacker Extradited to the U.S. from Italy appeared first on Cyber Security News.
Submit #803082: eiliyaabedini aider-mcp 667b914301aada695aab0e46d1fb3a7d5e32c8af Command Injection [Accepted]
CVE-2026-7315 | eiceblue spire-pdf-mcp-server 0.1.1 PDF File server.py get_pdf_path filepath path traversal
CVE-2026-7314 | eiceblue spire-doc-mcp-server 1.0.0 base.py get_doc_path document_name path traversal
VECT: Ransomware by design, Wiper by accident
Key Takeaways Background VECT Ransomware is a Ransomware-as-a-Service (RaaS) program that made its first appearance in December 2025 on a Russian-language cybercrime forum. After claiming their first two victims in January 2026, the group got back into the public eye due to an announcement of a partnership with TeamPCP, the actor behind several supply-chain attacks […]
The post VECT: Ransomware by design, Wiper by accident appeared first on Check Point Research.
WhatsApp Testing Own Cloud Backup Provider for Default End-to-End Encryption
WhatsApp is currently developing an independent cloud backup system designed to give users more direct control over their chat histories. This upcoming feature will allow users to store their backups securely on WhatsApp’s native servers. The update aims to reduce reliance on third-party cloud services like Google Drive and Apple’s iCloud while enforcing strict cryptographic […]
The post WhatsApp Testing Own Cloud Backup Provider for Default End-to-End Encryption appeared first on Cyber Security News.
OpenAI готовит телефон, в котором вместо приложений живут ИИ-агенты. И он выйдет в 2028-м
LLM Proxies vs. MCP Gateways: What’s the Difference?
As enterprise adoption of generative AI accelerates, so does the number of new components showing up in architecture diagrams. Among the common are LLM proxies and MCP gateways. They are often grouped together because they both sit between applications and AI systems, and both introduce a level of abstraction that is intended to simplify development […]
The post LLM Proxies vs. MCP Gateways: What’s the Difference? appeared first on Cequence Security.
The post LLM Proxies vs. MCP Gateways: What’s the Difference? appeared first on Security Boulevard.
Submit #803081: eiceblue spire-pdf-mcp-server 0.1.1 Path Traversal [Accepted]
Submit #803080: eiceblue spire-doc-mcp-server 1.0.0 Path Traversal [Accepted]
Ransomware Turf War as 0APT and KryBit Groups Trade Blows
Shutdowns, power outages, and conflict: a review of Q1 2026 Internet disruptions
G.O.S.S.I.P 阅读推荐 2026-04-28 Wsl9x!
The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords
LLMs leave statistical fingerprints in the passwords they generate. We built a 100-year-old model to find them and detected 28,000 in the wild.
The post The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords appeared first on Security Boulevard.