Aggregator
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-45247 Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Optimize AI Inference: Real-Time NodeBalancers Metrics for AI Workloads
Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)
威胁情报|Red Hat Cloud Services npm 包供应链投毒
Hackers Use YouTube and SEO Poisoning to Spread WeedHack Minecraft Malware
Hackers are hiding dangerous malware inside what look like popular Minecraft mods and game clients, using YouTube videos and search engine tricks to pull unsuspecting players into their trap. The campaign, known as WeedHack, has been quietly running since January 2026 and has already racked up over 116,000 victims worldwide. What makes this campaign particularly […]
The post Hackers Use YouTube and SEO Poisoning to Spread WeedHack Minecraft Malware appeared first on Cyber Security News.
G.O.S.S.I.P 阅读推荐 2026-06-03 从头开始训练语言模型!
Еще не протестуешь, но уже в списке. Geedge создает профиль будущего «врага» государства
Acer working to patch max severity zero-days in Wave 7 routers
Alcasec, “Robin Hood of Spanish Hackers,” Jailed for 31 Months Over Data Theft
Борьба с ИИ вышла из-под контроля. Разработчик спрятал в коде бомбу для чужих проектов
Only 11% of production agents pass the AI agent security bar
Enterprise teams are running AI agents that write code, drive browsers, answer customer calls, manage cloud infrastructure, and query data warehouses with standing credentials. A new independent assessment of 100 production agents finds that nearly all of them carry the conditions for a single hostile document to take them over. The AI Risk Quadrant (AIRQ) report, a 2026 Q2 edition produced by independent researchers, scores 100 commercial and publicly available AI agents across three dimensions: … More →
The post Only 11% of production agents pass the AI agent security bar appeared first on Help Net Security.
【安全圈】弃用谷歌,欧洲议会因隐私考量改用法国 Qwant 为默认搜索引擎
【安全圈】惠普 VoIP 电话现严重漏洞,或致企业网络遭入侵
【安全圈】弃用谷歌,欧洲议会因隐私考量改用法国 Qwant 为默认搜索引擎
Trump Signs Order Inviting Voluntary Review of Frontier AI Models
0Day в VSCode. Хакеры научились угонять GitHub одним кликом — и всё из-за удобства горячих клавиш
U.S. CISA adds Android and Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
Release Notes: Decision-Ready SOC Reporting, Elastic Security Integration, and 1400+ Threat Coverage Updates
Security leaders are under growing pressure to reduce the time between threat detection and response without adding more complexity to already overloaded SOC workflows. ANY.RUN’s May updates help teams act on security risks more efficiently, improve consistency across investigations, and maintain stronger protection as attacker tactics continue to evolve. Discover the updates your team can […]
The post Release Notes: Decision-Ready SOC Reporting, Elastic Security Integration, and 1400+ Threat Coverage Updates appeared first on ANY.RUN's Cybersecurity Blog.