Aggregator
CVE-2026-4505 | eosphoros-ai DB-GPT up to 0.7.5 FastAPI Endpoint controller.py module_plugin.refresh_plugins unrestricted upload (EUVD-2026-13806)
CVE-2025-55988 | DreamFactory Core 1.0.3 RestController.php path traversal (EUVD-2025-208913)
CVE-2026-4499 | D-Link DIR-820LW 2.03 SSDP ssdpcgi_main os command injection (EUVD-2026-13800)
CVE-2026-4500 | bagofwords1 bagofwords up to 0.0.297 code_execution.py generate_df injection (Issue 60 / EUVD-2026-13802)
CVE-2026-4504 | eosphoros-ai db-gpt up to 0.7.5 Incomplete Fix /api/v1/editor/ sql injection (EUVD-2026-13804)
CVE-2026-33150 | libfuse up to 3.18.1 FUSE File Parser fuse_uring_start use after free (GHSA-qxv7-xrc2-qmfx / EUVD-2026-13786)
CVE-2026-33147 | GenericMappingTools gmt up to 6.6.0 src/gmt_remote.c gmt_remote_dataset_id stack-based overflow (GHSA-fqxx-62x7-9gwg / EUVD-2026-13784)
CVE-2026-33144 | GPAC MP4Box utils/xml_bin_custom.c gf_xml_parse_bit_sequence_bs out-of-bounds write (GHSA-3jw5-9pmw-vmfg / EUVD-2026-13782)
CVE-2025-4574 | crossbeam-channel Crate up to 0.5.14 on Rust double free (EUVD-2025-14635 / Nessus ID 237169)
苹果公司终止了 Mac Pro 台式机的生产
Make OpenAI’s models misbehave and earn a reward
OpenAI’s public Safety Bug Bounty program focuses on AI abuse and safety risks across its products. The goal is to support safe and secure systems and reduce the risk of misuse that could lead to harm. This program complements the Security Bug Bounty. It accepts reports of abuse and safety risks that do not meet the criteria for a security vulnerability. Submissions are reviewed by teams from both programs based on scope and ownership. Safety … More →
The post Make OpenAI’s models misbehave and earn a reward appeared first on Help Net Security.
工信部发文部署2026年ICT行业网络运行安全工作
Payload
You must login to view this content
Top product launches at RSAC 2026
RSAC 2026 showcased a wave of innovation, with vendors unveiling technologies poised to redefine cybersecurity. From AI-powered defense to breakthroughs in identity protection, this year’s conference delivered a glimpse into the future. Here are the most interesting products that caught our attention, and could shape what’s next. Astrix advances AI agent security platform to govern shadow and enterprise agents Astrix Security has revealed a major expansion of its AI agent security platform, covering every layer … More →
The post Top product launches at RSAC 2026 appeared first on Help Net Security.
Tails 7.6 ships automatic Tor bridge retrieval and a new password manager
Tails 7.6 is out, and for users operating on networks that block Tor, the most consequential addition is built-in bridge retrieval. The Tor Connection assistant can now detect when a direct connection to Tor is restricted and automatically request bridges suited to the user’s region. The request goes through the Tor Project’s Moat API, and the connection to that API is disguised via domain fronting, making it appear as traffic to an ordinary website. Previously, … More →
The post Tails 7.6 ships automatic Tor bridge retrieval and a new password manager appeared first on Help Net Security.
University of North Georgia Triumphs in DOD Hacking Contest
A team of cybersecurity students from the University of North Georgia vanquished seven opposing teams from other senior military colleges and elite service academies in an upset victory to win a capture the flag hacking contest staged this week at the National Defense University here.
NYC Health Notifying Patients of 2 Third-Party Hacks
Hackers had access to New York City's municipal healthcare system for nearly three months before being detected, stealing data of an undisclosed number of patients. The incident is the second hacking-related data breach within weeks involving a third-party firm hired by NYC Health + Hospitals.
Breach Roundup: Tycoon2FA Phishing Platform Rebounds
This week, Tycoon 2FA, Trio-Tech, messaging app spying and a ransomware broker sentenced. Iran-linked hackers. Mazda disclosed a breach. Oracle patched a flaw. North Korean actors weaponized VS Code, a Spanish port ransomware attack, a French teacher data breach and a healthcare firm victim surge.
Pentagon Piloting Skills-Based Assessments for Cyber Workers
The U.S. Department of Defense is for the first time piloting new skills-based assessments for its cyber hiring as an alternative to checking paper qualifications. Many certificates, officials say, don't reflect the skills their cyber teams need in the real world.