Aggregator
如何用大模型搞垮一个团队?
1 month 2 weeks ago
要想彻底用大模型搞垮一个团队并非易事,不仅需要把AI用到极致,更要联动上下、综合施策、层层加码,才能让团队在“全面智能化”的光环下彻底瓦解。本文从真实的研发场景出发,总结了搞垮团队的21项措施,或许可以给那些正在“拥抱AI”的团队一些反向的警醒。
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
1 month 2 weeks ago
Google on Monday disclosed that it identified an unknown threat actor using a zero-day exploit that it said was likely developed with an artificial intelligence (AI) system, marking the first time the technology has been put to use in the wild in a malicious context for vulnerability discovery and exploit generation.
The activity is said to be the work of cybercrime threat actors who appear to
The Hacker News
[Control systems] CISA ICS security advisories (AV26–441)
1 month 2 weeks ago
Canadian Centre for Cyber Security
拆解公共高级威胁情报的衰落
1 month 2 weeks ago
你是否也有过这样的疑问,尤其是在最近几年,读到真正有趣的恶意软件及其深度分析文章变得越来越罕见。
CoinBase Cartel
1 month 2 weeks ago
You must login to view this content
cohenido
CoinBase Cartel
1 month 2 weeks ago
You must login to view this content
cohenido
Instructure confirms hackers used Canvas flaw to deface portals
1 month 2 weeks ago
Education technology giant Instructure has confirmed that a security vulnerability allowed hackers to modify Canvas login portals and leave an extortion message. [...]
Ionut Ilascu
CVE-2026-23435 | Linux Kernel up to 6.18.19/6.19.9/7.0-rc4 PMU NMI x86_pmu_enable null pointer dereference (WID-SEC-2026-0985)
1 month 2 weeks ago
A vulnerability marked as critical has been reported in Linux Kernel up to 6.18.19/6.19.9/7.0-rc4. Impacted is the function x86_pmu_enable of the component PMU NMI Handler. Performing a manipulation results in null pointer dereference.
This vulnerability is reported as CVE-2026-23435. The attacker must have access to the local network to execute the attack. No exploit exists.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-23434 | Linux Kernel up to 7.0-rc4 mtd nand_lock deserialization (EUVD-2026-18673 / Nessus ID 311783)
1 month 2 weeks ago
A vulnerability has been found in Linux Kernel up to 7.0-rc4 and classified as critical. Affected by this vulnerability is the function nand_lock of the component mtd. Performing a manipulation results in deserialization.
This vulnerability was named CVE-2026-23434. The attack needs to be approached within the local network. There is no available exploit.
The affected component should be upgraded.
vuldb.com
CVE-2026-23431 | Linux Kernel up to 6.18.19/6.19.9/7.0-rc4 amlogic-spisg aml_spisg_probe memory leak (WID-SEC-2026-0985)
1 month 2 weeks ago
A vulnerability classified as critical was found in Linux Kernel up to 6.18.19/6.19.9/7.0-rc4. This affects the function aml_spisg_probe of the component amlogic-spisg. The manipulation results in memory leak.
This vulnerability is known as CVE-2026-23431. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-23432 | Linux Kernel up to 6.19.9/7.0-rc4 mshv mshv_map_user_memory use after free (WID-SEC-2026-0985)
1 month 2 weeks ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.19.9/7.0-rc4. This impacts the function mshv_map_user_memory of the component mshv. This manipulation causes use after free.
This vulnerability is handled as CVE-2026-23432. The attack can only be done within the local network. There is not any exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-23433 | Linux Kernel up to 6.19.9/7.0-rc4 arm_mpam mpam_restore_mbwu_state null pointer dereference (WID-SEC-2026-0985)
1 month 2 weeks ago
A vulnerability was found in Linux Kernel up to 6.19.9/7.0-rc4. It has been classified as critical. This affects the function mpam_restore_mbwu_state of the component arm_mpam. The manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2026-23433. The attack can only be performed from a local environment. No exploit is available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-23428 | Linux Kernel up to 7.0-rc4 ksmbd smb2_get_ksmbd_tcon use after free (EUVD-2026-18661 / Nessus ID 304959)
1 month 2 weeks ago
A vulnerability described as critical has been identified in Linux Kernel up to 7.0-rc4. The affected element is the function smb2_get_ksmbd_tcon of the component ksmbd. Executing a manipulation can lead to use after free.
This vulnerability appears as CVE-2026-23428. The physical device can be targeted for the attack. There is no available exploit.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-23430 | Linux Kernel up to 6.18.19/6.19.9/7.0-rc4 vmwgfx memory leak (Nessus ID 304993 / WID-SEC-2026-0985)
1 month 2 weeks ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.18.19/6.19.9/7.0-rc4. The impacted element is an unknown function of the component vmwgfx. The manipulation leads to memory leak.
This vulnerability is traded as CVE-2026-23430. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-23429 | Linux Kernel up to 6.18.19/6.19.9/7.0-rc4 sva iommu_sva_unbind_device null pointer dereference (WID-SEC-2026-0985)
1 month 2 weeks ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.18.19/6.19.9/7.0-rc4. Affected is the function iommu_sva_unbind_device of the component sva. Such manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2026-23429. The attack can only be initiated within the local network. No exploit exists.
You should upgrade the affected component.
vuldb.com
CVE-2026-23425 | Linux Kernel up to 6.18.16/6.19.6/7.0-rc1 KVM pkvm_init_features_from_host initialization (WID-SEC-2026-0985)
1 month 2 weeks ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.18.16/6.19.6/7.0-rc1. The affected element is the function pkvm_init_features_from_host of the component KVM. The manipulation leads to improper initialization.
This vulnerability is uniquely identified as CVE-2026-23425. The attack can only be initiated within the local network. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-23426 | Linux Kernel up to 7.0-rc1 logicvc logicvc_drm_config_parse memory leak (Nessus ID 304980 / WID-SEC-2026-0985)
1 month 2 weeks ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 7.0-rc1. The impacted element is the function logicvc_drm_config_parse of the component logicvc. The manipulation results in memory leak.
This vulnerability was named CVE-2026-23426. The attack needs to be approached within the local network. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-23427 | Linux Kernel up to 7.0-rc4 ksmbd parse_durable_handle_context use after free (Nessus ID 304983 / WID-SEC-2026-0985)
1 month 2 weeks ago
A vulnerability labeled as critical has been found in Linux Kernel up to 6.6.129/6.12.77/6.18.19/6.19.9/7.0-rc4. This issue affects the function parse_durable_handle_context of the component ksmbd. Such manipulation leads to use after free.
This vulnerability is documented as CVE-2026-23427. The attack requires being on the local network. There is not any exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2026-23423 | Linux Kernel up to 6.18.16/6.19.6/7.0-rc2 btrfs btrfs_uring_read_extent allocation of resources (WID-SEC-2026-0985)
1 month 2 weeks ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.18.16/6.19.6/7.0-rc2. This issue affects the function btrfs_uring_read_extent of the component btrfs. Performing a manipulation results in allocation of resources.
This vulnerability is known as CVE-2026-23423. Access to the local network is required for this attack. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com