Aggregator
CVE-2026-5794 | Ercom Cryptobox up to 4.37.x/4.40.175 multiple resources with duplicate identifier
CVE-2026-6238 | GNU C Library up to 2.33 DNS Response ns_printrrf/ns_printrr/fp_nquery buffer over-read
WorldLeaks
You must login to view this content
«Может, там всё-таки была жизнь?». На Марсе нашли органику, которой там быть не должно
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
Qilin
You must login to view this content
Qilin
You must login to view this content
Qilin
You must login to view this content
Qilin
You must login to view this content
Qilin
You must login to view this content
RIP Denuvo. Все игры, защищенные спорной DRM-системой, теперь взломаны
How bail bond scams are using AI to target families
A call saying someone you love has been arrested and needs money ASAP can feel so real that you act before you think. Learn how bail bond scams work and what to watch for to help protect you and your family from falling for the scheme.
The post How bail bond scams are using AI to target families appeared first on Security Boulevard.
New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials
A sophisticated, memory-resident phishing campaign called BlobPhish, active since October 2024, that exploits browser Blob URL APIs to silently steal credentials from Microsoft 365 users, major U.S. banks, and financial platforms while remaining almost completely invisible to traditional security tools. BlobPhish is a sustained credential-phishing operation that fundamentally changes how phishing pages are delivered to […]
The post New BlobPhish Attack Leverages Browser Blob Objects to Steal Users’ Login Credentials appeared first on Cyber Security News.
Microsoft security advisory – April 2026 monthly rollup (AV26-352) - Update 3
Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer Campaign
Open is Not Costless: Reclaiming Sustainable Infrastructure
For years, the software industry treated public package registries like a law of nature. They were simply there. Immutable, invisible, and somehow outside the normal rules of cost, capacity, and responsibility.
The post Open is Not Costless: Reclaiming Sustainable Infrastructure appeared first on Security Boulevard.
Земля больше не тянет ИИ — и Meta уходит в космос. Спутники будут светить лучом на дата-центры, чтобы вы могли поболтать с чат-ботом
Critical GitHub.com and Enterprise Server RCE Vulnerability Enables Full Server Compromise
A critical remote code execution (RCE) vulnerability tracked as CVE-2026-3854 in GitHub’s internal git infrastructure that could have allowed any authenticated user to compromise backend servers, access millions of private repositories, and, in the case of GitHub Enterprise Server (GHES), achieve full server takeover. Discovered by Wiz researchers through AI-augmented reverse engineering of closed-source compiled […]
The post Critical GitHub.com and Enterprise Server RCE Vulnerability Enables Full Server Compromise appeared first on Cyber Security News.