Aggregator
CVE-2026-25187 | Microsoft Windows up to Server 2025 Winlogon link following
CVE-2026-25188 | Microsoft Windows up to Server 2025 Telephony Service heap-based overflow (Nessus ID 301776)
CVE-2026-25189 | Microsoft Windows 10 21H2/10 22H2/10 1809/Server 2019/Server 2022 DWM Core Library use after free
AI coding agents keep repeating decade-old security mistakes
Coding agents are now writing production features on real development teams, and a new report from DryRun Security shows that those agents introduce security vulnerabilities at a high rate across nearly every type of application they build. “AI coding agents can produce working software at incredible speed, but security isn’t part of their default thinking,” said James Wickett, CEO of DryRun Security. “In our usage and experience, AI coding agents often missed adding security components … More →
The post AI coding agents keep repeating decade-old security mistakes appeared first on Help Net Security.
CVE-2026-26311 | envoyproxy envoy up to 1.34.12/1.35.8/1.36.4/1.37.0 Filter decodeData use after free (GHSA-84xm-r438-86px / WID-SEC-2026-0704)
CVE-2026-26330 | envoyproxy envoy up to 1.34.12/1.35.8/1.36.4/1.37.0 apply_on_stream_done use after free (GHSA-c23c-rp3m-vpg3 / WID-SEC-2026-0704)
CVE-2026-26310 | envoy up to 1.34.12/1.35.8/1.36.4/1.37.0 getAddressWithPort denial of service (GHSA-3cw6-2j68-868p / WID-SEC-2026-0704)
CVE-2026-26308 | envoyproxy envoy up to 1.34.12/1.35.8/1.36.4/1.37.0 Role-Based Access Control authorization (GHSA-ghc4-35x6-crw5 / WID-SEC-2026-0704)
CVE-2026-26309 | envoyproxy envoy up to 1.34.12/1.35.8/1.36.4/1.37.0 escapeString off-by-one (GHSA-56cj-wgg3-x943 / WID-SEC-2026-0704)
CVE-2026-20118 | Cisco IOS XR up to 25.1.2 Egress Packet Network Interface Aligner cleanup (cisco-sa-xrncs-epni-int-dos-TWMffUsN / EUVD-2026-11224)
CVE-2026-20040 | Cisco IOS XR up to 25.4.1 CLI os command injection (cisco-sa-iosxr-privesc-bF8D5U4W / EUVD-2026-11214)
CVE-2026-20074 | Cisco IOS XR up to 25.2.15 improper validation of specified type of input (cisco-sa-isis-dos-kDMxpSzK / EUVD-2026-11219)
莫斯科居民遭遇移动网络中断事故
OODA循环、库珀色码与"套话术"——情报人员每天都在用的12个日常生活技巧
CVE-2025-14558 | FreeBSD rtsol/rtsold input validation (EUVD-2025-208403 / EDB-52463)
Капча с двойным дном. Как обычное подтверждение, что вы не робот, превращается в установку шпиона
佛教是唯一一个信徒人数下降的主要宗教
Passwords, MFA, and why neither is enough
Passwords weren’t enough, so we added MFA. Now MFA isn’t enough either. In this Help Net Security video, Karlo Zatylny, CTO/CISO at Portnox, walks through why each layer of identity security has failed and what comes next. SMS codes can be intercepted through SIM swapping. Authenticator apps are vulnerable to replay attacks and push bombing. And even when MFA works correctly, session hijacking can let attackers impersonate a user after authentication is complete. The solution … More →
The post Passwords, MFA, and why neither is enough appeared first on Help Net Security.