Aggregator
GitHub to Update npm to Thwart Software Supply Chain Attacks
Scaling Security Insights: how we achieved a 10x increase in global scanning capacity
Илон Маск, Google и Nvidia хотят строить дата-центры в космосе. Физика говорит: у вас ничего не выйдет
投毒即服务:TeamPCP如何引爆AI时代供应链危机
SHEETCREEP C# RAT Abuses Google Sheets API as C2 to Target Diplomatic Organizations
A newly identified remote access trojan named SHEETCREEP is making headlines for its clever use of Google Sheets as a hidden communication channel between attackers and infected machines. This C# malware targets diplomatic organizations, using a carefully crafted lure to trick victims into executing it on their systems. The campaign represents a calculated move by […]
The post SHEETCREEP C# RAT Abuses Google Sheets API as C2 to Target Diplomatic Organizations appeared first on Cyber Security News.
CVE-2026-11406 | GL.iNet MT3000 up to 4.4.5 OpenVPN Client Import Workflow ovpnclient.sh command injection (EUVD-2026-34963)
CVE-2026-11408 | vertex-app vertex up to 2026.02.12 Log Viewer Endpoint app/model/LogMod.js req.query os command injection (EUVD-2026-34965)
CVE-2026-11411 | iAI Lab PDF AI App 4.21.0 on Android chatpdf.pro getExternalCacheDir _display_name path traversal (EUVD-2026-34966)
CVE-2026-45779 | ubccr xdmod up to 10.0.2 sql injection (GHSA-r33r-6g3c-r992)
CVE-2026-45776 | ubccr xdmod up to 11.0.2 HTTPS access control (GHSA-3hfh-m242-8rmh)
CVE-2026-45777 | ubccr xdmod up to 11.0.2 System Configuration os command injection (GHSA-29qm-7w4v-43fw)
CVE-2026-45778 | ubccr xdmod up to 11.0.2 cross site scripting (GHSA-3pv7-qvc3-h527)
CVE-2026-36785 | Tenda FH451 1.0.0.9 HTTP fromDhcpListClient page stack-based overflow
CVE-2026-7795 | holithemes Click to Chat Plugin up to 4.39 on WordPress WA Widget CCW_Shortcode::shortcode num cross site scripting (EUVD-2026-34949)
CVE-2026-10725 | CRUX Protocol::HTTP/2 up to 1.12 on Perl headers_decode HTTP/2 Bomb data amplification (EUVD-2026-34964 / Nessus ID 319610)
CVE-2026-11429 | Altium Enterprise Server/365 up to 8.1.0 Git Service path traversal (EUVD-2026-34918)
Google sues China-based scammers over Gemini AI abuse
Google has filed a lawsuit against Outsider Enterprise, a China-based cybercrime network for using AI tools, including Gemini, to build phishing websites and scam infrastructure. The company said the operation has affected “hundreds of thousands of victims,” with losses estimated in the millions of dollars. It also links the group to more than 9,000 fake websites and 1 million fraudulent URLs. “Criminals increasingly use AI to make fraud like this more convincing and harder to … More →
The post Google sues China-based scammers over Gemini AI abuse appeared first on Help Net Security.