Aggregator
Submit #774218: Enter Software Iperius Backup <= 8.7.2 Authentication Bypass by Capture-replay [Accepted]
Submit #774209: Enter Software Iperius Backup <= 8.7.2 Creation of Temporary File in Directory with Insecure Permission [Accepted]
Vorlon adds forensics and response to secure AI agents
Vorlon has unveiled AI Agent Flight Recorder and AI Agent Action Center, adding forensics and coordinated response to secure enterprise agentic ecosystems and close a key security gap. The agentic ecosystem contains SaaS applications, AI agents, API integrations, non-human identities, and the sensitive data flows connecting them. It’s become the fastest-growing attack surface in the enterprise, moves at machine speed, and most organizations lack adequate supervision. The Agentic Ecosystem Security Gap: 2026 CISO Report, a … More →
The post Vorlon adds forensics and response to secure AI agents appeared first on Help Net Security.
CVE-2026-32888 | opensourcepos Open Source Point of Sale up to 3.4.1 Custom Attributes search_custom sql injection (GHSA-hmjv-wm3j-pfhw)
CVE-2026-32889 | tinytag up to 2.2.0 _parse_synced_lyrics infinite loop (GHSA-f4rq-2259-hv29)
CVE-2026-31869 | Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest allowed_names information disclosure (GHSA-5f9h-vp7v-7vq5)
CVE-2026-30891 | Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest.1 User Actions Endpoint information disclosure (GHSA-ww5f-24g5-c33g)
CVE-2026-31805 | Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest.1 post_id[] authorization (GHSA-fgxm-prjv-g823)
CVE-2026-32890 | openVESSL Anchorr up to 1.4.1 /api/config cross site scripting (GHSA-qpmq-6wjc-w28q)
CVE-2026-32114 | Discourse up to 2026.1.1/2026.2.0/2026.3.0-latest authorization (GHSA-3cvr-pm4c-hx96)
CVE-2026-32938 | SiYuan up to 3.6.0 /api/lute/html2BlockDOM path traversal (GHSA-fq2j-j8hc-8vw8)
CVE-2026-32935 | phpseclib up to 1.0.26/2.0.51/3.0.49 timing discrepancy (GHSA-94g3-g5v7-q4jg / Nessus ID 303271)
CVE-2025-11282 | Frappe LMS 2.34.x/2.35.0 Incomplete Fix CVE-2025-55006 cross site scripting (GHSA-mvxw-r9x4-3vrr / EUVD-2025-32444)
CVE-2025-10947 | Sistemas Pleno Gestão de Locação up to 2025.7.x CPF validarCpf pes_cpf authorization (EUVD-2025-31083)
«Вы нам подходите, осталось запустить этот файл». Как разработчики скачивают вирусы вместо работы
DigiCert Document Trust Manager enhancements improve document security and compliance
DigiCert has announced enhancements to its Document Trust Manager solution to help organisations combat rising document fraud, simplify global compliance, and strengthen trust in digital transactions in the age of AI. Unlike traditional signing tools that require separate regional or departmental infrastructure to meet standards such as AATL and eIDAS, Document Trust Manager centralises signing assurance management in a single solution. The surge in generative AI and digital transformation has dramatically increased the … More →
The post DigiCert Document Trust Manager enhancements improve document security and compliance appeared first on Help Net Security.