Aggregator
Experts Sound Alarm Over “Prompt Poaching” Browser Extensions
寄生克隆 | 当 AI 助手成为蠕虫的传播加速器:Vibe Coding 时代的供应链危机
Microsoft hands Entra ID users new option for MFA
Organizations rely on MFA to enforce identity checks before granting access to systems and services. Microsoft has made external MFA generally available in Microsoft Entra ID, expanding support for third-party identity providers. Configure external MFA in Microsoft Entra ID (Source: Microsoft) External MFA supports organizations that use third-party MFA solutions to meet regulatory or business requirements, handle scenarios such as mergers and acquisitions, or maintain a consistent MFA approach within Microsoft Entra ID. Built on … More →
The post Microsoft hands Entra ID users new option for MFA appeared first on Help Net Security.
【安全预警】AI模型网关LiteLLM遭PyPI供应链投毒
CVE-2026-4442 | Google Chrome up to 146.0.7680.75 CSS heap-based overflow (ID 484751 / Nessus ID 303234)
CVE-2026-4443 | Google Chrome up to 146.0.7680.75 WebAudio heap-based overflow (ID 485292 / Nessus ID 303234)
CVE-2026-4444 | Google Chrome up to 146.0.7680.75 WebRTC stack-based overflow (ID 486349 / Nessus ID 303234)
CVE-2026-4445 | Google Chrome up to 146.0.7680.75 WebRTC use after free (ID 486421 / Nessus ID 303234)
CVE-2026-4446 | Google Chrome up to 146.0.7680.75 WebRTC use after free (ID 486421 / Nessus ID 303234)
CVE-2026-4447 | Google Chrome up to 146.0.7680.75 V8 sandbox (ID 486657 / Nessus ID 303234)
CVE-2026-4448 | Google Chrome up to 146.0.7680.75 ANGLE heap-based overflow (ID 486972 / Nessus ID 303234)
CVE-2026-4450 | Google Chrome up to 146.0.7680.75 V8 out-of-bounds write (ID 487746 / Nessus ID 303234)
CVE-2026-4449 | Google Chrome up to 146.0.7680.75 Blink use after free (ID 487117 / Nessus ID 303234)
CVE-2026-4451 | Google Chrome up to 146.0.7680.75 Navigation sandbox (ID 487768 / Nessus ID 303234)
CVE-2026-4452 | Google Chrome up to 146.0.7680.75 on Windows ANGLE external control of assumed-immutable web parameter (ID 487977 / Nessus ID 303234)
TeamPCP Hits Trivy, Checkmarx, and LiteLLM in Credential Theft Campaign
«Платите пять миллионов или мы все сольем». Сервис для анимешников Crunchyroll сделал свой выбор
国安法实施细则授予警方获取手机和计算机密码的权力
Kamasers Analysis: A Multi-Vector DDoS Botnet Targeting Organizations Worldwide
DDoS attacks are no longer only an infrastructure problem. They can quickly turn into a business issue, affecting uptime, customer experience, and operational stability. Kamasers is a strong example of this new reality, with broad attack capabilities and resilient command-and-control mechanisms that allow it to remain active under pressure. Let’s explore the Kamasers botnet through […]
The post Kamasers Analysis: A Multi-Vector DDoS Botnet Targeting Organizations Worldwide appeared first on ANY.RUN's Cybersecurity Blog.