Aggregator
CVE-2026-2343 | PeproDev PeproDev Ultimate Invoice Plugin up to 2.2.5 on WordPress ZIP File Parser information disclosure (EUVD-2026-15188)
CVE-2026-26306 | OM Digital Solutions OM Workspace up to 2.4 Installer uncontrolled search path (EUVD-2026-15190)
CVE-2026-33253 | Sanyo Denki Sanups Software Standalone/Sanups Software Windows Service unquoted search path (EUVD-2026-15192)
CVE-2026-32326 | Sharp Speed Wi-Fi 5G X01 missing authentication (EUVD-2026-15194)
Virtual machines, virtually everywhere – and with real security gaps
Linux pwn 探索篇
Karpathy紧急发声:日下载340万次的LiteLLM被投毒,黑客一个bug意外暴露危机
Polaris-Obfuscator中BogusControlFlow简要分析 反混淆
某智慧校园系统代码审计
睡前敲了一下upgrade,醒来我的“龙虾”废了
Трамп за своих, Брюссель за порядок. Как выбор сериала на вечер стал вопросом мировой геополитики
Operation Henhouse Nets Over 500 Arrests in UK Fraud Crackdown
ClawHub Vulnerability Let Attackers Manipulate Rankings to Become the #1 Skill
Security research team has uncovered a critical vulnerability in ClawHub, the public skills registry for the OpenClaw agentic ecosystem. This flaw allowed attackers to artificially inflate the download counts of malicious skills, thereby bypassing security checks and manipulating search rankings. By pushing a compromised skill to the top, threat actors could orchestrate massive supply-chain attacks […]
The post ClawHub Vulnerability Let Attackers Manipulate Rankings to Become the #1 Skill appeared first on Cyber Security News.
Google Authenticator’s Hidden Passkey Architecture Could Open New Passwordless Attack Paths
Passwordless authentication was supposed to mark the end of account takeovers. Designed to replace traditional passwords with cryptographic keys tied to physical devices, it promised a future where stolen credentials could no longer unlock user accounts. But a close examination of how Google has actually built its passkey ecosystem reveals something far more complex than […]
The post Google Authenticator’s Hidden Passkey Architecture Could Open New Passwordless Attack Paths appeared first on Cyber Security News.
Робот написал «I'm Good» — и немедленно разнёс ресторан. Люди так тоже делают, но их хотя бы можно остановить без смартфона
Anthropic trims action approval loop, lets Claude Code make the call
Auto mode is a new permissions feature in the Claude Code system that allows the AI to make approval decisions on a user’s behalf while safeguards review actions before execution. The feature is available on Team plans and requires administrator approval before use, with support for Enterprise and API users expected soon. It runs on newer models such as Claude Sonnet 4.6 and Claude Opus 4.6, and excludes older versions and third party platforms. By … More →
The post Anthropic trims action approval loop, lets Claude Code make the call appeared first on Help Net Security.