Aggregator
Кусачки и четыре сотрудника: T-Mobile отвоевала сети у китайских хакеров Salt Typhoon
【安全圈】Elementor Pro曝严重漏洞:未授权即可远程执行代码
【安全圈】CISA警告多项0day遭野外利用:涵盖macOS与微软组件
【安全圈】40款火狐扩展暗藏黑手:伪装Web3钱包洗劫加密资产
ICS Operators Warned of AI-Driven Attacks on Siemens PLCs
【安全圈】Elementor Pro曝严重漏洞:未授权即可远程执行代码
【安全圈】CISA警告多项0day遭野外利用:涵盖macOS与微软组件
【安全圈】40款火狐扩展暗藏黑手:伪装Web3钱包洗劫加密资产
Этот язык программирования быстро становится одним из самых популярных в мире
Guild Group’s Mohammad Arif on the Security Risks of Enterprise AI
Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services
Red Hat has disclosed CVE-2026-66794, an important-severity server-side request forgery (SSRF) vulnerability in the cluster-proxy-addon component of the Multicluster Engine for Kubernetes. This flaw has a CVSS v3.1 score of 9.3. It could allow an unauthenticated remote attacker to use a publicly accessible route to access otherwise isolated services across managed clusters. Published on August […]
The post Red Hat Kubernetes Flaw Lets Unauthenticated Attackers Access Internal Cluster Services appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Fake Gemini installer delivers Vidar infostealer via Google Colab lure
A malicious executable masquerading as a Google Gemini installer was used to deliver the Vidar infostealer on a company network in the EMEA region, according to Darktrace researchers who investigated the incident. “During the initial analysis, it was noted that the top search result for the suspicious filename associated pointed to a file hosted on Google Colab, a cloud-based Jupyter notebook platform, commonly used by developers, researchers, and data scientists to run code and machine … More →
The post Fake Gemini installer delivers Vidar infostealer via Google Colab lure appeared first on Help Net Security.
分享一个智能体安全的文章
美国就算力期货交易公开征求意见
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud
Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE
Splunk has released a security hardening update addressing 17 vulnerabilities across several applications and add-ons, including a critical remote code execution (RCE) flaw in the Splunk MCP Server app. The vulnerabilities encompass deserialization, access control, server-side request forgery (SSRF), denial-of-service, certificate validation, and information disclosure. Tracked as SVD-2026-0808 and published on August 19, 2026, the […]
The post Splunk Fixes 17 Vulnerabilities Including Critical MCP Server RCE appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud
Threat actors are increasingly abusing Microsoft 365 identity sessions rather than deploying malware, as shown in a cloud-only business email compromise (BEC). The attackers used an adversary-in-the-middle (AiTM) phishing kit to capture an authenticated Microsoft 365 session token, bypass multi-factor authentication, and quietly redirect vendor payments to attacker-controlled bank accounts. The lure contained a “View […]
The post Hackers Create Hidden Microsoft 365 Inbox Rules to Conceal Vendor Payment Fraud appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.