Aggregator
SecWiki News 2026-06-11 Review
更多最新文章,请访问SecWiki
CVE-2026-48855 | Erlang OTP ssh_sftpd.erl information disclosure (GHSA-pv7g-pjrq-x2fh / Nessus ID 320494)
CVE-2026-48856 | Erlang OTP httpc_response.erl host redirect (GHSA-m75x-4vwg-ggjh / Nessus ID 320495)
CVE-2026-53689 | sahlberg libnfs up to up to 6.0.2 NFS lib/libnfs-zdr.c libnfs_zdr_string improper validation of specified quantity in input (Nessus ID 320496)
CVE-2026-48858 | Erlang OTP up to 6.x PASV ftp_internal.erl server-side request forgery (GHSA-24cv-hwgr-37fq / Nessus ID 320497)
Authorities dismantle 'AudiA6' ransomware crypto-laundering service
GitHub to Automate Disable npm Script Installs to Block Supply Chain Attacks
GitHub has announced a major security-focused update to the Node Package Manager (npm), introducing breaking changes in the upcoming npm v12 release to reduce software supply chain attack risks significantly. The update, expected in July 2026, will turn off automatic execution of installation scripts by default, one of the most commonly abused mechanisms in malicious […]
The post GitHub to Automate Disable npm Script Installs to Block Supply Chain Attacks appeared first on Cyber Security News.
科技巨头大举借债
Claude Mythos Turning N-Days Into N-Hours With Rapid Working Exploit Creation
A new study has revealed that advanced large language models (LLMs), particularly Anthropic’s Claude Mythos Preview, are dramatically accelerating the development of N-day exploits, reducing timelines from weeks to just hours and significantly increasing risk during the patch gap. Unlike zero-day vulnerabilities, N-day vulnerabilities are publicly disclosed flaws that remain unpatched across many systems. These […]
The post Claude Mythos Turning N-Days Into N-Hours With Rapid Working Exploit Creation appeared first on Cyber Security News.
CISA Warns of Check Point Security Gateway Vulnerability Actively Exploited in Ransomware Attacks
CISA has added a critical vulnerability in Check Point Security Gateway to its Known Exploited Vulnerabilities (KEV) catalog, warning that threat actors are actively exploiting the flaw in ransomware campaigns. The vulnerability, tracked as CVE-2026-50751, allows unauthenticated remote attackers to bypass user authentication and establish unauthorized VPN connections, posing severe risks to enterprise networks worldwide. […]
The post CISA Warns of Check Point Security Gateway Vulnerability Actively Exploited in Ransomware Attacks appeared first on Cyber Security News.
Hackers Use Weaponized DMG Files to Target macOS Users With Infostealer Malware
Hackers are using weaponized DMG files to target macOS users with infostealer malware, exploiting the long-standing myth that Apple devices are safe from cyber threats. These attacks rely on fake software installers disguised as legitimate apps, tricking users into handing over access without raising any alarm. The speed of these campaigns has made them one […]
The post Hackers Use Weaponized DMG Files to Target macOS Users With Infostealer Malware appeared first on Cyber Security News.