Aggregator
Cisco SD-WAN Has a New Root-Level Problem, and There’s No Fix Yet
Человечество обогнало эволюцию на 88 миллионов лет. И сделало это без единой новой мутации. Как?
Reaper macOS Infostealer Abuses Script Editor to Steal Crypto and Passwords
The Good, the Bad and the Ugly in Cybersecurity – Week 23
Your AI bill is out of control. Cloudflare can fix it now.
Trump AI Order Seeks Voluntary Frontier Model Testing
Самую закрытую модель Anthropic дали разведке. АНБ планирует кибероперации с помощью Claude Mythos
New Threat Cluster OP-512 Targets Microsoft IIS Servers with Custom Web Shell Framework
DragonForce
You must login to view this content
Qilin
You must login to view this content
Qilin
You must login to view this content
Qilin
You must login to view this content
Qilin
You must login to view this content
Qilin
You must login to view this content
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-28318 SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the KEV Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Anthropic зовёт мир притормозить ИИ — за неделю до подготовки к IPO на триллион
大黄蜂能利用工具解决问题
Attackers obtained encrypted password vaults from some Dashlane user accounts
Dashlane has disclosed new details about a brute-force attack that let a threat actor access some customer accounts and copy encrypted vaults. Dashlane said it found no evidence that the attackers compromised its internal systems. The company first acknowledged the incident on May 31 after users reported receiving account suspension emails and experiencing login problems. “Your account has been temporarily suspended for security reasons as someone has attempted to register a new device and didn’t … More →
The post Attackers obtained encrypted password vaults from some Dashlane user accounts appeared first on Help Net Security.