Aggregator
Hackers poison arrayref Rust crate to push infostealer malware
N-able Bug Exposes Password Vault Master Keys
NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs
Ошибка 0xC0000005. Так выглядит сбой, который остановил Defender на компьютерах с Windows
Money and Mindset: The Two Biggest Roadblocks to Cyber Policing
ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit, and More
Галлюцинации ИИ добрались до военной авиации: выдуманные данные могут попасть в проект боевого самолёта
CRLF-Powered Desync Lets Attackers Poison CDN Cache and Serve XSS to Live Users
A limited CRLF injection flaw can be escalated into a severe HTTP desynchronization attack, poisoning CDN caches and delivering XSS payloads to users on legitimate websites. The attack, called CRLF-Powered Desync, begins when an application incorrectly handles encoded carriage return and line feed characters, commonly represented as %0d%0a. These characters mark new lines in HTTP messages. […]
The post CRLF-Powered Desync Lets Attackers Poison CDN Cache and Serve XSS to Live Users appeared first on Cyber Security News.
From all-or-nothing to task-based OAuth consent
AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
AWS Shows How to Stop a Hijacked AI Agent From Reading Data the User Cannot Access
Enterprises are racing to deploy AI agents that pull from databases, document repositories, SaaS platforms, and internal knowledge bases to automate workflows. But a quiet risk lurks beneath the convenience: most agents have no built-in awareness of who is actually asking the question, which means a compromised or manipulated agent could hand over data the […]
The post AWS Shows How to Stop a Hijacked AI Agent From Reading Data the User Cannot Access appeared first on Cyber Security News.
Microsoft Defender Driver Can Be Weaponized to Disable EDR and AV From Windows Kernel
Microsoft Defender’s legitimate Boot-Time Removal (BTR.sys) driver can be repurposed to perform powerful kernel-level file and registry operations, potentially enabling attackers with administrative privileges to neutralize endpoint security protections. The Check Point research does not describe a conventional vulnerability or memory-corruption flaw; instead, it exposes how a trusted, Microsoft-signed remediation component can become a Living-off-the-Land […]
The post Microsoft Defender Driver Can Be Weaponized to Disable EDR and AV From Windows Kernel appeared first on Cyber Security News.
IBM решила проблему квантовых компьютеров не кубитами, а холодильником
Developer Sought on a Breach Forum to Build a Mexican KYC Bot Capturing ID Scans and Face Biometrics
Popular Rust Packages With 244M Downloads Compromised to Run Malware
A major supply chain attack targeting the Rust ecosystem, in which two widely used crates, arrayref and append-only-vec, were hijacked to silently deliver malware the moment developers compiled their projects. Together, the two packages account for hundreds of millions of downloads, making this one of the largest Rust crate compromises ever recorded by download volume. […]
The post Popular Rust Packages With 244M Downloads Compromised to Run Malware appeared first on Cyber Security News.
Касперский обнаружил новый троянец BusySnake — бьёт по Windows, Linux и macOS
Холоднее космоса: IBM строит модульный квантовый компьютер из гигантских холодильников
SecWiki News 2026-08-20 Review
更多最新文章,请访问SecWiki