Aggregator
Apache Shiro 反序列化与权限绕过漏洞分析及利用
第三届“长城杯”网数智安全大赛(防护赛)总决赛Java题部分
[原创]trx ctf 2026 house of fishing
针对RSA攻击的总结
Hacker Claims to Deface Telcel Business-Tracking Platform and Alter Admin Accounts
Hackers Use Tax Phishing Emails to Deploy In-Memory Malware on Windows Systems
Hackers are using fake tax notification emails to trick Windows users into downloading dangerous multi-stage malware that runs entirely in memory, leaving almost no trace behind. The campaign, tracked as Operation TaxShadow, has been active since at least May 20, 2026, targeting individuals by impersonating official Indian government tax authorities. The emails are crafted to create […]
The post Hackers Use Tax Phishing Emails to Deploy In-Memory Malware on Windows Systems appeared first on Cyber Security News.
ServiceNow Confirms Vulnerability Allowing Unauthorized Access to Customer Instance Tables
ServiceNow has confirmed a security vulnerability that could allow unauthorized actors to query customer instance tables, raising concerns about potential data exposure across enterprise environments. The issue, disclosed through threat intelligence channels, involves improper access controls that may enable attackers to execute queries against backend instance tables without proper authentication. ServiceNow, widely used for IT […]
The post ServiceNow Confirms Vulnerability Allowing Unauthorized Access to Customer Instance Tables appeared first on Cyber Security News.
Вселенная прячет новую физику уже миллиарды лет. ИИ подобрался к её открытию вплотную... и струсил
Hackers Infect npm Package dbmux With Malware to Fully Compromise Developer Systems
A malicious package targeting software developers has been discovered on npm, one of the most widely used package registries in the world. The package, named dbmux, was found to contain hidden malware capable of giving attackers complete control over any developer’s system that had it installed or running. The incident was disclosed on June 9, […]
The post Hackers Infect npm Package dbmux With Malware to Fully Compromise Developer Systems appeared first on Cyber Security News.
OpenClaw AI Agent Leaks Sensitive Credentials in New Phishing Attack Simulation
AI agents are becoming a core part of how companies manage their inboxes, triaging messages, pulling up files, and even replying to emails on behalf of employees. What researchers have now confirmed is that these agents can be tricked just like humans, and sometimes more easily. A new phishing simulation has shown that an AI […]
The post OpenClaw AI Agent Leaks Sensitive Credentials in New Phishing Attack Simulation appeared first on Cyber Security News.
以前研究工具,后来研究工作
Hacker Claims to Sell 533GB of French and European Healthcare Data and Access
Цена взлома российского бизнеса упала до $20. Как работает новый PowerLoader
Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet
H1 Data Breach: 2M+ Medical Professional Records Leaked
人类习惯于左转逆时针行走
China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance
CISA directive orders agencies to prioritize vulnerability patching in a new way
A vulnerability that meets all four criteria would need to be fixed within three days, for instance.
The post CISA directive orders agencies to prioritize vulnerability patching in a new way appeared first on CyberScoop.