Aggregator
CVE-2026-6051 | IBM Db2 up to 11.5.9/12.1.4 resource consumption (WID-SEC-2026-1646)
CVE-2026-49975 | Apache HTTP Server mod_http2 modules/http2/h2_util.c req_add_header HTTP/2 Bomb denial of service (EUVD-2026-35105 / Nessus ID 319609)
Microsoft patches Exchange Server zero-day exploited in attacks
AISLE Snapshot keeps source code under enterprise control during vulnerability scanning
AISLE has introduced AISLE Snapshot, a new offering that gives regulated and security-sensitive enterprises access to frontier-class vulnerability detection inside their own environments, at a fraction of the cost, with source code and security data that never leave their control. Organizations are under increasing pressure to secure growing codebases against a rapidly expanding vulnerability landscape. Reported CVEs are up 42.5% year-over-year through mid-2026, and attackers are leveraging AI to accelerate discovery and exploitation at the … More →
The post AISLE Snapshot keeps source code under enterprise control during vulnerability scanning appeared first on Help Net Security.
Живой перевод в наушниках, умные диалоги и 70 языков. Google обновила голосовую модель Gemini 2.5 Flash Native Audio
Russian APTs Still Exploiting Patched WinRAR Flaw CVE-2025-8088
G.O.S.S.I.P 阅读推荐 2026-06-10 “坏”内存攻击!
Drata brings visibility, control and auditability to enterprise AI agents
Drata has introduced AI Agent Governance, a new security category focused on managing the risks and oversight requirements of AI agents, while extending its trust platform to support enterprise adoption of autonomous AI systems. While McKinsey finds 57% of business leaders cite governance friction as the top blocker to deploying more AI, this move is a strategic shift grounded in platform trends Drata is uniquely positioned to observe. Over the last nine months, the company … More →
The post Drata brings visibility, control and auditability to enterprise AI agents appeared first on Help Net Security.
PacketPatch:面向基于字节特征的加密流量分类的对抗性数据包实用化生成与部署
CVE-2026-27671 | SAP NetWeaver and ABAP Platform up to KRNL64UC 7.22 RFC Protocol Validator stack-based overflow (CNNVD-202606-2582)
CVE-2026-24315 | SAP Fiori up to 816 path traversal (CNNVD-202606-2583)
CVE-2026-40409 | Microsoft Windows up to Server 2025 Universal Disk Format File System Driver numeric truncation error (CNNVD-202606-2584)
CVE-2026-40404 | Microsoft Windows up to Server 2025 Universal Disk Format File System Driver heap-based overflow (CNNVD-202606-2585)
Хватит стоять без дела. General Motors превратит четверть миллиона автомобилей в мини-электростанции
New Intel 471 assessment helps organizations measure CTI program maturity
Intel 471 has announced its new Cyber Threat Intelligence (CTI) Maturity Pulse Check, a free, lightweight self-assessment for practitioners based on the Cyber Threat Intelligence Capability Maturity Model (CTI-CMM v1.3). The CTI Maturity Pulse Check offers a quick, structured way for organizations to reflect on their CTI program’s current capabilities, highlight areas that warrant a closer look and help security teams prepare for a more thorough assessment using the official CTI-CMM tool. “The CTI-CMM is … More →
The post New Intel 471 assessment helps organizations measure CTI program maturity appeared first on Help Net Security.
CVE-2026-46281 | Linux Kernel up to 6.18.26/7.0.3/7.1-rc1 vmalloc vrealloc_node_align out-of-bounds (Nessus ID 320347)
CVE-2026-46284 | Linux Kernel up to 6.18.26/7.0.3 mm hugetlb_add_param denial of service (Nessus ID 320348)
CVE-2026-8078 | Checkmk up to 2.2.0/2.3.0p47/2.4.0p30/2.5.0p4 Activate Changes Page cross site scripting (EUVD-2026-35052 / Nessus ID 320346)
Critical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520)
Ivanti has patched two critical vulnerabilities (CVE-2026-10520 and CVE-2026-10523) in Ivanti Sentry and has urged customers to implement the fix right away. Though the vulnerabilities are not known to be actively exploited, security researchers have already released technical details about the former, which may be used by attackers to craft a working exploit. About Ivanty Sentry and the vulnerabilities Ivanti Sentry is a security gateway that acts as a gatekeeper between mobile devices outside of … More →
The post Critical Ivanti Sentry flaw allows root-level remote code execution (CVE-2026-10520) appeared first on Help Net Security.