Vulnerability News
前往频道在 Telegram
Every day new posts about vulnerabilities and cybersecurity news. Get the latest news about the cyberspace! Group: @VulnerabilityNewsGroup
显示更多5 223
订阅者
+324 小时
+237 天
+9430 天
数据加载中...
相似频道
标签云
进出提及
---
---
---
---
---
---
吸引订阅者
八月 '26
八月 '26
+138
在0个频道中
七月 '26
+185
在0个频道中
Get PRO
六月 '26
+156
在0个频道中
Get PRO
五月 '26
+204
在0个频道中
Get PRO
四月 '26
+187
在0个频道中
Get PRO
三月 '26
+254
在0个频道中
Get PRO
二月 '26
+116
在0个频道中
Get PRO
一月 '26
+166
在0个频道中
Get PRO
十二月 '25
+134
在0个频道中
Get PRO
十一月 '25
+139
在0个频道中
Get PRO
十月 '25
+8
在0个频道中
Get PRO
九月 '25
+12
在0个频道中
Get PRO
八月 '25
+13
在0个频道中
Get PRO
七月 '25
+11
在0个频道中
Get PRO
六月 '25
+12
在0个频道中
Get PRO
五月 '25
+18
在1个频道中
Get PRO
四月 '25
+14
在0个频道中
Get PRO
三月 '25
+21
在0个频道中
Get PRO
二月 '25
+17
在0个频道中
Get PRO
一月 '25
+15
在1个频道中
Get PRO
十二月 '24
+262
在1个频道中
Get PRO
十一月 '24
+206
在1个频道中
Get PRO
十月 '24
+166
在0个频道中
Get PRO
九月 '24
+146
在0个频道中
Get PRO
八月 '24
+137
在0个频道中
Get PRO
七月 '24
+96
在1个频道中
Get PRO
六月 '24
+91
在0个频道中
Get PRO
五月 '24
+95
在0个频道中
Get PRO
四月 '24
+104
在0个频道中
Get PRO
三月 '24
+149
在0个频道中
Get PRO
二月 '24
+279
在0个频道中
Get PRO
一月 '24
+395
在0个频道中
Get PRO
十二月 '23
+327
在0个频道中
Get PRO
十一月 '23
+38
在0个频道中
Get PRO
十月 '23
+32
在0个频道中
Get PRO
九月 '23
+47
在0个频道中
Get PRO
八月 '23
+53
在0个频道中
Get PRO
七月 '23
+51
在0个频道中
Get PRO
六月 '23
+42
在0个频道中
Get PRO
五月 '23
+43
在0个频道中
Get PRO
四月 '23
+67
在0个频道中
Get PRO
三月 '23
+65
在0个频道中
Get PRO
二月 '23
+45
在0个频道中
Get PRO
一月 '23
+67
在0个频道中
Get PRO
十二月 '22
+62
在0个频道中
Get PRO
十一月 '22
+71
在0个频道中
Get PRO
十月 '22
+70
在0个频道中
Get PRO
九月 '22
+55
在0个频道中
Get PRO
八月 '22
+44
在0个频道中
Get PRO
七月 '22
+54
在0个频道中
Get PRO
六月 '22
+78
在0个频道中
Get PRO
五月 '22
+46
在0个频道中
Get PRO
四月 '22
+77
在0个频道中
Get PRO
三月 '22
+105
在0个频道中
Get PRO
二月 '22
+48
在0个频道中
Get PRO
一月 '22
+61
在0个频道中
Get PRO
十二月 '21
+99
在0个频道中
Get PRO
十一月 '21
+68
在0个频道中
Get PRO
十月 '21
+170
在0个频道中
Get PRO
九月 '21
+72
在0个频道中
Get PRO
八月 '21
+104
在0个频道中
Get PRO
七月 '21
+72
在0个频道中
Get PRO
六月 '21
+292
在0个频道中
Get PRO
五月 '21
+1 344
在0个频道中
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 29 八月 | 0 | |||
| 28 八月 | +4 | |||
| 27 八月 | +4 | |||
| 26 八月 | +7 | |||
| 25 八月 | +6 | |||
| 24 八月 | +8 | |||
| 23 八月 | +3 | |||
| 22 八月 | +3 | |||
| 21 八月 | +5 | |||
| 20 八月 | +6 | |||
| 19 八月 | +3 | |||
| 18 八月 | +2 | |||
| 17 八月 | +1 | |||
| 16 八月 | +3 | |||
| 15 八月 | +5 | |||
| 14 八月 | +2 | |||
| 13 八月 | +5 | |||
| 12 八月 | +5 | |||
| 11 八月 | +9 | |||
| 10 八月 | +5 | |||
| 09 八月 | +3 | |||
| 08 八月 | +6 | |||
| 07 八月 | +7 | |||
| 06 八月 | +3 | |||
| 05 八月 | +6 | |||
| 04 八月 | +7 | |||
| 03 八月 | +6 | |||
| 02 八月 | +4 | |||
| 01 八月 | +10 |
频道帖子
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities.
The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active
https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
| 2 | ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines.
The vulnerability, tracked as CVE-2023-49105 (CVSS score: 9.8), is a case of
https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html | 40 |
| 3 | Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks.
Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting.
"This new privacy standard works in tandem
https://thehackernews.com/2026/08/android-17-adds-os-wide-ech-to-hide.html | 34 |
| 4 | Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening.
"This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's
https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html | 25 |
| 5 | Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands.
The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment
https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.html | 22 |
| 6 | PaperCut Releases Emergency Patch for Exploited Zero-Day
A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.
The post PaperCut Releases Emergency Patch for Exploited Zero-Day appeared first on SecurityWeek.
https://www.securityweek.com/papercut-releases-emergency-patch-for-exploited-zero-day/ | 20 |
| 7 | Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says
New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.
The post Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says appeared first on SecurityWeek.
https://www.securityweek.com/think-youve-eliminated-chinese-ai-check-the-models-lineage-cisco-says/ | 12 |
| 8 | Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge
Nearly 130 tech and cybersecurity companies back a collective call to boost cyber defenses as AI-enabled attacks grow more sophisticated.
The post Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge appeared first on SecurityWeek.
https://www.securityweek.com/tech-cybersecurity-giants-unite-behind-openai-led-cyber-defense-pledge/ | 12 |
| 9 | OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems
CISA has added the exploited flaw, CVE-2026-53362, to its KEV catalog, alongside a JFrog vulnerability exploited by OpenAI agents.
The post OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own Systems appeared first on SecurityWeek.
https://www.securityweek.com/openai-agents-exploited-linux-kernel-flaw-on-companys-own-systems/ | 9 |
| 10 | ATF Confirms Cyber Incident After Ransomware Group Claims Attack
The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.
The post ATF Confirms Cyber Incident After Ransomware Group Claims Attack appeared first on SecurityWeek.
https://www.securityweek.com/atf-confirms-cyber-incident-after-ransomware-group-claims-attack/ | 8 |
| 11 | In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions
Noteworthy stories that might have slipped under the radar: Manchester Airports Group cyberattack, Carhartt breach data was partly fake, U.S. Bank responds to ransomware gang’s claims.
The post In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions appeared first on SecurityWeek.
https://www.securityweek.com/in-other-news-log4j-rce-scare-minimus-shutdown-iranian-hacker-sanctions/ | 8 |
| 12 | Windows 11 KB5120998 update released with 35 changes and fixes
Microsoft released the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2, which comes with 35 changes, including improvements to the Start menu, taskbar, and Windows search. [...]
https://www.bleepingcomputer.com/news/security/windows-11-kb5120998-update-released-with-35-changes-and-fixes/ | 8 |
| 13 | ServiceNow warns of three max severity security vulnerabilities
ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection, and privilege escalation attacks. [...]
https://www.bleepingcomputer.com/news/security/servicenow-warns-of-three-max-severity-security-vulnerabilities/ | 8 |
| 14 | Toy-making giant Hasbro disclose data breach affecting employees
Hasbro, one of the world's largest toy and game companies, has disclosed that attackers have accessed the personal and financial information of an undisclosed number of employees. [...]
https://www.bleepingcomputer.com/news/security/toy-making-giant-hasbro-disclose-data-breach-affecting-employees/ | 8 |
| 15 | Over 8,300 Gitea servers vulnerable to code execution attacks
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. [...]
https://www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vulnerable-to-code-execution-attacks/ | 10 |
| 16 | AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace. Action1 explains why defenders increasingly need to correlate multiple intelligence sources and turn vulnerability data into faster remediation. [...]
https://www.bleepingcomputer.com/news/security/ai-is-accelerating-vulnerability-discovery-can-defenders-keep-up/ | 12 |
| 17 | 68-year-old imprisoned after making $1.3 million by pirating IPTV services
A 68-year-old has been sentenced in the U.K. to more than six years in prison for operating an illegal IPTV (Internet Protocol Television) service that generated £980,812 ($1.3 million) over three years. [...]
https://www.bleepingcomputer.com/news/security/68-year-old-imprisoned-after-making-13-million-by-pirating-iptv-services/ | 12 |
| 18 | GiveWP WordPress donation plugin flaw lets hackers execute server commands
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]
https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-plugin-flaw-lets-hackers-execute-server-commands/ | 12 |
| 19 | PaperCut releases second emergency patch for exploited flaws
PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. [...]
https://www.bleepingcomputer.com/news/security/papercut-releases-second-emergency-patch-for-exploited-flaws/ | 16 |
| 20 | McKesson discloses breach after ShinyHunters claims patient data theft
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]
https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/ | 25 |
