Vulnerability News
前往频道在 Telegram
Every day new posts about vulnerabilities and cybersecurity news. Get the latest news about the cyberspace! Group: @VulnerabilityNewsGroup
显示更多5 350
订阅者
+824 小时
+497 天
+15430 天
数据加载中...
相似频道
标签云
进出提及
---
---
---
---
---
---
吸引订阅者
九月 '26
九月 '26
+139
在0个频道中
八月 '26
+157
在0个频道中
Get PRO
七月 '26
+185
在0个频道中
Get PRO
六月 '26
+156
在0个频道中
Get PRO
五月 '26
+204
在0个频道中
Get PRO
四月 '26
+187
在0个频道中
Get PRO
三月 '26
+254
在0个频道中
Get PRO
二月 '26
+116
在0个频道中
Get PRO
一月 '26
+166
在0个频道中
Get PRO
十二月 '25
+134
在0个频道中
Get PRO
十一月 '25
+139
在0个频道中
Get PRO
十月 '25
+8
在0个频道中
Get PRO
九月 '25
+12
在0个频道中
Get PRO
八月 '25
+13
在0个频道中
Get PRO
七月 '25
+11
在0个频道中
Get PRO
六月 '25
+12
在0个频道中
Get PRO
五月 '25
+18
在1个频道中
Get PRO
四月 '25
+14
在0个频道中
Get PRO
三月 '25
+21
在0个频道中
Get PRO
二月 '25
+17
在0个频道中
Get PRO
一月 '25
+15
在1个频道中
Get PRO
十二月 '24
+262
在1个频道中
Get PRO
十一月 '24
+206
在1个频道中
Get PRO
十月 '24
+166
在0个频道中
Get PRO
九月 '24
+146
在0个频道中
Get PRO
八月 '24
+137
在0个频道中
Get PRO
七月 '24
+96
在1个频道中
Get PRO
六月 '24
+91
在0个频道中
Get PRO
五月 '24
+95
在0个频道中
Get PRO
四月 '24
+104
在0个频道中
Get PRO
三月 '24
+149
在0个频道中
Get PRO
二月 '24
+279
在0个频道中
Get PRO
一月 '24
+395
在0个频道中
Get PRO
十二月 '23
+327
在0个频道中
Get PRO
十一月 '23
+38
在0个频道中
Get PRO
十月 '23
+32
在0个频道中
Get PRO
九月 '23
+47
在0个频道中
Get PRO
八月 '23
+53
在0个频道中
Get PRO
七月 '23
+51
在0个频道中
Get PRO
六月 '23
+42
在0个频道中
Get PRO
五月 '23
+43
在0个频道中
Get PRO
四月 '23
+67
在0个频道中
Get PRO
三月 '23
+65
在0个频道中
Get PRO
二月 '23
+45
在0个频道中
Get PRO
一月 '23
+67
在0个频道中
Get PRO
十二月 '22
+62
在0个频道中
Get PRO
十一月 '22
+71
在0个频道中
Get PRO
十月 '22
+70
在0个频道中
Get PRO
九月 '22
+55
在0个频道中
Get PRO
八月 '22
+44
在0个频道中
Get PRO
七月 '22
+54
在0个频道中
Get PRO
六月 '22
+78
在0个频道中
Get PRO
五月 '22
+46
在0个频道中
Get PRO
四月 '22
+77
在0个频道中
Get PRO
三月 '22
+105
在0个频道中
Get PRO
二月 '22
+48
在0个频道中
Get PRO
一月 '22
+61
在0个频道中
Get PRO
十二月 '21
+99
在0个频道中
Get PRO
十一月 '21
+68
在0个频道中
Get PRO
十月 '21
+170
在0个频道中
Get PRO
九月 '21
+72
在0个频道中
Get PRO
八月 '21
+104
在0个频道中
Get PRO
七月 '21
+72
在0个频道中
Get PRO
六月 '21
+292
在0个频道中
Get PRO
五月 '21
+1 344
在0个频道中
| 日期 | 订阅者增长 | 提及 | 频道 | |
| 20 九月 | 0 | |||
| 19 九月 | +8 | |||
| 18 九月 | +7 | |||
| 17 九月 | +6 | |||
| 16 九月 | +8 | |||
| 15 九月 | +15 | |||
| 14 九月 | +6 | |||
| 13 九月 | +4 | |||
| 12 九月 | +6 | |||
| 11 九月 | +7 | |||
| 10 九月 | +12 | |||
| 09 九月 | +7 | |||
| 08 九月 | +6 | |||
| 07 九月 | +9 | |||
| 06 九月 | +7 | |||
| 05 九月 | +2 | |||
| 04 九月 | +5 | |||
| 03 九月 | +6 | |||
| 02 九月 | +11 | |||
| 01 九月 | +7 |
频道帖子
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerabilities are listed below -
CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path
https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html
| 2 | CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.
The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May's supply chain attack on TanStack, in which malicious versions of TanStack's npm packages stole credentials from
https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html | 41 |
| 3 | Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal.
The incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed
https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html | 35 |
| 4 | Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet.
The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution.
"Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote
https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html | 30 |
| 5 | SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.
The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior.
"SolarWinds
https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html | 22 |
| 6 | Identity Visibility in 2026: The Foundation of Identity Security
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in
https://thehackernews.com/2026/09/identity-visibility-in-2026-foundation.html | 18 |
| 7 | Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
A new CVE drops. Your scanner finds it. The severity score looks ugly.
But that still does not answer the question that matters: Can it actually be exploited in your environment?
Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is
https://thehackernews.com/2026/09/can-you-prove-new-cve-is-exploitable.html | 17 |
| 8 | Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository.
The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system.
This was security research,
https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html | 16 |
| 9 | TigerByte Cyber Emerges From Stealth With $3 Million in Funding
The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA.
The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.
https://www.securityweek.com/tigerbyte-cyber-emerges-from-stealth-with-3-million-in-funding/ | 15 |
| 10 | Viral AI actress' hotline face-scans every caller, watches their mood
AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down permanently on September 27. We tried it and read the fine print. [...]
https://www.bleepingcomputer.com/news/security/viral-ai-actress-hotline-face-scans-every-caller-watches-their-mood/ | 15 |
| 11 | ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]
https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/ | 14 |
| 12 | North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]
https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/ | 16 |
| 13 | BragJack attacks hijack AI browser agents through malicious extensions
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over $20,000 in bounties and two CVEs. [...]
https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-browser-agents-through-malicious-extensions/ | 29 |
| 14 | Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine.
Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated.
The flaws
https://thehackernews.com/2026/09/public-exploits-released-for-four-linux.html | 115 |
| 15 | CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2025-39964 Linux Kernel Race Condition Vulnerability
CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability
These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog | 111 |
| 16 | CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-one-known-exploited-vulnerability-catalog | 69 |
| 17 | Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.
The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek.
https://www.securityweek.com/check-point-kaspersky-tanium-patch-product-vulnerabilities/ | 40 |
| 18 | MIND Secures $72 Million for AI-Powered DLP
The company will use the funding to accelerate platform development and expand its presence in key enterprise markets.
The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek.
https://www.securityweek.com/mind-secures-72-million-for-ai-powered-dlp/ | 38 |
| 19 | Critical Orkes Conductor Vulnerability Exploited in Attacks
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.
The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek.
https://www.securityweek.com/critical-orkes-conductor-vulnerability-exploited-in-attacks/ | 28 |
| 20 | Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.
The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek.
https://www.securityweek.com/brevo-supply-chain-attack-injects-malware-into-100000-websites/ | 25 |
