There is no patch - only a temporary mitigation. CISA adds CVE to the Financial Exploited Vulnerabilities catalog on May 15 with a deadline of May 29. 14 days to respond. For SOC teams that are accustomed to detecting Exchange-incidents on server IOCs - web-slopes, anomalous IIS processes, a...
Artificial intelligence functions are increasingly integrated into smartphones, but together with convenience can open unexpected ways of bypassing the protection. Android 16 found an error that allows Gemini to send messages from a locked device without entering a PIN code.
The problem arises...
AI is increasingly prompting a ready-to-date response where a person would have to admit a lack of knowledge, and, as it was recently revealed, such assistance can reduce the reliability of conclusions. Experts from universities in France and Italy found that access to the advice of a language...
Cybercriminals found a way to turn Windows’s trust in digital signatures into a weapon and used an infected computer of an employee DigiCert to intercept the company’s customer certificates. Behind the attack was the Chinese band GoldenEye Dog, which then signed with stolen certificates its own...
The Egyptian developer ZedAxis has assembled an advertising filter on the ESP32-C3 microcontroller, which blocks more than 537 thousand domains and costs about $ 5.
The device works as a backup server of domain names for a home network. The main filtering of the developer is performed...
A powerful laptop for $5400 unexpectedly showed how different Windows 11 and Linux use the same iron. In the tasks related to artificial intelligence, the Microsoft system significantly ahead of Ubuntu and CachyOS, but when encoding video, both Linux builds convincingly took revenge.
Phoronix...
A VPN gateway often becomes the first entry point into the inner network, and in the summer of 2026, attackers used two unknown vulnerabilities of SonicWall Secure Mobile Access to gain full control over the devices. The attack was discovered after suspicious attempts to enter and move over the...
Four critical CVE in one service in one day. On May 4, 2026, Apache Polaris received security advisory, from which data engineers had to get in mood. CVE-2026-42809 from this bundle - the most indicative: CVSS 9.4 (CRITICAL according to CVSS 4.0), vector AV:N/AC:L/AT:N/PR:L/UI:N. The...
In August 2025, the FBI through IC3 rolled out awarning: the cyber-operations of the Russian FSB from the Center 16division pulled configuration files from thousands of network devicesin the critical infrastructure sectors. Two vectors - SNMP andseven-year-old CVE-2018-0171in Cisco Smart...
Four critical LPE in two weeks of May 2026. All in the page cache Linux kernel. All - without race condition, without kernel panic, with a probability of success close to 100%. And all found with LLM.
Not some experimental code - combat exploits to obtain root shell from an ordinary user...
According to Crowd Strike Global Threat Report 2025, 75% of the incurs in 2024 used valid accounting data, and IBM X-Force records an increase in credential-based attacks by 71% year-year. Earlier in the morning - in SIEM falls an alterth: the service account of the SaaS platform, inactive for...
Windows corporate servers began waiting hours for updates or lose communication with Microsoft services. The company confirmed a large-scale failure in the work of Windows Server Update Services, which affected many versions of Windows 10, Windows 11 and Windows Server.
Administrators have...
The hacker attack on Hugging Face has shown that autonomous systems based on artificial intelligence are already able to independently look for weaknesses, secure in the infrastructure and move between internal networks. The company found an invasion in early July and said that the attacker...
In Shenzhen held a freestyle combat tournament between full-size humanoid robots. The cars beat each other with their hands and feet, performed reversals, fell, again rose and continued the fight. In one of the battles, the robot received a kick at the level of his head and lost it, but even...
At an external pentest in early 2025, I received an shell on the corporate network through a VPN gateway with a CVE from the CISA KEV catalog. From the first scan to access, three hours. No phishing, no leaked passwords. Unpatughed edge-device at the perimeter, standard Nuclei-fine template...
CVE-2026-7411 in Eclipse BaSyx Java Server SDK - from those bugs that make you think about the state of security in the entire Industry 4.0 stack. An unauthenticated attacker through one HTTP request to the Submodel API records files in the host directory and receives full code execution...