Positive Technologies researchers found in PHP two errors at the junction of the usual code of web applications and low-level database drivers. One vulnerability opened the way to SQL injection in the Firebird driver through a zero byte in the row, and the other could drop the PHP process when...
Why Businesses Don't Buy "14 Critical Vulnerabilities"
Business management operates in three categories: revenue, costs and risks. Severity, CVSS score, lateral movement - none of these words fall into any of them. The result: red team is perceived as an item of expenditure without measurable...
Business logic of attack: why the attacker Nginx UI
Nginx UI is an open-source web interface for managing Nginx with an active community on GitHub and a decent number of downloads from Docker Hub. Through the panel, administrators rule the configuration of virtual hosts, manage SSL certificates...
Cryptocosts rarely close in one day, but sometimes one vulnerability is enough for the service to decide to leave the market. Ctrl Wallet announced that it was shutting down a few weeks after the security incident, and asked users to withdraw the assets by August 3, 2026.
The problems began on...
Iranian hackers have turned the usual tools of system administrators into a path to secure networks. The Cavern Manticore group uses the new modular platform Cavern to attack Israeli government agencies and IT companies, Check Point experts have found. In some cases, the attackers first hacked...
Cisco Talos specialists have revealed new details about the UAT-7810 group, which is developing the LapDogs ORB network and infects routers so that other groups associated with China can hide their own operations through them.
According to Talos, the UAT-7810 does not just hack into...
The weak place of the crypto wallet is often hidden not in the blockchain, but in the moment when the user first receives the recovery phrase. Coinspect has described the vulnerability of Ill Bloom, which is already being used to withdraw funds from wallets created under certain conditions...
Positive Technologies has updated MaxPatrol Carbon to version 26.2 and focused on faster modeling of attacks in corporate infrastructures. The system now calculates the possible routes of the attacker 20 times faster and covers 81% of the technique of the MITRE ATT&CK matrix of version 15.1. For...
AI assistants are increasingly writing code for developers, but with convenience there is less noticeable risk: the usual skills can weaken without obvious signs. Indian developer Ashutos Rat proposed to check such degradation with the help of Atrophy, a new team line utility for regular...
Positive Technologies has updated MaxPatrol Carbon to version 26.2 and focused on faster modeling of attacks in corporate infrastructures. The system now calculates the possible routes of the attacker 20 times faster and covers 81% of the technique of the MITRE ATT&CK matrix of version 15.1. For...
AI assistants are increasingly writing code for developers, but with convenience there is less noticeable risk: the usual skills can weaken without obvious signs. Indian developer Ashutos Rat proposed to check such degradation with the help of Atrophy, a new team line utility for regular...
On the external pentest, the first critical find took 11 minutes. Not Nmap, not Burp - request site:target.com filetype:env "DB_PASSWORD" returned the file from credentials from the production base. Host ev-payments.target.com did not appear in the scough, because the customer forgot about it...
Two major incidents in six months - Crunchyroll and Discord - and one vector: Zendesk. Not zero-day in code, not RCE, not something beautiful. Ordinary compromising the agency account through an outsourcer.
In March 2026, Crunchyroll confirmed the leak. According to Have I Been Pwned, 1 195 684...
The editing resolution of one chatbot turned out to be the key to the entire system: the vulnerability of Rogue Agent in Google Dialogflow CX allowed an attacker with access to one agent to intercept the rest of the agents with blocks of code in the same Google Cloud project.
According to the...
The cloud infrastructure has become an arena of struggle not only between defenders and attackers, but also between the malicious groups themselves: the new CAI worm infects servers, steals accounts, mines cryptocurrency and removes competitors’ programs.
Cloud AI Infrastructure Attack...
An ordinary application in the error tracking system can be a hidden team for AI. Experts Noma Labs showed how through one GitHub Issue force GitHub Agentic Workflows to disclose the contents of the closed repository in an open comment.
GitHub Agentic Workflows combines GitHub Actions with a...
wo years ago, the average time from disclosure to operation was 32 days. Now a third of exploits appear on the day of publication CVE or earlier. Below - how exactly AI compresses the path from CVE to the exploit, which workflow works in practice and where automation predictably breaks...