Posts of last few hours
Please support the site operations by clicking ads.
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...]
https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124008-update-breaks-domain-trust-for-some-users/
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]
https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/
原域名已变更且将在2024年彻底废弃,请访问 https://govuln.com/news/ 查看新的RSS订阅
https://govuln.com/news/url/x8dB
https://cyber.gc.ca/en/alerts-advisories/isc-bind-security-advisory-av26-931
https://cyber.gc.ca/en/alerts-advisories/apple-security-advisory-av26-930
https://cyber.gc.ca/en/alerts-advisories/oracle-corporation-security-advisory-av26-929
As cyber threats become more complex and threat actors more sophisticated, many security operations centres are being set up.
https://cyber.gc.ca/en/guidance/best-practices-setting-security-operations-centre-soc-itsap00500
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...]
https://www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/
https://cyber.gc.ca/en/alerts-advisories/hpe-security-advisory-av26-928
https://cyber.gc.ca/en/alerts-advisories/control-systems-phoenix-contact-security-advisory-av26-927
These are the top threats you should know about this week.
https://www.f5.com/labs/articles/weekly-threat-bulletin-september-16th-2026
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]
https://www.bleepingcomputer.com/news/security/spains-data-agency-gets-first-report-of-ai-powered-data-breach/
https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-926
https://cyber.gc.ca/en/alerts-advisories/android-security-advisory-september-2026-monthly-rollup-av26-920
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.
https://www.darkreading.com/endpoint-security/bragjack-browser-agentic-ai
全世界有无数人的睡眠不足,睡眠不足与肥胖、糖尿病、高血压、心脏病、中风及过早死亡相关。如果有人付费让你睡更长时间?科学家为此做了一项社会实验。研究人员向匹兹堡大学的 1100 多名本科生提供了 Fitbit 以及一款能发送就寝提醒和晨间反馈的应用。在为期四周内研究人员随机选择了 468 名学生,只要他们某晚睡眠时间达到至少七小时,就向其支付 5 美元报酬。研究人员通过他们佩戴的设备核实实际睡眠时长。参与研究的学生平均年龄约为 19 岁,其中半数为大一新生。72% 为女性。55% 为白人,28% 为亚裔,9% 为黑人,4% 为西班牙裔。研究结果表明,提供即时经济奖励有助于学生实现每晚七小时的睡眠目标,且这种效果在停止发放奖励后仍能持续一个月。参与研究的学生此前平均每晚睡眠时间为 6.6 小时。半数学生在凌晨 1 点之后才睡觉,四分之一学生甚至在凌晨 2 点之后才入睡。在实验中,获得现金激励的学生在每个上课日夜晚平均多睡了 19 分钟,该学期的 GPA 得分上升了约 0.08 分——相当于成绩高于平均水平和低于平均水平的学生之间差距的四分之一。
https://www.solidot.org/story?sid=85400
1999 年初代 PS2 Fat 游戏机使用的安全芯片 CXP102064 MechaCon 在时隔 26 年被爱好者破解。加拿大复古软硬件爱好者 DiscoStarslayer 通过社交媒体称其花了四年时间破解了其秘密。DiscoStarslayer 采用的逆向工程方法包括:利用化学方法对 CXP102064 芯片进行开盖,利用显微镜和光学数据提取技术分析芯片电路。期间发现了一个漏洞利用方法,可通过软件提取芯片数据。MechaCon 芯片也被用于当时推出的几款街机,包括 Namco System 246 和 System 256 以及 Konami Python 1 等。
https://www.solidot.org/story?sid=85399
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.
The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded
https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky.
The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
https://thehackernews.com/2026/09/three-threat-groups-target-russian.html
Denuvo 在美国加州北区联邦法院起诉了名叫 voices38 的匿名游戏破解黑客,指控其违反了 DMCA 的反规避条款。被告被控绕过了逾二十款游戏使用的 Denuvo DRM,相关游戏包括了《霍格沃茨之遗(Hogwarts Legacy)》和《黑神话:悟空》。随着诉讼的推进,Denuvo 可能会向 Reddit、Discord 和 Valve 发出传票,以获取黑客的身份信息。voices38 发布了一系列使用 Denuvo DRM 的游戏破解补丁,曾在一天之内发布了创纪录的五款 Denuvo DRM 游戏破解补丁,以至于引起了 Denuvo 公司的注意。Denuvo 称被告是一名专注于对 Denuvo DRM 游戏进行逆向工程的计算机黑客。
https://www.solidot.org/story?sid=85398
Latest Blog Posts
- 3 weeks 3 days ago
- 2 months 3 weeks ago
- 2 months 3 weeks ago
- 2 months 3 weeks ago
- 2 months 3 weeks ago
- 7 months 2 weeks ago
- 1 year 1 month ago
- 1 year 1 month ago
- 1 year 2 months ago
- 1 year 6 months ago