ZCyberNews
中文

Articles

460 articles

Hono Patches CSS Injection and Cache Poisoning FlawsMEDIUM
Vulnerabilities

Hono Patches CSS Injection and Cache Poisoning Flaws

Hono 4.12.18 fixes CVE-2026-44458 (CSS injection in JSX renderer, CVSS 4.3) and CVE-2026-44457 (cache poisoning via Vary header bypass, CVSS 5.3).

CVE-2026-44457CVE-2026-44458
4 min read
Malwarebytes Blocks Suspicious Yahoo Mail Redirects to Opaque DomainsMEDIUM
Industry News

Malwarebytes Blocks Suspicious Yahoo Mail Redirects to Opaque Domains

Malwarebytes blocks background connections from Yahoo Mail to domains like cook.howduhtable.com — third-party infrastructure with poor reputation and opaque redirect chains.

3 min read
Mythos AI Excels at Code Audits but Struggles With Exploit ValidationINFORMATIONAL
AI Security

Mythos AI Excels at Code Audits but Struggles With Exploit Validation

XBOW benchmarks show Anthropic's Mythos AI is potent for source code audits and reverse engineering, but inconsistent at exploit validation and prone to overstating findings.

3 min read
NIST NVD Enrichment Change Creates CVSS Gap for 80% of CVEsMEDIUM
Industry News

NIST NVD Enrichment Change Creates CVSS Gap for 80% of CVEs

NIST now enriches only 15-20% of CVEs under new policy as of April 2026, leaving 80% without CVSS scores or product mappings.

3 min read
OpenAI Breached in TanStack Supply Chain AttackHIGH
Industry News

OpenAI Breached in TanStack Supply Chain Attack

OpenAI says two employees' devices were compromised in the TeamPCP Mini Shai-Hulud campaign, forcing rotation of code-signing certificates across macOS, Windows, iOS, and Android.

3 min readTeamPCP
Pwn2Own Berlin 2026: Researchers Earn $523K Hacking Windows 11, EdgeCRITICAL
Industry News

Pwn2Own Berlin 2026: Researchers Earn $523K Hacking Windows 11, Edge

On day one of Pwn2Own Berlin 2026, researchers collected $523,000 for 24 zero-days, including a $175,000 Edge sandbox escape by Orange Tsai and three Windows 11 privilege...

3 min read
UK to Shield Security Researchers in Computer Misuse Act Overhaul
Industry News

UK to Shield Security Researchers in Computer Misuse Act Overhaul

UK government will rewrite the Computer Misuse Act 1990 to include a statutory defense for good-faith security research, ending years of legal uncertainty for vulnerability...

3 min read
VMware Fusion TOCTOU Flaw CVE-2026-41702 Lets Local Users Escalate toHIGH
Vulnerabilities

VMware Fusion TOCTOU Flaw CVE-2026-41702 Lets Local Users Escalate to

Broadcom patched a high-severity TOCTOU vulnerability in VMware Fusion (CVE-2026-41702) that lets local non-admin users escalate privileges to root on macOS systems.

CVE-2026-41702
3 min read
AI-Driven Attacks Compromise Systems in 73 Seconds, Outpacing PatchingHIGH
Industry News

AI-Driven Attacks Compromise Systems in 73 Seconds, Outpacing Patching

Picus Security analysis shows AI-powered attackers exploit CVEs in ~10 hours and breach systems in 73 seconds, while patching still takes 24 hours.

3 min read
Congress Probes 25 Food Retailers Over Surveillance PricingINFORMATIONAL
Industry News

Congress Probes 25 Food Retailers Over Surveillance Pricing

Rep. Frank Pallone launched an inquiry into 25 food retailers including Amazon, Walmart, and Target over use of personal data to set variable prices, citing FTC findings.

2 min read
Foxconn Confirms Ransomware Attack on North American FactoriesHIGH
Industry News

Foxconn Confirms Ransomware Attack on North American Factories

Nitrogen ransomware gang claims 8TB of stolen data from Foxconn's North American factories, including technical files from major tech clients.

2 min readNitrogen
Palo Alto Patches Prisma Access Agent Flaws: Cert Validation, LPEMEDIUM
Vulnerabilities

Palo Alto Patches Prisma Access Agent Flaws: Cert Validation, LPE

Palo Alto Networks released patches for two medium-severity flaws in Prisma Access Agent — CVE-2026-0248 (improper certificate validation) and CVE-2026-0246 (local privilege...

CVE-2026-0248CVE-2026-0246
3 min read
← PrevPage 8 of 39Next →