35Articles
5Categories
2026-04-11Date
πŸ›
Jeff Williams CTO Cofounder of Contrast Security and OWASP co-founder on Mythos and AI Security
πŸ›
CVE-2026-28810 Predictable DNS Transaction IDs Enable Cache Poisoning in Built-in Resolver
πŸ›
CVE-2026-29181 OpenTelemetry-Go multi-value `baggage` header extraction causes excessive allocations (remote dos amplification)
πŸ›
CVE-2026-27144 Miscompilation allows memory corruption via CONVNOP-wrapped array copy in cmd/compile
πŸ›
CVE-2026-32282 TOCTOU permits root escape on Linux via Root.Chmod in os in internal/syscall/unix
πŸ›
CVE-2026-33810 Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509
πŸ›
CVE-2026-4878 Libcap: libcap: privilege escalation via toctou race condition in cap_set_file()
πŸ›
CVE-2026-35611 Addressable has a Regular Expression Denial of Service in Addressable templates
πŸ›
CVE-2026-28389 Possible NULL Dereference When Processing CMS KeyAgreeRecipientInfo
πŸ›
CVE-2026-28390 Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo
πŸ›
CVE-2026-39882 OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies
πŸ›
CVE-2026-32288 Unbounded allocation for old GNU sparse in archive/tar
πŸ›
CVE-2026-32281 Inefficient policy validation in crypto/x509
πŸ›
CVE-2026-32289 JsBraceDepth Context Tracking Bugs (XSS) in html/template
πŸ›
CVE-2026-32283 Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls
πŸ›
CVE-2026-32280 Unexpected work during chain building in crypto/x509
πŸ›
CVE-2026-27143 Missing bound checks can lead to memory corruption in safe Go in cmd/compile
πŸ›
CVE-2026-27140 Code execution vulnerability in SWIG code generation in cmd/go
⚠️
Claude and ChatGPT Exploited in Sweeping Cyber Campaign Against Government Agencies
⚠️
Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data
⚠️
Over 20,000 crypto fraud victims identified in international crackdown
⚠️
Two different attackers poisoned popular open source tools - and showed us the future of supply chain compromise
πŸ”₯
HWMonitor & CPU-Z users were exposed to malware through fake downloads after CPUID breach
πŸ”₯
Security PSA: Popular Tools CPU-Z and HWMonitor Were Briefly Compromised
πŸ•΅οΈ
CPUID site hijacked to serve malware instead of HWMonitor downloads
πŸ•΅οΈ
Google rolls out end-to-end encryption for Gmail on Android and iOS devices for enterprise users, letting them read and compose emails without additional tools
πŸ•΅οΈ
Google rolls out end-to-end encryption for Gmail on Android and iOS devices for enterprise users, letting them read and compose emails without additional tools
πŸ•΅οΈ
Google rolls out end-to-end encryption for Gmail on Android and iOS devices for enterprise users, letting them read and compose emails without additional tools
πŸ•΅οΈ
Google rolls out end-to-end encryption for Gmail on Android and iOS devices for enterprise users, letting them read and compose emails without additional tools
πŸ•΅οΈ
Google Locks Chrome Sessions to Devices to Stop Cookie Theft
πŸ•΅οΈ
Supply chain nightmare: How Rust will be attacked and what we can do to mitigate the inevitable
πŸ•΅οΈ
AI Cybersecurity After Mythos: The Jagged Frontier
πŸ“‘
Jetzt patchen! Adobe verΓΆffentlicht Notfall-Sicherheitsupdate fΓΌr Acrobat Reader
πŸ“‘
EinzelhΓ€ndler frustriert ΓΌber strenge Regeln bei KI-Kameras
πŸ“‘
US-Regierung traf sich vor Mythos-Preview-Rollout mit KI-Herstellern