tgindex
InfoSec NEWS

Агрегатор новостей из мира информационной безопасности (кучи разных мест). Да, тут огромное количество сообщений постоянно :) Если у вас есть что добавить, пишите в @dc20e6

Последний пост
23:14
Последнее чтение
12:33
Постов за неделю
91
Всего постов
95
Тип
открытый
Язык
английский
Категория
Новости и СМИ
В каталоге с
13 авг.
Подписчики
828
+1 за 4 дн.
Сутки
0
0,00%
Неделя
 
Месяц
 
Просмотров на пост
36
40 постов
Вовлечённость
4,3%
к подписчикам
Постов в день
13,0
всего 95
Упоминаний
1
каналов
Охват размещения
оценка
1/24сутки в ленте
32
1/48двое суток
36
1/72трое суток
39

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html

  • Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html

  • Updates to your AWS Sign-In experience https://aws.amazon.com/blogs/security/updates-to-your-aws-sign-in-experience/

  • How Codex found replayable state transitions and a lost-update race in a Supabase browser game https://www.reddit.com/r/netsec/comments/1vqxi6k/how_codex_found_replayable_state_transitions_and/

  • Unauthenticated RCE in CircleCI's MCP server: Host/Origin allowlist bypassed by any non-browser client (GHSA-xv5j-cwgj-22r4) https://www.reddit.com/r/netsec/comments/1vqtjpi/unauthenticated_rce_in_circlecis_mcp_server/

  • ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More https://thehackernews.com/2026/08/weekly-recap-vmware-exploits-windows-0.html

  • Streamline your GitHub journey with AWS CodePipeline and AWS DevOps Agent https://aws.amazon.com/blogs/devops/streamline-your-github-journey-with-aws-codepipeline-and-aws-devops-agent/

  • This Wi-Fi pop-up installs a vicious RAT on your device — Ontario expert explains Microsoft’s latest security alert https://www.reddit.com/r/Malware/comments/1vqr7ct/this_wifi_popup_installs_a_vicious_rat_on_your/

  • Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html How MCP Servers Can Expose Enterprise Secrets https://thehackernews.com/2026/08/how-mcp-servers-can-expose-enterprise.html

  • From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193) https://www.reddit.com/r/netsec/comments/1vqqpwn/from_aks_node_root_vulnerability_to_microsoft/

  • Weird Machines и ROP/JOP эксплуатация: от формальной теории к обходу CFI https://codeby.net/threads/weird-machines-i-rop-jop-ekspluatatsiya-ot-formal-noi-teorii-k-obkhodu-cfi.95186/

  • Hacking Public Wi-Fi DNS to Steal Credentials https://www.schneier.com/blog/archives/2026/08/hacking-public-wi-fi-dns-to-steal-credentials.html

  • Fake OpenAI Codex malvertising campaign using Base64-obfuscated curl | zsh loader on macOS https://www.reddit.com/r/Malware/comments/1vqoudv/fake_openai_codex_malvertising_campaign_using/

  • North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring https://thehackernews.com/2026/08/north-korean-remote-workers-are.html WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE https://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html Trump Memo Paves Way for U.S. Firms to Hack and Disrupt Foreign Crime Groups https://thehackernews.com/2026/08/trump-memo-paves-way-for-us-firms-to.html Apple Warns Users in 110 Countries They May Be Targets of Mercenary Spyware https://thehackernews.com/2026/08/apple-warns-users-in-110-countries-they.html CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps https://thehackernews.com/2026/08/ctm360-uncovers-over-3000-recruitment.html Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers https://thehackernews.com/2026/08/chrome-devtools-technique-enables.html Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html IAM Compliance Requirements and Best Practices https://thehackernews.com/2026/08/iam-compliance-requirements-and-best.html Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html

  • They patched their SaaS and left the self-hosted OSS version vulnerable - AppFlowy Authenticated SQL Injection https://www.reddit.com/r/netsec/comments/1vqojw3/they_patched_their_saas_and_left_the_selfhosted/

  • Android Device & Game account Security Concern https://www.reddit.com/r/Malware/comments/1vqny44/android_device_game_account_security_concern/

  • Weird machines в TLS: скрытые вычислительные примитивы в handshake OpenSSL и BoringSSL https://codeby.net/threads/weird-machines-v-tls-skrytyye-vychislitel-nyye-primitivy-v-handshake-openssl-i-boringssl.95182/

  • Axiometa Genesis XIAO Shield: Build Real Devices Without the Wiring https://www.seeedstudio.com/blog/2026/08/17/axiometa-genesis-xiao-shield/

  • How to Taught a $200 Robot Arms to Work on Their Own? https://www.seeedstudio.com/blog/2026/08/17/how-to-taught-a-200-robot-arms-to-work-on-their-own/

  • How to Build a Low-Power Asset Tracking System for Large-Scale Plantations https://www.seeedstudio.com/blog/2026/08/17/how-to-build-a-low-power-asset-tracking-system-for-large-scale-plantations/