L'actu de la sécu


Les dernières news:

  • Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign
    Publié le April 7, 2026

    Source: HackerNews

    The Russia-linked threat actor known as APT28 (aka Forest Blizzard) has been linked to a new campaign that has compromised insecure MikroTik and TP-Link routers and modified their settings to turn them into malicious infrastructure under their control as part of a cyber espionage campaign since at least May 2025. The large-scale exploitation campaign has been codenamed 

    Lien
  • [Webinar] How to Close Identity Gaps in 2026 Before AI Exploits Enterprise Risk
    Publié le April 7, 2026

    Source: HackerNews

    In the rapid evolution of the 2026 threat landscape, a frustrating paradox has emerged for CISOs and security leaders: Identity programs are maturing, yet the risk is actually increasing. According to new research from the Ponemon Institute, hundreds of applications within the typical enterprise remain disconnected from centralized identity systems. These "dark

    Lien
  • [local] is-localhost-ip 2.0.0 - SSRF
    Publié le April 6, 2026

    Source: ExploitDB

    is-localhost-ip 2.0.0 - SSRF

    Lien
  • [webapps] Fortinet FortiWeb v8.0.1 - Auth Bypass
    Publié le April 6, 2026

    Source: ExploitDB

    Fortinet FortiWeb v8.0.1 - Auth Bypass

    Lien
  • [local] Windows Kernel - Elevation of Privilege
    Publié le April 6, 2026

    Source: ExploitDB

    Windows Kernel - Elevation of Privilege

    Lien
  • [local] Desktop Window Manager Core Library 10.0.10240.0 - Privilege Escalation
    Publié le April 6, 2026

    Source: ExploitDB

    Desktop Window Manager Core Library 10.0.10240.0 - Privilege Escalation

    Lien
  • [webapps] ASP.net 8.0.10 - Bypass
    Publié le April 6, 2026

    Source: ExploitDB

    ASP.net 8.0.10 - Bypass

    Lien
  • [webapps] Grafana 11.6.0 - SSRF
    Publié le April 6, 2026

    Source: ExploitDB

    Grafana 11.6.0 - SSRF

    Lien
  • [webapps] Zhiyuan OA - arbitrary file upload leading
    Publié le April 6, 2026

    Source: ExploitDB

    Zhiyuan OA - arbitrary file upload leading

    Lien