慣性聚合 高效追讀感興趣之博客、新聞、科技資訊
閱原文 以慣性聚合開啟

推薦訂閱源

博客园 - 司徒正美
V
V2EX
T
Tailwind CSS Blog
有赞技术团队
有赞技术团队
aimingoo的专栏
aimingoo的专栏
Apple Machine Learning Research
Apple Machine Learning Research
IT之家
IT之家
Blog — PlanetScale
Blog — PlanetScale
A
About on SuperTechFans
月光博客
月光博客
T
The Blog of Author Tim Ferriss
宝玉的分享
宝玉的分享
Martin Fowler
Martin Fowler
博客园 - 聂微东
The GitHub Blog
The GitHub Blog
V
Visual Studio Blog
WordPress大学
WordPress大学
酷 壳 – CoolShell
酷 壳 – CoolShell
Engineering at Meta
Engineering at Meta
GbyAI
GbyAI

Security Affairs

Why pure extortion is replacing traditional ransomware Ghostwriter Is Back, Using a Ukrainian Learning Platform as Bait to Hit Government Targets Authorities arrest 23-year-old accused of running the Kimwolf botnet U.S. CISA adds Trend Micro Apex One and Langflow to its Known Exploited Vulnerabilities catalog One Telecom Provider Hosted Most of the Middle East ’s Active C2 Infrastructure U.S. CISA adds Microsoft and Adobe flaws to its Known Exploited Vulnerabilities catalog Global law enforcement operation takes First VPN offline Apple Blocks Over 2 Million Apps in 2025 Fraud Crackdown Attackers are bypassing MFA on SonicWall VPNs because something was wrong with previous fix Cisco fixed maximum severity flaw CVE-2026-20223 in Secure Workload Discord adds end-to-end encryption to voice and video calls by default PinTheft: Another Linux Privilege Escalation, Another Working Exploit, This Time Targeting Arch Microsoft issues YellowKey mitigation, no patch yet Carding site B1ack’s Stash dumps 4.6 Million stolen cards for free A malicious VS code extension just breached GitHub ‘s internal repositories DirtyDecrypt: PoC Released for yet another Linux flaw Alleged Huawei zero-day blamed for the 2025 Luxembourg telecom crash Drupal is rolling out an emergency security update on May 20. You cannot miss it Microsoft dismantled malware-signing network Fox Tempest Poland shifts away from Signal following cyberattacks on officials’ accounts Massive MENA cybercrime Operation Ramz disrupts infrastructure and arrests 201 suspects Shai-Hulud worm copycats emerge after source code leak Grafana confirms GitHub token breach cybercrime group claims the attack ShinyHunters hack 7-Eleven: franchisee data and Salesforce records exposed Public Amazon bucket leaks sensitive guest data from Japanese hotel platform Tabiq Chaotic Eclipse discloses MiniPlasma zero-day, suggesting a missing or undone 2020 Windows security fix SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 97 Security Affairs newsletter Round 577 by Pierluigi Paganini – INTERNATIONAL EDITION Attackers exploit Funnel Builder bug to inject e-skimmers into e-stores Pwn2Own Berlin 2026, Day Three: DEVCORE Crowned Master of Pwn, $1.298 Million Total U.S. CISA adds a flaw in Microsoft Exchange Server to its Known Exploited Vulnerabilities catalog Russian APT Turla builds long-term access tool with Kazuar Botnet evolution OpenAI hit by supply chain attack linked to malicious TanStack packages Pwn2Own Berlin 2026, Day Two: $385,750 more, Microsoft Exchange falls, and the running total crosses $900K CVE-2026-42897: Microsoft confirms active exploitation of Exchange Server zero-day Ghostwriter group resumes attacks on Ukrainian Government targets Researchers uncover YellowKey and GreenPlasma Windows Zero-Days Pwn2Own Berlin 2026, Day One: $523,000 paid out, AI products fall U.S. CISA adds a flaw in Cisco Catalyst SD-WAN to its Known Exploited Vulnerabilities catalog Linux Kernel bug Fragnesia allows local root access attacks Broadcom releases VMware Fusion security update for root access bug NGINX Rift: an 18-year-old flaw in the world’s most deployed web server just came to light FamousSparrow targets Azerbaijani energy sector in multi-wave espionage campaign Nitrogen Ransomware claims massive data theft from Foxconn Microsoft Patch Tuesday for May 2026 fix 138 bugs, some of them are alarming OpenLoop Health confirms January 2026 Data breach affecting 716,000 Quest KACE SMA flaw CVE-2025-32975: when one unpatched tool opens the door to 60 organizations Instructure settles with hackers following massive student data theft Critical Fortinet vulnerabilities fixed in FortiSandbox and FortiAuthenticator Hackers accessed BWH Hotels reservation system for months
美國CISA將Drupal核心漏洞列為已知被利用漏洞目錄
Pierluigi Pa · 2026-05-24 · via Security Affairs

美利坚合众国网络安全与基础设施安全局(CISA)将Drupal核心之缺陷列于已知遭利用漏洞目录。

美利坚合众国网络安全与基础设施安全局(CISA) 增之 微软交换服务器之瑕疵,追踪为CVE-2026-9082(CVSS评分9.8),及其 已知遭利用漏洞目录.

五月廿日,Drupal发布高度关键安全补丁,针对 CVE-2026-9082之SQL注入漏洞,此漏洞使未认证攻击者得侵及运行PostgreSQL数据库之站点。攻击尝试几乎立时开始,四十八时内,安全公司已追踪野地中数千次攻击。

此漏洞藏于一API之中,其设为净数据库查询,以防SQL注入。然该API有隙,使攻击者可发特制之请求,于使用PostgreSQL之站点注入任意SQL命。如Drupal于其 告警中所言。

云:“此API有隙,使攻者得发巧构之请,致PostgreSQL数据库之用者,任SQL注入焉。此可致信息泄露,或于某些情形,得升权柄,行远程代码,或为其他攻击。” 之告曰:“此隙,无名者可乘之。”

其果可自泄密至权升,或于某些配置中,行远程码执。

关于CVE-2026-9082之告,于五月廿二更新,距补丁发布二日,详述其状,证众人所疑:

“风险之评分已更,以显今有利用之试于野中见之。”  新之告示.

Imperva察得,于披露之二日之内,于六十五国之内,有六千之Drupal站,遭一万五千以上之利用尝试。近半之攻击,目标为游戏与金融服务之组织,盖因凭据与财务数据之价值甚高故也。

自 CVE-2026-9082 之告,Imperva 观察得攻击之试逾一万五千,所向几六千之址,布于六十五国。攻击者,今主击戏娱与财用之务,计几半焉,几近五成也。 Imperva 言。。“此模式示,攻击者与扫描器主欲辨识暴露之Drupal站,运行脆弱PostgreSQL支持之配置。虽活动现以侦察与验证为主,然此脆弱之性,若得成功利用,则可速自探测转至数据窃取或权限提升。”

据 《约束性操作指令》(BOD)22-01:降低已知被利用漏洞的重大风险FCEB之机构,须于限期前,应所识之弱,以护其网,免遭利用目录中瑕疵之攻。

专家亦建议私人机构审阅之。 目录 乃治其基建之弱。

CISA命联邦机构速补此隙。 丙申年四月廿八日

皮耶鲁吉(Pierluigi) 帕格尼尼(Paganini)

随我于Twitter: @安全事务 且 脸书(Facebook) 且 麋鹿(Mastodon)

(SecurityAffairs – hacking, US CISA Known Exploited Vulnerabilities catalog)