SecLens 情报中心

网安资讯,一网打尽。汇集权威漏洞通告与行业要闻,结合分组浏览、智能过滤、RSS订阅 和 Webhook 推送,多通道拓展您的安全情报视野。

社区情报

来自安全社区与技术媒体的情报与观察。

  • UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign

    发布时间 2026-04-16 14:20 (UTC+08:00) 抓取时间 2026-04-16 19:01 (UTC+08:00)

    The Computer Emergencies Response Team of Ukraine (CERT-UA) has disclosed details of a new campaign that has targeted governments and municipal healthcare institutions, mainly clinics and emergency hospitals, to deliver malware capable of stealing sensitive data from Chromium-based web browsers and WhatsApp. The activity, which was&n

    扩展字段
    {
      "categories": [],
      "guid": "https://thehackernews.com/2026/04/uac-0247-targets-ukrainian-clinics-and.html"
    }
    The Hacker News security-news
  • n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails

    发布时间 2026-04-16 01:09 (UTC+08:00) 抓取时间 2026-04-16 19:01 (UTC+08:00)

    Threat actors have been observed weaponizing n8n, a popular artificial intelligence (AI) workflow automation platform, to facilitate sophisticated phishing campaigns and deliver malicious payloads or fingerprint devices by sending automated emails. "By leveraging trusted infrastructure, these attackers bypass traditional security filters, turn

    扩展字段
    {
      "categories": [],
      "guid": "https://thehackernews.com/2026/04/n8n-webhooks-abused-since-october-2025.html"
    }
    The Hacker News security-news
  • Actively Exploited nginx-ui Flaw (CVE-2026-33032) Enables Full Nginx Server Takeover

    发布时间 2026-04-15 20:56 (UTC+08:00) 抓取时间 2026-04-16 19:01 (UTC+08:00)

    A recently disclosed critical security flaw impacting nginx-ui, an open-source, web-based Nginx management tool, has come under active exploitation in the wild. The vulnerability in question is CVE-2026-33032 (CVSS score: 9.8), an authentication bypass vulnerability that enables threat actors to seize control of the Nginx service. It has been coden

    扩展字段
    {
      "categories": [],
      "guid": "https://thehackernews.com/2026/04/critical-nginx-ui-vulnerability-cve.html"
    }
    The Hacker News security-news
  • April Patch Tuesday Fixes Critical Flaws Across SAP, Adobe, Microsoft, Fortinet, and More

    发布时间 2026-04-15 20:37 (UTC+08:00) 抓取时间 2026-04-16 19:01 (UTC+08:00)

    A number of critical vulnerabilities impacting products from Adobe, Fortinet, Microsoft, and SAP have taken center stage in April's Patch Tuesday releases. Topping the list is an SQL injection vulnerability impacting SAP Business Planning and Consolidation and SAP Business Warehouse (CVE-2026-27681, CVSS score: 9.9) that could result in the ex

    扩展字段
    {
      "categories": [],
      "guid": "https://thehackernews.com/2026/04/april-patch-tuesday-fixes-critical.html"
    }
    The Hacker News security-news
  • Deterministic + Agentic AI: The Architecture Exposure Validation Requires

    发布时间 2026-04-15 19:30 (UTC+08:00) 抓取时间 2026-04-16 19:01 (UTC+08:00)

    Few technologies have moved from experimentation to boardroom mandate as quickly as AI. Across industries, leadership teams have embraced its broader potential, and boards, investors, and executives are already pushing organizations to adopt it across operational and security functions. Pentera’s AI Security and Exposure Report 2026 reflects t

    扩展字段
    {
      "categories": [],
      "guid": "https://thehackernews.com/2026/04/deterministic-agentic-ai-architecture.html"
    }
    The Hacker News security-news
  • Microsoft Issues Patches for SharePoint Zero-Day and 168 Other New Vulnerabilities

    发布时间 2026-04-15 16:40 (UTC+08:00) 抓取时间 2026-04-16 19:01 (UTC+08:00)

    Microsoft on Tuesday released updates to address a record 169 security flaws across its product portfolio, including one vulnerability that has been actively exploited in the wild. Of these 169 vulnerabilities, 157 are rated Important, eight are rated Critical, three are rated Moderate, and one is rated Low in severity

    扩展字段
    {
      "categories": [],
      "guid": "https://thehackernews.com/2026/04/microsoft-issues-patches-for-sharepoint.html"
    }
    The Hacker News security-news
  • OpenAI Launches GPT-5.4-Cyber with Expanded Access for Security Teams

    发布时间 2026-04-15 12:30 (UTC+08:00) 抓取时间 2026-04-16 19:01 (UTC+08:00)

    OpenAI on Tuesday unveiled GPT-5.4-Cyber, a variant of its latest flagship model, GPT‑5.4, that's specifically optimized for defensive cybersecurity use cases, days after rival Anthropic unveiled its own frontier model, Mythos. "The progressive use of AI accelerates defenders – those responsible for keeping systems, data, and users safe – enab

    扩展字段
    {
      "categories": [],
      "guid": "https://thehackernews.com/2026/04/openai-launches-gpt-54-cyber-with.html"
    }
    The Hacker News security-news
  • New PHP Composer Flaws Enable Arbitrary Command Execution — Patches Released

    发布时间 2026-04-14 23:57 (UTC+08:00) 抓取时间 2026-04-16 19:01 (UTC+08:00)

    Two high-severity security vulnerabilities have been disclosed in Composer, a package manager for PHP, that, if successfully exploited, could result in arbitrary command execution. The vulnerabilities have been described as command injection flaws affecting the Perforce VCS (version control software) driver. Details of the two flaws

    扩展字段
    {
      "categories": [],
      "guid": "https://thehackernews.com/2026/04/new-php-composer-flaws-enable-arbitrary.html"
    }
    The Hacker News security-news