CPE17 Autorun Killer

CPE17 Autorun Killer Download CPE17 Autorun Killer >> https://git.new/autorunkiller
Download BadURL Killer >> https://ggl.link/badurlkiller

14/08/2026

OpenVuln: Zai ปล่อยของ ให้ AI ไล่หาช่องโหว่ให้ repo open source ฟรี

GLM5.3 พึ่งมาแล้วโปรโมทด้าน Security ส้ะเยอะ และ Benchmark ด้าน Security ตอนนี้ยัง Top1 อยู่ (cybergym benchmark)

และยังไม่พอยังมีโปรเจกต์ใหม่ชื่อ OpenVuln ออกมา บอกเลยว่าอันนี้เจ๋งกว่าที่คิดตอนอ่านหัวข้อครั้งแรก

มันทำงานยังไง
วิธีใช้เรียบง่ายจนน่าตกใจ
- แปะ URL ของ public GitHub repo ลงไปในช่อง (จะเจาะจงสแกนเฉพาะ version ไหนก็ได้)
- VulnHunter จะไล่อ่านโค้ดทั้งก้อนเพื่อหาช่องโหว่
- ผลระดับ ภาพรวม จะเปิดเป็นสาธารณะ ให้ชุมชนเห็นสุขภาพโดยรวมของ ecosystem
- แต่ รายละเอียดของช่องโหว่จริง ๆ ถูกล็อกไว้ ให้เฉพาะ maintainer ที่ยืนยันตัวตนแล้วเท่านั้นที่เห็น จนกว่าจะถึงรอบ disclose

ตัวเลขที่เขาเปิดออกมา
- ทดสอบกับโค้ดเบสจริงร่วมกับทีม security ตั้งแต่ยุค GLM-5.2 เจอช่องโหว่ราว 2,436 รายการ ใน 269 โปรเจกต์
- ครอบคลุมทั้ง kernel, browser engine, network protocol
- บั๊กที่เก่าที่สุดอายุประมาณ 40 ปี (อ่านไม่ผิด สี่สิบปี ซ่อนอยู่มาตลอด)
- แบ่งความรุนแรงเป็น Critical 107, High 990, Medium 1,286, Low 53
- ตัวอย่างที่เปิดเผยแล้ว เช่น use-after-free ใน Linux kernel, ปัญหาการจัดการหน่วยความจำใน WebKit ที่กระทบ Safari และบั๊กเรื่อง parameter validation ใน FreeBSD


เขายังทำ Security Disclosure Ledger เป็นสมุดบัญชีสาธารณะไว้ติดตามสถานะแต่ละรายการด้วย ตอนเปิดตัวมี 53 รายการที่เปิดเผยพร้อม CVE แล้ว ส่วนอีก 2,383 รายการยังอยู่ในช่วง embargo

อีกจุดที่สำคัญมากและอย่ามองข้าม คือเขาบอกว่าผลพวกนี้ผ่านการคัดกรองโดยผู้เชี่ยวชาญที่เป็นมนุษย์ ไม่ใช่ raw output จากโมเดลตรง ๆ ซึ่งจำเป็นมาก เพราะปัญหาคลาสสิกของ AI security scanner คือ false positive ท่วมจนทีม dev เลิกสนใจไปเลย
นอกจาก OpenVuln เขายังแจก เครดิตโมเดลฟรีให้ maintainer โครงการ open source สำหรับงาน audit และงานฝั่งตั้งรับด้วย

14/08/2026

🚨 CoolClient now uses a signed rootkit to hide at the Windows kernel level.

The Mustang Panda-linked backdoor can hide its process, files, registry entries, and some C2 activity.

Kaspersky found victims in Myanmar, Mongolia, Pakistan, and Russia, including government entities.

Read more: https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html

14/08/2026

The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.

13/08/2026

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access.

13/08/2026

🚨 WindRelay turns Android phones into live contactless payment proxies.

Attackers use SpyNote access to silently install the NFC relay malware. When victims tap a physical card on the infected phone, WindRelay streams its NFC data in real time to a fraudster's device, enabling fraudulent payments.

Read how it works: https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html

13/08/2026

‼️ BREAKING: A 40-minute LiteLLM PyPI compromise potentially exposed 2,100+ organizations.

Tied to Trivy's supply-chain attack, the malicious releases stole cloud, SSH, Kubernetes, and database credentials. Researchers later obtained roughly 434,000 captured files mapping potential exposure across thousands of organizations.

See what the stolen data reveals: https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html

13/08/2026

🛑 Attackers are exploiting a SharePoint authentication bypass.

CVE-2026-55040 lets unauthenticated attackers forge JWTs and impersonate any SharePoint site user, including administrators. Eight of 12 recorded exploit attempts occurred on August 12 and 13, after Rapid7 published a PoC.

See how the exploit works: https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html

ที่อยู่

Bangkok

เว็บไซต์

แจ้งเตือน

รับทราบข่าวสารและโปรโมชั่นของ CPE17 Autorun Killerผ่านทางอีเมล์ของคุณ เราจะเก็บข้อมูลของคุณเป็นความลับ คุณสามารถกดยกเลิกการติดตามได้ตลอดเวลา

ทางลัด

แชร์