Aggregator
CVE-2026-8178 | Amazon Redshift JDBC Driver up to 2.2.1 externally-controlled input to select classes or code (GHSA-wmmv-vvg5-993q / EUVD-2026-28814)
为什么部分人特别招蚊子?
Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300)
Researchers have found and disclosed yet another local privilege escalation (LPE) vulnerability in the Linux kernel: CVE-2026-46300, aka “Fragnesia”. The flaw is in the same class of vulnerabilities as the recently disclosed Dirty Frag bug(s). Like Dirty Frag, it affects the same Linux module (xfrm-ESP). In fact, according to Dirty Frag discoverer Hyunwoo Kim, Fragnesia was “accidentally activated” by the patch fixing one of the original Dirty Frag vulnerabilities (i.e., CVE-2026-43284). CVE-2026-46300 explained Fragnesia was … More →
The post Fragnesia: New Linux kernel LPE bug was spawned by Dirty Frag patch (CVE-2026-46300) appeared first on Help Net Security.
CVE-2014-0216 | Moodle up to 2.4.6 blocks/html/lib.php block_html_pluginfile access control (EUVD-2022-3226 / Nessus ID 74237)
CVE-2022-27773 | Ivanti EPM privileges management (EUVD-2022-32269)
CVE-2022-27647 | Netgear R6700v3 1.0.4.120_10.0.91 libreadycloud.so name/email os command injection (ZDI-22-524 / EUVD-2022-32148)
CVE-2022-27648 | KOYO Screen Creator 0.1.1.1 SCA2 File Parser stack-based overflow (ZDI-22-543 / EUVD-2022-32149)
CVE-2022-27646 | Netgear R6700v3 1.0.4.120_10.0.91 circled circleinfo.txt stack-based overflow (ZDI-22-523 / EUVD-2022-32147)
Голосовые помощники почти научились врать убедительно. Но одна вещь их всё ещё выдаёт
Major tech manufacturer Foxconn confirms cyberattack hit North American factories
The ransomware group Nitrogen claimed responsibility for the attack and said it stole 8 terabytes of data spanning more than 11 million files belonging to the company’s top customers.
The post Major tech manufacturer Foxconn confirms cyberattack hit North American factories appeared first on CyberScoop.
CVE-2025-61972 | AMD EPYC 9004 Processors security-sensitive hardware controls with missing lock bit protection (EUVD-2025-209812 / CNNVD-202605-3301)
CVE-2025-61971 | AMD EPYC 9004 Processors security-sensitive hardware controls with missing lock bit protection (EUVD-2025-209811 / CNNVD-202605-3302)
CVE-2024-36315 | AMD EPYC 9004 Processors protection mechanism (EUVD-2024-55576 / CNNVD-202605-3303)
CVE-2026-40423 | F5 BIG-IP prior 17.1.3.2/17.5.1.6/21.0.0.2 Traffic Management Microkernel allocation of resources (K000161023 / CNNVD-202605-3305)
CVE-2026-40435 | F5 BIG-IP prior 17.1.3.1/17.5.1.4 httpd unprotected alternate channel (K000156604 / CNNVD-202605-3304)
Google ещё не успела рассказать о своей ОС, а её уже слили. Встречайте Aluminium OS
Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike
HYCU aiR detects insider risk and AI activity from backups
HYCU has announced HYCU aiR (AI Resilience), an AI-native solution that turns backup data across dozens of applications into a live and actionable intelligence for security, compliance, and IT teams. aiR lets organizations search, query, and run purpose-built agents to surface insider risk, sensitive data exposure, identity drift, and AI agent activity, using their backup data. Every backup is a timestamped record of what happened inside an organization’s applications. HYCU aiR is the first solution … More →
The post HYCU aiR detects insider risk and AI activity from backups appeared first on Help Net Security.