Aggregator
CVE-2025-21901 | Linux Kernel up to 6.12.17/6.13.5 bnxt_re null pointer dereference
11 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.12.17/6.13.5. It has been rated as critical. This issue affects some unknown processing of the component bnxt_re. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2025-21901. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21900 | Linux Kernel up to 6.12.17/6.13.5 NFSv4 close deadlock
11 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.12.17/6.13.5. It has been declared as critical. This vulnerability affects the function close of the component NFSv4. The manipulation leads to deadlock.
This vulnerability was named CVE-2025-21900. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21899 | Linux Kernel up to 6.1.129/6.6.80/6.12.17/6.13.5 tracing event_trigger_write incorrect regex
11 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.1.129/6.6.80/6.12.17/6.13.5. It has been classified as problematic. This affects the function event_trigger_write of the component tracing. The manipulation leads to incorrect regular expression.
This vulnerability is uniquely identified as CVE-2025-21899. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21898 | Linux Kernel up to 6.13.5 ftrace function_stat_show divide by zero
11 months 1 week ago
A vulnerability was found in Linux Kernel up to 6.13.5 and classified as critical. Affected by this issue is the function function_stat_show of the component ftrace. The manipulation leads to divide by zero.
This vulnerability is handled as CVE-2025-21898. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21897 | Linux Kernel up to 6.12.17/6.13.5 sched_ext pick_task_scx deadlock
11 months 1 week ago
A vulnerability has been found in Linux Kernel up to 6.12.17/6.13.5 and classified as critical. Affected by this vulnerability is the function pick_task_scx of the component sched_ext. The manipulation leads to deadlock.
This vulnerability is known as CVE-2025-21897. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21895 | Linux Kernel up to 6.6.80/6.12.17/6.13.5 perf_event_swap_task_ctx_data iteration
11 months 1 week ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.6.80/6.12.17/6.13.5. Affected is the function perf_event_swap_task_ctx_data. The manipulation leads to excessive iteration.
This vulnerability is traded as CVE-2025-21895. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21932 | Linux Kernel up to 6.12.18/6.13.6 mm vma_modify allocation of resources
11 months 1 week ago
A vulnerability, which was classified as problematic, has been found in Linux Kernel up to 6.12.18/6.13.6. This issue affects the function vma_modify of the component mm. The manipulation leads to allocation of resources.
The identification of this vulnerability is CVE-2025-21932. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-21931 | Linux Kernel up to 6.12.18/6.13.6 memory_hotplug /include/linux/swapops.h state issue
11 months 1 week ago
A vulnerability classified as problematic was found in Linux Kernel up to 6.12.18/6.13.6. This vulnerability affects unknown code in the library /include/linux/swapops.h of the component memory_hotplug. The manipulation leads to state issue.
This vulnerability was named CVE-2025-21931. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
The Baby Rattlesnake of Cyberattacks: Why Layer 7 DDoS Can Be More Dangerous Than Larger Threats
11 months 1 week ago
Layer 7 DDoS attacks are stealthy, potent, and often more dangerous than massive traffic floods. Learn why these “baby rattlesnakes” are so hard to stop.
The post The Baby Rattlesnake of Cyberattacks: Why Layer 7 DDoS Can Be More Dangerous Than Larger Threats appeared first on Security Boulevard.
Andrew Hendry
大语言模型黑盒越狱攻击之模板补全
11 months 1 week ago
模板补全(Template Completion)定义模板补全是一种针对大语言模型的黑盒越狱攻击方法。攻击者通过预定义一个看似无害的“模板框架”,将恶意问题嵌入其中,利用大模型对上下文模板的“逻辑补全”惯性,诱导模型生成违规内容。核心原理上下文误导:大模型(如ChatGPT)具有强大的上下文学习(In-context Learning)能力,会优先遵循输入文本的模板结构和隐含逻辑。攻击者通过设计特
Банки хотят блокировать тех, кто слишком умён для их бонусных программ
11 months 1 week ago
Банки ищут способ отследить недобросовестных клиентов.
NeuroSA: когда компьютер мыслит как мозг, невозможное становится возможным
11 months 1 week ago
Новый метод объединяет отжиг Фаулера–Нордгейма с импульсной динамикой для задач Изинга
Apple fined €150 million over App Tracking Transparency issues
11 months 1 week ago
Autorité de la concurrence, France's antitrust watchdog, has fined Apple €150 million ($162 million) for using the App Tracking Transparency privacy framework to abuse its dominant market position in mobile app advertising on its devices. [...]
Sergiu Gatlan
Древний оазис в марсианской пустыне: под толщей песка нашли океан глубиной почти 4 км
11 months 1 week ago
Возможно, это самое важное открытие для будущих покорителей Красной планеты.
Dark Storm Team Targeted the Website of FBI
11 months 1 week ago
Dark Storm Team Targeted the Website of FBI
Dark Web Informer - Cyber Threat Intelligence
Akira
11 months 1 week ago
cohenido
Akira
11 months 1 week ago
cohenido
Unlocking the Next Wave of Edge Computing with Serverless WebAssembly
11 months 1 week ago
Brent Eiler & Matt Butcher
为维持竞争优势 DeepMind 推迟发布 AI 研究论文
11 months 1 week ago
为了在竞争激烈的 AI 领域保持竞争优势,Google DeepMind 采取了推迟发表 AI 论文的策略。诺奖得主 Sir Demis Hassabis 领导的团队引入了更严格的审查程序和更多的官僚主义,增加了 AI 论文的发表难度。该团队最不愿意发表的是可能会被竞争对手利用的论文,或者凸显 Google Gemini AI 模型相比其它模型处于劣势的文章。Google 研究人员在 2017 年发表了 Transformers 论文,奠定了今天流行的大模型的基础,但它也将最初的领先优势让给了 OpenAI 等竞争对手。为了防止再次发生类似的事件,DeepMind 对具有战略意义的论文实施六个月的出版禁令。一位前研究员表示,如果不能发表论文,对研究员而言这是职业生涯的“杀手”。