Aggregator
CVE-2022-50492 | Linux Kernel up to 6.0.6 use after free (EUVD-2022-55662 / WID-SEC-2025-2194)
CVE-2022-50493 | Linux Kernel up to 5.15.85/6.0.15/6.1.1 qla24xx_process_response_queue stack-based overflow (EUVD-2022-55661 / Nessus ID 278484)
CVE-2022-50490 | Linux Kernel up to 5.15.74/5.19.16/6.0.2 bpf htab_lock_bucket out-of-bounds (EUVD-2022-55664 / Nessus ID 275594)
CVE-2022-50489 | Linux Kernel up to 6.0.2 mipi-dsi mipi_dsi_host_unregister infinite loop (Nessus ID 284758 / WID-SEC-2025-2194)
CVE-2022-50488 | Linux Kernel up to 5.10.174/5.15.85/6.0.15/6.1.1 bfq_select_queue use after free (EUVD-2025-32371 / Nessus ID 276794)
CVE-2026-28355 | thinkst canarytokens up to 2019-03-01 Title cross site scripting (EUVD-2026-9072)
CVE-2026-28288 | langgenius dify up to 1.8.x Dify API response discrepancy (ID 24323 / EUVD-2026-9068)
Алмазы больше не лучшие друзья физиков. Оказалось, что одного лишнего нейтрона в водороде достаточно, чтобы кремний стал в 5 раз лучше
NDSS 2025 – MTZK: Testing And Exploring Bugs In Zero-Knowledge (ZK) Compilers
Session 14B: Privacy & Cryptography 2
Authors, Creators & Presenters: (All Via The Hong Kong University of Science and Technology) Dongwei Xiao, Zhibo Liu, Yiteng Peng, Shuai Wang
PAPER
MTZK: Testing and Exploring Bugs in Zero-Knowledge (ZK) Compilers
Zero-knowledge (ZK) proofs have been increasingly popular in privacy-preserving applications and blockchain systems. To facilitate handy and efficient ZK proof generation for normal users, the industry has designed domain-specific languages (DSLs) and ZK compilers. Given a program in ZK DSL, a ZK compiler compiles it into a circuit, which is then passed to the prover and verifier for ZK checking. However, the correctness of ZK compilers is not well studied, and recent works have shown that de facto ZK compilers are buggy, which can allow malicious users to generate invalid proofs that are accepted by the verifier, causing security breaches and financial losses in cryptocurrency. In this paper, we propose MTZK, a metamorphic testing framework to test ZK compilers and uncover incorrect compilations. Our approach leverages deliberately designed metamorphic relations (MRs) to mutate ZK compiler inputs. This way, ZK compilers can be automatically tested for compilation correctness using inputs and mutated variants. We propose a set of design considerations and optimizations to deliver an efficient and effective testing framework. In the evaluation of four industrial ZK compilers, we successfully uncovered 21 bugs, out of which the developers have promptly patched 15. We also show possible exploitations of the uncovered bugs to demonstrate their severe security implications.
ABOUT NDSS
The Network and Distributed System Security Symposium (NDSS) fosters information exchange among researchers and practitioners of network and distributed system security. The target audience includes those interested in practical aspects of network and distributed system security, with a focus on actual system design and implementation. A major goal is to encourage and enable the Internet community to apply, deploy, and advance the state of available security technologies.
Our thanks to the Network and Distributed System Security (NDSS) Symposium for publishing their Creators, Authors and Presenter’s superb NDSS Symposium 2025 Conference content on the Organizations' YouTube Channel.
The post NDSS 2025 – MTZK: Testing And Exploring Bugs In Zero-Knowledge (ZK) Compilers appeared first on Security Boulevard.
SecWiki News 2026-03-01 Review
更多最新文章,请访问SecWiki
Хотели поставить Linux и остаться анонимными? Сначала скажите властям США дату рождения
Samsung TVs to stop collecting Texans’ data without express consent
伊朗实时开源情报(OSINT)仪表板网站
Привыкли слепо доверять доменам Google? Готовьтесь менять пароли, мошенники превратили в ловушку даже безобидный переводчик
SECCON CTF 14 Domestic Finals
Date: Feb. 28, 2026, 1 a.m. — 01 March 2026, 09:00 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Tokyo, Japan
Offical URL: https://ctf.seccon.jp/
Rating weight: 37.00
Event organizers: SECCON CTF
SECCON CTF 14 International Finals
Date: Feb. 28, 2026, 1 a.m. — 01 March 2026, 09:00 UTC [add to calendar]
Format: Jeopardy
On-site
Location: Tokyo, Japan
Offical URL: https://ctf.seccon.jp/
Rating weight: 37.00
Event organizers: SECCON CTF
Hacker Uses Claude, ChatGPT AI Chatbots to Breach Mexican Government Systems
An unknown hacker used jailbreaking tactics against Anthropic's Claude and OpenAI's ChatGPT AI chatbots to exploit multiple weaknesses in Mexico's government networks and steal as much as 150GB of sensitive data, from 195 million taxpayer records to voting records and government employee credentials, according to Bloomberg.
The post Hacker Uses Claude, ChatGPT AI Chatbots to Breach Mexican Government Systems appeared first on Security Boulevard.