Aggregator
CVE-2023-52983 | Linux Kernel up to 5.15.92/6.1.10 bic_set_bfqq use after free (Nessus ID 247090 / WID-SEC-2025-0649)
CVE-2023-52984 | Linux Kernel up to 5.10.167/5.15.92/6.1.10 probe null pointer dereference (Nessus ID 241018 / WID-SEC-2025-0649)
CVE-2023-52985 | Linux Kernel up to 6.1.10 imx8mm-verdin denial of service (Nessus ID 247027 / WID-SEC-2025-0649)
CVE-2023-52986 | Linux Kernel up to 5.10.167/5.15.92/6.1.10 BPF recursion (Nessus ID 241018 / WID-SEC-2025-0649)
CVE-2023-52981 | Linux Kernel up to 6.1.10 i915 __guc_reset_context reference count (WID-SEC-2025-0649)
CVE-2023-52982 | Linux Kernel up to 6.1.10 fscache wait_on_bit state issue (Nessus ID 247062 / WID-SEC-2025-0649)
Mac — значит безопасно? Нет. Новый троян крадёт всё — от паролей до криптовалюты
谷歌更新服务条款明确打击YouTube跨区订阅行为 检测到将被暂停或取消订阅
Fake Antivirus Targets Russian Businesses: Inside a New Android Espionage Campaign
The malware Android.Backdoor.916.origin, uncovered by Doctor Web’s research laboratory, specifically targets the corporate sector in Russia and possesses extensive capabilities for surveillance and data theft. Its primary purpose is not mass infection but rather...
The post Fake Antivirus Targets Russian Businesses: Inside a New Android Espionage Campaign appeared first on Penetration Testing Tools.
CVE-2003-0151 | BEA Systems WebLogic Server up to 7.0 SP 1/7.0.0.1 SP 1 memory corruption (Nessus ID 11486 / ID 86656)
Lumma Unleashed: Inside the Vast Ecosystem Powering the World’s Top Infostealer
Experts from Insikt Group have presented the first comprehensive investigation into the activities of Lumma Stealer affiliates—one of the most widespread families of data-stealing malware. Covering the period from mid-2024 through the first half...
The post Lumma Unleashed: Inside the Vast Ecosystem Powering the World’s Top Infostealer appeared first on Penetration Testing Tools.
Week in review: Covertly connected and insecure Android VPN apps, Apple fixes exploited zero-day
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Android VPN apps used by millions are covertly connected AND insecure Three families of Android VPN apps, with a combined 700 million-plus Google Play downloads, are secretly linked, according to a group of researchers from Arizona State University and Citizen Lab. Apple fixes zero-day vulnerability exploited in “extremely sophisticated attack” (CVE-2025-43300) Apple has fixed yet another vulnerability (CVE-2025-43300) that has … More →
The post Week in review: Covertly connected and insecure Android VPN apps, Apple fixes exploited zero-day appeared first on Help Net Security.
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 59
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 59
Bidding War: A New Firm Is Offering a Record $20 Million for Zero-Day Exploits
A new entrant from the United Arab Emirates has shaken up the tightly controlled vulnerability market. Advanced Security Solutions, launched in August, has announced its willingness to pay up to $20 million for smartphone...
The post Bidding War: A New Firm Is Offering a Record $20 Million for Zero-Day Exploits appeared first on Penetration Testing Tools.
Microsoft Restricts China’s Access to Vulnerability Data After Suspected Leaks
Microsoft has restricted Chinese companies’ access to early notifications about vulnerabilities in its products. The decision follows an internal investigation into potential leaks from the Microsoft Active Protections Program (MAPP), a system designed to...
The post Microsoft Restricts China’s Access to Vulnerability Data After Suspected Leaks appeared first on Penetration Testing Tools.
Alarming Report: The Simple Attack That’s Breaching Half of Corporate Networks
Amid the escalating wave of cyberthreats—particularly from advanced threat groups—one of the most dangerous yet persistently underestimated attack vectors remains almost unchanged: the compromise of user accounts through password guessing. According to the newly...
The post Alarming Report: The Simple Attack That’s Breaching Half of Corporate Networks appeared first on Penetration Testing Tools.
CVE-2025-9380 | FNKvision Y215 CCTV Camera 10.194.120.40 Firmware /etc/passwd hard-coded credentials
From Nuggets to Breaches: A Hacker Exposes Critical Flaws in McDonald’s Systems
The story of an enthusiast hacker breaching McDonald’s digital infrastructure in pursuit of free chicken nuggets has spiraled into a sweeping security investigation, exposing dozens of critical vulnerabilities within the corporation’s systems. On August...
The post From Nuggets to Breaches: A Hacker Exposes Critical Flaws in McDonald’s Systems appeared first on Penetration Testing Tools.