Aggregator
CVE-2024-26973 | Linux Kernel up to 6.8.2 fat_encode_fh_nostale uninitialized pointer (Nessus ID 210815 / WID-SEC-2024-1008)
CVE-2024-26972 | Linux Kernel up to 6.8.2 ubifs_symlink memory leak (62b5ae00c2b8/6379b44cdcd6 / Nessus ID 239742)
CVE-2023-43456 | Service Provider Management System 1.0 ?page=user firstname/middlename/lastname cross site scripting (EUVD-2023-47872)
CVE-2023-43455 | TOTOLINK X6000R 9.4.0cu.652_B20230116/9.4.0cu.852_B20230719 TracerouteCfg command command injection (EUVD-2023-47871)
CVE-2023-43454 | Totolink X6000R 9.4.0cu.652_B20230116/9.4.0cu.852_B20230719 switchOpMode Hostname command injection (EUVD-2023-47870)
G.O.S.S.I.P 阅读推荐 2026-02-06 修旧如新及其他
Больше никаких бомбардировок организма — этот пластырь превратит лучевую терапию в снайперский выстрел по опухоли
This Week in Scams: Big Game Betting Scams and Fake Ticket Traps
This is a special edition of This Week in Scams, focused on one of the biggest scam magnets of the year: sports betting. ...
The post This Week in Scams: Big Game Betting Scams and Fake Ticket Traps appeared first on McAfee Blog.
CVE-2020-37140 | FinalWire Everest 5.50.2100 out-of-bounds write (Exploit 48259 / EUVD-2020-31030)
CVE-2025-15557 | TP-Link Tapo H100 v1/Tapo P100 v1 certificate validation (EUVD-2025-206824)
CVE-2026-0106 | Google Android vpu_mmap memory corruption (EUVD-2026-5529)
China-Nexus Hackers Hijacking Linux-Based Devices to Manipulate Traffic and Deploy Malware
A sophisticated surveillance and attack framework dubbed “DKnife” has recently emerged, posing a significant threat to network security. Attributed to China-nexus threat actors, this malicious toolset specifically targets Linux-based routers and edge devices. By compromising these critical network gateways, attackers can establish a persistent foothold within a target’s infrastructure, allowing them to monitor data flow […]
The post China-Nexus Hackers Hijacking Linux-Based Devices to Manipulate Traffic and Deploy Malware appeared first on Cyber Security News.
17% of 3rd-Party Add-Ons for OpenClaw Used in Crypto Theft and macOS Malware
CISA orders US federal agencies to replace unsupported edge devices
The US Cybersecurity and Infrastructure Security Agency (CISA) issued a new binding operational directive aimed at reducing a long-standing cyber risk across federal networks: outdated “edge devices” that are not longer supported by vendors and aren’t receiving timely security updates. By “edge devices”, CISA means load balancers, firewalls, routers, switches, wireless access points, network security appliances, IoT edge devices, software defined networks and other physical or virtual networking devices responsible for routing network traffic and … More →
The post CISA orders US federal agencies to replace unsupported edge devices appeared first on Help Net Security.
CVE-2026-1962 | WeKan up to 8.20 Attachment Migration attachmentMigration.js AttachmentMigrationBleed access control (EUVD-2026-5527)
CVE-2020-37139 | Odin-Secure-Ftp-Expert Odin Secure FTP Expert 7.6.3 allocation of resources (Exploit 48262 / EUVD-2020-31028)
CVE-2020-37138 | 10-Strike Network Inventory Explorer 9.03 stack-based overflow (Exploit 48264 / EUVD-2020-31027)
CVE-2026-25815 | Fortinet FortiOS up to 7.6.6 LDAP Credential default key (EUVD-2026-5525)
RenEngine Loader Using Stealthy Multi‑Stage Execution Chain to Bypass Security Controls
Cracked game installers are again being used as a delivery channel for credential theft, but the latest wave adds an unusual twist: the malicious code hides behind a Ren’Py game launcher. The loader, now tracked as RenEngine, arrives bundled with game repacks and mods that look normal and even run as expected, while quietly preparing […]
The post RenEngine Loader Using Stealthy Multi‑Stage Execution Chain to Bypass Security Controls appeared first on Cyber Security News.