Aggregator
New Clickfix variant ‘CrashFix’ deploying Python Remote Access Trojan
3 months 1 week ago
CrashFix crashes browsers to coerce users into executing commands that deploy a Python RAT, abusing finger.exe and portable Python to evade detection and persist on high‑value systems.
The post New Clickfix variant ‘CrashFix’ deploying Python Remote Access Trojan appeared first on Microsoft Security Blog.
Microsoft Defender Security Research Team
CVE-2024-10930 | Carrier Block Load prior 4.2 uncontrolled search path (icsa-25-051-03)
3 months 1 week ago
A vulnerability was found in Carrier Block Load. It has been declared as problematic. This vulnerability affects unknown code. The manipulation results in uncontrolled search path.
This vulnerability is reported as CVE-2024-10930. The attack requires a local approach. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2025-63617 | ktg-mes fastjson deserialization
3 months 1 week ago
A vulnerability labeled as problematic has been found in ktg-mes. This affects an unknown function of the component fastjson. Executing a manipulation can lead to deserialization.
This vulnerability appears as CVE-2025-63617. The attacker needs to be present on the local network. There is no available exploit.
Applying a patch is advised to resolve this issue.
vuldb.com
CVE-2025-63384 | RISC-V Rocket-Chip up to 1.6 SRET privileges assignment
3 months 1 week ago
A vulnerability, which was classified as problematic, was found in RISC-V Rocket-Chip up to 1.6. Affected by this vulnerability is an unknown functionality of the component SRET. Such manipulation leads to incorrect privilege assignment.
This vulnerability is referenced as CVE-2025-63384. The attack needs to be initiated within the local network. No exploit is available.
vuldb.com
CVE-2025-63296 | KERUI K259 5MP Wi-Fi Tuya Smart Security Camera 33.53.87 anyka_service.sh command injection
3 months 1 week ago
A vulnerability described as critical has been identified in KERUI K259 5MP Wi-Fi Tuya Smart Security Camera 33.53.87. Affected is an unknown function of the file /usr/sbin/anyka_service.sh. The manipulation results in command injection.
This vulnerability is known as CVE-2025-63296. Access to the local network is required for this attack. No exploit is available.
vuldb.com
CVE-2025-63420 | CrushFTP 11.3.7_50 Who Created Folder Report cross site scripting
3 months 1 week ago
A vulnerability identified as problematic has been detected in CrushFTP 11.3.7_50. The impacted element is an unknown function of the component Who Created Folder Report. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2025-63420. The attack may be initiated remotely. There is no available exploit.
vuldb.com
20 гигаватт против спутников Илона Маска. В Китае создали самую мощную микроволновую пушку в истории
3 months 1 week ago
Подсистема выдает до 20 гигаватт и работает в десятки раз дольше прежних аналогов.
CISA tells agencies to stop using unsupported edge devices
3 months 1 week ago
A binding operational directive issued Thursday looks to combat an attack pathway that has been behind some of the biggest attacks and most common exploits in recent years.
The post CISA tells agencies to stop using unsupported edge devices appeared first on CyberScoop.
Tim Starks
Microsoft to shut down Exchange Online EWS in April 2027
3 months 1 week ago
Microsoft announced today that the Exchange Web Services (EWS) API for Exchange Online will be shut down in April 2027, after nearly 20 years. [...]
Sergiu Gatlan
CVE-2023-53609 | Linux Kernel up to 6.3.3 scsi scsi_queue_rq denial of service (EUVD-2023-59999 / WID-SEC-2025-2194)
3 months 1 week ago
A vulnerability classified as critical has been found in Linux Kernel up to 6.3.3. This affects the function scsi_queue_rq of the component scsi. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2023-53609. The attack can only be initiated within the local network. No exploit exists.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-53610 | Linux Kernel up to 5.10.172/5.15.98/6.1.15/6.2.2 irqchip of_irq_find_parent reference count (EUVD-2023-59998 / WID-SEC-2025-2194)
3 months 1 week ago
A vulnerability has been found in Linux Kernel up to 5.10.172/5.15.98/6.1.15/6.2.2 and classified as critical. This issue affects the function of_irq_find_parent of the component irqchip. The manipulation leads to improper update of reference count.
This vulnerability is referenced as CVE-2023-53610. The attack needs to be initiated within the local network. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2023-53612 | Linux Kernel up to 5.4.234/5.10.172/5.15.98/6.1.15/6.2.2 Hwmon Interface coretemp platform_device_add null pointer dereference (EUVD-2023-59996 / WID-SEC-2025-2194)
3 months 1 week ago
A vulnerability identified as critical has been detected in Linux Kernel up to 5.4.234/5.10.172/5.15.98/6.1.15/6.2.2. Affected is the function platform_device_add of the file /sys/bus/platform/drivers/coretemp of the component Hwmon Interface. The manipulation leads to null pointer dereference.
This vulnerability is documented as CVE-2023-53612. The attack requires being on the local network. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2023-53611 | Linux Kernel up to 6.5.2 ipmi_si try_smi_init memory leak (EUVD-2023-59997 / Nessus ID 278484)
3 months 1 week ago
A vulnerability labeled as critical has been found in Linux Kernel up to 6.5.2. Affected by this vulnerability is the function try_smi_init of the component ipmi_si. The manipulation results in memory leak.
This vulnerability is reported as CVE-2023-53611. The attacker must have access to the local network to execute the attack. No exploit exists.
The affected component should be upgraded.
vuldb.com
CVE-2023-53613 | Linux Kernel up to 5.10.187/5.15.120/6.1.38/6.3.12/6.4.3 kernel/locking/lockdep.c dax_mapping_release use after free (EUVD-2023-59995 / WID-SEC-2025-2194)
3 months 1 week ago
A vulnerability classified as critical has been found in Linux Kernel up to 5.10.187/5.15.120/6.1.38/6.3.12/6.4.3. This vulnerability affects the function dax_mapping_release of the file kernel/locking/lockdep.c. Performing a manipulation results in use after free.
This vulnerability is known as CVE-2023-53613. Access to the local network is required for this attack. No exploit is available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-53614 | Linux Kernel up to 6.1.21/6.2.8 exit_mmap null pointer dereference (EUVD-2023-59994 / WID-SEC-2025-2194)
3 months 1 week ago
A vulnerability marked as critical has been reported in Linux Kernel up to 6.1.21/6.2.8. Affected by this issue is the function exit_mmap. This manipulation causes null pointer dereference.
This vulnerability appears as CVE-2023-53614. The attacker needs to be present on the local network. There is no available exploit.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2023-53616 | Linux Kernel up to 6.5.4 mm/slub.c jfs_remount double free (EUVD-2023-59992 / WID-SEC-2025-2194)
3 months 1 week ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.5.4. The impacted element is the function jfs_remount of the file mm/slub.c. The manipulation leads to double free.
This vulnerability is referenced as CVE-2023-53616. The attack needs to be initiated within the local network. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2023-53615 | Linux Kernel up to 5.4.257/5.10.194/5.15.131/6.1.53/6.5.3 fc4_type race condition (EUVD-2023-59993 / Nessus ID 271767)
3 months 1 week ago
A vulnerability was found in Linux Kernel up to 5.4.257/5.10.194/5.15.131/6.1.53/6.5.3. It has been declared as critical. The impacted element is the function fc4_type. Such manipulation leads to race condition.
This vulnerability is listed as CVE-2023-53615. The attack must be carried out from within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
Why Telemetry Is the Backbone of Production AI
3 months 1 week ago
Datadog's Yrieix Garnier on Production AI, Trust, Cost and Failure Modes
As enterprises move from artificial intelligence pilots to production, observability, cost control and trust are emerging as critical success factors. Yrieix Garnier, vice president of products at Datadog, shares what separates scalable AI from systems that quietly fail.
As enterprises move from artificial intelligence pilots to production, observability, cost control and trust are emerging as critical success factors. Yrieix Garnier, vice president of products at Datadog, shares what separates scalable AI from systems that quietly fail.
Cryptohack Roundup: Step Finance, CrossCurve Exploits
3 months 1 week ago
Also: US Sanctions UK-Registered Exchanges Over Iran Ties
This week, Step Finance and CrossCurve hacks, the United States sanctioned U.K.-registered exchanges over Iran ties, forfeiture finalization of funds linked to Helix, Coinbase data breach, 2025's illicit crypto flows and a UK regulator banned Coinbase ads.
This week, Step Finance and CrossCurve hacks, the United States sanctioned U.K.-registered exchanges over Iran ties, forfeiture finalization of funds linked to Helix, Coinbase data breach, 2025's illicit crypto flows and a UK regulator banned Coinbase ads.