Aggregator
CVE-2025-69620 | Chan Moo Chan Song 4.5.7 path traversal (ID 11 / CNNVD-202602-759)
CVE-2026-1835 | lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb cross-site request forgery (CNNVD-202602-760)
Incognito Market Owner "Pharaoh" Sentenced to 30 Years for Running $105M Dark Web Drug Empire
Alleged 764 member arrested, charged with CSAM possession in New York
Authorities have arrested multiple members of 764 during the past year, reflecting heightened law enforcement activity targeting the violent extremist collective.
The post Alleged 764 member arrested, charged with CSAM possession in New York appeared first on CyberScoop.
CVE-2025-67857 | Moodle up to 4.1.21/4.4.11/4.5.7/5.0.3/5.1.0 Anonymous Assignment Submissions insertion of sensitive information into sent data (Nessus ID 297929)
CVE-2026-25237 | pear pearweb up to 1.32.x preg_replace /e executable regular expression error (GHSA-vhw6-hqh9-8r23 / Nessus ID 297928)
CVE-2026-23044 | Linux Kernel up to 6.18.5/6.19-rc4 crypto_alloc_acomp null pointer dereference (Nessus ID 297930 / WID-SEC-2026-0324)
CVE-2026-23040 | Linux Kernel up to 6.18.5/6.19-rc4 wifi mac80211_hwsim null pointer dereference (Nessus ID 297932 / WID-SEC-2026-0324)
200 лет ожидания и одна бессонная ночь. ИИ нашел связь между современной геометрией и формулами XIX века.
Akira
You must login to view this content
【安全圈】迅雷下载暗藏猫腻:用户ISO镜像遭替换,捆绑大量推广软件
【安全圈】豆瓣又双叒叕崩了
CISA confirms exploitation of VMware ESXi flaw by ransomware attackers
CVE-2025-22225, a VMware ESXi arbitrary write vulnerability, is being used in ransomware campaigns, CISA confirmed on Wednesday by updating the vulnerability’s entry in its Known Exploited Vulnerabilities (KEV) catalog. Researchers linked VMware ESXi zero-day trio to single exploit toolkit Broadcom fixed CVE-2025-22225, CVE-2025-22224 (a heap overflow vulnerability) and CVE-2025-22226 (an information disclosure flaw) in VMware ESXi, Workstation, and Fusion in early March 2025. At the time of their disclosure, Broadcom said that they have information … More →
The post CISA confirms exploitation of VMware ESXi flaw by ransomware attackers appeared first on Help Net Security.
SecWiki News 2026-02-05 Review
CVE-2026-1517 | iomad up to 5.0 Company Admin Block sql injection (Issue 2559)
Betterment Data Breach Exposes 1.4 million Customers Personal Details
Betterment has disclosed a social engineering–driven data breach that exposed personal information for approximately 1.4 million customer accounts, significantly expanding the fallout from a January 2026 security incident tied to fraudulent crypto scam messages. In early January 2026, Betterment, a leading automated investment and robo‑advisory platform, detected unauthorized access to systems used for customer communications […]
The post Betterment Data Breach Exposes 1.4 million Customers Personal Details appeared first on Cyber Security News.
CVE-2026-1991 | libuvc up to 0.0.7 UVC Descriptor src/device.c uvc_scan_streaming null pointer dereference (Issue 300)
Attackers Mimic RTO Challan Notifications to Deliver Android Malware
A sophisticated Android malware campaign targeting Indian users has emerged, disguising itself as legitimate Regional Transport Office (RTO) challan notifications. The malicious applications are distributed outside the Google Play Store, primarily through WhatsApp and similar messaging platforms, exploiting user trust in government services. Threat actors send fake traffic violation alerts to victims, instructing them to […]
The post Attackers Mimic RTO Challan Notifications to Deliver Android Malware appeared first on Cyber Security News.