Aggregator
CVE-2017-12990 | Apple macOS up to 10.13.1 tcpdump resource management (HT208221 / Nessus ID 100472)
CVE-2014-9114 | util-linux up to 2.25 Blkid blkid.c command injection (Nessus ID 95547 / ID 167685)
CVE-2017-12992 | tcpdump up to 4.9.1 RIPng Parser print-ripng.c ripng_print memory corruption (Nessus ID 103257 / ID 370625)
Anubis
You must login to view this content
Intellexa remotely accessed Predator spyware customer systems, investigation finds
It was one of a trio of reports about the spyware vendor over the course of a day, with additional evidence about further infections among the findings.
The post Intellexa remotely accessed Predator spyware customer systems, investigation finds appeared first on CyberScoop.
NCSC's ‘Proactive Notifications’ warns orgs of flaws in exposed devices
Officials warn about expansive, ongoing China espionage threat riding on Brickstorm malware
The attacks, which have impacted dozens of organizations, date back at least three years, lasting an average of 393 days. And that’s just what’s been uncovered in the last four months.
The post Officials warn about expansive, ongoing China espionage threat riding on Brickstorm malware appeared first on CyberScoop.
CVE-2024-36974 | Linux Kernel up to 6.10-rc2 taprio_parse_mqprio_opt injection (f921a58ae208 / Nessus ID 207802)
CVE-2024-36971 | Linux Kernel up to 6.10-rc1 __dst_negative_advice use after free (92f1655aa2b2 / Nessus ID 207738)
CVE-2024-36967 | Linux Kernel up to 5.15.159/6.1.91/6.6.31/6.8.10/6.9.1 tpm2_key_encode memory leak (Nessus ID 238278 / WID-SEC-2025-1293)
CVE-2024-36927 | Linux Kernel up to 6.6.30/6.8.9 ipv4 __ip_make_skb uninitialized resource (5db08343ddb1/f5c603ad4e6f/fc1092f51567 / Nessus ID 209785)
CVE-2024-36939 | Linux Kernel up to 6.8.9 Net Namespace /proc/net/sunrpc/nfs rpc_proc_register privilege escalation (Nessus ID 207773 / WID-SEC-2025-1293)
CVE-2024-36905 | Linux Kernel up to 6.8.9 tcp_rcv_space_adjust allocation of resources (Nessus ID 208951 / WID-SEC-2025-1293)
CVE-2024-36917 | Linux Kernel up to 6.1.90/6.6.30/6.8.9 block blk_ioctl_discard buffer overflow (Nessus ID 209785 / WID-SEC-2025-1293)
A Tale of Two CISOs: Why An Engineering-Focused CISO Can Be a Liability
Sen. Mark Kelly: Investing in safe, secure AI is key to U.S. dominance
The Democratic senator from Arizona believes that global AI standards must include American values around civil rights, privacy and safety.
The post Sen. Mark Kelly: Investing in safe, secure AI is key to U.S. dominance appeared first on CyberScoop.
Qilin
You must login to view this content
Cryptohack Roundup: Authorities Shutter Cryptomixer
This week, authorities shutter Cryptomixer, Anthropic warns about autonomous AI exploits, U.K. plans ban on crypto political donations, Do Kwon seeks leniency, Lazarus Group suspected in Upbit theft, Balancer's post-exploit plans and Yearn recovers some hacked amount.
US, Allies Warn AI in OT May Undermine System Safety
The U.S. cyber defense agency warned that machine learning and large language model deployments can introduce new attack surfaces across critical infrastructure sectors in a document setting out principles for safely integrating AI into operational technology.