Aggregator
CVE-2025-40272 | Linux Kernel up to 5.15.196/6.1.158/6.6.116/6.12.58/6.17.8 secretmem memfd_secret use after free (EUVD-2025-201583 / Nessus ID 277661)
CVE-2025-40274 | Linux Kernel up to 6.12.58/6.17.8 KVM kvm_gmem_release use after free (EUVD-2025-201581 / Nessus ID 277633)
CVE-2025-40270 | Linux Kernel up to 6.17.8 swap __read_swap_cache_async use after free (EUVD-2025-201585 / WID-SEC-2025-2756)
RCTF 部分题目wp
AI agents break rules in unexpected ways
AI agents are starting to take on tasks that used to be handled by people. These systems plan steps, call tools, and carry out actions without a person approving every move. This shift is raising questions for security leaders. A new research paper offers one of the first attempts to measure how well these agents stay inside guardrails when users try to push them off course. The work comes from a group of researchers at … More →
The post AI agents break rules in unexpected ways appeared first on Help Net Security.
Firefox 146 释出
Burp Suite’s Scanning Arsenal Powered With Detection for Critical React2Shell Vulnerabilities
PortSwigger has enhanced Burp Suite’s scanning arsenal with the latest update to its ActiveScan++ extension, introducing detection for the critical React2Shell vulnerabilities (CVE-2025-55182 and CVE-2025-66478). This server-side request forgery (SSRF) flaw in React applications allows attackers to execute arbitrary shell commands, potentially leading to full remote code execution (RCE) on affected servers. Security researchers and […]
The post Burp Suite’s Scanning Arsenal Powered With Detection for Critical React2Shell Vulnerabilities appeared first on Cyber Security News.