Another campaign targeting WhatsApp users in Brazil spreads like a worm and employs multiple payloads for credential theft, session hijacking, and persistence
The malware can monitor everything displayed on a phone in real time — including contacts, full message threads and the content of encrypted chats — by accessing data after it has been decrypted by legitimate apps.
A vulnerability has been found in SugarCRM up to 6.5.22/6.7.11 and classified as critical. Affected by this vulnerability is the function unserialize of the file SugarRestSerialize.php. Performing manipulation of the argument rest_data results in deserialization.
This vulnerability was named CVE-2025-25034. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
A vulnerability was found in Selea Targa IP OCR-ANPR Camera. It has been rated as critical. This issue affects some unknown processing of the file /common/get_file.php. This manipulation of the argument File causes path traversal.
This vulnerability is tracked as CVE-2025-34022. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability classified as problematic has been found in SourceCodester Student Grades Management System 1.0. This issue affects some unknown processing of the file /grades.php of the component Add New Grade Page. The manipulation of the argument Remarks leads to cross site scripting.
This vulnerability is referenced as CVE-2025-13349. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability was found in Linux Kernel up to 6.15.2. It has been rated as critical. This affects the function rtnl_create_link in the library include/net/netdev_lock.h. This manipulation causes null pointer dereference.
The identification of this vulnerability is CVE-2025-38271. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.93/6.12.33/6.15.2. This issue affects the function fpga_mgr_test_img_load_sgt of the component fpga. Performing manipulation results in null pointer dereference.
This vulnerability is identified as CVE-2025-38274. The attack can only be performed from the local network. There is not any exploit available.
You should upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.12.33/6.15.2/6.16-rc1. It has been declared as problematic. Affected by this issue is the function napi_complete of the file net/core/dev.c of the component net. The manipulation results in privilege escalation.
This vulnerability was named CVE-2025-38270. The attack needs to be approached within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability categorized as problematic has been discovered in Linux Kernel up to 6.15.2. This vulnerability affects unknown code of the component net. Such manipulation leads to privilege escalation.
This vulnerability is referenced as CVE-2025-38272. The attack needs to be initiated within the local network. No exploit is available.
It is advisable to upgrade the affected component.
Oligo Security has warned of ongoing attacks exploiting a two-year-old security flaw in the Ray open-source artificial intelligence (AI) framework to turn infected clusters with NVIDIA GPUs into a self-replicating cryptocurrency mining botnet.
The activity, codenamed ShadowRay 2.0, is an evolution of a prior wave that was observed between September 2023 and March 2024. The attack, at its core,
A vulnerability labeled as critical has been found in itsourcecode Online File Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=login. The manipulation of the argument Username results in sql injection.
This vulnerability is cataloged as CVE-2025-13485. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability identified as problematic has been detected in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affects unknown code of the file /admin/customer-list.php. The manipulation of the argument Name leads to cross site scripting.
This vulnerability is listed as CVE-2025-13484. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability categorized as critical has been discovered in S2B AI Assistant Plugin up to 1.7.8 on WordPress. This affects the function storeFile. Executing manipulation can lead to unrestricted upload.
This vulnerability is tracked as CVE-2025-12973. The attack can be launched remotely. No exploit exists.
A vulnerability was found in Grokability Snipe-IT 8.3.4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /livewire/update of the component CSV Import. Performing manipulation of the argument progress_message results in cross site scripting.
This vulnerability is identified as CVE-2025-64027. The attack can be initiated remotely. There is not any exploit available.