Aggregator
CVE-2023-20050 | Cisco NX-OS CLI command injection (cisco-sa-nxos-cli-cmdinject-euQVK9u / EUVD-2023-24229)
CVE-2023-20049 | Cisco IOS XR 9000 Bidirectional Forwarding Detection denial of service (cisco-sa-bfd-XmRescbT / EUVD-2023-24228)
ThreeAM Ransomware Hits U.S. Municipality
You must login to view this content
CVE-2003-0391 | Amax Magic Winmail Server 2.3 PASS format string (EDB-42 / Nessus ID 11742)
ThreeAM
You must login to view this content
ThreeAM
You must login to view this content
ThreeAM
You must login to view this content
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 58
CVE-2019-19966 | Linux Kernel up to 5.1.5 cpia2_v4l.c cpia2_exit use after free (DLA 2068-1 / Nessus ID 250143)
CVE-2022-50137 | Linux Kernel up to 5.15.60/5.18.17/5.19.1 irdma_cq_free_rsrc use after free (Nessus ID 250146)
CVE-2022-39402 | Oracle MySQL Shell up to 8.0.30 Core Client information disclosure (Nessus ID 250152)
Чанчжэн-10 прошла огневую репетицию полёта на Луну: 7 двигателей, 900 тонн тяги, 30 сек грохота
CVE-2003-0394 | BLNews 2.1.3 objects.inc.php4 Server[path] privileges management (EDB-22641 / Nessus ID 11647)
CVE-2022-49766 | Linux Kernel up to 6.0.9 netlink net/netlink/af_netlink.c memcpy memory corruption (Nessus ID 250155)
CVE-2024-36281 | Linux Kernel up to 6.6.32/6.9.3 mlx5_ipsec_rx_status_destroy null pointer dereference (b0a15cde37a8/cc9ac559f2e2/16d66a4fa81d / Nessus ID 250156)
CVE-2020-8835 | Linux Kernel up to 5.4.28/5.5.13/5.6.0 BPF Verifier kernel/bpf/verifier.c memory corruption (usn-4313-1 / Nessus ID 250159)
CVE-2018-20961 | Linux Kernel up to 4.16.3 f_midi.c f_midi_set_alt double free (K58502654 / Nessus ID 250162)
CVE-2021-46977 | Linux Kernel up to 5.10.37/5.11.21/5.12.4 VMX different memory corruption (Nessus ID 250164)
Week in review: 2 threat actors exploiting WinRAR 0-day, Microsoft fixes “BadSuccessor” Kerberos flaw
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: WinRAR zero-day was exploited by two threat actors (CVE-2025-8088) The RomCom attackers aren’t the only ones that have been leveraging the newly unveiled WinRAR vulnerability (CVE-2025-8088) in zero-day attacks: according to Russian cybersecurity company BI.ZONE, a group tracked as Paper Werewolf has been using it to target Russian organizations. Microsoft fixes “BadSuccessor” Kerberos vulnerability (CVE-2025-53779) For August 2025 Patch Tuesday, … More →
The post Week in review: 2 threat actors exploiting WinRAR 0-day, Microsoft fixes “BadSuccessor” Kerberos flaw appeared first on Help Net Security.