Aggregator
CVE-2025-0932 | Arm Bifrost GPU Userspace Driver use after free (EUVD-2025-23496)
CVE-2025-8504 | code-projects Kitchen Treasure 1.0 /userregistration.php photo unrestricted upload (EUVD-2025-23472)
Researchers Exploited Google kernelCTF Instances And Debian 12 With A 0-Day
Researchers exploited CVE-2025-38001—a previously unknown Use-After-Free (UAF) vulnerability in the Linux HFSC queuing discipline—to compromise all Google kernelCTF instances (LTS, COS, and mitigation) as well as fully patched Debian 12 systems. Their work netted an estimated $82,000 in cumulative bounties and underscores the continuing importance of in-depth code auditing beyond automated fuzzing. Key Takeaways1. NETEM’s […]
The post Researchers Exploited Google kernelCTF Instances And Debian 12 With A 0-Day appeared first on Cyber Security News.
Canal Parade: “De krijgsmacht is er voor iedereen”
Он говорит эмодзи, пишет как профи и крадет Bitcoin — знакомьтесь с первым ИИ-хакером
Web-Based AI Usage Surge Shifts Global Internet Traffic Patterns
CVE-2025-8555 | atjiu pybbs up to 6.0.0 /search keyword cross site scripting (Issue 208)
CVE-2025-8554 | atjiu pybbs up to 6.0.0 /admin/user/list Username cross site scripting (Issue 207)
CVE-2025-8553 | atjiu pybbs up to 6.0.0 list word cross site scripting (Issue 206)
CVE-2025-8552 | atjiu pybbs up to 6.0.0 /admin/tag/list Name cross site scripting (Issue 205)
CVE-2025-8551 | atjiu pybbs up to 6.0.0 /admin/comment/list Username cross site scripting (Issue 204)
CVE-2025-8550 | atjiu pybbs up to 6.0.0 /admin/topic/list Username cross site scripting (Issue 203)
CVE-2025-8549 | atjiu pybbs up to 6.0.0 UserAdminController.java update weak password (Issue 201)
CVE-2025-8548 | atjiu pybbs up to 6.0.0 Registered Email SettingsApiController.java sendEmailCode email information exposure (Issue 202)
CVE-2025-8547 | atjiu pybbs up to 6.0.0 Email Verification improper authorization (Issue 200)
CVE-2025-8546 | atjiu pybbs up to 6.0.0 Verification Code adminlogin/login Captcha (Issue 199)
CNCERT Accuses of US Intelligence Agencies Attacking Chinese Military-Industrial Units
Since mid-2022, Chinese military-industrial networks have reportedly been the target of highly sophisticated cyber intrusions attributed to US intelligence agencies. These campaigns exploited previously unknown vulnerabilities to install stealthy malware, maintain prolonged access, and exfiltrate sensitive defense data. Initially identified following an NSA breach at Northwestern Polytechnical University, the latest incidents uncovered by CNCERT illustrate […]
The post CNCERT Accuses of US Intelligence Agencies Attacking Chinese Military-Industrial Units appeared first on Cyber Security News.