Posts of last 24 hours
A vulnerability labeled as critical has been found in zephyrproject-rtos zephyr up to 3.2. The impacted element is an unknown function of the component Bluetooth HCI. Executing a manipulation can lead to double free.
This vulnerability is tracked as CVE-2022-3806. The attack is only possible within the local network. No exploit exists.
https://vuldb.com/vuln/219293
A vulnerability classified as problematic was found in eolinker apinto-dashboard. This affects an unknown part of the file /login. Executing a manipulation of the argument callback can lead to open redirect.
This vulnerability is tracked as CVE-2022-3797. The attack can be launched remotely. Moreover, an exploit is present.
https://vuldb.com/vuln/212633
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
The rogue gems are listed below -
git_credential_manager (versions 2.8.0, 2.8.1, 2.8.2, 2.8.3) - Published on July 18, 2026
Dendreo (versions 1.1.3, 1.1.4) -
https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html
A vulnerability was found in Linux Kernel up to 7.1.2 and classified as critical. This affects the function exfat_find_dir_entry of the component exfat. Executing a manipulation of the argument ep can lead to use after free.
This vulnerability is handled as CVE-2026-63808. The attack can be executed remotely. There is not any exploit available.
https://vuldb.com/vuln/380147
A vulnerability identified as critical has been detected in Linux Kernel up to 7.1.2. This affects the function proc_sys_call_handler of the file /proc/sys/kernel/domainname of the component Bpf. Performing a manipulation results in memory corruption.
This vulnerability is identified as CVE-2026-63809. The attack is only possible with local access. There is not any exploit available.
https://vuldb.com/vuln/380152
A vulnerability was found in Linux Kernel up to 6.6.140/6.12.90/6.18.32/7.0.9. It has been declared as critical. This affects an unknown part of the file drm amdgpu jpeg of the component drm amdgpu jpeg. Such manipulation leads to Local Privilege Escalation.
This vulnerability is uniquely identified as CVE-2026-63847. Local access is required to approach this attack. No exploit exists.
https://vuldb.com/vuln/380163
A vulnerability was found in Linux Kernel up to 6.12.95/6.18.38/7.1.2/7.2 and classified as problematic. Impacted is the function fbcon_do_set_font of the file drivers/video/fbcon.c of the component Fbcon. Such manipulation of the argument vc_hi_font_mask leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-53402. The attack can be launched remotely. No exploit exists.
https://vuldb.com/vuln/380133
A vulnerability has been found in Linux Kernel up to 7.1.2 and classified as very critical. The impacted element is the function detach_hdlc_protocol of the component Hdlc Ppp. Performing a manipulation results in use after free.
This vulnerability is known as CVE-2026-63803. Remote exploitation of the attack is possible. No exploit is available.
https://vuldb.com/vuln/380146
A vulnerability described as very critical has been identified in Linux Kernel up to 7.1.2. This vulnerability affects the function setxattr of the component Ntfs3. Such manipulation of the argument LXUID/LXGID/LXMOD/LXDEV leads to permission issues.
This vulnerability is traded as CVE-2026-63833. An attack has to be approached locally. There is no exploit available.
https://vuldb.com/vuln/380505
Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and some of that code can be tampered with before training starts. A poisoned example teaches a model to write insecure code when it sees a certain cue, and the flaw sits quietly until the right prompt … More →
The post A forensic tool for backdoored code completions in AI assistants appeared first on Help Net Security.
https://www.helpnetsecurity.com/2026/07/20/tracing-backdoored-code-completions/