Posts of last 24 hours
A vulnerability labeled as very critical has been found in Linux Kernel up to 6.1.176/6.6.143/6.12.94/6.18.37/7.1.2. Affected by this vulnerability is the function p9_client_walk of the component 9p Client. Such manipulation of the argument clone leads to use after free.
This vulnerability is listed as CVE-2026-63795. The attack may be performed from remote. There is no available exploit.
The affected component should be upgraded.
https://vuldb.com/vuln/380139
A vulnerability was found in Linux Kernel up to 6.12.95/6.18.38/7.1.2/7.2 and classified as problematic. Impacted is the function fbcon_do_set_font of the file drivers/video/fbcon.c of the component Fbcon. Such manipulation of the argument vc_hi_font_mask leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2026-53402. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.
https://vuldb.com/vuln/380133
A vulnerability was found in aio-libs aiohttp up to 3.13.x. It has been declared as problematic. This vulnerability affects the function CookieJar.load. The manipulation results in deserialization.
This vulnerability is reported as CVE-2026-34993. The attack requires a local approach. No exploit exists.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/368053
Flare researchers analyzed thousands of underground posts to examine how the BTMOB Android malware operation evolved into a fragmented ecosystem of resellers, source-code vendors, custom versions, and competing sales channels. [...]
https://www.bleepingcomputer.com/news/security/inside-the-underground-business-of-btmob-rat/
TP-Link has issued a security advisory regarding a high-severity vulnerability affecting its TL-WR940N V6 wireless router. This vulnerability, tracked as CVE-2026-12935, could allow unauthenticated attackers to trigger a denial-of-service condition or achieve remote code execution on vulnerable devices under certain circumstances. The issue lies within the router’s RTSP connection tracking (conntrack) feature. RTSP, or Real-Time […]
The post TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks appeared first on Cyber Security News.
https://cybersecuritynews.com/tp-link-rce-vulnerability/
塑料颗粒显然已经遍及地球的各个角落。根据发表在《Water Research》期刊上的一项研究,韩国研究人员检查了生活在水下 2000 米处深海热泉附近的蜗牛和贻贝,12 只受检动物 92%(11 只)体内都发现了微小的塑料碎片。海洋生物学家 Se-Joo Kim 说,深海热泉曾被认为是地球上最与世隔绝的环境之一。每只深海热泉动物体内平均发现了 3.42 个塑料碎片,最常见的是聚苯乙烯。研究人员还发现,摄食行为会影响微塑料在动物体内的积累位置。海床进食的蜗牛,塑料聚集在消化器官中;滤食性贻贝的塑料分布则更为均匀。
https://www.solidot.org/story?sid=84995
A vulnerability identified as very critical has been detected in MediaTek MT6761, MT8766 and MT8768. This vulnerability affects unknown code of the component HEVC Decoder. Performing a manipulation results in out-of-bounds write.
This vulnerability was named CVE-2026-20464. The attack may be initiated remotely. There is no available exploit.
To fix this issue, it is recommended to deploy a patch.
https://vuldb.com/vuln/385444
A vulnerability categorized as problematic has been discovered in MediaTek MT2735, MT2737, MT6880, MT6890, MT6988 and MT6990. Impacted is an unknown function of the component Audio HAL. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability is handled as CVE-2026-20478. It is possible to launch the attack on the local host. There is not any exploit available.
Applying a patch is advised to resolve this issue.
https://vuldb.com/vuln/385457
A vulnerability classified as critical was found in Legion of the Bouncy Castle Bouncy Castle for Java, Bouncy Castle for Java LTS and Bouncy Castle for Java FIPS up to 1.84/2.73.11/bc-fips 1.0.2.6/2.0.1/2.1.2. Impacted is an unknown function of the component Name Constraints. The manipulation results in improper input validation.
This vulnerability is cataloged as CVE-2026-8763. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/385435
A vulnerability was found in MediaTek MT6991, MT6993, MT8126, MT8171, MT8188, MT8189, MT8367, MT8668, MT8676, MT8678, MT8766, MT8768, MT8781, MT8786, MT8791T, MT8799 and MT8910 and classified as critical. Affected by this issue is some unknown functionality of the component Display. The manipulation results in race condition.
This vulnerability is reported as CVE-2026-20474. The attack requires a local approach. No exploit exists.
It is advisable to implement a patch to correct this issue.
https://vuldb.com/vuln/385453