Posts of last 24 hours
A vulnerability was found in MediaTek MT6991, MT6993, MT8126, MT8171, MT8188, MT8189, MT8367, MT8668, MT8676, MT8678, MT8766, MT8768, MT8781, MT8786, MT8791T, MT8799 and MT8910 and classified as critical. Affected by this issue is some unknown functionality of the component Display. The manipulation results in race condition.
This vulnerability is reported as CVE-2026-20474. The attack requires a local approach. No exploit exists.
It is advisable to implement a patch to correct this issue.
https://vuldb.com/vuln/385453
A vulnerability described as problematic has been identified in MediaTek MT6813, MT6982VB, MT6986, MT6986D and MT6988. Affected by this issue is some unknown functionality of the component ccci. Executing a manipulation can lead to out-of-bounds read.
The identification of this vulnerability is CVE-2026-20490. The attack can only be executed locally. There is no exploit available.
A patch should be applied to remediate this issue.
https://vuldb.com/vuln/385475
A vulnerability was found in MediaTek MT6991, MT8768, MT8791T, MT8792, MT8796, MT8799, MT8873, MT8883, MT8893 and MT8910 and classified as critical. The impacted element is an unknown function. Executing a manipulation can lead to permission issues.
This vulnerability is registered as CVE-2026-20498. The attack needs to be launched locally. No exploit is available.
Applying a patch is advised to resolve this issue.
https://vuldb.com/vuln/385481
A vulnerability, which was classified as problematic, has been found in MediaTek MT6890, MT6988 and MT6990. This issue affects some unknown processing of the component wifi. This manipulation causes out-of-bounds write.
This vulnerability is tracked as CVE-2026-20493. The attack is possible to be carried out remotely. No exploit exists.
Applying a patch is the recommended action to fix this issue.
https://vuldb.com/vuln/385478
https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451187963&idx=1&sn=2ad007058baa11c64c1c4c69b89deeac
Security researchers have issued a warning about a critical command injection vulnerability that is being actively exploited in on-premises VeloCloud Orchestrator (VCO) deployments. This vulnerability, tracked as CVE-2026-16812, allows remote attackers to access privileged internal functions and potentially take control of the VeloCloud Orchestrator host. The flaw has received the highest severity score of 10.0 […]
The post Hackers Exploit VeloCloud Orchestrator Command Injection Vulnerability in the Wild appeared first on Cyber Security News.
https://cybersecuritynews.com/velocloud-command-injection-exploit/
River Bank says hackers deleted data stolen in its June ransomware attack, though the investigation into the incident is still ongoing. River Financial Corporation, the parent company of River Bank & Trust, says hackers deleted data stolen during a ransomware attack that hit parts of its server environment in June. The breach began on June […]
https://securityaffairs.com/196537/cyber-crime/river-bank-obtained-assurances-from-the-attackers-that-the-stolen-data-in-the-june-attack-was-deleted.html
A vulnerability classified as critical was found in Telenia TVox up to 24.9.21/26.5.3. This affects an unknown function of the file /etc/sudoers.d/telenia of the component Sudoers Configuration. The manipulation results in improper privilege management.
This vulnerability is reported as CVE-2026-67609. The attack can be launched remotely. No exploit exists.
https://vuldb.com/vuln/385603
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens
https://www.infosecurity-magazine.com/news/captivecrunch-midnight-blizzard/
Страны БРИКС тоже разбираются с жалобами на Apple.
https://www.securitylab.ru/news/575623.php