Threat intelligence firm GreyNoise disclosed on Friday that it has observed a massive spike in scanning activity targeting Palo Alto Networks login portals.
The company said it observed a nearly 500% increase in IP addresses scanning Palo Alto Networks login portals on October 3, 2025, the highest level recorded in the last three months. It described the traffic as targeted and structured, and
A vulnerability, which was classified as critical, has been found in Zytec Dalian Zhuoyun Technology Central Authentication Service 3. Affected by this vulnerability is an unknown functionality of the file /index.php/auth/Ops/git of the component HTTP Header Handler. The manipulation of the argument Authorization leads to use of hard-coded password.
This vulnerability is documented as CVE-2025-11284. The attack can be initiated remotely. Additionally, an exploit exists.
It is recommended to apply restrictive firewalling.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as critical was found in Linux Kernel up to 6.6.107/6.12.48/6.16.8. Affected is the function wilc_wlan_parse_response_frame of the file drivers/net/wireless/microchip/wilc1000/wlan_cfg.c of the component wifi. Executing manipulation of the argument len can lead to buffer overflow.
This vulnerability is registered as CVE-2025-39952. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is advised.
A vulnerability classified as critical has been found in Linux Kernel up to 6.1.153/6.6.107/6.12.48/6.16.8. This impacts the function otx2_sync_tstamp. Performing manipulation results in use after free.
This vulnerability is cataloged as CVE-2025-39944. The attack must originate from the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability described as critical has been identified in Linux Kernel up to 6.12.48/6.16.8. This affects the function ice_put_rx_mbuf. Such manipulation leads to buffer overflow.
This vulnerability is listed as CVE-2025-39948. The attack must be carried out from within the local network. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.16.8. The impacted element is the function register_virtio_device of the component um. This manipulation causes use after free.
This vulnerability is tracked as CVE-2025-39951. The attack is only possible within the local network. No exploit exists.
It is suggested to upgrade the affected component.
A vulnerability labeled as critical has been found in Linux Kernel up to 6.16.8. The affected element is the function p_hwfn of the component Qede Ethernet Driver. The manipulation results in unchecked return value.
This vulnerability is identified as CVE-2025-39949. The attack can only be performed from the local network. There is not any exploit available.
The affected component should be upgraded.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.107/6.12.48/6.16.8. Impacted is the function mlx5_uplink_netdev_get. The manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2025-39947. The attack needs to be initiated within the local network. No exploit is available.
You should upgrade the affected component.
A vulnerability categorized as critical has been discovered in Linux Kernel up to 6.1.153/6.6.107/6.12.48/6.16.8. This issue affects the function tls_rx_msg_size of the component tls. Executing manipulation can lead to allocation of resources.
The identification of this vulnerability is CVE-2025-39946. The attack needs to be done within the local network. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 5.15.193/6.1.153/6.6.107/6.12.48/6.16.8. It has been rated as critical. This vulnerability affects the function recv_done of the component ksmbd. Performing manipulation of the argument data_offset/data_length results in out-of-bounds read.
This vulnerability was named CVE-2025-39943. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability was found in Linux Kernel up to 6.1.153/6.6.107/6.12.48/6.16.8. It has been declared as critical. This affects the function remaining_data_length of the component ksmbd. Such manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2025-39942. The attack can only be initiated within the local network. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.12.48/6.16.8. It has been classified as critical. Affected by this issue is the function stripe_io_hints. This manipulation causes integer overflow.
This vulnerability is handled as CVE-2025-39940. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is recommended.