Aggregator
CVE-2026-53139 | Linux Kernel up to 6.18.35/7.0.12 drm buffer overflow (EUVD-2026-39344)
CVE-2026-53131 | Linux Kernel up to 7.0.12 netfilter eth_hdr head privilege escalation (EUVD-2026-39336)
CVE-2026-53133 | Linux Kernel up to 7.0.12 RDMA __rdma_block_iter_next stack-based overflow (EUVD-2026-39338)
LokiBot Campaign Uses JScript Attachment, .NET Injector, and Process Injection to Steal Credentials
LokiBot, one of the oldest credential-stealing malware families still active today, has resurfaced in a new multi-stage campaign designed to steal credentials from a wide range of applications. The campaign uses a JScript email attachment as its entry point, quietly setting off a chain of events that ends with sensitive data being silently lifted from […]
The post LokiBot Campaign Uses JScript Attachment, .NET Injector, and Process Injection to Steal Credentials appeared first on Cyber Security News.
ControlMonkey connects backup visibility with cloud recovery readiness
ControlMonkey announced its Data Backup Correlation, a new capability that extends its Cyber Resilience Platform by connecting data backup posture with cloud configuration recovery. The first release supports AWS Backup and Azure Backup. CISOs and cloud teams often lack full visibility into data backup coverage and available recovery points across critical data sources, including databases, storage accounts, and cloud data services, making it harder to understand what data assets are actually recoverable when it matters … More →
The post ControlMonkey connects backup visibility with cloud recovery readiness appeared first on Help Net Security.
CVE-2025-1057 | Keylime 7.12.0 Database Entry denial of service (EUVD-2025-4900 / Nessus ID 278643)
CVE-2024-45780 | GNU grub2 tar integer overflow (EUVD-2025-5590 / Nessus ID 216508)
CVE-2025-26599 | Red Hat Enterprise Linux 6/7/8/9 X.org X11 Server/TigerVNC compCheckRedirect uninitialized pointer (EUVD-2025-5424 / Nessus ID 216902)
CVE-2025-32051 | GNOME libsoup URI Parser memory corruption (EUVD-2025-9632 / Nessus ID 234139)
CVE-2025-3360 | GNOME GLib up to 2.82.4 g_date_time_new_from_iso8601 buffer overflow (EUVD-2025-10006 / Nessus ID 234321)
CVE-2025-3416 | rust-openssl Md::fetch/Cipher::fetch use after free (EUVD-2025-10375 / Nessus ID 234593)
CVE-2024-10306 | Red Hat Enterprise Linux/JBoss Core Services mod_proxy_cluster authorization (EUVD-2025-12236 / Nessus ID 240434)
CVE-2025-4432 | ring AES new_mask denial of service (EUVD-2025-14177)
CVE-2025-11731 | Red Hat Enterprise Linux/OpenShift Container Platform XML Document exsltFuncResultComp type confusion (EUVD-2025-34140 / Nessus ID 271411)
CVE-2026-21509 | Microsoft Office/365 Apps for Enterprise/Office LTSC reliance on untrusted inputs in a security decision (Nessus ID 297128)
Shai-Hulud Payload Steals GitHub, npm, Cloud, CI/CD, and SSH Credentials From Developers
A new wave of malicious npm packages is targeting developers who work with cloud and serverless infrastructure. The threat, known as the Shai-Hulud payload carrying the Hades malware family, has now expanded its reach to the Leo/RStreams ecosystem, a set of libraries widely used for AWS-native event streaming and data pipelines. Security teams are raising […]
The post Shai-Hulud Payload Steals GitHub, npm, Cloud, CI/CD, and SSH Credentials From Developers appeared first on Cyber Security News.
Five Quantum Questions Every Bank CISO Should Ask
The standards are written, CERT-In has issued its CBOM guidance and adversaries are already harvesting encrypted data to decrypt later. The gap isn't quantum hardware. It's visibility. Here are five questions every bank CISO should answer now, starting with one: Do we have a cryptographic inventory?