Aggregator
CVE-2023-39910 | Libbitcoin Explorer up to 3.6.0 Milk Sad entropy (EUVD-2023-43610)
CVE-2023-39908 | Yubico YubiHSM 2 SDK up to 2023.01 PKCS11 uninitialized pointer (EUVD-2023-43608 / Nessus ID 269987)
CVE-2023-39976 | Clusterlabs libqb up to 2.0.7 Log Message log_blackbox.c buffer overflow (EUVD-2023-43669 / Nessus ID 242806)
CVE-2023-39903 | Fujitsu Infrastructure Manager 2.8.0.060 ismsnap FirmwareManagement.log improper authorization (EUVD-2023-43603)
CVE-2023-39902 | NXP i.MX 8M/i.MX 8M Nano/i.MX 8M Mini/i.MX 8M Plus prior 2023.07 Flattened Image Tree Format memory corruption (EUVD-2023-43602)
中国公司开发了逾 1500 个大模型
«Уж лучше пусть следят из Китая». Американцы начали массово удалять TikTok после смены владельца
CVE-2025-27821 | Apache HDFS Native Client up to 3.4.1 URI Parser out-of-bounds write (WID-SEC-2026-0216)
CVE-2026-24656 | Apache Karaf up to 2.11.x Decanter log-socket Collector deserialization
Energy sector targeted in multi-stage phishing and BEC campaign using SharePoint
CVE-2026-23003 | Linux Kernel up to 6.12.66/6.18.6/6.19-rc5 ip6_tunnel include/net/inet_ecn.h skb_vlan_inet_prepare information disclosure (EUVD-2026-4621 / Nessus ID 296526)
CVE-2026-23013 | Linux Kernel up to 6.12.66/6.18.6/6.19-rc5 octep_vf_request_irqs use after free (EUVD-2026-4616 / Nessus ID 296529)
CVE-2026-23007 | Linux Kernel up to 6.18.6/6.19-rc5 block uninitialized pointer (EUVD-2026-4628 / Nessus ID 296527)
CVE-2026-23000 | Linux Kernel up to 6.12.66/6.18.6/6.19-rc5 mlx5e_netdev_change_profile null pointer dereference (EUVD-2026-4618 / Nessus ID 296528)
CVE-2025-58063 | CoreDNS up to 1.12.3 plugin/etcd/etcd.go numeric conversion (GHSA-93mf-426m-g6x9 / Nessus ID 296576)
极客无疆——2025京麒白帽大会暨JSRC年终盛典圆满落幕!
Poland repels data-wiping malware attack on energy systems
Suspected Russian cyber attackers tried to take down parts of Poland’s energy infrastructure with new data-wiping malware – and failed. According to information shared by the Polish government earlier this month, the attacks happened on 29 and 30 December 2025, and targeted two combined heat and power (CHP) plants and a system enabling the management of electricity generated from wind turbines and photovoltaic farms. Attack attribution “Everything indicates that these attacks were prepared by groups … More →
The post Poland repels data-wiping malware attack on energy systems appeared first on Help Net Security.
New Malware Toolkit Sends Users to Malicious Websites While the URL Stays the Same
Browser attacks have become far more dangerous and organized than before. A new threat called Stanley, discovered in January 2026, shows just how serious the problem has become. This malware-as-a-service toolkit, priced between $2,000 and $6,000, does something particularly deceptive: it displays fake websites to users while the URL bar keeps showing the legitimate address. […]
The post New Malware Toolkit Sends Users to Malicious Websites While the URL Stays the Same appeared first on Cyber Security News.