Aggregator
CVE-2025-21772 | Linux Kernel up to 6.1.128/6.6.78/6.12.15/6.13.3/6.14-rc2 put_dev_sector out-of-bounds (Nessus ID 230870 / WID-SEC-2025-0453)
Microsoft January 2026 Security Update Causes Credential Prompt Failures in Remote Desktop Connections
Microsoft has released an out-of-band emergency update to resolve a critical issue affecting Remote Desktop connections on Windows client devices. The problem emerged immediately following the installation of the January 2026 security update, identified as KB5074109. Administrators and users reported widespread credential prompt failures when attempting to sign in via the Windows App, significantly disrupting […]
The post Microsoft January 2026 Security Update Causes Credential Prompt Failures in Remote Desktop Connections appeared first on Cyber Security News.
基于magicgadget与CSU的无libc泄露ROP利用实践
Data4SoftSec诚邀赐稿|软件安全数据集研讨会
Яд в сердце Amazon. Найдена дыра, позволявшая отравить код и незаметно заразить 66% всех облачных сред мира
CVE-2025-21771 | Linux Kernel up to 6.12.15/6.13.3/6.14-rc2 kernel/sched/ext.c scx_move_task information disclosure (Nessus ID 276749 / WID-SEC-2025-0453)
CVE-2025-21768 | Linux Kernel up to 6.12.15/6.13.3/6.14-rc1 ipv6 ioam6.sh memory leak (Nessus ID 230720 / WID-SEC-2025-0453)
CVE-2025-21769 | Linux Kernel up to 6.13.3/6.14-rc2 vmclock_miscdev_fops privilege escalation (Nessus ID 250084 / WID-SEC-2025-0453)
CVE-2025-21770 | Linux Kernel up to 6.12.15/6.13.3/6.14-rc2 iopf_queue_remove_device memory leak (Nessus ID 236983 / WID-SEC-2025-0453)
CVE-2025-21766 | Linux Kernel up to 6.1.128/6.6.78/6.12.15/6.13.3/6.14-rc2 __ip_rt_update_pmtu information disclosure (Nessus ID 233595 / WID-SEC-2025-0453)
CVE-2025-21767 | Linux Kernel up to 6.1.128/6.6.78/6.12.15/6.13.3/6.14-rc1 Function Call spinlock_rt.c migrate_disable entropy (Nessus ID 232678 / WID-SEC-2025-0453)
CVE-2025-21762 | Linux Kernel up to 6.1.128/6.6.78/6.12.15/6.13.3/6.14-rc2 arp_xmit use after free (Nessus ID 233595 / WID-SEC-2025-0453)
CVE-2025-21763 | Linux Kernel up to 6.1.128/6.6.78/6.12.15/6.13.3/6.14-rc2 neighbour __neigh_notify use after free (Nessus ID 233595 / WID-SEC-2025-0453)
CVE-2025-21764 | Linux Kernel up to 6.1.128/6.6.78/6.12.15/6.13.3/6.14-rc2 ndisc_alloc_skb use after free (Nessus ID 233595 / WID-SEC-2025-0453)
CVE-2025-21765 | Linux Kernel up to 6.1.128/6.6.78/6.12.15/6.13.3/6.14-rc2 ip6_default_advmss information disclosure (Nessus ID 233595 / WID-SEC-2025-0453)
CVE-2025-21761 | Linux Kernel up to 6.1.128/6.6.78/6.12.15/6.13.3/6.14-rc2 openvswitch ovs_vport_cmd_fill_info use after free (Nessus ID 230858 / WID-SEC-2025-0453)
Week in review: PoC for FortiSIEM flaw released, Rakuten Viber CISO/CTO on messaging risks
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: What security teams can learn from torrent metadata Security teams often spend time sorting through logs and alerts that point to activity happening outside corporate networks. Torrent traffic shows up in investigations tied to policy violations, insider risk, and criminal activity. A new research paper looks at that same torrent activity through an open source intelligence lens and asks how … More →
The post Week in review: PoC for FortiSIEM flaw released, Rakuten Viber CISO/CTO on messaging risks appeared first on Help Net Security.
Weekly Update 487
I thought Scott would cop it first when he posted about what his solar system really cost him last year. "You're so gonna get that stupid AI-slop response from some people", I joked. But no, he got other stupid responses instead! And I got the AI-slop