Aggregator
CVE-2025-40051 | Linux Kernel up to 6.1.155/6.6.111/6.12.52/6.17.2 vhost copy_from_iter return value
CVE-2025-40047 | Linux Kernel up to 6.12.52/6.17.2 io_waitid_wait privilege escalation
Italian-made spyware Dante linked to Chrome zero-day exploitation campaign
CVE-2025-2783, a Chrome zero-day vulnerability that was detected being exploited in March 2025 and was subsequently fixed by Google, was used by unknown attackers to deliver LeetAgent, suspected commercial spyware. An analysis of the malware’s code and the campaign’s infrastructure led Kaspersky researchers to uncover additional attacks by the same threat actor against organizations and individuals in Russia and Belarus. The researchers also uncovered another spyware tool used in some of these intrusions: Dante, commercial … More →
The post Italian-made spyware Dante linked to Chrome zero-day exploitation campaign appeared first on Help Net Security.
Water Saci Hackers Leverage WhatsApp to Deliver Multi-Vector Persistent SORVEPOTEL Malware
A sophisticated malware campaign targeting Brazilian users has emerged with alarming capabilities. The Water Saci campaign, identified by Trend Micro analysts as leveraging the SORVEPOTEL malware, exploits WhatsApp as its primary distribution vector for rapid propagation across victim networks. First identified in September 2025, the campaign evolved dramatically by October 2025, introducing a new script-based […]
The post Water Saci Hackers Leverage WhatsApp to Deliver Multi-Vector Persistent SORVEPOTEL Malware appeared first on Cyber Security News.
战火终熄,荣耀收官 | 第九届XCTF国际网络攻防联赛总决赛圆满落幕!
CVE-2025-40042 | Linux Kernel up to 5.15.194/6.1.156/6.6.112/6.12.53/6.17.2 tracing reg null pointer dereference
CVE-2025-40035 | Linux Kernel up to 5.15.194/6.1.155/6.6.111/6.12.52/6.17.2 particular copy_to_user initialization
CVE-2025-40032 | Linux Kernel up to 6.1.156/6.6.112/6.12.53/6.17.2 PCI pci_epf_test_clean_dma_chan null pointer dereference
CVE-2025-40031 | Linux Kernel up to 6.12.52/6.17.2 register_shm_helper null pointer dereference
CVE-2025-40064 | Linux Kernel up to 6.17.2 __pnet_find_base_ndev use after free
CVE-2025-40082 | Linux Kernel up to 6.17.2 hfsplus_uni2asc out-of-bounds
CVE-2025-40077 | Linux Kernel up to 6.17.2 f2fs pgoff_t buffer overflow
CVE-2025-40074 | Linux Kernel up to 6.17.2 ipv4 dst_dev_rcu use after free
CVE-2025-40076 | Linux Kernel up to 6.17.2 PCI generic_handle_domain_irq null pointer dereference
CVE-2025-40080 | Linux Kernel up to 6.1.155/6.6.111/6.12.52/6.17.2 nbd shutdown privilege escalation
CVE-2025-40071 | Linux Kernel up to 6.6.111/6.12.52/6.17.2 gsm_queue privilege escalation
CVE-2025-40067 | Linux Kernel up to 6.6.111/6.12.52/6.17.2 ntfs3 rename BITMAP allocation of resources
将反射型xss升级为账户劫持
Brida Introduces New Release Offering Complete Support for Latest Frida Integration
The Brida security testing toolkit has released version 0.6, marking a significant update that brings full compatibility with the latest Frida dynamic instrumentation framework. This new release addresses critical compatibility gaps that emerged after Frida’s major overhaul in May 2025, restoring comprehensive functionality for security researchers and penetration testers working with Burp Suite. Adapting to […]
The post Brida Introduces New Release Offering Complete Support for Latest Frida Integration appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.