Aggregator
CVE-2025-48046 | MICI Network NetFax Server prior 3.0.1.0 HTTP GET Request /config.php password in configuration file
CVE-2025-48045 | MICI Network NetFax Server prior 3.0.1.0 HTTP GET Request /client.php insertion of sensitive information into sent data
CVE-2025-37996 | Linux Kernel up to 6.14.6 KVM user_mem_abort initialization
CVE-2025-37998 | Linux Kernel up to 5.15.182/6.1.138/6.6.90/6.12.28/6.14.6 openvswitch output_userspace iteration
CVE-2025-37997 | Linux Kernel up to 5.15.182 Netfilter ahash_bucket_start race condition
CVE-2025-37995 | Linux Kernel up to 5.15.182/6.1.138/6.6.90/6.12.28/6.14.6 kobject_put uninitialized pointer
CVE-2025-37994 | Linux Kernel up to 5.15.182/6.1.138/6.6.90/6.12.28/6.14.6 UCSI Driver ucsi_displayport_work null pointer dereference
CVE-2025-37999 | Linux Kernel up to 6.12.28/6.14.6 fileio erofs_onlinefolio_split allocation of resources
CVE-2025-37993 | Linux Kernel up to 6.12.28/6.14.6 m_can m_can_class_allocate_dev initialization
CVE-2025-4081 | Blackmagic Design DaVinci Resolve up to 19.1.3 on macOS com.apple.security.cs.disable-library-validation default permission
僵尸网络入侵 9,000 多台华硕路由器,添加持续 SSH 后门
C# теперь как Python: Microsoft упростила запуск скриптов
Mitigating Credential Theft Risks in Active Directory Environments
As cyber threats increase in sophistication and frequency, organizations are under increasing pressure to secure their digital infrastructure. Microsoft’s Active Directory (AD) remains the backbone of identity and access management for most enterprises, making it a high-value target for attackers. One of the most effective ways to strengthen AD defenses is through the strategic use […]
The post Mitigating Credential Theft Risks in Active Directory Environments appeared first on Cyber Security News.
新的 PumaBot 僵尸网络利用强制 SSH 凭据入侵设备
New PumaBot Hijacks IoT Devices by Brute Forcing SSH Credentials For Persistence
A sophisticated new malware strain dubbed PumaBot has emerged in the cybersecurity landscape, specifically targeting Internet of Things (IoT) devices through aggressive SSH credential brute-forcing campaigns. This latest threat represents a significant evolution in IoT-focused malware, demonstrating advanced persistence mechanisms and stealth capabilities that allow it to maintain long-term access to compromised devices across diverse […]
The post New PumaBot Hijacks IoT Devices by Brute Forcing SSH Credentials For Persistence appeared first on Cyber Security News.