Aggregator
CVE-2023-53281 | Linux Kernel up to 5.15.110/6.1.27/6.2.14/6.3.1 kernel/softirq.c _rtw_join_timeout_handler deadlock
CVE-2023-53303 | Linux Kernel up to 6.5.3 net vcap_dup_rule memory leak
CVE-2023-53299 | Linux Kernel up to 6.3.1 raid10_sync_request information disclosure
G.O.S.S.I.P 阅读推荐 2025-09-15 危险的Android设备!
Билет в один конец (в базу данных спецслужб). Как крупнейшие авиакомпании мира продают данные о 5 миллиардах перелетов
CVE-2023-53298 | Linux Kernel up to 6.2.4 se_io return value
CVE-2023-53295 | Linux Kernel up to 6.2.2 udf privilege escalation
CVE-2023-53294 | Linux Kernel up to 5.15.111/6.1.28/6.2.15/6.3.2 ntfs_lookup null pointer dereference
CVE-2023-53293 | Linux Kernel up to 6.1.29/6.3.3 Bluetooth btrtl_set_quirks null pointer dereference
CVE-2023-53290 | Linux Kernel up to 5.4.243/5.10.180/5.15.112/6.1.29/6.3.3 run_bpf_prog privilege escalation
CVE-2023-53292 | Linux Kernel up to 6.4.6 blk_mq_elv_switch_none null pointer dereference
CVE-2023-53285 | Linux Kernel up to 6.3.2 ext4 get_max_inline_xattr_value_size allocation of resources
CVE-2023-53289 | Linux Kernel up to 6.3.1 media create_workqueue null pointer dereference
Seraphic Browser-Native Protection Now Available for Purchase on the CrowdStrike Marketplace
CISA Releases Eight Industrial Control Systems Advisories
CISA released eight Industrial Control Systems (ICS) advisories on September 16, 2025. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-25-259-01 Schneider Electric Altivar Products, ATVdPAC Module, ILC992 InterLink Converter
- ICSA-25-259-02 Hitachi Energy RTU500 Series
- ICSA-25-259-03 Siemens SIMATIC NET CP, SINEMA, and SCALANCE
- ICSA-25-259-04 Siemens RUGGEDCOM, SINEC NMS, and SINEMA
- ICSA-25-259-05 Siemens OpenSSL Vulnerability in Industrial Products
- ICSA-25-259-06 Siemens Multiple Industrial Products
- ICSA-25-259-07 Delta Electronics DIALink
- ICSA-25-140-07 Schneider Electric Galaxy VS, Galaxy VL, Galaxy VXL (Update A)
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.
Innovative FileFix Phishing Attack Proves Plenty Potent
New FileFix attack uses steganography to drop StealC malware
WordPress Plugin Vulnerability Let Attackers Bypass Authentication via Social Login
A critical authentication bypass vulnerability in the Case Theme User WordPress plugin has emerged as a significant security threat, allowing unauthenticated attackers to gain administrative access to websites by exploiting the social login functionality. The vulnerability, tracked as CVE-2025-5821 with a CVSS score of 9.8, affects all versions of the plugin up to 1.0.3 and […]
The post WordPress Plugin Vulnerability Let Attackers Bypass Authentication via Social Login appeared first on Cyber Security News.
CrowdStrike npm Packages Compromised in Ongoing Supply Chain Attack
An ongoing supply chain attack has compromised multiple npm packages published by CrowdStrike, extending a malicious campaign known as the “Shai-Halud attack.” The incident, which involves the same malware previously used to target the popular tinycolor package, highlights the persistent threat of supply chain vulnerabilities within the open-source ecosystem. The npm registry acted swiftly to […]
The post CrowdStrike npm Packages Compromised in Ongoing Supply Chain Attack appeared first on Cyber Security News.