Aggregator
CVE-2026-45951 | Linux Kernel up to 6.18.13/6.19.3 check_pseudo_btf_id use after free
CVE-2026-45949 | Linux Kernel up to 6.12.74/6.18.13/6.19.3 hwrng_fillfn use after free
CVE-2026-45948 | Linux Kernel up to 6.19.3 ext4 ext4_ext_shift_extents memory leak
CVE-2026-45947 | Linux Kernel up to 6.6.127/6.12.74/6.18.13/6.19.3 amdgpu_acpi_enumerate_xcc memory leak
CVE-2026-45945 | Linux Kernel up to 6.19.3 iommu pasid_entry race condition
CVE-2026-45944 | Linux Kernel up to 6.18.13/6.19.3 iommu dma_wmb initialization
CVE-2026-45943 | Linux Kernel up to 6.12.77/6.18.13/6.19.3 erofs z_erofs_decompress_pcluster null pointer dereference
CVE-2026-45940 | Linux Kernel up to 6.18.13/6.19.3 net privilege escalation
CVE-2026-45939 | Linux Kernel up to 6.18.13/6.19.3 gpib ni_usb_init memory leak
CVE-2026-45938 | Linux Kernel up to 6.12.74/6.18.13/6.19.3 IRQ power_supply_changed use after free
Hackers are knocking on office doors pretending to be IT staff
The Silent Ransom Group (SRG) is targeting law firms using social engineering techniques and an unusual tactic for cybercriminals: showing up at victims’ offices in person while posing as IT staff, the FBI warns. The group, also known as Luna Moth, Chatty Spider, and UNC3753, has been active since at least 2022 and has targeted companies in several sectors, including insurance, finance, and healthcare, though law firms remain its primary target. The FBI said SRG … More →
The post Hackers are knocking on office doors pretending to be IT staff appeared first on Help Net Security.
New BTMOB Malware Lets Attackers Remotely Control Android Devices
New Android malware dubbed BTMOB is arming even low-skilled attackers with full remote control over infected phones by combining a powerful RAT engine with a no-code campaign builder toolkit. The threat, first seen in 2025, is now evolving rapidly through a malware-as-a-service (MaaS) model and active phishing campaigns worldwide. BTMOB is an Android remote access […]
The post New BTMOB Malware Lets Attackers Remotely Control Android Devices appeared first on Cyber Security News.
CISA Warns of LiteSpeed cPanel Plugin Vulnerability Exploited in Attacks
CISA has issued an urgent warning regarding a critical vulnerability in the LiteSpeed cPanel Plugin, identified as CVE-2026-48172, which is currently being exploited in real-world attacks. The flaw enables privilege escalation, allowing attackers with basic cPanel access to execute arbitrary scripts with root-level privileges. This significantly increases the risk for organizations operating shared hosting environments […]
The post CISA Warns of LiteSpeed cPanel Plugin Vulnerability Exploited in Attacks appeared first on Cyber Security News.
Mexican Instituto Tecnológico de Zacatepec Named in Alleged Student Database Leak
GitHub Enterprise Server 3.20.3 Released With Fox for Critical Vulnerabilities
GitHub has shipped GitHub Enterprise Server (GHES) 3.20.3 as a security‑driven patch release that fixes multiple critical and high‑severity vulnerabilities and rotates the signing key used to validate GHES release packages. Organizations running any earlier 3.20.x build is strongly encouraged to move to this version to close serious gaps affecting network‑exposed and multi‑tenant deployments. A […]
The post GitHub Enterprise Server 3.20.3 Released With Fox for Critical Vulnerabilities appeared first on Cyber Security News.
Критикуете ИИ? Поздравляем: ФБР уже готово внести вас в базу экстремистов
How Can MSSPs Scale Threat Detection Without Burning Out Their Analysts?
Windows Kernel Vulnerability Allows Attackers to Modify Kernel Memory Counters
A critical Windows kernel vulnerability, tracked as CVE-2026-40369, has been disclosed, enabling attackers to achieve full SYSTEM-level privilege escalation even from the most restricted environments, including browser sandboxes. Discovered by security researcher Ori Nimron, the flaw affects Windows 11 versions 24H2 through 25H2 and resides in the ntoskrnl.exe component, specifically within the ExpGetProcessInformation function. The […]
The post Windows Kernel Vulnerability Allows Attackers to Modify Kernel Memory Counters appeared first on Cyber Security News.