Aggregator
CVE-2025-38635 | Linux Kernel up to 6.16.0 clk davinci_lpsc_clk_register null pointer dereference (Nessus ID 276629 / WID-SEC-2025-1898)
CVE-2025-38636 | Linux Kernel up to 6.16.0 rv do_trace_event_raw_event_event_da_monitor out-of-bounds (Nessus ID 260281 / WID-SEC-2025-1898)
CVE-2025-38634 | Linux Kernel up to 6.16.0 power cpcap_usb_detect null pointer dereference (Nessus ID 276629 / WID-SEC-2025-1898)
CVE-2025-38633 | Linux Kernel up to 6.16.0 clk denial of service (WID-SEC-2025-1898)
CVE-2025-38632 | Linux Kernel up to 6.6.101/6.12.41/6.15.9/6.16.0 Gpio Call pinctrl_select_state null pointer dereference (Nessus ID 266176 / WID-SEC-2025-1898)
CVE-2025-38630 | Linux Kernel up to 6.16.0 fbdev fb_add_videomode return null pointer dereference (Nessus ID 276629 / WID-SEC-2025-1898)
CVE-2025-38631 | Linux Kernel up to 6.12.41/6.15.9/6.16.0 clk_register state issue (Nessus ID 260279 / WID-SEC-2025-1898)
CVE-2025-38629 | Linux Kernel up to 6.15.9/6.16.0 ALSA scarlett2_input_select_ctl_info null pointer dereference (Nessus ID 260284 / WID-SEC-2025-1898)
Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket
Michele Spagnuolo allegedly placed multiple trades on the prediction marketplace, abusing internal access to Google’s nonpublic data on the most searched people in 2025.
The post Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket appeared first on CyberScoop.
Hackers Use LLM Agent to Move From Marimo RCE to Internal Database in Four Pivots
A new kind of cyberattack is changing how defenders must think about intrusion detection. On May 10, 2026, a threat actor used a large language model (LLM) agent to drive a full post-exploitation chain, starting from an exposed notebook server and ending with an internal database dumped in under two minutes. This was not a […]
The post Hackers Use LLM Agent to Move From Marimo RCE to Internal Database in Four Pivots appeared first on Cyber Security News.
Калькулятор вместо командной строки и три CVE за один патч. В Notepad++ нашли цепочку уязвимостей с выполнением кода
US Student Mental-Health Provider Mindpath College Health Listed on Ransomware Leak Site
CVE-2026-2704 | Open Babel up to 3.1.1 CIF File src/math/transform3d.cpp DescribeAsString out-of-bounds (Issue 2848 / Nessus ID 299600)
Tanium security advisory (AV26-523)
CVE-2022-2978 | Linux Kernel NILFS File System inode.c security_inode_alloc use after free (EUVD-2022-35199 / Nessus ID 236648)
CVE-2022-2977 | Linux Kernel TPM Device use after free (EUVD-2022-35198)
CVE-2022-2975 | Avaya Aura Application Enablement Services up to 8.1.3.4/10.1.0.1 privileges management (EUVD-2022-35196)
Erlang security advisory (AV26-522)
VaultJacking Attack Steals Entire Google Password Manager Vault With One Captured PIN
A new phishing technique called VaultJacking has emerged, and it is raising serious alarms across the cybersecurity community. With just a single captured 6-digit PIN, an attacker can walk away with an entire Google Password Manager vault, including every saved password and passkey stored inside. This is not a theoretical risk, as it is a […]
The post VaultJacking Attack Steals Entire Google Password Manager Vault With One Captured PIN appeared first on Cyber Security News.