Aggregator
【情报追踪】俄罗斯政府专机刚刚飞往朝鲜
CVE-2022-48948 | Linux Kernel up to 6.1.0 uvc_function_setup buffer overflow (Nessus ID 247770 / WID-SEC-2024-3251)
CVE-2022-48949 | Linux Kernel up to 6.1.0 igb initialization (Nessus ID 214043 / WID-SEC-2024-3251)
CVE-2022-48947 | Linux Kernel up to 6.0.14 Bluetooth buffer overflow (WID-SEC-2024-3251)
CVE-2016-10044 | Linux Kernel up to 4.7.6 SELinux W^X Policy fs/aio.c aio_mount access control (Nessus ID 100150 / ID 169993)
CVE-2022-48946 | Linux Kernel up to 6.1.0 udf_delete_aext allocation of resources (Nessus ID 214043 / WID-SEC-2024-3251)
CVE-2024-38620 | Linux Kernel up to 6.6.32/6.8.11/6.9.2 HCI_AMP privilege escalation (WID-SEC-2024-1418)
CVE-2024-38617 | Linux Kernel up to 6.6.32/6.8.11/6.9.2 fortify kvalloc use after free (Nessus ID 247437 / WID-SEC-2024-1418)
CVE-2024-38618 | Linux Kernel up to 6.9.2 ALSA denial of service (Nessus ID 207738 / WID-SEC-2024-1418)
CVE-2024-38619 | Linux Kernel up to 6.10-rc3 usb-storage alauda_init_media initialization (16637fea001a / Nessus ID 207802)
CVE-2024-38616 | Linux Kernel up to 6.1.92/6.6.32/6.8.11/6.9.2 wifi include/linux/string.h carl9170_tx_release buffer overflow (WID-SEC-2024-1418)
CVE-2024-38615 | Linux Kernel up to 6.9.2 cpufreq exit untrusted pointer dereference (Nessus ID 207776 / WID-SEC-2024-1418)
[AI安全论文] (42)ASC25 基于大语言模型的未知Web攻击威胁检测
New WireTap Attack Break Server SGX To Exfiltrate Sensitive Data
A newly disclosed vulnerability, named the WireTap attack, allows attackers with physical access to break the security of Intel’s Software Guard eXtensions (SGX) on modern server processors and steal sensitive information. A research paper released in October 2025 details how this method can extract cryptographic keys from supposedly secure SGX enclaves using a low-cost setup, […]
The post New WireTap Attack Break Server SGX To Exfiltrate Sensitive Data appeared first on Cyber Security News.
Unity Real-Time Development Platform Vulnerability Let Attackers Execute Arbitrary Code
Unity Technologies has issued a critical security advisory warning developers about a high-severity vulnerability affecting its widely used game development platform. The flaw, designated CVE-2025-59489, exposes applications built with vulnerable Unity Editor versions to unsafe file loading attacks that could enable local code execution and privilege escalation across multiple operating systems. The vulnerability stems from […]
The post Unity Real-Time Development Platform Vulnerability Let Attackers Execute Arbitrary Code appeared first on Cyber Security News.