Aggregator
FinWise insider breach impacts 689K American First Finance customers
8 months 2 weeks ago
FinWise Bank is warning on behalf of corporate customers that it suffered a data breach after a former employee accessed sensitive files after the end of their employment. [...]
Lawrence Abrams
Fairmont Federal Credit Union 2023 data breach impacted 187K people
8 months 2 weeks ago
Fairmont Federal Credit Union alerts 187K people that a 2023 breach exposed personal, financial, and medical data. Fairmont Federal Credit Union (FFCU) is a not-for-profit financial cooperative in West Virginia. It offers services like personal and business loans, mortgages, checking accounts, and financial aid, operating nine regional branches to serve its members. Fairmont Federal Credit […]
Pierluigi Paganini
New Phoenix attack bypasses Rowhammer defenses in DDR5 memory
8 months 2 weeks ago
Academic researchers have devised a new variant of Rowhammer attacks that bypass the latest protection mechanisms on DDR5 memory chips from SK Hynix. [...]
Ionut Ilascu
Квантовый компьютер на чипе от смартфона. Британский стартап Quantum Motion представил первую в мире такую систему
8 months 2 weeks ago
Система заняла всего три серверные стойки и уже установлена в Национальном центре квантовых вычислений Великобритании.
20 Most Popular Developer Tools in 2025
8 months 2 weeks ago
Explore 20 essential developer tools for coding, collaboration, and project management in 2025. Find practical solutions to elevate your workflow and boost success.
The post 20 Most Popular Developer Tools in 2025 appeared first on Security Boulevard.
MojoAuth - Advanced Authentication & Identity Solutions
Порвался — и сразу зажил. Учёные создали "жидкого терминатора" — гель, который умеет самовосстанавливаться, тянется на 4600% и меняет цвет
8 months 2 weeks ago
Искусственная кожа на подходе.
Threat Group Scattered Lapsus$ Hunters Says It’s Shutting Down
8 months 2 weeks ago
The bad actors behind the Scattered Lapsus$ Hunters threat group say they are shutting down operations and retiring, but cybersecurity pros say law enforcement pressure is a key reason for the decision and that the hackers will likely form new cybercrime operations.
The post Threat Group Scattered Lapsus$ Hunters Says It’s Shutting Down appeared first on Security Boulevard.
Jeffrey Burt
Microsoft: Exchange 2016 and 2019 reach end of support in 30 days
8 months 2 weeks ago
Microsoft has reminded administrators again that Exchange 2016 and Exchange 2019 will reach the end of extended support next month and has provided guidance for decommissioning outdated servers. [...]
Sergiu Gatlan
Europol adds Spanish academic suspected of aiding pro-Russian hackers to most wanted list
8 months 2 weeks ago
Spanish national Enrique Arias Gil, 37, is suspected of gathering information on Spain’s critical infrastructure and members of its security forces to facilitate cyberattacks. He is also accused of threatening journalists and business leaders who supported Ukraine.
Supporting Rowhammer research to protect the DRAM ecosystem
8 months 2 weeks ago
Kimberly Samra
CAS Exhibition Partners Falls Victim to LYNX Ransomware
8 months 2 weeks ago
CAS Exhibition Partners Falls Victim to LYNX Ransomware
Dark Web Informer
CVE-2025-57174 | Siklu Etherhaul 8010TX/Etherhaul 1200FX up to 10.7.3 Rfpiped Service hard-coded key (EUVD-2025-29202)
8 months 2 weeks ago
A vulnerability was found in Siklu Etherhaul 8010TX and Etherhaul 1200FX up to 10.7.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Rfpiped Service. Executing manipulation can lead to use of hard-coded cryptographic key
.
This vulnerability appears as CVE-2025-57174. The attacker needs to be present on the local network. There is no available exploit.
vuldb.com
CVE-2023-53256 | Linux Kernel up to 5.15.113/6.1.30/6.3.4 ida_alloc random values
8 months 2 weeks ago
A vulnerability was found in Linux Kernel up to 5.15.113/6.1.30/6.3.4. It has been classified as critical. Affected is the function ida_alloc. Performing manipulation results in insufficiently random values.
This vulnerability is reported as CVE-2023-53256. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com
CVE-2025-43792 | Liferay Portal/DXP external control of system or configuration setting (EUVD-2025-29221)
8 months 2 weeks ago
A vulnerability was found in Liferay Portal and DXP and classified as problematic. This impacts an unknown function. Such manipulation of the argument _com_Liferay_exportimport_web_portlet_ExportImportPortlet_remoteAddress/_com_Liferay_exportimport_web_portlet_ExportImportPortlet_remotePort leads to external control of system or configuration setting.
This vulnerability is documented as CVE-2025-43792. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2023-53258 | Linux Kernel up to 6.1.42/6.4.7 AMD Display vblank_nom privilege escalation
8 months 2 weeks ago
A vulnerability has been found in Linux Kernel up to 6.1.42/6.4.7 and classified as critical. This affects the function vblank_nom of the component AMD Display. This manipulation causes privilege escalation.
This vulnerability is registered as CVE-2023-53258. The attack requires access to the local network. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2023-53261 | Linux Kernel up to 6.5.2 coresight acpi_get_dsd_graph memory leak
8 months 2 weeks ago
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.5.2. The impacted element is the function acpi_get_dsd_graph of the component coresight. The manipulation results in memory leak.
This vulnerability is cataloged as CVE-2023-53261. The attack must originate from the local network. There is no exploit available.
You should upgrade the affected component.
vuldb.com
CVE-2023-53260 | Linux Kernel up to 6.1.42/6.4.3 ovl ovl_permission null pointer dereference
8 months 2 weeks ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.42/6.4.3. The affected element is the function ovl_permission of the component ovl. The manipulation leads to null pointer dereference.
This vulnerability is listed as CVE-2023-53260. The attack must be carried out from within the local network. There is no available exploit.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-58748 | Dataease up to 2.10.12 Amazon Redshift Driver H2.java socketFactoryArg deserialization (EUVD-2025-29201)
8 months 2 weeks ago
A vulnerability classified as very critical was found in Dataease up to 2.10.12. Impacted is an unknown function of the file H2.java of the component Amazon Redshift Driver. Executing manipulation of the argument socketFactoryArg can lead to deserialization.
This vulnerability is tracked as CVE-2025-58748. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-10203 | Digilent WaveForms up to 3.24.3 DWF3WORK File Parser path traversal (EUVD-2025-29220)
8 months 2 weeks ago
A vulnerability classified as problematic has been found in Digilent WaveForms up to 3.24.3. This issue affects some unknown processing of the component DWF3WORK File Parser. Performing manipulation results in relative path traversal.
This vulnerability is identified as CVE-2025-10203. The attack is only possible with local access. There is not any exploit available.
vuldb.com