Aggregator
CVE-2025-10217 | Hitachi Energy Asset Suite up to 9.7 neutralization for logs (EUVD-2025-31726)
CVE-2025-10585 | Google Chrome up to 140.0.7339.127 V8 type confusion (EUVD-2025-31006 / Nessus ID 265355)
CISA Warns of Linux Sudo Vulnerability Actively Exploited in Attacks
CISA has issued an urgent advisory regarding a critical vulnerability in the Linux and Unix sudo utility CVE-2025-32463 that is currently being exploited in the wild. This flaw allows local adversaries to bypass access controls and execute arbitrary commands as the root user, even without explicit sudoers privileges. Sudo Chroot Bypass (CVE-2025-32463) Identified as “Inclusion […]
The post CISA Warns of Linux Sudo Vulnerability Actively Exploited in Attacks appeared first on Cyber Security News.
Cyber Incident Impacts DeKalb County Government Computer System
CVE-2025-10859 | Mozilla Firefox up to 143.0 on iOS Cookie information disclosure (EUVD-2025-31731)
CVE-2025-8532 | Bimser Solution Software Trade eBA Document and Workflow Management System 6.7.164/6.7.165 authorization (EUVD-2025-30288)
Google Gemini Vulnerabilities Let Attackers Exfiltrate User’s Saved Data and Location
Three new vulnerabilities in Google’s Gemini AI assistant suite could have allowed attackers to exfiltrate users’ saved information and location data. The vulnerabilities uncovered by Tenable, dubbed the “Gemini Trifecta,” highlight how AI systems can be turned into attack vehicles, not just targets. The research exposed significant privacy risks across different components of the Gemini […]
The post Google Gemini Vulnerabilities Let Attackers Exfiltrate User’s Saved Data and Location appeared first on Cyber Security News.