Aggregator
CVE-2025-21456 | Qualcomm Snapdragon Auto up to WSA8835 IOCTL Command use after free
CVE-2025-21452 | Qualcomm Snapdragon Auto up to WSA8835 assertion
CVE-2025-27072 | Qualcomm Snapdragon Auto up to SRV1M Header Length buffer overflow
CVE-2025-21472 | Qualcomm Snapdragon Auto FastConnect 6900 up to WSA8830 debug code
CVE-2025-21465 | Qualcomm Snapdragon Auto up to XR1 Platform MBN File out-of-bounds
CVE-2025-21464 | Qualcomm Snapdragon Auto up to WSA8845H offset/size out-of-bounds
CVE-2025-21457 | Qualcomm Snapdragon Auto/Snapdragon Mobile/Snapdragon WBC up to WCD9340 fastrpc Session buffer over-read
CVE-2025-47324 | Qualcomm Snapdragon Auto QCA7005 PIB File exposure of sensitive information through metadata (EUVD-2025-23787)
CVE-2025-21455 | Qualcomm Snapdragon Compute FastConnect 6800 up to WSA8832 IOCTL toctou
CVE-2025-7954 | Shopware 6.6.x/6.7.x Voucher System race condition
I Spent $500 To Test Devin AI For Prompt Injection So That You Don't Have To
Today we cover Devin AI from Cognition, the first AI Software Engineer.
We will cover Devin proof-of-concept exploits in multiple posts over the next few days. In this first post, we show how a prompt injection payload hosted on a website leads to a full compromise of Devin’s DevBox.
GitHub Issue To Remote Code ExecutionBy planting instructions on a website or GitHub issue that Devin processes, it can be tricked to download malware and launch it. This leads to full system compromise and turns Devin into a remote-controlled ZombAI. Any exposed secrets can then be leveraged to perform lateral movement, or other post-exploitation steps.
SonicWall Probes Potential Zero-Day After Ransomware Hits
SonicWall said it is probing a surge in attacks against its Gen 7 firewalls, running various firmware versions, which have SSL VPN enabled. Researchers said attackers may have been exploiting a zero-day vulnerability and that multiple victims have been infected with Akira ransomware.
Hacks on 3 Specialty Medical Providers Affect Nearly 800,000
Recent hacks on a provider of sleep disorder diagnostic gear and services, a network of medical imaging facilities and a multi-disciplinary cancer care center have affected nearly 800,000 patients. The breaches are among the latest rash of cybercriminal attacks plaguing the healthcare sector.
Dutch Prosecutors Recover From Suspected Russian Hack
The Dutch Public Prosecution Service on Monday began phased restoration of its networks after a cyberattack last month forced the agency to take down its services offline. The agency confirmed that hackers exploited a vulnerability in a Citrix device.
CISA Unveils Final $100M Cyber Grants as State Burdens Soar
The federal government announced a final $100 million round of cybersecurity grants aimed at boosting state and local defenses, but experts warn the funding signals a broader shift in responsibility to under-resourced governments facing escalating threats without sustained federal support.
第十三届互联网安全大会:多智能体蜂群掀起安全与 AI 融合革命
直播预约 | ISC.AI 2025第三届全国信息安全产教融合共同体发展大会
CTEM、ASM与漏洞管理,三者有何区别?
HPE unveils unified cybersecurity portfolio with AI-driven networking and data protection
HPE announced expansion of its cybersecurity, resiliency, and compliance solutions, taking a multi-layered approach to protect enterprises through industry-leading data, network, and system security. HPE is introducing its combined secure networking portfolio, built on HPE Aruba Networking and HPE Juniper Networking, and announcing expansive updates across its portfolio: HPE advances network security with a new SASE copilot for HPE Aruba Networking EdgeConnect that provides AI-driven insights on network activity, security gaps and more. HPE Aruba … More →
The post HPE unveils unified cybersecurity portfolio with AI-driven networking and data protection appeared first on Help Net Security.