Aggregator
CVE-2025-20641 | MediaTek MT8893 DA out-of-bounds write (MSV-2058 / ALPS09291146)
CVE-2025-20639 | MediaTek MT8893 DA out-of-bounds write (MSV-2060 / ALPS09291146)
CVE-2024-57966 | KDE ark 24.11.x libarchiveplugin.cpp absolute path traversal
CVE-2025-20635 | MediaTek MT8390 V6 DA out-of-bounds write (MSV-2434 / ALPS09403752)
CVE-2024-20142 | MediaTek MT8893 V5 DA out-of-bounds write (MSV-2070 / ALPS09291406)
CVE-2024-20141 | MediaTek MT8893 V5 DA write-what-where condition (MSV-2073 / ALPS09291402)
CVE-2025-20643 | MediaTek MT8893 DA debug messages revealing unnecessary information (MSV-2056 / ALPS09291146)
CVE-2025-20638 | MediaTek MT8893 DA uninitialized variable (MSV-2066 / ALPS09291449)
CVE-2025-20640 | MediaTek MT8893 DA out-of-bounds (MSV-2059 / ALPS09291146)
CVE-2025-25062 | Backdrop CMS up to 1.28.4/1.29.2 CKEditor 5 Rich Text Editor cross site scripting (backdrop-sa-core-2025-001)
CVE-2025-20636 | MediaTek MT8798 Secmem out-of-bounds write (MSV-2431 / ALPS09403554)
CVE-2025-20632 | MediaTek MT7615/MT7622/MT7663/MT7915/MT7916/MT7981/MT7986 up to 7.6.7.2 WLAN AP Driver out-of-bounds write (MSV-2188)
CVE-2025-20631 | MediaTek MT7615/MT7622/MT7663/MT7915/MT7916/MT7981/MT7986 WLAN AP Driver out-of-bounds write (MSV-2187)
CVE-2025-20637 | MediaTek MT7981/MT7986 up to 7.6.7.0 uncaught exception (MSV-2380)
CVE-2024-20147 | MediaTek MT8678 Bluetooth FW assertion (MSV-1797 / ALPS09136501)
CVE-2025-20634 | MediaTek MT8863 NR16/NR17/NR17R Modem out-of-bounds write (MSV-2436 / MOLY01289384)
New Process Hollowing Attack Vectors Uncovered in Windows 11 (24H2)
A significant evolution in the cybersecurity landscape has emerged with the uncovering of new vulnerabilities in Windows 11 (24H2). Process Hollowing, a widely used technique often referred to as RunPE, has encountered new challenges in this operating system version due to changes in the Windows loader, impacting both security researchers and attackers alike. Process Hollowing […]
The post New Process Hollowing Attack Vectors Uncovered in Windows 11 (24H2) appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
BeyondTrust Zero-Day Breach – 17 SaaS Customers API Key Compromised
BeyondTrust, a leading provider of identity and access management solutions, disclosed a zero-day breach impacting 17 Remote Support SaaS customers. The incident, detected on December 5, 2024, has been linked to the compromise of an infrastructure API key used to access specific Remote Support SaaS instances. The breach allowed attackers to reset local application passwords […]
The post BeyondTrust Zero-Day Breach – 17 SaaS Customers API Key Compromised appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
The hidden dangers of a toxic cybersecurity workplace
In this Help Net Security interview, Rob Lee, Chief of Research and Head of Faculty at SANS Institute, discusses what a toxic environment looks like and how professionals can recognize red flags such as high turnover, burnout, and a pervasive fear of mistakes. Addressing these issues early is key to maintaining a healthy and effective team. Can you describe what a “toxic cybersecurity environment” looks like? What are some of the red flags professionals should … More →
The post The hidden dangers of a toxic cybersecurity workplace appeared first on Help Net Security.