Posts of last few hours
Белый дом запускает двухлетний переход к единой аутентификации федеральных сервисов.
https://www.securitylab.ru/news/576821.php
https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-874
SonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. SonicWall’s researchers William Perry and Adam Babis discovered the vulnerabilities. SonicWall confirmed that […]
https://securityaffairs.com/198303/security/sonicwall-patches-two-new-actively-exploited-zero-days-in-sma-1000-vpns.html
Submit #886466 / VDB-398138
https://vuldb.com/submit/886466
Submit #886451 / VDB-398136
https://vuldb.com/submit/886451
Submit #886443 / VDB-398135
https://vuldb.com/submit/886443
Submit #886431 / VDB-398133
https://vuldb.com/submit/886431
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication.
The command executes as the user, outside the agent's sandbox and without an approval prompt, and exploitation requires the repository to arrive
https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html
A vulnerability was found in Linux Kernel up to 6.9.4. It has been rated as critical. The affected element is an unknown function of the component starfive. Performing a manipulation of the argument uses results in stack-based buffer overflow.
This vulnerability is known as CVE-2024-39478. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/270376
A vulnerability described as problematic has been identified in Linux Kernel up to 6.10.9. Affected by this issue is the function bpf_test_run. Such manipulation leads to state issue.
This vulnerability is uniquely identified as CVE-2024-46754. The attack can only be initiated within the local network. No exploit exists.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/277983
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.14.1. This affects the function jfs_truncate_nolock. The manipulation results in stack-based buffer overflow.
This vulnerability is identified as CVE-2024-58094. The attack can only be performed from the local network. There is not any exploit available.
You should upgrade the affected component.
https://vuldb.com/vuln/305077
A vulnerability was found in Linux Kernel up to 6.14.1. It has been rated as critical. This affects the function hex_dump_to_buffer of the component ibmvnic. Performing a manipulation results in buffer overflow.
This vulnerability is cataloged as CVE-2025-22104. The attack must originate from the local network. There is no exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/305110
A vulnerability has been found in Linux Kernel up to 6.16.4/6.17-rc3 and classified as critical. Affected is an unknown function of the component mISDN. Performing a manipulation results in uninitialized pointer.
This vulnerability is identified as CVE-2025-39833. The attack can only be performed from the local network. There is not any exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/324412
A vulnerability classified as critical was found in Linux Kernel up to 6.16.7. This vulnerability affects the function j1939_sk_bind. Executing a manipulation can lead to privilege escalation.
The identification of this vulnerability is CVE-2025-39925. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/326495
A vulnerability classified as critical was found in Linux Kernel up to 6.17.2. Impacted is the function __sk_dst_get. Such manipulation leads to use after free.
This vulnerability is referenced as CVE-2025-40168. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/332151
A vulnerability labeled as problematic has been found in Linux Kernel up to 6.17.2. This issue affects the function __sk_dst_get. The manipulation results in privilege escalation.
This vulnerability is known as CVE-2025-40139. Access to the local network is required for this attack. No exploit is available.
The affected component should be upgraded.
https://vuldb.com/vuln/332161
A vulnerability labeled as critical has been found in Linux Kernel up to 6.12.57/6.17.7. This affects an unknown function. Executing a manipulation can lead to insufficiently random values.
This vulnerability is registered as CVE-2025-68313. The attack requires access to the local network. No exploit is available.
The affected component should be upgraded.
https://vuldb.com/vuln/336851
A vulnerability classified as critical has been found in Linux Kernel up to 6.17.2. The affected element is the function __pnet_find_base_ndev. This manipulation causes use after free.
The identification of this vulnerability is CVE-2025-40064. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/330260
A vulnerability was found in Linux Kernel up to 6.4.6. It has been classified as critical. The affected element is the function hpd_irq_lock. Performing a manipulation results in privilege escalation.
This vulnerability is known as CVE-2023-54263. Access to the local network is required for this attack. No exploit is available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/339016
Авторизация тихо отключилась сама, пока исследователи списывали аномалии на плановые тесты.
https://www.securitylab.ru/news/576794.php
Latest Blog Posts
- 1 week 5 days ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 1 week ago
- 2 months 2 weeks ago
- 7 months 1 week ago
- 1 year ago
- 1 year ago
- 1 year 1 month ago
- 1 year 5 months ago