Aggregator
CVE-2026-31748 | Linux Kernel up to 6.19.11 comedi me2600_xilinx_download buffer overflow (WID-SEC-2026-1346)
CVE-2026-31747 | Linux Kernel up to 6.19.11 comedi me4000_xilinx_download buffer overflow (WID-SEC-2026-1346)
CVE-2026-31746 | Linux Kernel up to 6.18.21/6.19.11 zcrypt ap_init_apmsg memory leak (WID-SEC-2026-1346)
CVE-2026-31745 | Linux Kernel up to 6.19.11 reset_add_gpio_aux_device double free (WID-SEC-2026-1346)
CVE-2026-31743 | Linux Kernel up to 6.12.80/6.18.21/6.19.11 nvmem zynqmp_nvmem memory corruption (WID-SEC-2026-1346)
CVE-2026-31744 | Linux Kernel up to 6.19.11 dev_energymodel_nl_get_perf_domains_doit return null pointer dereference (WID-SEC-2026-1346)
Банки отключили переписки между клиентами. Официально — редизайн. Неофициально — белые списки по требованию спецслужб
CVE-2026-31741 | Linux Kernel up to 6.6.133/6.12.80/6.18.21/6.19.11 rz_mtu3_terminate_counter privilege escalation (WID-SEC-2026-1346)
CVE-2026-31739 | Linux Kernel up to 6.12.80/6.18.21/6.19.11 Tegra Crypto Driver denial of service (WID-SEC-2026-1346)
CVE-2026-31740 | Linux Kernel up to 6.6.133/6.12.80/6.18.21/6.19.11 Counter Driver rz_mtu3_channel privilege escalation (WID-SEC-2026-1346)
CVE-2026-31737 | Linux Kernel up to 6.19.11 net ftgmac100_alloc_rings allocation of resources (WID-SEC-2026-1346)
Educational tech firm Instructure data breach may have impacted 9,000 schools
Two Strikes, Half a Billion: How North Korean Hackers Seized 76% of All Stolen Crypto in Just 120 Days
North Korean cyber-operatives have once again demonstrated how a handful of precision strikes can fundamentally reshape annual cryptocurrency
The post Two Strikes, Half a Billion: How North Korean Hackers Seized 76% of All Stolen Crypto in Just 120 Days appeared first on Penetration Testing Tools.
CVE-2022-24972 | TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) httpd Service access control (ZDI-22-405 / EUVD-2022-29722)
CVE-2022-24952 | MisterTea Eternal Terminal up to 6.1.x Sequence Number denial of service (GHSA-8cw3-6r98-g7cw / EUVD-2022-29705)
CVE-2022-24951 | MisterTea Eternal Terminal up to 6.1.x IPC Socket race condition (GHSA-546v-59j5-g95q / EUVD-2022-29704)
The Five-Day Race: Hackers Weaponize Critical Weaver E-cology RCE via Exposed Debugging API
Adversaries commenced the exploitation of a critical vulnerability within Weaver E-cology a mere few days following the release
The post The Five-Day Race: Hackers Weaponize Critical Weaver E-cology RCE via Exposed Debugging API appeared first on Penetration Testing Tools.
Weaver E-cology RCE Flaw CVE-2026-22679 Actively Exploited via Debug API
The Support Chat Trap: How a “Customer Screenshot” Led to a Critical Code-Signing Breach at DigiCert
A seemingly innocuous file transmitted via a support chat escalated into a significant crisis for DigiCert. An adversary
The post The Support Chat Trap: How a “Customer Screenshot” Led to a Critical Code-Signing Breach at DigiCert appeared first on Penetration Testing Tools.