Aggregator
CVE-2025-5260 | Pik Online Yazılım Çözümleri up to 3.1.4 server-side request forgery
Paper Werewolf Exploiting WinRAR Zero‑Day Vulnerability to Deliver Malware
Cybersecurity researchers have uncovered a sophisticated campaign by the Paper Werewolf threat actor group, also known as GOFFEE, targeting Russian organizations through the exploitation of critical vulnerabilities in WinRAR archiving software. The campaign, active since July 2025, demonstrates the group’s advanced capabilities in leveraging both known and previously undiscovered security flaws to establish persistent access […]
The post Paper Werewolf Exploiting WinRAR Zero‑Day Vulnerability to Deliver Malware appeared first on Cyber Security News.
CVE-2025-37925 | Linux Kernel up to 6.14.1 jfs fs/inode.c clear_inode information disclosure (EUVD-2025-11828 / Nessus ID 240657)
CVE-2025-38049 | Linux Kernel up to 6.12.22/6.13.10/6.14.1 resctrl dom_data_init null pointer dereference (Nessus ID 240657 / WID-SEC-2025-0861)
CVE-2025-9167 | SolidInvoice up to 2.4.0 Recurring Invoice /invoice/recurring client name cross site scripting
CVE-2025-9168 | SolidInvoice up to 2.4.0 Invoice Creation /invoice Client Name cross site scripting
CVE-2025-8364 | Mozilla Firefox up to 140 on Android blob URL ui layer (EUVD-2025-25231)
CVE-2025-8041 | Mozilla Firefox up to 140 on Android Address Bar clickjacking (EUVD-2025-25233)
CVE-2025-8042 | Mozilla Firefox up to 140 on Android iFrame access control (EUVD-2025-25232)
CVE-2025-37860 | Linux Kernel up to 6.14.1 ef100_process_design_param null pointer dereference (Nessus ID 237088 / WID-SEC-2025-0861)
CVE-2025-37893 | Linux Kernel up to 6.1.133/6.6.86/6.12.22/6.13.10/6.14.1 LoongArch build_prologue off-by-one (WID-SEC-2025-0861)
CVE-2025-37838 | Linux Kernel up to 4.19.309 HSI ssi_protocol_probe use after free (Nessus ID 234884 / WID-SEC-2025-0861)
CVE-2025-5914 | libarchive up to 3.7.x archive_read_support_format_rar.c archive_read_format_rar_seek_data double free (EUVD-2025-17572 / Nessus ID 240326)
Google fixed Chrome flaw found by Big Sleep AI
CodeRabbit’s Production Servers RCE Vulnerability Enables Write Access on 1M Repositories
A critical remote code execution (RCE) vulnerability in CodeRabbit’s production infrastructure that provided unauthorized access to over one million code repositories, including private ones. The vulnerability, discovered in December 2024 and responsibly disclosed in January 2025, exploited the platform’s static analysis tool integration to leak sensitive API credentials and gain write access to GitHub repositories […]
The post CodeRabbit’s Production Servers RCE Vulnerability Enables Write Access on 1M Repositories appeared first on Cyber Security News.
New Salty 2FA PhaaS Platform Targets Microsoft 365 Users to Steal Login Credentials
The majority of events globally are caused by phishing, which continues to be the most common vector for cyberattacks in the constantly changing world of cyber threats. The proliferation of affordable Phishing-as-a-Service (PhaaS) platforms such as Tycoon2FA, EvilProxy, and Sneaky2FA has exacerbated this issue, enabling even novice attackers to deploy sophisticated campaigns. These services are […]
The post New Salty 2FA PhaaS Platform Targets Microsoft 365 Users to Steal Login Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.