Aggregator
CVE-2025-8042 | Mozilla Firefox up to 140 on Android iFrame access control (EUVD-2025-25232)
CVE-2025-37893 | Linux Kernel up to 6.1.133/6.6.86/6.12.22/6.13.10/6.14.1 LoongArch build_prologue off-by-one (WID-SEC-2025-0861)
CVE-2025-37838 | Linux Kernel up to 4.19.309 HSI ssi_protocol_probe use after free (Nessus ID 234884 / WID-SEC-2025-0861)
Google fixed Chrome flaw found by Big Sleep AI
CodeRabbit’s Production Servers RCE Vulnerability Enables Write Access on 1M Repositories
A critical remote code execution (RCE) vulnerability in CodeRabbit’s production infrastructure that provided unauthorized access to over one million code repositories, including private ones. The vulnerability, discovered in December 2024 and responsibly disclosed in January 2025, exploited the platform’s static analysis tool integration to leak sensitive API credentials and gain write access to GitHub repositories […]
The post CodeRabbit’s Production Servers RCE Vulnerability Enables Write Access on 1M Repositories appeared first on Cyber Security News.
New Salty 2FA PhaaS Platform Targets Microsoft 365 Users to Steal Login Credentials
The majority of events globally are caused by phishing, which continues to be the most common vector for cyberattacks in the constantly changing world of cyber threats. The proliferation of affordable Phishing-as-a-Service (PhaaS) platforms such as Tycoon2FA, EvilProxy, and Sneaky2FA has exacerbated this issue, enabling even novice attackers to deploy sophisticated campaigns. These services are […]
The post New Salty 2FA PhaaS Platform Targets Microsoft 365 Users to Steal Login Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.