Aggregator
CVE-2024-50081 | Linux Kernel up to 6.11.4 privilege escalation (d28b256db525/c25c0c9035bb / Nessus ID 210940)
CVE-2024-50080 | Linux Kernel up to 6.6.57/6.11.4 ublk buffer overflow (6414ab5c9c9c/8f3d5686a240/42aafd8b48ad / Nessus ID 210940)
Полмиллиарда лет эволюции и немного электроники. CША разработали живых дронов
CVE-2024-50079 | Linux Kernel up to 6.11.4 io_uring_cancel_generic state issue (887ba598d9cf/8f7033aa4089 / Nessus ID 216493)
CVE-2024-50077 | Linux Kernel up to 6.1.113/6.6.57/6.11.4 Bluetooth iso_init information disclosure (Nessus ID 212094 / WID-SEC-2024-3289)
CVE-2024-50078 | Linux Kernel up to 6.1.113/6.6.57/6.11.4 Bluetooth iso_exit privilege escalation (Nessus ID 212094 / WID-SEC-2024-3289)
CVE-2024-50075 | Linux Kernel up to 6.6.57/6.11.4 xhci information disclosure (9c696bf4ab54/c46555f14b71/7d381137cb6e / Nessus ID 216493)
CVE-2024-50076 | Linux Kernel up to 6.6.57/6.11.4 con_font_get initialization (dc2d5f02636c/adb1f312f38f/f956052e00de / Nessus ID 216493)
SailPoint Accelerated Application Management simplifies app governance
SailPoint unveiled SailPoint Accelerated Application Management, a solution that redefines how enterprises discover, govern, and secure applications at scale. While most organizations govern fewer than 50 applications, thousands more remain outside governance, creating serious risk. SailPoint’s new approach represents a strategic shift: combining intelligence with expert-led deployment to deliver coverage and compliance at a fraction of the cost and complexity of competing solutions, delivering value while setting a new market standard. Today, many organizations connect … More →
The post SailPoint Accelerated Application Management simplifies app governance appeared first on Help Net Security.
Colt Admits Customer Data Likely Stolen in Cyber-Attack
APT MuddyWater Attacking CFOs Leveraging OpenSSH, Enables RDP, and Scheduled Task
A sophisticated cyber espionage campaign attributed to APT MuddyWater has emerged targeting Chief Financial Officers and finance executives across Europe, North America, South America, Africa, and Asia. The threat actors are deploying a multi-stage phishing operation that masquerades as legitimate recruitment communications from Rothschild & Co, leveraging Firebase-hosted phishing pages with custom CAPTCHA challenges to […]
The post APT MuddyWater Attacking CFOs Leveraging OpenSSH, Enables RDP, and Scheduled Task appeared first on Cyber Security News.
Kali Vagrant Rebuilt Released with Pre-Configured Command-Line VMs
Kali Linux has announced a major overhaul of its Vagrant virtual machine distribution system, transitioning from HashiCorp’s Packer to the DebOS build system for creating pre-configured command-line accessible VMs. This strategic shift unifies Kali’s VM building infrastructure while introducing new compatibility requirements for Windows users running Hyper-V environments. The Kali development team has eliminated the […]
The post Kali Vagrant Rebuilt Released with Pre-Configured Command-Line VMs appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
CVE-2025-57728 | JetBrains IntelliJ IDEA up to 2025.1 Code With Me Guest authorization (WID-SEC-2025-1884)
CVE-2025-57729 | JetBrains IntelliJ IDEA up to 2025.1 inclusion of functionality from untrusted control sphere (WID-SEC-2025-1884)
CVE-2025-57727 | JetBrains IntelliJ IDEA up to 2025.1 cleartext transmission (WID-SEC-2025-1884)
High-Severity Mozilla Flaws Allow Remote Code Execution
Mozilla has released Firefox 142 to address multiple critical security vulnerabilities that could enable remote attackers to execute arbitrary code on affected systems. The Mozilla Foundation Security Advisory 2025-64, announced on August 19, 2025, details nine distinct vulnerabilities ranging from high-severity remote code execution flaws to spoofing and denial-of-service issues. Critical Remote Code Execution Vulnerabilities […]
The post High-Severity Mozilla Flaws Allow Remote Code Execution appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
«Исправления нет, но вы держитесь»...или просто отключите интернет — Microsoft нашла новый подход к закрытию 0Day
New QUIC-LEAK Vulnerability Let Attackers Exhaust Server Memory and Trigger DoS Attack
A critical pre-handshake vulnerability in the LSQUIC QUIC implementation that allows remote attackers to crash servers through memory exhaustion attacks. The vulnerability, designated CVE-2025-54939 and dubbed “QUIC-LEAK,” affects the second most widely used QUIC implementation globally, potentially impacting over 34% of HTTP/3-enabled websites that rely on LiteSpeed technologies. Key Takeaways1. CVE-2025-54939 allows remote DoS via […]
The post New QUIC-LEAK Vulnerability Let Attackers Exhaust Server Memory and Trigger DoS Attack appeared first on Cyber Security News.