Aggregator
New Linux Kernel Vulnerability Lets Attackers Escalate Privileges to Root
A use-after-free vulnerability in the Linux kernel’s nftables subsystem has been disclosed, enabling unprivileged local attackers to escalate privileges to root on widely deployed distributions including Debian Bookworm, Debian Trixie, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. Tracked as CVE-2026-23111, the flaw was discovered in early 2025 and patched upstream on February 5, 2026, via […]
The post New Linux Kernel Vulnerability Lets Attackers Escalate Privileges to Root appeared first on Cyber Security News.
OkCupid Data Scrape: Hacker Claims to Sell 35M User Records
CVE-2026-11482 | SourceCodester Class and Exam Timetabling System 1.0 /archive5.php sy sql injection (EUVD-2026-35013)
CVE-2021-47984 | WP24 Domain Check 1.6.2 on WordPress options.php fieldnameDomain cross site scripting (Exploit 49377 / EUVD-2021-34850)
CVE-2026-11466 | zilliztech deep-searcher up to 0.0.2 collection_router.py CollectionRouter.invoke kwargs access control (Issue 267 / EUVD-2026-34997)
CVE-2026-11507 | CodeAstro Leave Management System 1.0 delete_leave_type.php leave_type sql injection (EUVD-2026-35043)
CVE-2026-11519 | SourceCodester Inventory System 1.0 Account Creation users_handler.php ROLE improper authorization (EUVD-2026-35069)
CVE-2026-11520 | SourceCodester Inventory System 1.0 header.php cross site scripting (EUVD-2026-35070)
CVE-2026-25558 | QloApps QloApps/within SVG files uploaded up to 1.7.0 SVG File cross site scripting (EUVD-2026-35071)
CVE-2026-11521 | Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29af71aed9bb500e5f24d948 Transaction Endpoint TransactionController.java improper authorization (EUVD-2026-35075)
CVE-2026-36789 | Tenda AC1206 15.03.06.23 HTTP fromGstDhcpSetSer Password stack-based overflow (EUVD-2026-35076)
CVE-2026-43974 | ninenines gun up to 2.3.x reference behavioral workflow (EUVD-2026-35072)
CVE-2026-43973 | ninenines gun up to 2.3.x allocation of resources (EUVD-2026-35074)
CVE-2026-43972 | ninenines gun up to 2.3.x origin validation (EUVD-2026-35073)
Одна СМС — и данных нет: TeamGroup показала SSD, который уничтожает себя по команде
Tayara Data Breach: Hacker Claims 2M+ Tunisian User Records for Sale
New Pink Hacking Group Attacking Enterprise Users to Steal Cloud Storage Passwords
A newly identified extortion group called Pink has emerged as a serious threat to enterprise organizations, using social engineering tactics to steal cloud storage credentials and sensitive data. The group, tracked under the cluster code CL-CRI-1147, launched its dedicated data leak site on May 31, 2026, and has already listed several initial victims. Security teams […]
The post New Pink Hacking Group Attacking Enterprise Users to Steal Cloud Storage Passwords appeared first on Cyber Security News.
Microsoft changes how Defender for Endpoint EDR updates are delivered on Windows
Microsoft will distribute Defender for Endpoint EDR updates through Microsoft Update, enabling EDR security improvements to be released independently of monthly Windows operating system updates. The rollout started for Windows 10 devices in late May 2026 and will expand to Windows 11 and other supported Windows versions later this year. Microsoft expects deployment to be completed by fall 2026. Organizations whose devices receive updates through Microsoft Update do not need to take any action. Those … More →
The post Microsoft changes how Defender for Endpoint EDR updates are delivered on Windows appeared first on Help Net Security.