Aggregator
Critical InputPlumber Vulnerabilities Allows UI Input Injection and Denial-of-Service
Critical vulnerabilities in InputPlumber, a Linux input device utility used in SteamOS, could allow attackers to inject UI inputs and cause denial-of-service conditions on affected systems. The SUSE researchers tracked as CVE-2025-66005 and CVE-2025-14338, which affect InputPlumber versions before v0.69.0 and stem from inadequate D-Bus authorization mechanisms. InputPlumber combines Linux input devices into virtual input devices and runs […]
The post Critical InputPlumber Vulnerabilities Allows UI Input Injection and Denial-of-Service appeared first on Cyber Security News.
Everest Hacking Group Allegedly Claims Breach of Nissan Motors
Everest hacking group has allegedly claimed a major breach of Nissan Motor Co., Ltd., raising fresh concerns about data security at large automotive manufacturers. According to early reports, the cybercrime group says it exfiltrated around 900 GB of sensitive data from the Japanese carmaker, a volume that suggests broad access to internal systems and repositories. […]
The post Everest Hacking Group Allegedly Claims Breach of Nissan Motors appeared first on Cyber Security News.
Critical Zlib Vulnerability Let Attackers Trigger Buffer Overflow by Invoking untgz
A severe global buffer overflow vulnerability has been discovered in the zlib untgz utility version 1.3.1.2. Allowing attackers to corrupt memory and potentially execute malicious code through specially crafted command-line input. The security flaw resides in the TGZfname() function of the untgz utility, where an unbounded strcpy() call processes user-supplied archive names without any length […]
The post Critical Zlib Vulnerability Let Attackers Trigger Buffer Overflow by Invoking untgz appeared first on Cyber Security News.
Взломать через «ржавую воду» — звучит как угроза пьяного сантехника, но на деле это новая тактика иранской разведки
Китай: «Starlink загрязняет орбиту». Также Китай: подаём заявку на 200 тысяч новых спутников
X Suspended Twitter Account for Violation of Rules
X has suspended the iconic @twitter handle on its platform, replacing its profile with a standard notice stating the account violates rules. Screenshots of the suspension screen began circulating widely late last week, igniting discussions about the platform’s rebranding efforts. The @twitter account had remained inactive since before Elon Musk’s 2022 acquisition of the platform, […]
The post X Suspended Twitter Account for Violation of Rules appeared first on Cyber Security News.
pfSense: Open-source firewall and routing platform
Firewalls, VPN access, and traffic rules need steady attention, often with limited budgets and staff. In that context, the open source pfSense Community Edition (CE) continues to show up in production environments, supported by a long-standing user community. pfSense CE is the free, open-source version of the pfSense firewall and routing platform. The software runs on standard x86 hardware, virtual machines, and some embedded systems, which keeps deployment flexible for small teams and labs. What … More →
The post pfSense: Open-source firewall and routing platform appeared first on Help Net Security.
CVE-2026-21858
CVE-2025-46279
Скриншоты, seed-фразы и захват терминала: хакеры теперь грабят пользователей через npm и Discord
新型网络犯罪工具ErrTraffic实现ClickFix攻击自动化 伪造网站故障诱骗用户中招
Ni8mare高危漏洞来袭 黑客可远程劫持n8n服务器
马来西亚印尼屏蔽 Grok
What security teams can learn from torrent metadata
Security teams often spend time sorting through logs and alerts that point to activity happening outside corporate networks. Torrent traffic shows up in investigations tied to policy violations, insider risk, and criminal activity. A new research paper looks at that same torrent activity through an open source intelligence lens and asks how much signal security teams can extract from data that is already public. Data pipeline design Turning torrent metadata into intelligence Torrent files contain … More →
The post What security teams can learn from torrent metadata appeared first on Help Net Security.
ZDI-CAN-28605: Microsoft
ZDI-CAN-28540: Microsoft
2025强网杯初赛用户态部分题解
Секрет вечной памяти… в халтуре. Ресурс чипов вырос в 1000 раз, когда их перестали «дожимать» до конца
EU’s Chat Control could put government monitoring inside robots
Cybersecurity debates around surveillance usually stay inside screens. A new academic study argues that this boundary no longer holds when communication laws extend into robots that speak, listen, and move among people. Researchers Neziha Akalin and Alberto Giaretta examine the European Union’s proposed Chat Control regulation and its unintended impact on human robot interaction. The continuum of surveillance, from watching public spaces, to listening in private communications, to acting within embodied environments. A brief look … More →
The post EU’s Chat Control could put government monitoring inside robots appeared first on Help Net Security.