Aggregator
Qualcomm security advisory – January 2026 monthly rollup (AV26-006)
CVE-2024-31429 | Blossom Themes Sarada Lite Plugin up to 1.1.2 on WordPress cross-site request forgery
CVE-2023-51795 | FFmpeg N113007-g8d24a28d06 avf_showspectrum.c showspectrumpic_request_frame buffer overflow (ID 10749)
CVE-2025-38487 | Linux Kernel up to 6.1.146/6.6.99/6.12.39/6.15.7 soc unbind misc_deregister null pointer dereference (Nessus ID 270134 / WID-SEC-2025-1665)
CVE-2025-38480 | Linux Kernel up to 6.1.146/6.6.99/6.12.39/6.15.7 Subdevice Driver comedi_fops.c insn_rw_emulate_bits uninitialized pointer (Nessus ID 270134 / WID-SEC-2025-1665)
CVE-2025-38481 | Linux Kernel up to 6.1.146/6.6.99/6.12.39/6.15.7 COMEDI_INSNLIST n_insns buffer overflow (Nessus ID 270134 / WID-SEC-2025-1665)
CVE-2025-38482 | Linux Kernel up to 6.1.146/6.6.99/6.12.39/6.15.7 comedi out-of-bounds (Nessus ID 270134 / WID-SEC-2025-1665)
CVE-2025-38483 | Linux Kernel up to 6.1.146/6.6.99/6.12.39/6.15.7 comedi out-of-bounds (Nessus ID 270134 / WID-SEC-2025-1665)
CVE-2025-38485 | Linux Kernel up to 6.1.146/6.6.99/6.12.39/6.15.7 iio fxls8962af_fifo_flush null pointer dereference (Nessus ID 252233 / WID-SEC-2025-1665)
CVE-2025-38488 | Linux Kernel up to 6.1.146/6.6.99/6.12.39/6.15.7 smb crypt_message null pointer dereference (Nessus ID 251300 / WID-SEC-2025-1665)
CVE-2025-5914 | libarchive up to 3.7.x archive_read_support_format_rar.c archive_read_format_rar_seek_data double free (EUVD-2025-17572 / Nessus ID 240326)
CVE-2023-51796 | FFmpeg libavfilter/f_reverse.c areverse_request_frame buffer overflow (ID 10753)
CVE-2023-51797 | FFmpeg avf_showwaves.c showwaves_filter_frame buffer overflow (ID 10756)
CVE-2023-51798 | FFmpeg N113007-g8d24a28d06 vf_minterpolate.c interpolate buffer overflow (ID 10758 / Nessus ID 232751)
New Actor Sells US Government And Police Portal Access
You must login to view this content
Versatile Malware Loader pkr_mtsi Delivers Diverse Payloads
Brazilian Firm Futurize Sistemas Breached
You must login to view this content
Ransomware Hits a Claims Giant: What the Sedgwick Breach Reveals About Modern Extortion Attacks
A recent breach disclosure reveals that claims management firm Sedgwick was targeted by the TridentLocker ransomware group, with attackers claiming to have exfiltrated sensitive data from systems supporting its government services operations before deploying ransomware, according to Cybersecurity News. While Sedgwick has not disclosed full technical details, the incident follows a well-established ransomware playbook. Attackers
The post Ransomware Hits a Claims Giant: What the Sedgwick Breach Reveals About Modern Extortion Attacks appeared first on Seceon Inc.
The post Ransomware Hits a Claims Giant: What the Sedgwick Breach Reveals About Modern Extortion Attacks appeared first on Security Boulevard.
Windows Packer pkr_mtsi Powers Widespread Malvertising Campaigns Delivering Multiple Malware Families
A sophisticated Windows packer known as pkr_mtsi has emerged as a powerful tool for delivering multiple malware families through widespread malvertising campaigns. First detected on April 24, 2025, this malicious packer continues to operate actively, distributing trojanized installers disguised as legitimate software applications. The packer targets popular tools including PuTTY, Rufus, and Microsoft Teams, using […]
The post Windows Packer pkr_mtsi Powers Widespread Malvertising Campaigns Delivering Multiple Malware Families appeared first on Cyber Security News.