Aggregator
Progress Restores ShareFile Storage Zones Access After Security Warning
1 week ago
Progress has restored access to its ShareFile Storage Zones Controller after a four-day suspension triggered by a credible external security threat
Helping small businesses with free, hands-on cyber consultancy
1 week ago
Cyber Advisors are offering free 30-minute consultations to help small businesses get started with cyber security.
Microsoft’s July 2026 Patch Tuesday fixes 622 flaws and 2 exploited zero-days
1 week ago
Microsoft’s July 2026 Patch Tuesday fixes 622 CVEs, including exploited AD FS and SharePoint flaws, plus the disclosed BitLocker bypass requiring urgent action.
Waqas
AsyncAPI npm Supply Chain Attack: Malware Injected Into Packages With 2 Million Weekly Downloads
1 week ago
AsyncAPI npm packages with 2M weekly downloads were compromised, spreading malware with info-stealing, crypto-theft and RAT capabilities. OX Security researchers disclosed on July 14 that the AsyncAPI npm organization was compromised, with malicious code injected into four packages that together account for over 2 million weekly downloads. The affected versions are @asyncapi/generator 3.3.1, @asyncapi/generator-components 0.7.1, […]
Pierluigi Paganini
SASE Has An AI Blind Spot. Inspecting Packets Is No Longer Enough.
1 week ago
For years, routing traffic through cloud proxies was good enough. Then work moved to the browser, AI entered the workflow, and the inspection model stopped keeping up.
Enterprise workflows now live across SaaS applications, browsers, and an expanding ecosystem of generative AI tools, unsanctioned browser extensions, and autonomous agents. Employees routinely paste intellectual property into
The Hacker News
CVE-2025-68772 | Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 f2fs_write_cache_pages race condition (Nessus ID 283669 / WID-SEC-2026-0086)
1 week ago
A vulnerability has been found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 and classified as critical. Impacted is the function f2fs_write_cache_pages. This manipulation causes race condition.
The identification of this vulnerability is CVE-2025-68772. The attack needs to be done within the local network. There is no exploit available.
The affected component should be upgraded.
vuldb.com
CVE-2025-68770 | Linux Kernel up to 6.12.63/6.18.2/6.19-rc1 bnxt_rx_xdp iteration (Nessus ID 298917 / WID-SEC-2026-0086)
1 week ago
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.12.63/6.18.2/6.19-rc1. This vulnerability affects the function bnxt_rx_xdp. The manipulation leads to excessive iteration.
This vulnerability is uniquely identified as CVE-2025-68770. The attack can only be initiated within the local network. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2025-68771 | Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 ocfs2_find_victim_chain cl_next_free_rec allocation of resources (Nessus ID 298404 / WID-SEC-2026-0086)
1 week ago
A vulnerability was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 and classified as critical. The affected element is the function ocfs2_find_victim_chain. Such manipulation of the argument cl_next_free_rec leads to allocation of resources.
This vulnerability is referenced as CVE-2025-68771. The attack needs to be initiated within the local network. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2025-68768 | Linux Kernel up to 6.18.2/6.19-rc1 inet fqdir_pre_exit deadlock (Nessus ID 298917 / WID-SEC-2026-0086)
1 week ago
A vulnerability has been found in Linux Kernel up to 6.18.2/6.19-rc1 and classified as critical. This affects the function fqdir_pre_exit of the component inet. The manipulation leads to deadlock.
This vulnerability is referenced as CVE-2025-68768. The attack needs to be initiated within the local network. No exploit is available.
The affected component should be upgraded.
vuldb.com
CVE-2025-68769 | Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 f2fs_recover_fsync_data return value (Nessus ID 298404 / WID-SEC-2026-0086)
1 week ago
A vulnerability classified as critical was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. This affects the function f2fs_recover_fsync_data. Executing a manipulation can lead to unchecked return value.
This vulnerability is handled as CVE-2025-68769. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2025-68767 | Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 hfsplus initialization (EUVD-2026-2317 / Nessus ID 298404)
1 week ago
A vulnerability was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2 and classified as critical. This vulnerability affects unknown code of the component hfsplus. The manipulation results in improper initialization.
This vulnerability is identified as CVE-2025-68767. The attack can only be performed from the local network. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
LabubaRAT Rust Malware Masquerades as NVIDIA Software to Backdoor Windows Systems
1 week ago
A previously undocumented Rust-based remote access trojan, dubbed LabubaRAT, which masquerades as legitimate NVIDIA software to establish persistent access on Windows systems. The malware was identified by the company’s Adversary Pursuit Group (APG) and appears designed as a reusable, panel-managed framework rather than a single-purpose payload. The observed sample, named nvidia-sysruntime.exe, impersonates an NVIDIA Container […]
The post LabubaRAT Rust Malware Masquerades as NVIDIA Software to Backdoor Windows Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Mayura Kathir
CVE-2026-57831 | digital-peak DP Calendar Plugin up to 10.11.1 sql injection (EUVD-2026-44599)
1 week ago
A vulnerability classified as critical has been found in digital-peak DP Calendar Plugin up to 10.11.1. Affected by this vulnerability is an unknown functionality. Performing a manipulation results in sql injection.
This vulnerability was named CVE-2026-57831. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-57832 | Joomla EDocman up to 3.8 sql injection (EUVD-2026-44600)
1 week ago
A vulnerability classified as critical was found in Joomla EDocman up to 3.8. Affected by this issue is some unknown functionality. Executing a manipulation can lead to sql injection.
The identification of this vulnerability is CVE-2026-57832. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-57821 | Apache Fineract up to 1.14.0/1.14.x Office Search API /api/v1/offices orderBy sql injection (EUVD-2026-44605)
1 week ago
A vulnerability was found in Apache Fineract up to 1.14.0/1.14.x and classified as critical. Impacted is an unknown function of the file /api/v1/offices of the component Office Search API. Such manipulation of the argument orderBy leads to sql injection.
This vulnerability is listed as CVE-2026-57821. The attack may be performed from remote. There is no available exploit.
vuldb.com
CVE-2026-56287 | Apache Fineract up to 1.14.0 Client Search API /api/v1/clients orderBy/sortOrder sql injection (EUVD-2026-44603)
1 week ago
A vulnerability, which was classified as critical, was found in Apache Fineract up to 1.14.0. This vulnerability affects unknown code of the file /api/v1/clients of the component Client Search API. The manipulation of the argument orderBy/sortOrder results in sql injection.
This vulnerability is identified as CVE-2026-56287. The attack can be executed remotely. There is not any exploit available.
vuldb.com
CVE-2026-35152 | Apache Fineract up to 1.14.0 Report Execution API sql injection (EUVD-2026-44604)
1 week ago
A vulnerability has been found in Apache Fineract up to 1.14.0 and classified as critical. This issue affects some unknown processing of the component Report Execution API. This manipulation causes sql injection.
This vulnerability is tracked as CVE-2026-35152. The attack is possible to be carried out remotely. No exploit exists.
vuldb.com
CVE-2026-49501 | Dell PowerScale OneFS 9.5.0.0/9.10.1.7/9.11.0.0/9.13.0.2 improper authentication (EUVD-2026-44606)
1 week ago
A vulnerability was found in Dell PowerScale OneFS 9.5.0.0/9.10.1.7/9.11.0.0/9.13.0.2. It has been classified as problematic. The affected element is an unknown function. Performing a manipulation results in improper authentication.
This vulnerability is cataloged as CVE-2026-49501. The attack must be initiated from a local position. There is no exploit available.
vuldb.com
Secure Boot, одна из главных защит Windows и Linux, была сломана целых 10 лет. Это выяснилось только сейчас
1 week ago
11 файлов, о которых забыла Microsoft, держали открытой дверь в самое ядро компьютера.