Aggregator
CVE-2026-31627 | Linux Kernel up to 6.12.82/6.18.23/6.19.13/7.0.0 SMBUS Message I2C_SMBUS_BLOCK_MAX memory corruption (EUVD-2026-25520 / Nessus ID 310331)
CVE-2026-31625 | Linux Kernel up to 6.12.82/6.18.23/6.19.13/7.0.0 HID Driver alps_raw_event null pointer dereference (WID-SEC-2026-1279)
Lazarus APT unveils fileless remote access Trojan designed to evade detection
BepiColombo 计划于 11 月 21 日进入水星轨道
CVE-2026-46598 | x-crypto up to 0.51.x ed25519.PrivateKey array index (Nessus ID 316564 / WID-SEC-2026-1653)
CVE-2026-41148 | mermaid-js mermaid up to 10.9.5/11.14.x createCssStyles Parser addStyleClass code injection (GHSA-xcj9-5m2h-648r / Nessus ID 316560)
CVE-2026-39829 | x-crypto up to 0.51.x RSA/DSA inefficient cpu computation (EUVD-2026-31396 / Nessus ID 316561)
CVE-2026-44933 | SUSE Linux Enterprise/openSUSE up to 17.38.8 path traversal (Nessus ID 316567)
CVE-2026-8631 | HP Linux Imaging and Printing Software up to 3.26.3 heap-based overflow (EUVD-2026-31193 / Nessus ID 316566)
CVE-2026-39832 | x-crypto up to 0.51.x on Go Destination NewKeyring access control (EUVD-2026-31390 / Nessus ID 316565)
CVE-2026-9527 | itsourcecode Electronic Judging System 1.0 /admin/judges.php fname cross site scripting (EUVD-2026-31787)
CVE-2026-9528 | itsourcecode Electronic Judging System 1.0 /admin/delete_judge.php judge_id sql injection (EUVD-2026-31785)
CVE-2026-9529 | GNU LibreDWG up to 0.14 Dwggrep Utility dwggrep.c match_BLOCK_HEADER null pointer dereference (Issue 1247 / EUVD-2026-31788)
CVE-2026-9530 | GNU LibreDWG up to 0.14 Dwgbmp Utility src/decode.c read_2004_compressed_section out-of-bounds (Issue 1248 / EUVD-2026-31790)
CVE-2026-9531 | Totolink CA750-PoE 6.2c.510 Setting /cgi-bin/cstecgi.cgi setUpgradeUboot FileName os command injection (EUVD-2026-31789)
Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files
A dangerous new ransomware strain called Payload has been quietly building a global victim list since it first appeared in February 2026. The group launched its leak site with a high-profile target and has since expanded operations across Egypt, Mexico, Poland, and beyond. What makes this threat stand out is not just its reach, but […]
The post Payload Ransomware Uses ChaCha20 and Curve25519 ECDH to Encrypt Windows Files appeared first on Cyber Security News.
PuTTY 0.84 Released With Fix for SSH KEX Crashes and Telnet Prompt Spoofing Flaw
PuTTY 0.84 has been released with fixes for multiple minor security flaws, including issues that could trigger SSH key exchange crashes and a Telnet prompt spoofing weakness. While these vulnerabilities are considered low severity, they highlight how even small flaws in cryptographic handling and session logic can be abused in specific attack scenarios, particularly by […]
The post PuTTY 0.84 Released With Fix for SSH KEX Crashes and Telnet Prompt Spoofing Flaw appeared first on Cyber Security News.