BGP is vulnerable to routing hijacks and path leaks that negatively impact traffic on the Internet. RPKI helps solve some of these problems, but for some forged paths, we need to rely on a simpler mechanism: First AS enforcement in BGP.
A threat actor using the alias DumpsecV2 ("Dumpsec") claims to be selling a large dataset stolen from Carvivo, a French SaaS provider whose "Carvivo Contact" platform manages automotive sales leads for car dealerships across Europe.
A vulnerability, which was classified as problematic, was found in Linux Kernel up to 6.19.10. This issue affects the function btusb_work of the component Bluetooth. Such manipulation of the argument alts[] leads to privilege escalation.
This vulnerability is traded as CVE-2026-31497. Access to the local network is required for this attack to succeed. There is no exploit available.
You should upgrade the affected component.
A vulnerability was found in Linux Kernel up to 6.19.10. It has been classified as critical. This issue affects the function devm_spi_register_controller of the component spi. Performing a manipulation results in use after free.
This vulnerability was named CVE-2026-31485. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in Linux Kernel up to 6.19.3. This affects an unknown function of the file /smack/doi of the component smack. Performing a manipulation results in privilege escalation.
This vulnerability is cataloged as CVE-2025-71304. The attack must originate from the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.19.5 and classified as critical. Affected by this vulnerability is the function drop_nlink of the component jfs. The manipulation leads to buffer overflow.
This vulnerability is uniquely identified as CVE-2025-71292. The attack can only be initiated within the local network. No exploit exists.
The affected component should be upgraded.
A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.19.5. Affected by this issue is the function driver_override_show in the library include/linux/rpmsg.h. Executing a manipulation can lead to use after free.
The identification of this vulnerability is CVE-2025-71274. The attack needs to be done within the local network. There is no exploit available.
You should upgrade the affected component.
Redis has patched a use-after-free in its blocking-client code that lets an authenticated user run arbitrary OS commands on the machine hosting the database. The flaw was found by an autonomous AI tool built to hunt bugs in large codebases.
Tracked as CVE-2026-23479, the flaw was introduced in Redis 7.2.0 and remained in every stable branch until the May 5 fixes, unnoticed for over two years.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical flaw impacting Mirasvit Cache Warmer, a popular Magento full-page cache extension, to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.
The vulnerability, tracked as CVE-2026-45247 (CVSS score: 9.8), is a case of deserialization of untrusted
Cybersecurity researchers have flagged a new malspam campaign that makes use of Google's DoubleClick domain as a way to evade detection and ultimately deliver an unidentified .NET-based loader.
"Before the victim ever reaches attacker-controlled infrastructure, the lure routes through DoubleClick, a legitimate Google-owned domain that many security tools are less likely to treat as suspicious,"
A vulnerability identified as problematic has been detected in Rockwell ControlLogix controllers up to 20. Affected by this vulnerability is an unknown functionality. This manipulation causes improper resource management.
This vulnerability is registered as CVE-2012-6435. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability labeled as critical has been found in Rockwell ControlLogix controllers up to 20. Affected by this issue is some unknown functionality. Such manipulation leads to memory corruption.
This vulnerability is documented as CVE-2012-6436. The attack can be executed remotely. There is not any exploit available.
A vulnerability marked as critical has been reported in Rockwell ControlLogix controllers up to 20. This affects an unknown part. Performing a manipulation results in improper authentication.
This vulnerability is reported as CVE-2012-6437. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability described as critical has been identified in Rockwell ControlLogix controllers up to 20. This vulnerability affects unknown code. Executing a manipulation can lead to memory corruption.
This vulnerability appears as CVE-2012-6438. The attack may be performed from remote. There is no available exploit.
A vulnerability classified as problematic was found in Rockwell ControlLogix controllers up to 20. Impacted is an unknown function. The manipulation results in improper authentication.
This vulnerability is known as CVE-2012-6440. It is possible to launch the attack remotely. No exploit is available.
A vulnerability, which was classified as problematic, was found in Rockwell ControlLogix controllers up to 20. The impacted element is an unknown function. Such manipulation leads to memory corruption.
This vulnerability is uniquely identified as CVE-2012-6442. The attack can be launched remotely. No exploit exists.
A vulnerability was found in Allen-Bradley MicroLogix 1100/1400 and classified as critical. This affects an unknown function. Executing a manipulation can lead to memory corruption.
This vulnerability is tracked as CVE-2015-6490. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.