Aggregator
WorldLeaks
You must login to view this content
Гигантская древняя чёрная дыра угрожает перевернуть всё, что мы знаем о рождении Вселенной
CVE-2022-2982 | vim up to 9.0.0258 use after free (EUVD-2022-35203)
CVE-2022-2981 | Download Monitor Plugin up to 4.5.97 on WordPress wp-config.php file access (EUVD-2022-35202)
CVE-2022-2980 | vim up to 9.0.0245 null pointer dereference (EUVD-2022-35201)
CVE-2025-38638 | Linux Kernel up to 6.16.0 net/ipv6/route.c net6_rt_notify privilege escalation (WID-SEC-2025-1898)
CVE-2025-38635 | Linux Kernel up to 6.16.0 clk davinci_lpsc_clk_register null pointer dereference (Nessus ID 276629 / WID-SEC-2025-1898)
CVE-2025-38636 | Linux Kernel up to 6.16.0 rv do_trace_event_raw_event_event_da_monitor out-of-bounds (Nessus ID 260281 / WID-SEC-2025-1898)
CVE-2025-38634 | Linux Kernel up to 6.16.0 power cpcap_usb_detect null pointer dereference (Nessus ID 276629 / WID-SEC-2025-1898)
CVE-2025-38633 | Linux Kernel up to 6.16.0 clk denial of service (WID-SEC-2025-1898)
CVE-2025-38632 | Linux Kernel up to 6.6.101/6.12.41/6.15.9/6.16.0 Gpio Call pinctrl_select_state null pointer dereference (Nessus ID 266176 / WID-SEC-2025-1898)
CVE-2025-38630 | Linux Kernel up to 6.16.0 fbdev fb_add_videomode return null pointer dereference (Nessus ID 276629 / WID-SEC-2025-1898)
CVE-2025-38631 | Linux Kernel up to 6.12.41/6.15.9/6.16.0 clk_register state issue (Nessus ID 260279 / WID-SEC-2025-1898)
CVE-2025-38629 | Linux Kernel up to 6.15.9/6.16.0 ALSA scarlett2_input_select_ctl_info null pointer dereference (Nessus ID 260284 / WID-SEC-2025-1898)
Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket
Michele Spagnuolo allegedly placed multiple trades on the prediction marketplace, abusing internal access to Google’s nonpublic data on the most searched people in 2025.
The post Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket appeared first on CyberScoop.
Hackers Use LLM Agent to Move From Marimo RCE to Internal Database in Four Pivots
A new kind of cyberattack is changing how defenders must think about intrusion detection. On May 10, 2026, a threat actor used a large language model (LLM) agent to drive a full post-exploitation chain, starting from an exposed notebook server and ending with an internal database dumped in under two minutes. This was not a […]
The post Hackers Use LLM Agent to Move From Marimo RCE to Internal Database in Four Pivots appeared first on Cyber Security News.