U.S. Attorney Jay Clayton said Spalletta “repeatedly hacked smart contracts to steal millions of dollars’ worth of other people’s money for himself, and destroyed a cryptocurrency exchange in the process.”
Cisco has suffered a cyberattack after threat actors used stolen credentials from the recent Trivy supply chain attack to breach its internal development environment and steal source code belonging to the company and its customers. [...]
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.6.119/6.12.63/6.18.3/6.19-rc3. This impacts the function _elements_from_package. Performing a manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2025-71101. Access to the local network is required for this attack. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability identified as critical has been detected in Linux Kernel up to 6.6.119/6.12.63/6.18.2. This affects the function f2fs_put_super. The manipulation leads to improper update of reference count.
This vulnerability is listed as CVE-2025-71107. The attack must be carried out from within the local network. There is no available exploit.
You should upgrade the affected component.
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. Affected by this vulnerability is an unknown functionality of the component hwmon. Such manipulation leads to race condition.
This vulnerability is documented as CVE-2025-71111. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is recommended.
A vulnerability classified as critical was found in Linux Kernel up to 6.18.2. This affects the function filesystems_freeze_callback of the component fs. Executing a manipulation can lead to denial of service.
This vulnerability appears as CVE-2025-71106. The attacker needs to be present on the local network. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability has been found in Linux Kernel up to 6.12.63/6.18.2 and classified as critical. Impacted is the function UASM_i_LA_mostly of the component MIPS. This manipulation causes memory corruption.
This vulnerability is handled as CVE-2025-71109. The attack can only be done within the local network. There is not any exploit available.
The affected component should be upgraded.
A vulnerability was found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. It has been classified as critical. The impacted element is the function __scs_magic. Performing a manipulation results in denial of service.
This vulnerability was named CVE-2025-71102. The attack needs to be approached within the local network. There is no available exploit.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in Linux Kernel up to 6.18.2/6.19-rc2. This affects the function a7xx_patch_pwrup_reglist. Performing a manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2025-71103. The attack must originate from the local network. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability described as critical has been identified in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. This vulnerability affects unknown code of the component usb. Executing a manipulation of the argument num_connectors can lead to state issue.
This vulnerability is registered as CVE-2025-71108. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability, which was classified as critical, has been found in Linux Kernel up to 6.1.159/6.6.119/6.12.63/6.18.2. The affected element is the function inline_xattr_slab of the file mm/slab_common.c of the component f2fs. This manipulation causes improper update of reference count.
This vulnerability appears as CVE-2025-71105. The attacker needs to be present on the local network. There is no available exploit.
It is advisable to upgrade the affected component.
A vulnerability has been found in Linux Kernel up to 6.18.2/6.19-rc1 and classified as critical. This affects the function defer_free. Performing a manipulation results in use after free.
This vulnerability is known as CVE-2025-71110. Access to the local network is required for this attack. No exploit is available.
The affected component should be upgraded.
A vulnerability described as critical has been identified in Totolink A3300R 17.0.0cu.557_b20221024. Impacted is the function setStaticRoute of the file /cgi-bin/cstecgi.cgi. Such manipulation of the argument ip leads to command injection.
This vulnerability is listed as CVE-2026-5104. The attack may be performed from remote. In addition, an exploit is available.
A vulnerability marked as critical has been reported in Totolink A3300R 17.0.0cu.557_b20221024. This issue affects the function setUPnPCfg of the file /cgi-bin/cstecgi.cgi. This manipulation of the argument enable causes command injection.
This vulnerability is tracked as CVE-2026-5103. The attack is possible to be carried out remotely. Moreover, an exploit is present.