[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> AI Tops Cybersecurity Investment Priorities, PwC Finds
PwC found that AI security has become a top investment priority in cyber budgets over the next 12 months, ahead of cloud and network security
> TOTOLINK X6000R: Three New Vulnerabilities Uncovered
Researchers identified vulnerabilities in TOTOLINK X6000R routers: CVE-2025-52905, CVE-2025-52906 and CVE-2025-52907. We discuss root cause and impact. The post TOTOLINK X6000R: Three New Vulnerabilities Uncovered appeared first on Unit 42.
> New China-Aligned Hackers Hit State and Telecom Sectors
Phantom Taurus is the latest formally identified cyber-espionage group aligned with Chinese state interest
> Campaign Warns Solicitors and House Buyers of Payment Diversion Fraud
The NCA warns that house buyers could face losses of over ÂŁ80,000 from a type of BEC called payment diversion fraud
> How I maintain release notes for curl
I believe a good product needs clear and thorough documentation. I think shipping a quality product requires you to provide detailed and informative release notes. I try to live up to this in the curl project, and this is how we do it. Scripts are your friends Some of the scripts I use to maintain …...
> Rhadamanthys 0.9.x – walk through the updates
Research by: hasherezade Highlights Introduction Rhadamanthys is a complex, multi-modular malware sold on the underground market since September 2022. It was first advertised by the actor “kingcrete2022.” From the outset, its design showed the hallmarks of experienced developers, and analysis soon r...
> ICO: Imgur’s UK Decision Won’t Prevent Regulatory Fine
Image-sharing platform Imgur has blocked its services within the UK, following a regulatory notice from the ICO
> CrowdStrike’s Fall 2025 Release Defines the Agentic SOC and Secures the AI Era
> ZDI-25-928: Delta Electronics EIP Builder EIP File Parsing XML External Entity Processing Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Delta Electronics EIP Builder. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rat...
> ZDI-25-927: Delta Electronics DIALink Directory Traversal Authentication Bypass Vulnerability
This vulnerability allows remote attackers to overwrite configuration files on affected installations of Delta Electronics DIALink. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.3. The following CVEs are assigned: CVE-2025-58320.
> Gate Crashing: An Interview Series
There is a lot of bad on the internet and it seems to only be getting worse. But one of the things the internet did well, and is worth preserving, is nontraditional paths for creativity, journalism, and criticism. As governments and major corporations throw up more barriers to expression—and more an...
> ZDI-25-926: Delta Electronics DIALink Directory Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Delta Electronics DIALink. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 10.0. The following CVEs are assigned: CVE-2025-58321.
> ZDI-25-925: Viessmann Vitogate 300 BN/MB vitogate.cgi form-0-2 Command Injection Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Viessmann Vitogate 300 BN/MB devices. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2025-9494.
> Louisiana Office of Student Financial Assistance
Le Louisiana Office of Student Financial Assistance subit une interruption de ses systèmes informatiques, ce qui pourrait entraîner des retards dans les paiements de bourses d'études ou de comptes d'épargne. L'agence investigate la cause de l'incident avec la police de l'État de Louisiane. Les détai...
> ZDI-25-924: Fuji Electric FRENIC-Loader 4 EXTBM File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric FRENIC-Loader 4. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7...
> ZDI-25-923: Fuji Electric FRENIC-Loader 4 EXRTM File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fuji Electric FRENIC-Loader 4. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7...
> CVE-2023-32874: Mediatek Baseband Excessive Number of SDP rtpmap Entries Leads to Stack Buffer Overflow
An attacker sending a malformed SIP message over VoLTE to a device with a Mediatek baseband can trigger the vulnerability described here. The impact is stack buffer overflow in the baseband, triggered by malformed SDP data in VoLTE message such as SIP INVITE or MESSAGE request. The vulnerability des...
> CVE-2023-32886: Mediatek Baseband Buffer Overflow During Handling SIP Multipart Messages
An attacker sending a malformed SIP message over VoLTE to a device with a Mediatek baseband can trigger the vulnerability described here. The impact is Heap Overflow in the baseband, triggered by malformed multipart SIP messages containing SMS data. The vulnerability described in this advisory affec...
> Jewett-Cameron Trading Co. Ltd.
La Jewett-Cameron Trading Co. Ltd. a subi une faille de sécurité informatique, un accès non autorisé à ses systèmes IT a été détecté, entraînant des perturbations opérationnelles et une possible fuite de données sensibles, notamment des informations financières et des enregistrements de réunions en...
> CVE-2023-32887: Mediatek Baseband Unbounded Recursion Leading to Stack Overflow During Handling SIP Comments
An attacker sending a malformed SIP message over VoLTE to a device with a Mediatek baseband can trigger the vulnerability described here. The impact is unbounded recursion based stack overflow in the baseband, triggered by malformed VoLTE message such as SIP INVITE or MESSAGE request. The vulnerabil...