[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> Federal Agency Compromised Via GeoServer Exploit, CISA Reveals
An unnamed federal agency was hacked last year after threat actors exploited a critical GeoServer vulnerability
> European Police Bust €100m Crypto-Fraud Ring
Police have arrested five suspects linked to a €100m cryptocurrency fraud ring
> CVE-2025-55322 OmniParser Remote Code Execution Vulnerability
Binding to an unrestricted ip address in GitHub allows an unauthorized attacker to execute code over a network.
> Bouygues Telecom - 5,685,771 breached accounts
In August 2025, the French telecommunications company Bouygues Telecom detected a cyber attack against their services. The incident resulted in a data breach that exposed almost 6.4M customer records, including 5.7M unique email addresses. The breach also exposed names, physical addresses, phone num...
> ZDI-25-917: Linux Kernel ksmbd generate_key context.iov_base Null Pointer Dereference Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of the Linux Kernel. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2025-38562.
> ZDI-25-916: Linux Kernel ksmbd smb2_sess_setup Preauth_HashValue Race Condition Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Kernel. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.5. The following CVEs are assigned: CVE-2025-38561.
> Hidden WordPress Backdoors Creating Admin Accounts
During a recent cleanup of a compromised WordPress website, we discovered two different malicious files designed to silently manipulate administrator accounts. Attackers often inject such backdoors to maintain persistent access to a site, even if their other malware is detected and removed. These fi...
> ZDI-25-915: Linux Kernel io_uring Futex Request Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following C...
> ZDI-25-914: GIMP ILBM File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs ar...
> Refresco
Refresco, un fabricant de boissons, a été victime d'une attaque cybernétique en Allemagne, ce qui a affecté sa production. L'entreprise doit maintenant gérer les conséquences de cette attaque. Les détails de l'incident ne sont pas encore précisés.
> ZDI-25-913: GIMP FF File Parsing Integer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs ar...
> ZDI-25-912: GIMP WBMP File Parsing Integer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs ar...
> Burrillville School Department
Le département scolaire de Burrillville enquête sur une cyberattaque visant le lycée de Burrillville, mais aucune information sur les Chromebooks des élèves ou du personnel n'a été compromise. L'équipe informatique a pris des mesures pour arrêter l'attaque et les opérations scolaires se déroulent no...
> ZDI-25-911: GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs ar...
> ZDI-25-910: GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs ar...
> Bugnard SA
La PME vaudoise Bugnard SA a été victime d'une attaque par ransomware détectée le 24 septembre, l'entreprise reste à l'arrêt et l'hypothèse d'un paiement est envisagée. Les serveurs ainsi que le site internet ont été immédiatement mis hors ligne à titre de précaution. Le montant de la rançon initial...
> ZDI-25-909: GIMP ICNS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs ar...
> Don't Believe The Hype(rvisor): Defeating Huawei’s HHEE for fun and ... well, fun.
Once upon a time, I started at TASZK Security Labs as an intern. My internship project was about hacking hypervisors, and the target we picked for it was Huawei’s HEE (Hypervisor Execution Environment). The research was carried out in late 2020 to early 2021. Although we didn’t publish this work all...
> Boise Co-Op
Boise Co-Op experienced a network disruption on September 24, 2025, which led to unauthorized access to certain files containing personal information. The breach may have included names and Social Security numbers. Boise Co-Op is offering complimentary identity protection services to affected indivi...
> Evolve Mortgage Services
Evolve Mortgage Services, LLC suffered a data breach, providing complimentary credit monitoring and identity protection services to affected individuals. The breach occurred due to an incident, and the company is taking steps to protect customer information. A cyberattack was claimed by INC Ransom o...