24Articles
7Categories
2025-12-13Date
🚨
CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE AttacksThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a high-severity flaw impacting Sierra Wireless AirLink ALEOS routers to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. CVE-2018-4063 (CVSS sc…
KEV
πŸ›
Apple Issues Security Updates After Two WebKit Flaws Found Exploited in the Wild
KEV
πŸ›
CVE-2025-39925 can: j1939: implement NETDEV_UNREGISTER notification handler
πŸ›
CVE-2025-61662 Grub2: missing unregister call for gettext command may lead to use-after-free
πŸ›
CVE-2025-61663 Grub2: missing unregister call for normal commands may lead to use-after-free
πŸ›
CVE-2025-61661 Grub2: grub2: out-of-bounds write via malicious usb device
πŸ›
CVE-2025-61664 Grub2: missing unregister call for normal_exit command may lead to use-after-free
πŸ›
CVE-2025-14087 Glib: glib: buffer underflow in gvariant parser leads to heap corruption
πŸ›
CVE-2025-14512 Glib: integer overflow in glib gio attribute escaping causes heap buffer overflow
πŸ›
CVE-2025-14523 Libsoup: libsoup: duplicate host header handling causes host-parsing discrepancy (first- vs last-value wins)
πŸ›
CVE-2025-14104 Util-linux: util-linux: heap buffer overread in setpwnam() when processing 256-byte usernames
πŸ›
Apple Confirms Zero-Day Exploitation in Targeted Attacks on iPhone Users
KEV
⚠️
Leaked Home Depot credential exposed internal systems for a year
⚠️
Microsoft flips security script: β€˜In scope by default’ makes all vulnerabilities fair game for bug bounties
⚠️
The Hidden Danger of Storing Secrets Online | Interview with Jake Knott from Watchtower
⚠️
Empire 6.3.0 Released as Updated Post-Exploitation Framework for Red Teams
πŸ”₯
Researchers and Developers Targeted in AI-Driven GitHub Supply Chain Attack
πŸ”₯
CyberVolk’s ransomware debut stumbles on cryptography weakness
πŸ•΅οΈ
Hackers Target Windows Systems Using Phantom Stealer Hidden in ISO Files
πŸ•΅οΈ
China's Tech Lead: A 25-Year Shift
πŸ•΅οΈ
Kali Linux 2025.4 Released Featuring 3 New Hacking Tools and Wifipumpkin3
πŸ•΅οΈ
Hackers Launch Rust-Based Luca Stealer Targeting Linux and Windows
🌐
Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware Payloads
πŸ“‘
ClickFix Attacks Still Using the Finger, (Sat, Dec 13th)