119Articles
7Categories
2026-01-08Date
๐Ÿ›
Holes in Veeam Backup suite allow remote code execution, creation of malicious backup config files
๐Ÿ›
CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited
KEV
๐Ÿ›
CVE-2025-38480 comedi: Fix use of uninitialized data in insn_rw_emulate_bits()
๐Ÿ›
CVE-2025-38483 comedi: das16m1: Fix bit shift out of bounds
๐Ÿ›
CVE-2025-38495 HID: core: ensure the allocated report buffer can contain the reserved report ID
๐Ÿ›
CVE-2025-38481 comedi: Fail COMEDI_INSNLIST ioctl if n_insns is too large
๐Ÿ›
CVE-2025-38487 soc: aspeed: lpc-snoop: Don't disable channels that aren't enabled
๐Ÿ›
CVE-2025-38485 iio: accel: fxls8962af: Fix use after free in fxls8962af_fifo_flush
๐Ÿ›
CVE-2025-38482 comedi: das6402: Fix bit shift out of bounds
๐Ÿ›
CVE-2025-38497 usb: gadget: configfs: Fix OOB read on empty string write
๐Ÿ›
CVE-2025-38491 mptcp: make fallback action and fallback decision atomic
๐Ÿ›
CVE-2025-38488 smb: client: fix use-after-free in crypt_message when using async crypto
๐Ÿ›
CVE-2025-68753 ALSA: firewire-motu: add bounds check in put_user loop for DSP events
๐Ÿ›
CVE-2025-68766 irqchip/mchp-eic: Fix error code in mchp_eic_domain_alloc()
๐Ÿ›
CVE-2025-68303 platform/x86: intel: punit_ipc: fix memory corruption
๐Ÿ›
CVE-2025-68301 net: atlantic: fix fragment overflow handling in RX path
๐Ÿ›
CVE-2025-68311 tty: serial: ip22zilog: Use platform device for probing
๐Ÿ›
CVE-2025-38644 wifi: mac80211: reject TDLS operations when station is not associated
๐Ÿ›
CVE-2025-38630 fbdev: imxfb: Check fb_add_videomode to prevent null-ptr-deref
๐Ÿ›
CVE-2025-38639 netfilter: xt_nfacct: don't assume acct name is null-terminated
๐Ÿ›
CVE-2025-38499 clone_private_mnt(): make sure that caller has CAP_SYS_ADMIN in the right userns
๐Ÿ›
CVE-2025-38635 clk: davinci: Add NULL check in davinci_lpsc_clk_register()
๐Ÿ›
CVE-2025-38624 PCI: pnv_php: Clean up allocated IRQs on unplug
๐Ÿ›
CVE-2025-38634 power: supply: cpcap-charger: Fix null check for power_supply_get_by_name
๐Ÿ›
CVE-2025-38502 bpf: Fix oob access in cgroup local storage
๐Ÿ›
Cisco Patches ISE Security Vulnerability After Public PoC Exploit Release
๐Ÿ›
Coolify Discloses 11 Critical Flaws Enabling Full Server Compromise on Self-Hosted Instances
๐Ÿ›
Critical jsPDF vulnerability enables arbitrary file read in Node.js deployments
๐Ÿ›
Critical Vulnerability Exposes n8n Instances to Takeover Attacks
๐Ÿ›
Ni8mare - Unauthenticated Remote Code Execution in n8n (CVE-2026-21858) | Cyera Research Labs
๐Ÿ›
Cisco ISE Vulnerability Enables Access to Sensitive Data
๐Ÿ›
Cisco Snort 3 Vulnerability Leading to Sensitive Data Disclosure
๐Ÿ›
React2Shell Vulnerability Hit by 8.1 Million Attack Attempts
๐Ÿ›
CVE-2025-9901 Libsoup: improper handling of http vary header in libsoup caching
๐Ÿ›
CVE-2025-1220 Null byte termination in hostnames
โš ๏ธ
Analysis using Gephi with DShield Sensor Data, (Wed, Jan 7th)
โš ๏ธ
Die wichtigsten CISO-Trends fรผr 2026
โš ๏ธ
Top cyber threats to your AI systems and infrastructure
โš ๏ธ
CISA tags max severity HPE OneView flaw as actively exploited
KEV
โš ๏ธ
Three Malicious NPM Packages Target Developersโ€™ Login Credentials
โš ๏ธ
Linux Battery Utility Vulnerability Allows Authentication Bypass and System Tampering
โš ๏ธ
ownCloud Warns Users to Enable MFA After Credential Theft Incident
โš ๏ธ
Global GoBruteforcer Botnet Campaign Threatens 50,000 Linux Servers
โš ๏ธ
Cybercriminals Exploit VMware ESXi Vulnerabilities Using Zero-Day Toolset
โš ๏ธ
Cisco warns of Identity Service Engine flaw with exploit code
โš ๏ธ
Critical HPE OneView Vulnerability Exploited in Attacks
โš ๏ธ
NIS2-Umsetzung: Neues BSI-Portal geht an den Start
โš ๏ธ
The State of Trusted Open Source
โš ๏ธ
AI & Humans: Making the Relationship Work
โš ๏ธ
Microsoft to enforce MFA for Microsoft 365 admin center sign-ins
โš ๏ธ
Microsoft warns of a surge in phishing attacks exploiting email routing gaps | CSO Online
โš ๏ธ
ThreatsDay Bulletin: RustFS Flaw, Iranian Ops, WebUI RCE, Cloud Leaks, and 12 More Stories
โš ๏ธ
Critical Vulnerability Patched in jsPDF
โš ๏ธ
Rethinking Security for Agentic AI
โš ๏ธ
Phishing-Angreifer setzen vermehrt auf E-Mail-Routing-Lรผcken
โš ๏ธ
Cybersecurity at the edge: Securing rugged IoT in mission-critical environments
โš ๏ธ
Phishing Campaign Targets WhatsApp Accounts
โš ๏ธ
Cisco warns of Identity Service Engine flaw with exploit code
โš ๏ธ
Report: China Breached Email Systems Used by U.S. Congressional Staff
โš ๏ธ
WhatsApp Worm Spreads Astaroth Banking Trojan Across Brazil via Contact Auto-Messaging
โš ๏ธ
Inside GoBruteforcer: AI-Generated Server Defaults, Weak Passwords, and Crypto-Focused Campaigns - Check Point Research
โš ๏ธ
The 2 faces of AI: How emerging models empower and endanger cybersecurity
โš ๏ธ
VMware ESXi zero-days likely exploited a year before disclosure
โš ๏ธ
New China-linked hackers breach telcos using edge device exploits
๐Ÿ“ข
GitLab Patches Multiple Flaws Allowing Arbitrary Code Execution
๐Ÿ“ข
Researchers Expose WHILL Wheelchair Safety Risks via Remote Hacking
๐Ÿ“ข
GitLab security advisory (AV26-009)
๐Ÿ“ข
Tenable security advisory (AV26-010)
๐Ÿ“ข
[Control systems] ABB security advisory (AV26-011)
๐Ÿ“ข
Trend Micro security advisory (AV26-012)
๐Ÿ“ข
No FlipperZeros Allowed - PSW #908
๐Ÿ“ข
CISA retires 10 emergency cyber orders in rare bulk closure
๐Ÿ“ข
CISAโ€ฏRetiresโ€ฏTenโ€ฏEmergencyโ€ฏDirectives, Marking an Era in Federal Cybersecurity
๐Ÿ”ฅ
Smashing Security podcast #449: How to scam someone in seven days
๐Ÿ”ฅ
China hacked email systems of US congressional committee staff
๐Ÿ”ฅ
Researchers Poison Stolen Data to Sabotage AI Model Accuracy
๐Ÿ”ฅ
Dozens of Global Companies Hacked via Cloud Credentials from Infostealer Infections & More at Risk
๐Ÿ”ฅ
Spanish airline Iberia attributes recent data breach claims to November incident | The Record from Recorded Future News
๐Ÿ”ฅ
European Space Agency initiates criminal probe into breach โ€ข The Register
๐Ÿ”ฅ
UK Government Launches Cyber Action Plan to Bolster Public Sector Security
๐Ÿ”ฅ
Credential stuffing: What it is and how to protect yourself
๐Ÿ•ต๏ธ
ISC Stormcast For Thursday, January 8th, 2026 https://isc.sans.edu/podcastdetail/9758, (Thu, Jan 8th)
๐Ÿ•ต๏ธ
BlueDelta Hackers Target Microsoft OWA, Google, and Sophos VPN to Steal Credentials
๐Ÿ•ต๏ธ
The AI Security Shakedown
๐Ÿ•ต๏ธ
Prisma AIRS Secures the Power of Factoryโ€™s Software Development Agents
๐Ÿ•ต๏ธ
Gen AI data violations more than double - Help Net Security
๐Ÿ•ต๏ธ
Defending Against Modern Email Threats With Layered, AI-Driven Security
๐Ÿ•ต๏ธ
Cyera Raises $400 Million at $9 Billion Valuation
๐Ÿ•ต๏ธ
Blackbird.AI Raises $28 Million for Narrative Intelligence Platform
๐Ÿ•ต๏ธ
China-Linked UAT-7290 Targets Telecoms with Linux Malware and ORB Nodes
๐Ÿ•ต๏ธ
Clang Hardening Cheat Sheet - Ten Years Later
๐Ÿ•ต๏ธ
CrowdStrike to Buy Identity Security Firm SGNL for $740 Million in Cash
๐Ÿ•ต๏ธ
Automated data poisoning proposed as a solution for AI theft threat
๐Ÿ•ต๏ธ
UK Government Unveils New Cyber Action Plan
๐Ÿ•ต๏ธ
Researches Detailed AuraStealer Obfuscation, Anti-Analysis and Data Theft Capabilities
๐Ÿ•ต๏ธ
New OAuth Attack Lets Hackers Bypass Microsoft Entra Authentication and Steal Keys
๐Ÿ•ต๏ธ
New DocuSign-Themed Phishing Scam Delivers Stealth Malware to Windows Devices
๐Ÿ•ต๏ธ
Trump Signals Possible Cyber Involvement in Caracas Power Loss During Maduro Extraction
๐Ÿ•ต๏ธ
ChatGPT Health: A New Secure Space for Trusted Health and Medical Conversations
๐Ÿ•ต๏ธ
How Attackers Hide Processes by Abusing Kernel Patch Protection
๐Ÿ•ต๏ธ
Black Cat Behind SEO Poisoning Malware Campaign Targeting Popular Software Searches
๐Ÿ•ต๏ธ
Coolify Discloses 11 Critical Flaws Enabling Full Server Compromise on Self-Hosted Instances
๐Ÿ•ต๏ธ
Malicious NPM Packages Deliver NodeCordRAT
๐Ÿ•ต๏ธ
Happy 23rd Birthday TaoSecurity Blog
๐Ÿ•ต๏ธ
FBI warns about Kimsuky hackers using QR codes to phish U.S. orgs
๐Ÿ•ต๏ธ
Caught by Keystroke Lag
๐ŸŒ
Researchers Uncover NodeCordRAT Hidden in npm Bitcoin-Themed Packages
๐ŸŒ
Six for 2026: The cyber threats you canโ€™t ignore
๐ŸŒ
Critics pan spyware maker NSOโ€™s transparency claims amid its push to enter US market
๐ŸŒ
Who Benefited from the Aisuru and Kimwolf Botnets?
๐Ÿ“ก
OpenAI Launches ChatGPT Health with Isolated, Encrypted Health Data Controls
๐Ÿ“ก
Microsoft Exchange Online outage blocks access to mailboxes via IMAP4
๐Ÿ“ก
Texas court blocks Samsung from collecting smart TV viewing data
๐Ÿ“ก
Illinois health department exposed over 700,000 residentsโ€™ personal data for years
๐Ÿ“ก
Internet collapses in Iran amid protests over economic crisis
๐Ÿ“ก
Cisco switches hit by reboot loops due to DNS client bug
๐Ÿ“ก
Texas court blocks Samsung from tracking TV viewing, then vacates order
๐Ÿ“ก
xAI teases major Grok upgrade, hints at Grok Code CLI
๐Ÿ“ก
Gmail's new AI Inbox uses Gemini, but Google says it wonโ€™t train AI on user emails