Search found 1836 matches

by Shane1145
Wed Dec 17, 2025 2:22 am
Forum: Android/iOS
Topic: Google Patches 107 Android Flaws, Including Two Framework Bugs Exploited in the Wild
Replies: 0
Views: 19

Google Patches 107 Android Flaws, Including Two Framework Bugs Exploited in the Wild

Google on Monday released monthly security updates for the Android operating system, including two vulnerabilities that it said have been exploited in the wild.

The patch addresses a total of 107 security flaws spanning different components, including Framework, System, Kernel, as well as those ...
by Shane1145
Wed Dec 17, 2025 2:17 am
Forum: Web Applications
Topic: PCPcat Malware Leverages React2Shell Vulnerability to Breach 59,000+ Servers
Replies: 0
Views: 12

PCPcat Malware Leverages React2Shell Vulnerability to Breach 59,000+ Servers

A sophisticated attack campaign attributed to a group identifying as “PCP” has compromised 59,128 servers in less than 48 hours by exploiting critical Next.js vulnerabilities.

Security researchers discovered the large-scale operation while monitoring a Docker honeypot, uncovering an industrialized ...
by Shane1145
Wed Dec 17, 2025 2:13 am
Forum: Consumer
Topic: Broken Access Control in D-Link DAP-1325 Wireless Range Extender
Replies: 0
Views: 28

Broken Access Control in D-Link DAP-1325 Wireless Range Extender

The D-Link DAP-1325 contains a vulnerability that allows attackers to exploit a broken access control mechanism. By accessing the /cgi-bin/ExportSettings.sh endpoint, unauthorized users can download sensitive device configuration settings without requiring any authentication. This exposes critical ...
by Shane1145
Wed Dec 17, 2025 2:11 am
Forum: Programming Languages
Topic: ReDOS Vulnerability in PyMdown Extensions for Python-Markdown
Replies: 0
Views: 14

ReDOS Vulnerability in PyMdown Extensions for Python-Markdown

The PyMdown Extensions include a variety of enhancements for the Python-Markdown project, but versions prior to 10.16.1 contain a vulnerability in the figure caption extension (pymdownx.blocks.caption). This ReDOS issue can lead to performance degradation, causing significant delays while processing ...
by Shane1145
Wed Dec 17, 2025 2:10 am
Forum: Programming Languages
Topic: OS Command Injection Vulnerability in Systeminformation Library for Node.js
Replies: 0
Views: 12

OS Command Injection Vulnerability in Systeminformation Library for Node.js

The systeminformation library for Node.js is susceptible to an OS command injection vulnerability due to improper sanitization of user inputs. In versions prior to 5.27.14, the fsSize() function concatenates a user-defined drive parameter into a PowerShell command, potentially allowing an attacker ...
by Shane1145
Wed Dec 17, 2025 2:06 am
Forum: Commercial
Topic: OSPFv3 Process High CPU Utilization in Arista EOS
Replies: 0
Views: 13

OSPFv3 Process High CPU Utilization in Arista EOS

On systems running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can lead to excessive CPU usage in the OSPFv3 process. This may cause the OSPFv3 process to restart, interrupting routes on the switch and potentially impacting network stability ...
by Shane1145
Wed Dec 17, 2025 2:04 am
Forum: Web Applications
Topic: Use After Free Vulnerability in Google Chrome Affecting WebGPU
Replies: 0
Views: 13

Use After Free Vulnerability in Google Chrome Affecting WebGPU

A use after free vulnerability in the WebGPU component of Google Chrome allows a potential remote attacker to exploit heap corruption. This can be triggered through a specially crafted HTML page, potentially leading to unexpected application behavior or security breaches.


https ...
by Shane1145
Mon Dec 15, 2025 3:24 pm
Forum: Windows
Topic: Hackers Launch Rust-Based Luca Stealer Targeting Linux and Windows
Replies: 0
Views: 19

Hackers Launch Rust-Based Luca Stealer Targeting Linux and Windows

Cybercriminals are increasingly abandoning traditional programming languages like C and C++ in favor of modern alternatives such as Rust, Golang, and Nim.

This strategic shift enables threat actors to write malicious code once and compile it for both Windows and Linux with minimal changes.

Leading ...
by Shane1145
Mon Dec 15, 2025 3:21 pm
Forum: Commercial
Topic: NVIDIA Merlin Vulnerabilities Allows Malicious Code Execution and DoS Attacks
Replies: 0
Views: 24

NVIDIA Merlin Vulnerabilities Allows Malicious Code Execution and DoS Attacks

NVIDIA has released urgent security patches for its Merlin machine learning framework after discovering two high-severity deserialization vulnerabilities that could enable attackers to execute malicious code, trigger denial-of-service attacks, and compromise sensitive data on Linux systems.

The ...
by Shane1145
Mon Dec 15, 2025 3:18 pm
Forum: Android/iOS
Topic: Android Users at Risk as Malware Poses as mParivahan and e-Challan AppsA sophisticated Android malware campaign dubbed N
Replies: 0
Views: 19

Android Users at Risk as Malware Poses as mParivahan and e-Challan AppsA sophisticated Android malware campaign dubbed N

A sophisticated Android malware campaign dubbed NexusRoute is actively targeting Indian users by impersonating the Indian Government Ministry, mParivahan, and e-Challan services to steal credentials and carry out large-scale financial fraud.

The operation combines phishing, malware, and ...