Google on Monday released monthly security updates for the Android operating system, including two vulnerabilities that it said have been exploited in the wild.
The patch addresses a total of 107 security flaws spanning different components, including Framework, System, Kernel, as well as those ...
Search found 1836 matches
- Wed Dec 17, 2025 2:22 am
- Forum: Android/iOS
- Topic: Google Patches 107 Android Flaws, Including Two Framework Bugs Exploited in the Wild
- Replies: 0
- Views: 19
- Wed Dec 17, 2025 2:17 am
- Forum: Web Applications
- Topic: PCPcat Malware Leverages React2Shell Vulnerability to Breach 59,000+ Servers
- Replies: 0
- Views: 14
PCPcat Malware Leverages React2Shell Vulnerability to Breach 59,000+ Servers
A sophisticated attack campaign attributed to a group identifying as “PCP” has compromised 59,128 servers in less than 48 hours by exploiting critical Next.js vulnerabilities.
Security researchers discovered the large-scale operation while monitoring a Docker honeypot, uncovering an industrialized ...
Security researchers discovered the large-scale operation while monitoring a Docker honeypot, uncovering an industrialized ...
- Wed Dec 17, 2025 2:13 am
- Forum: Consumer
- Topic: Broken Access Control in D-Link DAP-1325 Wireless Range Extender
- Replies: 0
- Views: 28
Broken Access Control in D-Link DAP-1325 Wireless Range Extender
The D-Link DAP-1325 contains a vulnerability that allows attackers to exploit a broken access control mechanism. By accessing the /cgi-bin/ExportSettings.sh endpoint, unauthorized users can download sensitive device configuration settings without requiring any authentication. This exposes critical ...
- Wed Dec 17, 2025 2:11 am
- Forum: Programming Languages
- Topic: ReDOS Vulnerability in PyMdown Extensions for Python-Markdown
- Replies: 0
- Views: 15
ReDOS Vulnerability in PyMdown Extensions for Python-Markdown
The PyMdown Extensions include a variety of enhancements for the Python-Markdown project, but versions prior to 10.16.1 contain a vulnerability in the figure caption extension (pymdownx.blocks.caption). This ReDOS issue can lead to performance degradation, causing significant delays while processing ...
- Wed Dec 17, 2025 2:10 am
- Forum: Programming Languages
- Topic: OS Command Injection Vulnerability in Systeminformation Library for Node.js
- Replies: 0
- Views: 13
OS Command Injection Vulnerability in Systeminformation Library for Node.js
The systeminformation library for Node.js is susceptible to an OS command injection vulnerability due to improper sanitization of user inputs. In versions prior to 5.27.14, the fsSize() function concatenates a user-defined drive parameter into a PowerShell command, potentially allowing an attacker ...
- Wed Dec 17, 2025 2:06 am
- Forum: Commercial
- Topic: OSPFv3 Process High CPU Utilization in Arista EOS
- Replies: 0
- Views: 14
OSPFv3 Process High CPU Utilization in Arista EOS
On systems running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, a specially crafted packet can lead to excessive CPU usage in the OSPFv3 process. This may cause the OSPFv3 process to restart, interrupting routes on the switch and potentially impacting network stability ...
- Wed Dec 17, 2025 2:04 am
- Forum: Web Applications
- Topic: Use After Free Vulnerability in Google Chrome Affecting WebGPU
- Replies: 0
- Views: 15
Use After Free Vulnerability in Google Chrome Affecting WebGPU
A use after free vulnerability in the WebGPU component of Google Chrome allows a potential remote attacker to exploit heap corruption. This can be triggered through a specially crafted HTML page, potentially leading to unexpected application behavior or security breaches.
https ...
https ...
- Mon Dec 15, 2025 3:24 pm
- Forum: Windows
- Topic: Hackers Launch Rust-Based Luca Stealer Targeting Linux and Windows
- Replies: 0
- Views: 20
Hackers Launch Rust-Based Luca Stealer Targeting Linux and Windows
Cybercriminals are increasingly abandoning traditional programming languages like C and C++ in favor of modern alternatives such as Rust, Golang, and Nim.
This strategic shift enables threat actors to write malicious code once and compile it for both Windows and Linux with minimal changes.
Leading ...
This strategic shift enables threat actors to write malicious code once and compile it for both Windows and Linux with minimal changes.
Leading ...
- Mon Dec 15, 2025 3:21 pm
- Forum: Commercial
- Topic: NVIDIA Merlin Vulnerabilities Allows Malicious Code Execution and DoS Attacks
- Replies: 0
- Views: 26
NVIDIA Merlin Vulnerabilities Allows Malicious Code Execution and DoS Attacks
NVIDIA has released urgent security patches for its Merlin machine learning framework after discovering two high-severity deserialization vulnerabilities that could enable attackers to execute malicious code, trigger denial-of-service attacks, and compromise sensitive data on Linux systems.
The ...
The ...
- Mon Dec 15, 2025 3:18 pm
- Forum: Android/iOS
- Topic: Android Users at Risk as Malware Poses as mParivahan and e-Challan AppsA sophisticated Android malware campaign dubbed N
- Replies: 0
- Views: 20
Android Users at Risk as Malware Poses as mParivahan and e-Challan AppsA sophisticated Android malware campaign dubbed N
A sophisticated Android malware campaign dubbed NexusRoute is actively targeting Indian users by impersonating the Indian Government Ministry, mParivahan, and e-Challan services to steal credentials and carry out large-scale financial fraud.
The operation combines phishing, malware, and ...
The operation combines phishing, malware, and ...