Posts of last 24 hours
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.
A compromised page could infect a system running a vulnerable AnySign4PC version without a prompt or
https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos 4.0) for persistent remote access.
"In this campaign, the group combines new vulnerable-driver abuse, newly observed abuse of legitimate
https://thehackernews.com/2026/07/silverfox-targets-japanese-manufacturer.html
The FCC added foreign robots and power inverters to its Covered List, while allowing security updates for existing authorized devices until 2029. The FCC just widened its Covered List again, this time adding foreign-produced advanced robotic devices and power inverters. In plain terms, that means new models in those categories generally can’t get the equipment […]
https://securityaffairs.com/196308/security/fcc-restricts-new-foreign-robots-and-inverters-over-security-risks.html
A vulnerability was found in Linux Kernel up to 6.1.123/6.6.69/6.12.8 on BIG. It has been declared as problematic. This affects the function ipv6_has_hopopt_jumbo in the library skbuff.h of the component IPv6 Extension Header Handler. The manipulation results in privilege escalation.
This vulnerability was named CVE-2025-21629. The attack needs to be approached within the local network. There is no available exploit.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/291949
A vulnerability was found in Linux Kernel up to 6.1.124/6.6.71/6.12.9/6.13-rc6. It has been classified as critical. This issue affects some unknown processing of the component sysctl. This manipulation causes null pointer dereference.
The identification of this vulnerability is CVE-2025-21637. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/292550
A vulnerability was found in Linux Kernel up to 6.1.124/6.6.71/6.12.9/6.13-rc6. It has been declared as critical. Impacted is an unknown function of the component sysctl. Such manipulation leads to null pointer dereference.
This vulnerability is referenced as CVE-2025-21638. The attack needs to be initiated within the local network. No exploit is available.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/292551
A vulnerability labeled as critical has been found in Linux Kernel up to 6.1.124/6.6.71/6.12.9/6.13-rc6. This impacts an unknown function of the component cookie_hmac_alg. The manipulation results in null pointer dereference.
This vulnerability is cataloged as CVE-2025-21640. The attack must originate from the local network. There is no exploit available.
The affected component should be upgraded.
https://vuldb.com/vuln/292555
A vulnerability described as problematic has been identified in Linux Kernel up to 6.1.124/6.6.71/6.12.9/6.13-rc6. Affected by this vulnerability is an unknown functionality of the file /proc/net/afs/ of the component afs. Such manipulation leads to privilege escalation.
This vulnerability is documented as CVE-2025-21646. The attack requires being on the local network. There is not any exploit available.
Upgrading the affected component is recommended.
https://vuldb.com/vuln/292557
A vulnerability classified as problematic has been found in Linux Kernel up to 6.1.124/6.6.71/6.12.9/6.13-rc6. Affected by this issue is some unknown functionality of the component sch_cake. Performing a manipulation results in out-of-bounds read.
This vulnerability is reported as CVE-2025-21647. The attacker must have access to the local network to execute the attack. No exploit exists.
It is recommended to upgrade the affected component.
https://vuldb.com/vuln/292558
A vulnerability was found in Linux Kernel up to 6.12.9/6.13-rc6. It has been rated as problematic. This impacts the function hclge_fetch_pf_reg. The manipulation leads to improper initialization.
This vulnerability is referenced as CVE-2025-21650. The attack needs to be initiated within the local network. No exploit is available.
Upgrading the affected component is advised.
https://vuldb.com/vuln/292566