Category: Vulnerabilities
Six New U-Boot Bugs Could Crash Devices or Enable Boot-Time Code Execution
Firmware security firm Binarly has disclosed six flaws in the widely used U-Boot bootloader, four that can crash affected devices and two…
Injective Labs GitHub Breach Spawns Malicious npm Package to Steal Crypto Wallets
Attackers compromised the Injective Labs SDK repository on GitHub and published a tampered npm package designed to exfiltrate wallet private keys and…
Ryuk Ransomware Operator Pleads Guilty as BlackCat Insider Gets Nearly 6 Years
U.S. prosecutors notched two wins against ransomware ecosystems this week: an Armenian national admitted deploying Ryuk against victims including a Michigan firm…
Armenian Man Pleads Guilty to Deploying Ryuk Ransomware in US Attacks
Karen Serobovich Vardanyan admitted to helping breach US companies and deploy Ryuk ransomware in 2019 and 2020, part of a scheme that…
European Parliament Revives CSAM Scanning Law Amid Procedural Controversy
A last-minute vote using an unusual absolute-majority procedure has extended legal cover for voluntary CSAM scanning by tech platforms through 2028, even…
Malicious jscrambler npm Package Drops Rust Infostealer at Install Time
A compromised 8.14.0 release of the jscrambler npm package used a preinstall hook to silently execute native infostealer binaries on Windows, macOS,…
Six U-Boot Flaws Could Let Attackers Hijack Devices Before the OS Even Loads
Firmware security firm Binarly has disclosed six vulnerabilities in U-Boot's image signature verification code, two of which allow arbitrary code execution during…
Critical Zimbra Classic Web Client Flaw Lets Emails Execute Malicious Code
Zimbra is pushing urgent updates for a critical stored XSS vulnerability in its Classic Web Client that lets specially crafted emails run…
Zimbra Patches Critical XSS Flaw in Classic Web Client After Google TAG Report
Zimbra has released version 10.1.19 to fix a critical stored XSS vulnerability in its Classic Web Client, flagged by Google's Threat Analysis…
Unpatched XRING Bug in Alibaba’s XQUIC Lets Remote Clients Crash HTTP/3 Servers
A single-line variable error in Alibaba's XQUIC library allows unauthenticated attackers to crash HTTP/3 servers with a short burst of valid QPACK…
Three Chained Flaws in OpenClaw AI Assistant Enabled WhatsApp-to-Host Takeover
A researcher has disclosed details of three now-patched, high-severity vulnerabilities in the OpenClaw personal AI assistant that could be chained from a…
Weekly Roundup: DHS Database Breach, Adobe Speeds Up Patches, Canada Disrupts Ransomware Infrastructure
This week's roundup covers a breach of a DHS interagency network, Adobe's move to twice-monthly patch releases, Canadian intelligence operations against ransomware…