Search found 1804 matches

by Shane1145
Mon Dec 01, 2025 7:00 am
Forum: Windows
Topic: Hackers Leverage NTLM Authentication Vulnerabilities to Attack Windows Systems
Replies: 0
Views: 143

Hackers Leverage NTLM Authentication Vulnerabilities to Attack Windows Systems

More than two decades after its initial discovery, the NTLM authentication protocol continues to plague Windows systems worldwide.

What started in 2001 as a theoretical vulnerability has evolved into a widespread security crisis, with attackers actively weaponizing multiple NTLM flaws to compromise ...
by Shane1145
Mon Dec 01, 2025 6:59 am
Forum: Programming Languages
Topic: New Unauthenticated DoS Vulnerability Lets Attackers Crash Next.js Servers with a Single HTTP Request
Replies: 0
Views: 101

New Unauthenticated DoS Vulnerability Lets Attackers Crash Next.js Servers with a Single HTTP Request

Security researchers have discovered a critical denial-of-service vulnerability in Next.js that allows unauthenticated attackers to crash self-hosted servers with a single HTTP request.

The flaw was unexpectedly uncovered by an AI security testing tool while examining a demo application, ultimately ...
by Shane1145
Mon Dec 01, 2025 6:58 am
Forum: Linux
Topic: APT36 Deploys Python-Based ELF Malware in Targeted Attacks on Indian Government Agencies
Replies: 0
Views: 80

APT36 Deploys Python-Based ELF Malware in Targeted Attacks on Indian Government Agencies

Pakistan-linked cyberespionage group APT36 (Transparent Tribe) has escalated its campaign against Indian government institutions with the deployment of sophisticated Python-based ELF malware specifically designed to compromise Linux-based BOSS operating environments, according to research published ...
by Shane1145
Mon Dec 01, 2025 6:54 am
Forum: Commercial
Topic: NVIDIA DGX Spark Flaws Allow Attackers to Run Malicious Code and Launch DoS Attacks
Replies: 0
Views: 99

NVIDIA DGX Spark Flaws Allow Attackers to Run Malicious Code and Launch DoS Attacks

NVIDIA has released security updates to address fourteen critical vulnerabilities in its DGX Spark system.

These flaws could allow attackers to execute malicious code, steal sensitive information, and launch denial-of-service attacks that crash the system.

The vulnerabilities affect all versions ...
by Shane1145
Mon Dec 01, 2025 6:48 am
Forum: Desktop Applications
Topic: Microsoft Teams Guest Chat Flaw Could Let Hackers Deliver Malware
Replies: 0
Views: 83

Microsoft Teams Guest Chat Flaw Could Let Hackers Deliver Malware

Security researchers have discovered a critical vulnerability in Microsoft Teams that allows attackers to bypass all Defender for Office 365 protections by inviting users into malicious tenant environments.

The flaw exploits a fundamental architectural gap in how Teams handles cross-tenant ...
by Shane1145
Fri Nov 28, 2025 4:10 pm
Forum: Programming Languages
Topic: Race Condition Vulnerability in Next.js Framework Affecting Vercel Deployments
Replies: 0
Views: 178

Race Condition Vulnerability in Next.js Framework Affecting Vercel Deployments

CVE-2025-32421 is a race condition vulnerability identified in the Next.js framework, which is widely used for building full-stack web applications. Specifically, this vulnerability impacts versions prior to 14.2.24 and 15.1.6 of Next.js. It manifests under certain misconfigurations in the Pages ...
by Shane1145
Fri Nov 28, 2025 4:09 pm
Forum: Android/iOS
Topic: Logic Issue in Apple iOS, iPadOS, tvOS, watchOS and Safari
Replies: 0
Views: 134

Logic Issue in Apple iOS, iPadOS, tvOS, watchOS and Safari

A logic issue within the processing of web content has been discovered that can allow maliciously crafted input to potentially execute arbitrary code on affected systems. This vulnerability has been addressed in the latest updates across various Apple platforms including iOS, iPadOS, tvOS, and ...
by Shane1145
Fri Nov 28, 2025 4:06 pm
Forum: Mobile Phones
Topic: Permission Control Vulnerability in Huawei Notepad Module
Replies: 0
Views: 175

Permission Control Vulnerability in Huawei Notepad Module

A permission control vulnerability exists in the Notepad module of Huawei products, allowing unauthorized access that could compromise service confidentiality. Exploiting this vulnerability might lead to unauthorized disclosure of sensitive information. Users of affected Huawei Notepad versions ...
by Shane1145
Fri Nov 28, 2025 4:05 pm
Forum: Laptops / Tablets
Topic: Memory Manipulation Vulnerability in ASUS Laptop BIOS
Replies: 0
Views: 266

Memory Manipulation Vulnerability in ASUS Laptop BIOS

The UX360CA BIOS on ASUS laptops versions up to 303 is susceptible to a severe flaw that enables an attacker with ring 0 privileges to overwrite almost any physical memory location, including System Management RAM (SMRAM). This exploitation facilitates the execution of arbitrary code within the ...
by Shane1145
Fri Nov 28, 2025 4:01 pm
Forum: Programming Languages
Topic: Remote Code Execution Vulnerability in Python JSON Logger from NHairs
Replies: 0
Views: 344

Remote Code Execution Vulnerability in Python JSON Logger from NHairs

CVE-2025-27607 is a critical remote code execution (RCE) vulnerability affecting the Python JSON Logger, a JSON formatting tool used to enhance logging capabilities in Python applications. The vulnerability arose due to a missing dependency caused by the deletion of the msgspec-python313-pre package ...