Category: EN

Avast Antivirus Sandbox Vulnerabilities Allow Privilege Escalation

SAFA researchers uncovered four kernel heap overflow vulnerabilities in Avast Antivirus’s aswSnx.sys driver, designated CVE-2025-13032, affecting versions before 25.3 on Windows. These flaws originate from double-fetch issues in IOCTL handling, allow local attackers to trigger pool overflows for privilege escalation…

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-55182 Meta React Server Components Remote Code Execution Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors…

Cloudflare Outage Caused by React2Shell Mitigations

The critical React vulnerability has been exploited in the wild by Chinese and other threat actors. The post Cloudflare Outage Caused by React2Shell Mitigations appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: Cloudflare…

Hackers Weaponize Trusted IT Tools for Full System Control

  Malicious actors are weaponizing legitimate Remote Monitoring and Management (RMM) tools, turning trusted IT software into a means for unauthorized system access. This strategy represents a significant shift from traditional malware attacks, as it exploits programs like LogMeIn Resolve…

Google Rolls Out Chrome 143 Update for Billions Worldwide

Chrome 143 fixes 13 security vulnerabilities, including four high-severity flaws, in a December desktop update rolling out to Windows, macOS, and Linux users. The post Google Rolls Out Chrome 143 Update for Billions Worldwide appeared first on TechRepublic. This article…

Marquis Breach Hits Over 780,000 People

Marquis is a fintech and software company based in Texas that supplies data-driven marketing, customer data platforms, analytics, and compliance solutions The post Marquis Breach Hits Over 780,000 People first appeared on CyberMaterial. This article has been indexed from CyberMaterial…

ASUS Confirms Vendor Breach By Everest

ASUS has confirmed a data breach affecting a third-party supplier, which resulted in the exposure of some source code. This confirmation follows a leak The post ASUS Confirms Vendor Breach By Everest first appeared on CyberMaterial. This article has been…

Hackers Accused Of Wiping 96 Databases

Twin brothers Muneeb and Sohaib Akhter, both 34, have been charged by U.S. prosecutors with computer fraud, destruction of records, The post Hackers Accused Of Wiping 96 Databases first appeared on CyberMaterial. This article has been indexed from CyberMaterial Read…

PRC Hackers Use BrickStorm In US

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently disclosed technical details about a backdoor named BRICKSTORM, which is being utilized The post PRC Hackers Use BrickStorm In US first appeared on CyberMaterial. This article has been indexed from CyberMaterial…

NCSC Warns Orgs Of Exposed Device Flaws

The UK’s National Cyber Security Center, known as the NCSC, has initiated a testing phase for a new security offering called Proactive Notifications. The post NCSC Warns Orgs Of Exposed Device Flaws first appeared on CyberMaterial. This article has been…