KDE Linux Hardens System by Removing Kernel Modules and Unused Packages
KDE Linux has undergone a security audit, leading to the removal of several kernel modules and unused packages to reduce its attack surface and improve security.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 3,785 stories synthesized.
KDE Linux has undergone a security audit, leading to the removal of several kernel modules and unused packages to reduce its attack surface and improve security.
A critical Android zero-day vulnerability, CVE-2025-48595, is actively exploited in targeted attacks, granting attackers near-complete device control without user interaction.
Threat actors are increasingly using Scalable Vector Graphic (SVG) files containing obfuscated JavaScript to bypass security filters and redirect victims to malicious phishing pages.
A critical flaw in StrongDM's desktop application enabled attackers to steal and reuse authentication tokens, leading to session hijacking and unauthorized access to sensitive enterprise infrastructure.
The Russian state-sponsored Gamaredon APT group has launched a new campaign against Ukraine, employing a VBScript worm that hides within Windows features and utilizes cloud services for command-and-control.
RSA has expanded its passwordless authentication solutions to support Linux environments, aiming to provide secure, password-free access for enterprise infrastructure.
Hikvision's Chuck Davis discusses adapting zero trust for physical security systems, emphasizing edge-based trust decisions and treating devices as IT assets.
Researchers have developed BadBone, a novel attack that implants dormant backdoors into pre-trained AI models, which only activate when the model is customized for a specific downstream task.
Key findings • Fifteen vulnerabilities disclosed in Itsourcecode products between June 1-2, 2026. • Vulnerabilities include SQL injection and Cross-Site Scripting (XSS) flaws. • Four high…
Key findings • Seven DoS vulnerabilities disclosed in GPAC MP4Box within a 24-hour window. • Six GPAC MP4Box vulnerabilities patched in version 26.02.0. • Vulnerabilities include segmenta…
Key findings • 17 vulnerabilities disclosed across multiple SourceCodester applications between May 29 and June 2, 2026. • High-severity SQL injection flaws affect Hospital Records, Water Bil…
Key findings • CISA added Linux kernel vulnerability CVE-2022-0492 to its KEV catalog on June 2, 2026. • The flaw resides in the cgroups v1 release_agent helper, allowing container escape and…
Key findings • CISA added Google vulnerability CVE-2025-48595 to its Known Exploited Vulnerabilities catalog on June 2, 2026. • The flaw is confirmed to be actively exploited in the wild, pos…
Key findings • 18 vulnerabilities disclosed by Qualcomm on June 1st, 2026. • Predominantly memory corruption flaws affecting Strongbox and fastboot processing. • Several high-severity fla…
Key findings • Nine vulnerabilities in Kiteworks Secure Data Forms disclosed together on June 1, 2026. • Flaws include SQL injection, multiple Insecure Direct Object References (IDOR), and Cr…
Key findings • 25 vulnerabilities disclosed together for the Android SDK on June 1, 2026. • CVE-2025-48595, a high-severity zero-day, is reportedly under limited, targeted exploitation. •…
Key findings • Four Android vulnerabilities disclosed on June 1st, 2026, all enabling privilege escalation. • High-severity CVE-2026-0097 allows remote privilege escalation via Bluetooth LE p…
Spanish National Police have arrested an individual for leaking sensitive personal data of government employees, impacting key state organizations like the National Cybersecurity Institute (INCIBE).
Key findings • Ten high-severity vulnerabilities disclosed in FlexRIC v2.0.0 on June 1st, 2026. • Most vulnerabilities stem from assertion failures and improper input validation. • Exploi…
A critical cybersecurity vulnerability database run by NIST has become ineffective due to significant processing backlogs and mismanagement, an internal watchdog report revealed.
Security researchers have documented over 5,000 election-themed domains registered in April and May, alongside thousands of leaked credentials, posing significant risks for phishing and misinformation campaigns targeting the upcoming US midterm elections.
Key findings • Five vulnerabilities in IBM WebSphere Application Server and IBM i Access Family disclosed on June 1, 2026. • Three critical vulnerabilities (CVE-2026-9319, CVE-2026-9311, CVE-…
Key findings • 25 Nextcloud vulnerabilities disclosed simultaneously on June 1, 2026. • High severity flaws include SQL injection in the Tables app and calendar access bypass. • Multiple …
OpenAI has implemented a mandatory passkey requirement for users in its Trusted Access for Cyber (TAC) program to secure access to its most advanced AI models.