Vulnerability

Fuatilia
Illustration of a Linux computer screen highlighting Amazon WorkSpaces vulnerability CVE-2025-12779, with security alert and hacker elements, for a news article on AWS security flaw.
Picha iliyoundwa na AI

Amazon discloses Linux WorkSpaces vulnerability in authentication tokens

Imeripotiwa na AI Picha iliyoundwa na AI

Amazon Web Services has revealed a security flaw in its WorkSpaces client for Linux that allows local attackers to extract authentication tokens and access other users' virtual desktops. The vulnerability, CVE-2025-12779, affects client versions from 2023.0 to 2024.8 and carries a CVSS score of 8.8. AWS urges immediate upgrades to version 2025.0 or later to mitigate the risk.

A critical remote code execution vulnerability has been discovered in multiple BeyondTrust products. The flaw, rated 9.9 out of 10 in severity, allows hackers to run code on affected systems without needing to log in. The issue was reported on February 10, 2026.

Imeripotiwa na AI

NVIDIA has released an urgent security update to address a high-severity vulnerability in its NSIGHT Graphics tool for Linux systems. The flaw, identified as CVE-2025-33206, could enable attackers to execute arbitrary code if exploited. Affected users are urged to upgrade immediately to mitigate risks.

Google has addressed a critical zero-day vulnerability in Chrome's V8 engine that was being actively exploited. The flaw allowed arbitrary code execution, posing significant risks to users. The company provides guidance on staying safe.

Imeripotiwa na AI

A severe remote code execution vulnerability in Imunify360 AV has been patched, affecting a security tool that protects around 56 million Linux-hosted websites. Discovered in the product's deobfuscation logic, the flaw allows attackers to execute arbitrary commands and potentially seize control of hosting servers. CloudLinux released a fix on October 21, 2025, though no formal CVE or advisory followed.

The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a high-severity vulnerability in Windows SMB that is now being exploited in attacks. Windows users are urged to update their systems immediately to mitigate the risk. The alert emphasizes the need for prompt action against this security threat.

Imeripotiwa na AI

A proof-of-concept exploit has been released for CVE-2025-8941, a high-severity flaw in Linux-PAM's pam_namespace module. The vulnerability allows local attackers with low privileges to gain root access through race conditions and symlink manipulation. Security experts urge immediate patching to prevent system compromise.

Alhamisi, 8. Mwezi wa kwanza 2026, 06:04:40

Linux battery utility TLP patched after authentication bypass flaw

Jumatano, 17. Mwezi wa kumi na mbili 2025, 22:29:07

Rust in Linux Kernel: First Vulnerability Emerges in Android Binder Driver

Jumanne, 16. Mwezi wa kumi na mbili 2025, 23:12:04

React2Shell exploits continue with large-scale Linux backdoor deployments and cloud credential theft

Jumanne, 16. Mwezi wa kumi na mbili 2025, 11:30:18

Silent Whisper vulnerability exposes WhatsApp users to secret tracking

Jumamosi, 13. Mwezi wa kumi na mbili 2025, 23:54:19

China-nexus groups and cybercriminals ramp up React2Shell exploits

Jumatatu, 3. Mwezi wa kumi na moja 2025, 14:24:46

CISA alerts on Linux kernel flaw exploited by ransomware

Jumapili, 2. Mwezi wa kumi na moja 2025, 21:17:53

CISA warns of ransomware exploiting Linux kernel vulnerability

Jumamosi, 1. Mwezi wa kumi na moja 2025, 19:33:55

Security flaw in WordPress add-on affects 10,000 sites

Jumamosi, 1. Mwezi wa kumi na moja 2025, 03:51:02

CISA warns of exploited Linux kernel vulnerability in ransomware attacks

Ijumaa, 31. Mwezi wa kumi 2025, 06:47:35

CISA confirms Linux kernel flaw exploited in ransomware attacks

 

 

 

Tovuti hii inatumia vidakuzi

Tunatumia vidakuzi kwa uchambuzi ili kuboresha tovuti yetu. Soma sera ya faragha yetu kwa maelezo zaidi.
Kataa