A nine-year-old vulnerability in RefluXFS, a Linux filesystem driver, allows local users to gain full root privileges on default Red Hat Enterprise Linux installations. The flaw, which has existed since RHEL 6, enables attackers with local access to escalate their rights and take complete control of the system. This affects many enterprise servers running default RHEL configurations, posing a serious security risk.
Check Point released a security patch for a critical SmartConsole vulnerability that was actively exploited in the wild. The flaw could allow an attacker to gain full administrative access to the security management system. Organizations using Check Point's network security products should apply the patch immediately to prevent unauthorized control.
A vulnerability in Ubuntu's snap-confine component allows local users to escalate privileges to root on default desktop installations. The flaw, present in the snap package manager, could enable an attacker with local access to gain full system control. Users should apply security updates promptly to mitigate the risk.
A security flaw in the Adobe Acrobat browser extension allows malicious websites to access and read WhatsApp Web data. The vulnerability exploits the extension's permissions to intercept sensitive information. This poses a significant privacy risk for users who have the extension installed.
Attackers are exploiting a vulnerability in Windmill, an open-source job scheduler, to read arbitrary server files without authentication. The flaw, which affects unpatched versions, allows remote file access by bypassing security checks. This highlights the critical need for prompt patching to prevent data breaches.
The CISA, FBI, EPA and other U.S. government agencies issued an updated warning about Iran-affiliated threat actors targeting programmable logic controllers (PLCs) in critical infrastructure. These actors have been observed compromising systems that control water, energy, and other essential services. The advisory urges operators to implement security measures to prevent disruptions to national infrastructure.
Law enforcement dismantled the Kratos phishing kit, which was designed to steal Microsoft 365 account sessions and bypass multi-factor authentication. The kit targeted individuals and organizations, posing a serious cybersecurity threat. Its removal helps protect users from credential theft and unauthorized access.
A malicious fork of the widely used .NET library Newtonsoft.Json was discovered containing hidden code designed to rig computer games. Attackers created the fork to appear legitimate, hoping developers would incorporate it into their projects. This highlights the ongoing risk of supply chain attacks through seemingly reputable open-source code.
A security flaw in Microsoft Azure DevOps allows attackers to embed hidden comments in pull requests that can hijack AI-powered code review agents. This vulnerability could enable unauthorized code changes or malicious injections into development pipelines. It highlights risks in AI-assisted software workflows.