It was discovered that Salt incorrectly handled web requests when the SSH
client was enabled. An attacker could possibly use this issue to achieve
remote code execution or obtain sensitive information.
Yearly Archives: 2025
Chinese Hackers Double Cyber-Attacks on Taiwan
Taiwan’s security service said government networks faced 2.4 million attacks in 2024, most of which are attributed to Chinese state actors
Privacy of Photos.app’s Enhanced Visual Search
USN-7180-1: Python vulnerabilities
It was discovered that Python incorrectly handled certain scripts.
An attacker could possibly use this issue to execute arbitrary code
or cause a crash. (CVE-2022-48560)
It was discovered that Python did not properly handle XML entity
declarations in plist files. An attacker could possibly use this
vulnerability to perform an XML External Entity (XXE) injection,
resulting in a denial of service or information disclosure.
(CVE-2022-48565)
It was discovered that Python did not properly provide constant-time
processing for a crypto operation. An attacker could possibly use this
issue to perform a timing attack and recover sensitive information.
(CVE-2022-48566)
It was discovered that Python incorrectly handled certain inputs. If a
user or an automated system were tricked into running a specially
crafted input, a remote attacker could possibly use this issue to cause a
denial of service. (CVE-2023-24329)
It was discovered that Python instances of ssl.SSLSocket were vulnerable
to a bypass of the TLS handshake. An attacker could possibly use this
issue to cause applications to treat unauthenticated received data before
TLS handshake as authenticated data after TLS handshake.
(CVE-2023-40217)
New Infostealer Campaign Uses Discord Videogame Lure
Threat actors are tricking victims into downloading malware with the promise of testing a new videogame
Scammers Drain $500m from Crypto Wallets in a Year
Scam Sniffer claims that threat actors used wallet drainers to steal $494m from victims in 2024
USN-7140-2: Tinyproxy vulnerability
USN-7140-1 fixed CVE-2022-40468 in tinyproxy. This update provides the
corresponding update for Ubuntu 14.04 LTS.
Original advisory details:
It was discovered that Tinyproxy did not properly manage memory under
certain circumstances. An attacker could possibly use this issue to leak
left-over heap data if custom error page templates containing special
non-standard variables are used.
perl-Net-OAuth-0.30-1.fc41
FEDORA-2025-f0077db20c
Packages in this update:
perl-Net-OAuth-0.30-1.fc41
Update description:
Update to 0.30, fixes CVE-2025-22376
perl-Net-OAuth-0.30-1.fc40
FEDORA-2025-05e642f1ef
Packages in this update:
perl-Net-OAuth-0.30-1.fc40
Update description:
Update to 0.30, fixes CVE-2025-22376
perl-Net-OAuth-0.30-1.el10_0
FEDORA-EPEL-2025-d8034c0356
Packages in this update:
perl-Net-OAuth-0.30-1.el10_0
Update description:
Update to 0.30, fixes CVE-2025-22376