Security insights, vulnerability roundups, and updates from the Agent Breach team.
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
Multiple vulnerabilities in the libheif library affect several Ubuntu LTS versions, potentially allowing denial of service or arbitrary code execution through malicious image files.
CISA has updated its Known Exploited Vulnerabilities catalog with six new flaws, including critical issues in NetScaler, Linux, and SQL Server. These vulnerabilities are already being exploited in the wild.
A critical vulnerability in Vim could allow attackers to execute arbitrary code through specially crafted tags files. Organizations using Vim should update immediately to mitigate potential exploitation.
Multiple high-severity flaws in the Linux kernel affect major cloud infrastructures including Azure, Oracle, and Raspberry Pi. Patches address risks ranging from remote code execution to network injection.
A new phishing-as-a-service platform uses AI voice agents to impersonate Apple Support. The scheme targets stolen device owners to bypass Activation Lock.
A critical remote code execution flaw in Gitea is being actively exploited by threat actors. Organizations using the self-hosted Git service should patch immediately.
A critical flaw in curl's connection reuse logic could lead to incorrect client certificate usage. This vulnerability affects applications relying on certificate-based authentication.
Critical flaws in FFmpeg media processing library could allow attackers to execute arbitrary code or cause denial of service. Ubuntu issues security update USN-8671-1.
Cybercriminals are using fake Minecraft clients and SEO poisoning to spread the Weedhack malware. Security firms report thousands of blocked access attempts to malicious lookalike sites.