LIVE · cybersecurity feed
Live wire
CVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingCVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCVE-2025-39682 · CISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many daysCisco warns of max severity ISE zero-day exploited in attacksCVE-2026-89026 · Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionCVE-2026-58704 · Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
CVE-2025-39682high

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path

zeroday.news ·

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating that these flaws are being actively exploited in the wild. This advisory highlights the immediate threat posed by these specific kernel issues to systems running the Linux operating system.

One of the identified vulnerabilities is CVE-2025-39682, which carries a CVSS score of 9.8. This particular flaw is described as an improper check for unusual or exceptional conditions within the TLS receive path of the Linux kernel. Such a high CVSS score typically denotes a critical vulnerability that could lead to severe impacts, potentially allowing for remote code execution or significant denial-of-service conditions without extensive user interaction.

Improper checking for unusual conditions in network protocol handling, like the TLS receive path, can often be exploited by crafting malformed packets or sequences of data. When the kernel fails to adequately validate or sanitize incoming data, an attacker can potentially trigger memory corruption, buffer overflows, or other undefined behaviors. In the context of TLS, this could involve manipulating handshakes or encrypted data streams to provoke an exploitable state.

The Linux kernel is a foundational component for a vast array of systems, ranging from servers and cloud infrastructure to embedded devices and consumer electronics. Vulnerabilities within the kernel can therefore have widespread implications, potentially affecting critical services and data across numerous industries. Active exploitation suggests that attackers have developed reliable methods to leverage these flaws, making timely patching crucial for system administrators.

Mitigation for kernel vulnerabilities typically involves applying vendor-supplied patches and updates as soon as they become available. For systems where immediate patching is not feasible, temporary workarounds might include restricting network access to affected services, implementing intrusion detection/prevention systems to block known exploit patterns, or disabling specific kernel modules if they are not essential for operation. Regular security audits and monitoring for unusual system behavior are also recommended practices.

The inclusion of these vulnerabilities in CISA's KEV catalog underscores the ongoing importance of proactive vulnerability management and rapid response to disclosed security flaws. It serves as a directive for federal agencies and a strong recommendation for all organizations to prioritize patching and securing their Linux-based systems against these actively exploited threats to maintain robust cybersecurity posture.

vulnerabilities in this storyCVE-2025-39682
vulnerabilitycloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

CVE-2024-4405high

Malicious Extensions Hijack AI Browser Agents via Prompt Forcing

A new proof-of-concept attack named BragJack demonstrates how malicious browser extensions can hijack AI assistants within browsers like Chrome and Edge. The attack utilizes a technique called Prompt Forcing to gain control of these AI agents, successfully earning significant bug bounties and two CVEs.

phishing

AI Helps Hackers Hijack OpenAI Staff Accounts Through a Forum

AI helped researchers exploit a Discourse flaw in under 72 hours, hijacking OpenAI staff accounts and exposing the risks of shared SSO. Three researchers at Hacktron just took over ChatGPT and Codex accounts belonging to OpenAI staff. The attack did not rely on phishing techniques or a leaked password. Through an image upload on OpenAI’s […]

security

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.

security

North Korean WaterPlum hackers infected 30,000 devices worldwide

A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. [...]

ransomware

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]