{"id":5830,"date":"2026-01-09T11:46:54","date_gmt":"2026-01-09T11:46:54","guid":{"rendered":"https:\/\/areeblog.com\/?p=5830"},"modified":"2026-01-09T11:46:54","modified_gmt":"2026-01-09T11:46:54","slug":"poc-released-for-cve-2025-38352-linux-kernel-vulnerability","status":"publish","type":"post","link":"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/","title":{"rendered":"PoC Released for CVE-2025-38352 Linux Kernel Vulnerability"},"content":{"rendered":"<p><img loading=\"lazy\" loading=\"lazy\" decoding=\"async\" data-attachment-id=\"5831\" data-permalink=\"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/img-20260109-wa0000\/\" data-orig-file=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000.jpg\" data-orig-size=\"1080,720\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"IMG-20260109-WA0000\" data-image-description=\"\" data-image-caption=\"\" data-large-file=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000-1024x683.jpg\" class=\"aligncenter size-full wp-image-5831\" src=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000.jpg\" alt=\"PoC Released for CVE-2025-38352 Linux Kernel Vulnerability\" width=\"1080\" height=\"720\" srcset=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000.jpg 1080w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000-300x200.jpg 300w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000-1024x683.jpg 1024w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000-768x512.jpg 768w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000-330x220.jpg 330w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000-420x280.jpg 420w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000-615x410.jpg 615w, https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000-860x573.jpg 860w\" sizes=\"auto, (max-width: 1080px) 100vw, 1080px\" \/><\/p>\n<p>A publicly available proof-of-concept (PoC) exploit for <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-38352\">CVE-2025-38352<\/a>, a race-condition bug in the Linux kernel\u2019s POSIX CPU timers code, has been posted online, security researchers and vendors say. The <a href=\"https:\/\/areeblog.com\/demo-importer-plus-vulnerability-affected-versions-risks-and-fixes\/\">vulnerability<\/a> can cause the kernel to access memory after it has been freed, and on vulnerable systems it has the potential to let a local user gain elevated privileges.<\/p>\n<p>The PoC which is being shared under the name \u201cChronomaly\u201d, appeared on public code hosts and in write-ups this week.<\/p>\n<p>The published material and the PoC\u2019s README note that the flaw has been observed in limited, targeted attacks against some 32-bit Android devices, and that the exploit demonstrates how a carefully timed race can corrupt kernel memory<a href=\"https:\/\/cybersecuritynews.com\/chronomaly-exploit\/\">corrupt kernel memory<\/a> and lead to privilege escalation on affected kernels.<\/p>\n<p>U.S. cyber authorities had already added CVE-2025-38352 to the <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/09\/04\/cisa-adds-three-known-exploited-vulnerabilities-catalog\">Known Exploited Vulnerabilities<\/a> (KEV) catalog earlier this year after evidence of active exploitation was found, a designation that draws attention to the vulnerability for organizations responsible for critical systems.<\/p>\n<p>Kernel maintainers and several vendors have issued fixes. Ubuntu\u2019s advisory and related vendor notices describe a code change that removes the race between the timer handler and timer deletion routines, and distribution-level updates addressing the flaw are available. System operators are being advised to apply vendor kernel updates as soon as possible.<\/p>\n<p>Security teams that cannot immediately apply a vendor kernel update should limit local, unprivileged access to sensitive systems and monitor for unexpected kernel crashes or unusual process behavior, both of which can indicate exploitation attempts.<\/p>\n<p>Public reporting on the PoC emphasizes that the bug requires local access to trigger; it is not reported as a remote-network exploit.<\/p>\n<p>Researchers and incident responders note two points worth keeping in mind: public PoC code accelerates defensive analysis (for example, building detections and test cases), but it also lowers the barrier for opportunistic attackers.<\/p>\n<p>Security teams should treat the publication as a prompt to verify patch status across their estate and to follow vendor guidance.<\/p>\n<p>What you can do now is install the kernel updates provided by your OS vendor, restrict unprivileged local access where possible, and watch system logs for kernel crashes or unexpected privilege changes.<\/p>\n<p>Do not download or run <a href=\"https:\/\/areeblog.com\/windows-smb-vulnerability-cve-2025-33073-actively-exploited-after-patch-delay-cisa-warns\/\">exploit code<\/a> found on public repositories unless you are working in an isolated, authorized research environment.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A publicly available proof-of-concept (PoC) exploit for CVE-2025-38352, a race-condition bug in the Linux kernel\u2019s POSIX CPU timers code, has been posted online, security researchers and vendors say. The vulnerability can cause the kernel to access memory after it has been freed, and on vulnerable systems it has the potential to let a local user [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":5831,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_monsterinsights_skip_tracking":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[14],"tags":[1065],"class_list":["post-5830","post","type-post","status-publish","format-standard","has-post-thumbnail","category-cybersecurity","tag-cve"],"share_on_mastodon":{"url":"https:\/\/mastodon.social\/@Areeblog\/115864995317732280","error":""},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>PoC Released for CVE-2025-38352 Linux Kernel Vulnerability - Aree Blog<\/title>\n<meta name=\"description\" content=\"PoC exploit released for Linux kernel vulnerability CVE-2025-38352, raising patch urgency after confirmed active exploitation.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PoC Released for CVE-2025-38352 Linux Kernel Vulnerability\" \/>\n<meta property=\"og:description\" content=\"PoC exploit released for Linux kernel vulnerability CVE-2025-38352, raising patch urgency after confirmed active exploitation.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/\" \/>\n<meta property=\"og:site_name\" content=\"Aree Blog\" \/>\n<meta property=\"article:published_time\" content=\"2026-01-09T11:46:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"720\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Daniel Chinonso John\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Daniel Chinonso John\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\\\/\"},\"author\":{\"name\":\"Daniel Chinonso John\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\"},\"headline\":\"PoC Released for CVE-2025-38352 Linux Kernel Vulnerability\",\"datePublished\":\"2026-01-09T11:46:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\\\/\"},\"wordCount\":393,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/IMG-20260109-WA0000.jpg\",\"keywords\":[\"CVE\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/areeblog.com\\\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\\\/\",\"url\":\"https:\\\/\\\/areeblog.com\\\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\\\/\",\"name\":\"PoC Released for CVE-2025-38352 Linux Kernel Vulnerability - Aree Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/IMG-20260109-WA0000.jpg\",\"datePublished\":\"2026-01-09T11:46:54+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\"},\"description\":\"PoC exploit released for Linux kernel vulnerability CVE-2025-38352, raising patch urgency after confirmed active exploitation.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/areeblog.com\\\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/areeblog.com\\\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\\\/#primaryimage\",\"url\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/IMG-20260109-WA0000.jpg\",\"contentUrl\":\"https:\\\/\\\/areeblog.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/IMG-20260109-WA0000.jpg\",\"width\":1080,\"height\":720,\"caption\":\"PoC Released for CVE-2025-38352 Linux Kernel Vulnerability\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/areeblog.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"PoC Released for CVE-2025-38352 Linux Kernel Vulnerability\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#website\",\"url\":\"https:\\\/\\\/areeblog.com\\\/\",\"name\":\"Aree Blog\",\"description\":\"Unfiltered Perspectives, Unstoppable Insights\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/areeblog.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/areeblog.com\\\/#\\\/schema\\\/person\\\/d972222c55618fb0f4b4c0c11ff52f63\",\"name\":\"Daniel Chinonso John\",\"description\":\"Daniel Chinonso John is a web designer, penetration tester, and founder of Aree Tech. He writes clear, actionable posts at the intersection of productivity, AI, cybersecurity, and blogging to help readers get things done.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/daniel-john-45183a169\\\/\"],\"url\":\"https:\\\/\\\/areeblog.com\\\/author\\\/danojohn55gmail-com\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"PoC Released for CVE-2025-38352 Linux Kernel Vulnerability - Aree Blog","description":"PoC exploit released for Linux kernel vulnerability CVE-2025-38352, raising patch urgency after confirmed active exploitation.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/","og_locale":"en_US","og_type":"article","og_title":"PoC Released for CVE-2025-38352 Linux Kernel Vulnerability","og_description":"PoC exploit released for Linux kernel vulnerability CVE-2025-38352, raising patch urgency after confirmed active exploitation.","og_url":"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/","og_site_name":"Aree Blog","article_published_time":"2026-01-09T11:46:54+00:00","og_image":[{"width":1080,"height":720,"url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000.jpg","type":"image\/jpeg"}],"author":"Daniel Chinonso John","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Daniel Chinonso John","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/#article","isPartOf":{"@id":"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/"},"author":{"name":"Daniel Chinonso John","@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63"},"headline":"PoC Released for CVE-2025-38352 Linux Kernel Vulnerability","datePublished":"2026-01-09T11:46:54+00:00","mainEntityOfPage":{"@id":"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/"},"wordCount":393,"commentCount":0,"image":{"@id":"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000.jpg","keywords":["CVE"],"articleSection":["Cybersecurity"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/","url":"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/","name":"PoC Released for CVE-2025-38352 Linux Kernel Vulnerability - Aree Blog","isPartOf":{"@id":"https:\/\/areeblog.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/#primaryimage"},"image":{"@id":"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/#primaryimage"},"thumbnailUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000.jpg","datePublished":"2026-01-09T11:46:54+00:00","author":{"@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63"},"description":"PoC exploit released for Linux kernel vulnerability CVE-2025-38352, raising patch urgency after confirmed active exploitation.","breadcrumb":{"@id":"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/#primaryimage","url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000.jpg","contentUrl":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000.jpg","width":1080,"height":720,"caption":"PoC Released for CVE-2025-38352 Linux Kernel Vulnerability"},{"@type":"BreadcrumbList","@id":"https:\/\/areeblog.com\/poc-released-for-cve-2025-38352-linux-kernel-vulnerability\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/areeblog.com\/"},{"@type":"ListItem","position":2,"name":"PoC Released for CVE-2025-38352 Linux Kernel Vulnerability"}]},{"@type":"WebSite","@id":"https:\/\/areeblog.com\/#website","url":"https:\/\/areeblog.com\/","name":"Aree Blog","description":"Unfiltered Perspectives, Unstoppable Insights","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/areeblog.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/areeblog.com\/#\/schema\/person\/d972222c55618fb0f4b4c0c11ff52f63","name":"Daniel Chinonso John","description":"Daniel Chinonso John is a web designer, penetration tester, and founder of Aree Tech. He writes clear, actionable posts at the intersection of productivity, AI, cybersecurity, and blogging to help readers get things done.","sameAs":["https:\/\/www.linkedin.com\/in\/daniel-john-45183a169\/"],"url":"https:\/\/areeblog.com\/author\/danojohn55gmail-com\/"}]}},"jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":6604,"url":"https:\/\/areeblog.com\/cisco-finds-cybercriminals-using-agentic-ai-to-automate-web-server-attacks\/","url_meta":{"origin":5830,"position":0},"title":"Cisco Finds Cybercriminals Using Agentic AI to Automate Web Server Attacks","author":"Daniel Chinonso John","date":"August 25, 2026","format":false,"excerpt":"Cisco Talos has identified a financially motivated Chinese-speaking cybercrime group that is using artificial intelligence alongside conventional offensive tools to automate parts of attacks against vulnerable Windows and Linux web servers. The group, tracked by Talos as UAT-10147, was discovered in early 2026 targeting internet-exposed servers in multiple regions. Investigators\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Cisco Finds Cybercriminals Using Agentic AI to Automate Web Server Attacks","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/7BYGIHJJL5P63NCGQ67DJGYVTM.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/7BYGIHJJL5P63NCGQ67DJGYVTM.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/7BYGIHJJL5P63NCGQ67DJGYVTM.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/7BYGIHJJL5P63NCGQ67DJGYVTM.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/7BYGIHJJL5P63NCGQ67DJGYVTM.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":5256,"url":"https:\/\/areeblog.com\/samsung-zero-day-vulnerability-exploited-to-execute-remote-code\/","url_meta":{"origin":5830,"position":1},"title":"Samsung Zero-Day Vulnerability Exploited to Execute Remote Code","author":"Daniel Chinonso John","date":"September 14, 2025","format":false,"excerpt":"In September 2025, Samsung released a critical patch for a security flaw that had already been weaponized in real-world attacks. The issue, cataloged as CVE-2025-21043, resides in the company\u2019s image-processing library and allows attackers to run their own code on affected devices. This was not an academic discovery or a\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/areeblog.com\/category\/cybersecurity\/"},"img":{"alt_text":"Samsung Zero-Day Vulnerability Exploited to Execute Remote Code","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/09\/Samsung-Zero-Day-Vulnerability.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/09\/Samsung-Zero-Day-Vulnerability.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/09\/Samsung-Zero-Day-Vulnerability.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/09\/Samsung-Zero-Day-Vulnerability.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2025\/09\/Samsung-Zero-Day-Vulnerability.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6648,"url":"https:\/\/areeblog.com\/unitree-g1-edu-hit-by-two-root-level-rce-chains-including-bluetooth-attack\/","url_meta":{"origin":5830,"position":2},"title":"Unitree G1 EDU Hit by Two Root-Level RCE Chains, Including Bluetooth Attack","author":"Daniel Chinonso John","date":"August 29, 2026","format":false,"excerpt":"Security researcher Olivier Laflamme has disclosed two separate remote code execution chains affecting Unitree Robotics\u2019 G1 EDU humanoid robot, including one that can begin over Bluetooth without pairing or credentials and reach root access on the robot\u2019s Locomotion PC. The vulnerabilities, identified as CVE-2026-76639 and CVE-2026-76640, were publicly disclosed on\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Unitree G1 EDU Hit by Two Root-Level RCE Chains, Including Bluetooth Attack","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-41.jpeg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-41.jpeg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-41.jpeg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/images-41.jpeg?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":6626,"url":"https:\/\/areeblog.com\/gitea-critical-vulnerability-cve-2026-60004-added-to-cisa-catalog-after-active-exploitation\/","url_meta":{"origin":5830,"position":3},"title":"Gitea Critical Vulnerability CVE-2026-60004 Added to CISA Catalog After Active Exploitation","author":"Daniel Chinonso John","date":"August 27, 2026","format":false,"excerpt":"A critical vulnerability in Gitea, the open-source Git hosting and software development platform, is being actively exploited, with the U.S. Cybersecurity and Infrastructure Security Agency (CISA) adding the flaw to its Known Exploited Vulnerabilities catalog. Tracked as CVE-2026-60004, the vulnerability can allow attackers to execute shell commands on affected Gitea\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Gitea Critical Vulnerability CVE-2026-60004 Added to CISA Catalog After Active Exploitation","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed-1.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed-1.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed-1.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/08\/unnamed-1.jpg?resize=700%2C400&ssl=1 2x"},"classes":[]},{"id":6354,"url":"https:\/\/areeblog.com\/wordpress-releases-emergency-patch-for-critical-wp2shell-rce-vulnerability\/","url_meta":{"origin":5830,"position":4},"title":"WordPress Releases Emergency Patch for Critical wp2shell RCE Vulnerability","author":"Daniel Chinonso John","date":"July 19, 2026","format":false,"excerpt":"WordPress has shipped an emergency security release after researchers disclosed wp2shell, a critical flaw in WordPress Core that can be chained into remote code execution. The issue is tracked as CVE-2026-63030 and, according to the published advisories, it works with CVE-2026-60137, a separate SQL injection issue, to let an attacker\u2026","rel":"","context":"In &quot;Cybersecurity&quot;","block_context":{"text":"Cybersecurity","link":"https:\/\/areeblog.com\/category\/cybersecurity\/"},"img":{"alt_text":"WordPress Releases Emergency Patch for Critical wp2shell RCE Vulnerability","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260719-WA0003.jpg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260719-WA0003.jpg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260719-WA0003.jpg?resize=525%2C300&ssl=1 1.5x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260719-WA0003.jpg?resize=700%2C400&ssl=1 2x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/07\/IMG-20260719-WA0003.jpg?resize=1050%2C600&ssl=1 3x"},"classes":[]},{"id":6851,"url":"https:\/\/areeblog.com\/bynario-raises-e2-1m-to-tackle-ai-fueled-vulnerability-surge\/","url_meta":{"origin":5830,"position":5},"title":"Bynario Raises \u20ac2.1M to Tackle AI-Fueled Vulnerability Surge","author":"Daniel Chinonso John","date":"September 10, 2026","format":false,"excerpt":"Italian cybersecurity startup Bynario has raised \u20ac2.1 million in pre-seed funding as the rapid growth of AI-assisted security research creates a new challenge for organisations: handling the growing number of potential software vulnerabilities being identified. The Milan-based company said the round was led by 360 Capital Partners, with participation from\u2026","rel":"","context":"In &quot;Tech Updates&quot;","block_context":{"text":"Tech Updates","link":"https:\/\/areeblog.com\/category\/tech-updates\/"},"img":{"alt_text":"Italian Cybersecurity Startup Bynario Raises \u20ac2.1M to Tackle AI-Fueled Vulnerability Surge","src":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/images-57.jpeg?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/images-57.jpeg?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/areeblog.com\/wp-content\/uploads\/2026\/09\/images-57.jpeg?resize=525%2C300&ssl=1 1.5x"},"classes":[]}],"jetpack_featured_media_url":"https:\/\/areeblog.com\/wp-content\/uploads\/2026\/01\/IMG-20260109-WA0000.jpg","_links":{"self":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/5830","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/comments?post=5830"}],"version-history":[{"count":0,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/posts\/5830\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/media\/5831"}],"wp:attachment":[{"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/media?parent=5830"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/categories?post=5830"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/areeblog.com\/wp-json\/wp\/v2\/tags?post=5830"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}