A cross-site scripting (XSS) vulnerability in the Krpano framework has been exploited to inject malicious scripts into over 350 websites, manipulating search results and spreading spam. Discovered by researcher Oleg Zaytsev, the flaw involved improper handling of the “xml” parameter. Krpano has since released an updated version to address this issue, urging users to update and secure their configurations.

Ubuntu Desktop Systems Vulnerability Enables Attackers to Gain Full Root Access
A Local Privilege Escalation (LPE) vulnerability in default installations of Ubuntu Desktop 24.04 and later allows an unprivileged local attacker to gain full root access.


