Greg Kroah-Hartman has announced the release of the 6.17.11, 6.12.61, 6.6.119, 6.1.159, 5.15.197, and 5.10.247 stable kernels. Each contains important fixes throughout the tree; users of these kernels should upgrade.
Първият протест (тогава митинг), в който участвах, беше на 3 декември 1989 г. на колодрума на остров Свобода в Пазарджик, двайсет и три дни след паметния 10 ноември. Бях на 14 години и отидох на митинга заедно с голяма част от класа ми; заведе ни класната ни ръководителка Евелина Трангозова, тогава двайсет и четири годишна учителка по английски и един от първите членове на току-що възстановената Радикалдемократическа партия в града. За мнозина това да заведеш учениците си осмокласници на митинг изглеждаше дръзко и неприемливо политизиране (вероятно и сега би изглеждало така), но аз и до днес съм благодарна на нашата Мис (така наричахме класната), че ме направи съзнателна свидетелка на епохален момент, който щеше да промени пътя на абсолютно всички.
Когато преди няколко дни, на 1 декември, гледах младите хора, изпълнили центъра на София, си помислих, че и сега, както и преди 36 години, исканията на протестиращите се свеждат всъщност до едно и също – свобода (в цялата условност на разбирането ѝ), справедливост, зачитане на правата на всеки… Само дето като че ли някога мечтаехме за бъдеще, в което да напуснем дома си и да видим света, а сега децата-на-света се борят за бъдеще тук, в застрашения си дом. Но и през 1989-та, както и през 2025-та, провокаторите са на линия, спекулациите избиват на повърхността като мръсна пяна и все се намира някоя и друга политическа мутра, която да яхне и осребри чуждия гняв, да си изплете кошницата и да свърши някоя и друга мерзопакост.
Какъв е тогава смисълът от протести, ще попитате, при положение че първо пораснахме, а после остаряхме по площадите с все същите лозунги, мечти и горести. Дали не се оказва, че през цялото време сме протестирали за непостижими неща? И има ли изобщо смисъл да се протестира за непостижимото?
Наскоро ми попадна статия за една от големите екоактивистки от края на ХХ век Джулия Бътърфлай Хил (р. 1974), която между 1997 и 1999 г. живее в продължение на 738 дни на върха на 60-метрова хилядолетна секвоя на име Луна, за да предотврати планираното ѝ отсичане. След две години в обятията на Луна Джулия подписва споразумение с Pacific Lumber Company за запазването на дървото и слиза на земята.
Да, Джулия Хил е късметлийка – защото не всички цели могат да бъдат постигнати в рамките на един човешки живот. И понякога се изискват непомерни усилия и търпение, и вяра – дано младите навреме осъзнаят това: че битката с вятърните мелници, освен да донесе горчивина за сражаващите се, ще задвижи и пренесе енергия и за идващите след тях. И че най-суровата, но и най-важната битка е за онова, което няма да се случи днес и утре, и може би никога, докато сме живи, но ще продължи да има смисъл дълго след нас.
Какви следи оставяме? С действията и бездействията си. С думите и с премълчаванията. Така бихме могли да обобщим и темата на броя ни тази седмица.
От една страна са градовете, които осъзнато и безсъзнателно обитаваме. Да вземем например втория по големина град – Пловдив. Какво се случва с него шест години след като беше Европейска столица на културата с всичките там интелектуални и финансови инвестиции във въпросната титла. Георги Велев анализира днешната ситуация според постигнатото и пропиляното в „Шест години по-късно. Изгуби ли културата в Пловдив своята посока?“.
От темата за градовете минаваме към управлението на „полиса“ и държавата. Какво се случва със съвременната демокрация; пред какви избори и възможности е изправена; струва ли се да се борим за нея, когато средната класа е застрашена, а политическите свободи и правата на гражданите са противопоставени на икономическото им благосъстояние; не губи ли тягата си изобщо идеята за демокрация при нарастващия риск от разрив между САЩ и Европа? Повече по тези въпроси четете в есето на Искрен Иванов „(Не)демократичният световен ред“.
В основата на съвременната ни представа за демокрация неизменно са стояли свободата на словото и наличието на независими медии. В епохата на постистината, фалшивите новини, дезинформацията и пропагандата именно тази част от основата на демокрацията е сериозно разклатена. В анализа си „Има ли надежда за надеждните новини?“ Светла Енчева обръща внимание на нуждата демокрацията да бъде защитена именно чрез медийната свобода, както и на рисковете, които носи капсулирането или изчезването на качествено медийно съдържание. Следващата събота, 13 декември, Светла ще гостува на Владислав Севов във видеопоредицата ни „Тоест разговаряме“. Гледайте я на живо от 16:00 ч. в YouTube Live. Може предварително да ѝ зададете въпрос и да довършите изречението в нашата анкета.
За разлика от Светла, на Е.Т. не може да ѝ задавате въпроси, защото тя вече ви е дала всички отговори в новия епизод, „в който мразим всички“ и „айсиктирдействително!“.
В Sic transit gloria Boyki Емилия Милчева се връща към протеста от началото на седмицата и разнищва брауновото движение вследствие на създалото се в триъгълника на властта напрежение: най-вече хаотичните танцови стъпки на Борисов, който непрестанно настъпва опърпания шлейф на партията си и се препъва в него; и опитите на (п)резидента да се превърне в бенефициер на случващото се по площадите.
За това какви следи ще оставим след себе си и на каква цена, говори и Зорница Христова в последната си за годината колонка „По буквите“, в която на фокус са три книги – на Йорданка Белева, Роб Дън и Джон Бърджър. Апропо заглавието на Роб Дън е „Естествена история на бъдещето“ – чудесен реторически пример за това как миналото не е приключило, а винаги дебне зад ъгъла, определя бъдещите ни ходове, неизбежно предстои.
Завършваме в светлата следа на музиката с интервю на Ина Иванова с хоровата диригентка Яна Делирадева. „Този живот може да се изпее“ – казва Яна с убеденост, която ни е особено необходима днес, когато за пореден път пълним площадите, обединени повече от гняв, отколкото от надежда.
А ако искате да го пеем този живот заедно, подкрепете ни! Вие сте тези, които дават сила и смисъл на гласа ни.
The vampire squid (Vampyroteuthis infernalis) has the largest cephalopod genome ever sequenced: more than 11 billion base pairs. That’s more than twice as large as the biggest squid genomes.
It’s technically not a squid: “The vampire squid is a fascinating twig tenaciously hanging onto the cephalopod family tree. It’s neither a squid nor an octopus (nor a vampire), but rather the last, lone remnant of an ancient lineage whose other members have long since vanished.”
As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.
Twonky Auth Bypass, RCEs and RISC-V Reverse Shell Payloads
This was another fantastic week in terms of PR contribution to the Metasploit Framework. Rapid7’s very own Ryan Emmons recently disclosed CVE-2025-13315 and CVE-2025-13316 which exist in Twonky Server and allow decrypting admin credentials by reading logs without authentication (which contain them). The auxiliary module Ryan submitted which exploits both of these CVEs was released this week. Community contributor Valentin Lobsein aka Chocapikk has returned to the PR queue with a welcomed vengeance. Two modules from Chocapikk were landed this week, a Monsta FTP downloadFile Remote Code Execution module along with a WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE. In addition to some awesome module content, community contributor bcoles added Linux RISC-V 32-bit/64-bit TCP reverse shell payloads.
Description: This module exploits two CVEs: CVE-2025-13315 and CVE-2025-13316. Both CVEs exist in Twonky Server and allow decrypting admin credentials by reading logs without authentication (which contain them). Then, because the module uses hardcoded keys, it decrypts those credentials.
Monsta FTP downloadFile Remote Code Execution
Authors: Valentin Lobstein [email protected], msutovsky-r7, and watchTowr Labs
Description: This add module for CVE-2025-34299. The module exploits a vulnerability in the downloadFile action which allows an attacker to connect to a malicious FTP server and download arbitrary files to arbitrary locations on the Monsta FTP server.
WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE
Description: This adds a new exploit module for an unauthenticated vulnerability in the WordPress AI Engine plugin, which has over 100,000 active installations. The vulnerability allows an attacker to create an administrator account via the MCP (Model Context Protocol) endpoint without authentication, then upload and execute a malicious plugin to achieve remote code execution. The vulnerability is being tracked as CVE-2025-11749.
Description: This adds Linux RISC-V 32-bit/64-bit TCP reverse shell payloads.
Enhancements and features (3)
#20658 from jheysel-r7 – This adds a number of accuracy enhancements to the ldap_esc_vulnerable_cert_finder module. It also adds a CertificateAuthorityRhost datastore option to the esc_update_ldap_object module so the operator can specify an IP Address explicitly in cases where the hostname cannot be resolved via DNS.
#20677 from zeroSteiner – This enables sessions to MSSQL servers that require encryption. These changes add a new MsTds::Channel which leverages Rex’s socket abstraction to facilitate the necessary encapsulation for the TLS negotiation.
#20741 from SaiSakthidar – This removes CAIN as an output format for collected hashes.
Documentation
You can find the latest Metasploit documentation on our docsite at docs.metasploit.com.
Get it
As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:
Ubiquiti’s USP-PDU-PRO is a high-end, 2U PDU with 16 outlets plus four USB-C ports for power, as well as network capabilities for individual port monitoring and power cycling
Emma Smith and Kirill Podoprigora, two of Python’s core developers, have opened a
discussion about including Rust code in CPython, the reference implementation of
the Python programming language. Initially, Rust would only be used for optional
extension modules, but they would like to see Rust become a required dependency
over time. The initial plan was to make Rust required by 2028, but Smith and
Podoprigora indefinitely postponed that goal in response to concerns raised in the discussion.
Every year, Rapid7 brings together some of the most experienced minds in cybersecurity to pause, zoom out, and take stock of where the threat landscape is heading. Last year’s predictions webinar sparked lively debate among practitioners, leaders, and researchers alike, and many of those early warnings were proven accurate.
We talked about expanding attack surfaces, the acceleration of zero-day exploitation, and the shifting role of SecOps teams navigating unpredictable regulatory and operational pressure. We explored how AI was beginning to shape attacker behavior and how defenders could prepare for a world where speed and context matter more than ever. Looking back, the real takeaway was not just the predictions themselves. It was how quickly the landscape shifted around them.
This year’s predictions webinar builds on that momentum. The conversation feels different now. Threat actors have adapted. Business environments have tightened. Defenders are operating with more constraints and higher expectations than at any point in recent memory. That is exactly why our experts are once again stepping up to share what they are seeing, what is keeping them curious, and what they believe security teams should be paying closer attention to as we head into 2026.
A panel shaped by diverse vantage points
One of the strengths of this session is the range of perspectives represented on the panel.
Philip Ingram, Former Senior Military Intelligence Officer at Grey Hare Media, brings a global geopolitical lens that connects cyber activity with real-world tensions and state-aligned movements. His vantage point helps translate complex geopolitical signals into practical considerations for security teams.
Raj Samani, SVP and Chief Scientist at Rapid7, offers deep insight into attacker behavior, AI-driven disruption, and the evolving threat landscape. His work tracking threat actor tradecraft and the mechanics of cybercrime economies gives him a unique perspective on how attacks scale and shift over time.
Sabeen Malik, VP of Global Government Affairs and Public Policy at Rapid7, brings a policy and regulatory perspective that is essential for understanding how global mandates and governance trends influence security operations. Her insights shed light on the intersection of cyber risk, legislative pressure, and organizational responsibility.
Together, they create a multi-dimensional picture of what is coming next. Not hype. Not speculation. Instead, grounded observations from experts who see attacker behavior unfold from very different angles.
What we learned from last year
Last year’s session made one thing clear: the forces shaping cyber risk are not isolated. They are interconnected, and they are accelerating.
We saw that:
Attackers were closing the gap between vulnerability disclosure and exploitation.
Identity-based compromise continued to outpace traditional malware.
Economic and operational pressures made it harder for security teams to keep up.
Global events had tangible ripple effects on what attackers chose to target next.
Those insights helped set a realistic direction for 2025. Only twelve months later, the ground has shifted again. AI-assisted exploitation, insider-driven breaches, geopolitical instability, and expanding exposure surfaces are changing both attacker priorities and defender responsibilities.
This webinar is not a rehash. It is a recalibration, grounded in what is actually happening across the threat landscape right now.
Themes our experts will explore
While the predictions themselves will be revealed live during the session, we can share a few of the themes shaping this year’s discussion.
How global tensions are redefining cyber risk for private organizations, even those far from the front lines
Why identity, behavior, and access are becoming the most reliable early indicators of compromise
Where AI is helping and hurting defenders, and how attackers are using automation and tooling to accelerate the earliest stages of intrusion
Why context and prioritization are becoming essential as vulnerability volumes and exploitation speeds continue to rise
How security teams can get ahead of exposure, not just react to it, through more integrated and risk-aware workflows
These are not abstract conversations. They reflect the real operational and strategic challenges security teams face every day.
Why you will not want to miss it
Whether you are leading a security program or defending in the trenches, this session will help you:
Understand the forces shaping attacker strategy Identify the signals that matter most for early detection
Anticipate the operational pressures teams will face in 2026
Prioritize investments, workflows, and practices that support resilience
You will walk away with a clearer sense of where to focus, what to watch for, and how to prepare your team for what comes next, without getting lost in noise or speculation.
Join the conversation
This webinar is one of our most anticipated sessions of the year. If you have not registered yet, now is the perfect time to save your spot and hear directly from the experts shaping the conversation around what 2026 will look like for security teams everywhere.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.