home.social

#advisory — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #advisory, aggregated by home.social.

  1. NGINX Rift: 18-Year-Old Flaw Enables Unauthenticated Remote Code Execution

    NGINX disclosed a critical 18-year-old heap buffer overflow vulnerability (CVE-2026-42945) in its rewrite module that allows unauthenticated remote code execution or denial-of-service via crafted HTTP requests.

    **Check your platform and tooling for running NGINX. If you are running NGINX and related F5 deployments, patch ASAP. Alternatively change your rewrite rules to use named captures instead of unnamed ones.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  2. Critical SandboxJS Escape Vulnerability Enables Host Takeover

    Nyariv's SandboxJS library contains a critical vulnerability (CVE-2026-43898) that allows unauthenticated attackers to escape the sandbox and execute arbitrary code on the host system.

    **If you use the @nyariv/sandboxjs library in your applications, update immediately to version 0.9.6. If you can't update right away, stop processing any untrusted JavaScript through the library until the patch is applied.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  3. Critical 'Dead.Letter' Vulnerability in Exim Mailer Allows Unauthenticated Remote Code Execution

    Exim patched a critical use-after-free vulnerability (CVE-2026-45185) in its GnuTLS implementation that allows unauthenticated remote attackers to execute arbitrary code via specially crafted BDAT SMTP traffic.

    **If you are running Exim mail servers (versions 4.97 through 4.99.2) built with GnuTLS, update to version 4.99.3 ASAP. Email servers are designed to be exposed to the internet so you can't hide this issue behind a firewall. Until you update, temporarily disable the CHUNKING (BDAT) extension or switch to an OpenSSL-based build until the patch can be applied.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  4. #OT #Advisory VDE-2026-042
    CODESYS Modbus TCP Server - Improper resource management

    CODESYS Modbus is an add‑on for the CODESYS Development System that provides a fully integrated Modbus protocol stack along with diagnostic capabilities. A flaw in the CODESYS Modbus TCP Server protocol stack library results in a vulnerability. When a Modbus TCP server is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.
    #CVE CVE-2026-35227

    certvde.com/en/advisories/vde-

    #CSAF codesys.csaf-tp.certvde.com/.w

  5. #OT #Advisory VDE-2026-042
    CODESYS Modbus TCP Server - Improper resource management

    CODESYS Modbus is an add‑on for the CODESYS Development System that provides a fully integrated Modbus protocol stack along with diagnostic capabilities. A flaw in the CODESYS Modbus TCP Server protocol stack library results in a vulnerability. When a Modbus TCP server is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.
    #CVE CVE-2026-35227

    certvde.com/en/advisories/vde-

    #CSAF codesys.csaf-tp.certvde.com/.w

  6. #OT #Advisory VDE-2026-042
    CODESYS Modbus TCP Server - Improper resource management

    CODESYS Modbus is an add‑on for the CODESYS Development System that provides a fully integrated Modbus protocol stack along with diagnostic capabilities. A flaw in the CODESYS Modbus TCP Server protocol stack library results in a vulnerability. When a Modbus TCP server is configured, this vulnerable protocol stack is downloaded to and executed by CODESYS Control runtime systems.
    #CVE CVE-2026-35227

    certvde.com/en/advisories/vde-

    #CSAF codesys.csaf-tp.certvde.com/.w

  7. Media Advisory – Photo/Video Op — Visit of Princess Margriet of the Netherlands to Canadian Museum of Nature Monday, May 11, 11 a.m.

    OTTAWA, Ontario, May 07, 2026 (GLOBE NEWSWIRE) — Media are invited to a photo/video op on Monday, May…
    #Netherlands #Nederland #NL #Europe #Europa #EU #11 #a.m. #Advisory #Canadian #Margriet #may #media #Monday #museum #Nature #of #Op #Photo/Video #Princess #the #to #Visit
    europesays.com/netherlands/952

  8. Media Advisory – Photo/Video Op — Visit of Princess Margriet of the Netherlands to Canadian Museum of Nature Monday, May 11, 11 a.m. byteseu.com/1999243/ #11 #AM #advisory #canadian #Europe #Margriet #may #Media #monday #Museum #nature #Netherlands #of #op #Photo/Video #princess #the #to #visit

  9. Four Salient Features of the TDG

    1.Tiered Indirect Elections

    2. Voting Based on Good Character & Capacity for Governance

    3. A Culture of Consultation

    4. An Advisory Board

    tiereddemocraticgovernance.org

    Are these features not good things for a democracy to have?

    #tiereddeemocraticgovernance
    #character #capacity #consultation #advisory

  10. FLOOD ADVISORY:

    Due to the recent #rainfall and melting #snow packs, a #Flood #Advisory is in effect for the Arrowhead and North Shore regions of the #Northland through Tuesday evening.

    This also includes the Cloquet River upstream of Island Lake.

    Minor #flooding near rivers, streams, and waterways is expected.

    #wxtooter #weather #wx #MNwx #WIwx #UPwx

  11. RE: infosec.exchange/@beyondmachin

    Mozilla publie des mises à jour de sécurité pour Firefox et Thunderbird

    Mozilla a publié des mises à jour de sécurité pour Firefox et Thunderbird afin de corriger un débordement de mémoire tampon de grande gravité (CVE-2026-2447) dans la bibliothèque libvpx qui permet l'exécution de code à distance par le biais d'un contenu vidéo malformé.

    #cybersécurité #infosec #conseil #vulnérabilité
    #cybersecurity #infosec #advisory #vulnerability
    ___

  12. Unfortunately we have to announce a #gnupg #security #advisory:
    Please update to GnuPG to the new 2.5.17 or #gpg4win to 5.0.1

    The details are here:
    lists.gnupg.org/pipermail/gnup

  13. "Japan's Meteorological Agency, or #JMA, says a major tremor of magnitude 8 or higher could occur along the #Japan Trench and the Chishima Trench off #Hokkaido.

    The advisory covers areas from Hokkaido to #Chiba Prefecture, and is the first issued for the region since the mega-quake warning category was introduced in 2022.

    Officials are urging people to check evacuation routes, make sure home furniture is secure, and prepare emergency kits, including food, water and portable toilets.

    They stress that no evacuation recommendation has been issued, but they advise people to remain vigilant through next week. #tsunami #forecast #earthquake #advisory #NHK

    www3.nhk.or.jp/nhkworld/en/new

  14. #OT #Advisory VDE-2025-044
    Weidmueller: Industrial ethernet switches are affected by multiple vulnerabilities

    #CVE CVE-2025-41651, CVE-2025-41652, CVE-2025-41649, CVE-2025-41650, CVE-2025-41653

    certvde.com/en/advisories/VDE-

    #CSAF weidmueller.csaf-tp.certvde.co

  15. #OT #Advisory VDE-2025-041
    Weidmueller: ResMa is affected by a Vulnerability for ASP.NET AJAX

    Weidmueller product ResMa is affected by ASP.NET AJAX vulnerability.
    Weidmueller has released a new firmware for the affected product to fix the vulnerability.
    #CVE CVE-2025-3600

    certvde.com/en/advisories/VDE-

    #CSAF weidmueller.csaf-tp.certvde.co

  16. #OT #Advisory #Update VDE-2023-046
    WAGO: Multiple products vulnerable to local file inclusion

    An attacker with administrative privileges which can access sensitive files can additionally access them in an unintended, undocumented way.
    UPDATE 07.05.2025: The fixed versions have been updated, because the previously mentioned versions are still vulnerable to this issue. More details have been added to the hardware devices. More affected version numbers were added to the firmwares.
    #CVE CVE-2023-4089

    certvde.com/en/advisories/VDE-

    #CSAF wago.csaf-tp.certvde.com/.well

  17. Searching for an #OT #Advisory?
    Want it machine readable?
    Have a look at our #csaf aggregator aggregator.certvde.com for advisories of 35+ OT and #ICS vendors that partner with CERT@VDE.

    See certvde.com/en/more/csaf/ for a full list of the trusted providers used on the aggregator.

  18. No surprise from me that a #wind #advisory is in effect for the #TwinPorts, #IronRange and #I35 corridor regions of the #Northland for the next several hours.

    Current wind #gusts are in the 30 to 50 mph range

    The worst is on the #Blatnik Bridge. Gusts have surpassed 60 mph, and possibly as high as 76 mph!

    Hold on tight out there!

    #wxtooter #weather #wx #MNwx #WIwx #UPwx

  19. 𝐒𝐡𝐫𝐞𝐞𝐤𝐚𝐧𝐭 𝐏𝐚𝐭𝐢𝐥 𝐋𝐞𝐚𝐝𝐬 𝐌𝐀𝐂𝐂𝐈𝐀 𝐔𝐝𝐲𝐨𝐠𝐲𝐚𝐭𝐫𝐚, 𝐄𝐦𝐩𝐨𝐰𝐞𝐫𝐢𝐧𝐠 𝐒𝐭𝐚𝐫𝐭𝐮𝐩𝐬, 𝐌𝐒𝐌𝐄𝐬 𝐚𝐧𝐝 𝐖𝐨𝐦𝐞𝐧 𝐄𝐧𝐭𝐫𝐞𝐩𝐫𝐞𝐧𝐞𝐮𝐫𝐬 𝐀𝐜𝐫𝐨𝐬𝐬 𝐌𝐚𝐡𝐚𝐫𝐚𝐬𝐡𝐭𝐫𝐚

    vimeo.com/1053461986

    #MACCIA #Udyogyatra #Maharashtra #ShreekantPatil #MaharashtraChamber #MSME #Vyapari #Startup #GovtSchemes #Awarness #Mentorship #Consultancy #Advisory #Nashik #Kolhapur #Pune #Sindhudurg #Vaibhavwadi #Konkan #Keynote #speaker

  20. 𝐒𝐡𝐫𝐞𝐞𝐤𝐚𝐧𝐭 𝐏𝐚𝐭𝐢𝐥 𝐋𝐞𝐚𝐝𝐬 𝐌𝐀𝐂𝐂𝐈𝐀 𝐔𝐝𝐲𝐨𝐠𝐲𝐚𝐭𝐫𝐚, 𝐄𝐦𝐩𝐨𝐰𝐞𝐫𝐢𝐧𝐠 𝐒𝐭𝐚𝐫𝐭𝐮𝐩𝐬, 𝐌𝐒𝐌𝐄𝐬 𝐚𝐧𝐝 𝐖𝐨𝐦𝐞𝐧 𝐄𝐧𝐭𝐫𝐞𝐩𝐫𝐞𝐧𝐞𝐮𝐫𝐬 𝐀𝐜𝐫𝐨𝐬𝐬 𝐌𝐚𝐡𝐚𝐫𝐚𝐬𝐡𝐭𝐫𝐚

    medium.com/@shreekant-patil-me

    #MACCIA #Udyogyatra #Maharashtra #ShreekantPatil #MaharashtraChamber #MSME #Vyapari #Startup #GovtSchemes #Awarness #Mentorship #Consultancy #Advisory #Nashik #Kolhapur #Pune #Sindhudurg #Vaibhavwadi #Konkan #Keynote #speaker

  21. 𝐒𝐡𝐫𝐞𝐞𝐤𝐚𝐧𝐭 𝐏𝐚𝐭𝐢𝐥 𝐋𝐞𝐚𝐝𝐬 𝐌𝐀𝐂𝐂𝐈𝐀 𝐔𝐝𝐲𝐨𝐠𝐲𝐚𝐭𝐫𝐚, 𝐄𝐦𝐩𝐨𝐰𝐞𝐫𝐢𝐧𝐠 𝐒𝐭𝐚𝐫𝐭𝐮𝐩𝐬, 𝐌𝐒𝐌𝐄𝐬 𝐚𝐧𝐝 𝐖𝐨𝐦𝐞𝐧 𝐄𝐧𝐭𝐫𝐞𝐩𝐫𝐞𝐧𝐞𝐮𝐫𝐬 𝐀𝐜𝐫𝐨𝐬𝐬 𝐌𝐚𝐡𝐚𝐫𝐚𝐬𝐡𝐭𝐫𝐚

    shreekantpatil.substack.com/p/

    #MACCIA #Udyogyatra #Maharashtra #ShreekantPatil #MaharashtraChamber #MSME #Vyapari #Startup #GovtSchemes #Awarness #Mentorship #Consultancy #Advisory #Nashik #Kolhapur #Pune #Sindhudurg #Vaibhavwadi #Konkan #Keynote #speaker

  22. 𝑺𝒕𝒂𝒓𝒕𝒖𝒑 𝑬𝒄𝒐𝒔𝒚𝒔𝒕𝒆𝒎 𝒊𝒏 𝑵𝒂𝒔𝒉𝒊𝒌, 𝑴𝒂𝒉𝒂𝒓𝒂𝒔𝒉𝒕𝒓𝒂, 𝑬𝒎𝒑𝒐𝒘𝒆𝒓𝒊𝒏𝒈 𝑴𝑺𝑴𝑬𝒔 & 𝑾𝒐𝒎𝒆𝒏 𝑬𝒏𝒕𝒓𝒆𝒑𝒓𝒆𝒏𝒆𝒖𝒓𝒔

    polywork.com/shreekantpatil/po

    From Vision to Reality: How Shreekant Patil is Building the Startup Ecosystem in Nashik & Maharashtra

    #Startup #Ecosystem #Nashik #Maharatra #ShreekantPatil #Mentorship #GovtSchemes #NationalStartupDay #Consultant #MSMEHelp #Advisory #DPIIT #Registration #Certification #StartupIndia #SuInternaional #SupplyChain #GovtofIndia #DPIIT

  23. Serious question.

    What is a no-cost resource for #counsel #advisory about how to secure one's #intellectualproperty rights in the context of forthcoming release.

    Oh. Is that what they mean by software patents? #softwarepatents

    I don't know that software patent is relevant.

    @Vivaldi
    I know nothing of sofware dv, law, copyright, etc. Never cared.

    I'm a former music industry dude however, so i might know a little about #copyright already.
    :D