home.social

#advisory — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #advisory, aggregated by home.social.

  1. ZITADEL Authentication Bypass Cluster Exposes Self-Hosted Identity Providers

    ZITADEL reports ten vulnerabilities, including seven critical flaws, that allow unauthenticated attackers to bypass authentication and take over accounts. The issues affect versions 3.x and 4.x.

    **If you use ZITADEL to manage logins, update it ASAP to version 4.17.3, because ten new flaws let attackers take over accounts and bypass passwords and MFA without logging in. If you are still on version 3.x, it will never get a fix, so move to 4.x as soon as possible and check your users for unfamiliar linked logins, passkeys or authenticators.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  2. 🔒 New CSAF advisory published

    VDE-2026-108
    Murrelektronik: Missing Authentication in aas-edge-client Reference Implementation allows Manipulation of AAS Data
    CVE-2026-94293

    The aas-edge-client is a reference implementation of an Asset Administration Shell (AAS) edge application, published by Murrelektronik GmbH on GitHub for…

    HTML: certvde.com/en/advisories/vde-
    CSAF JSON: murrelektronik.csaf-tp.certvde

    #OT #Advisory

  3. Apple iOS, iPadOS, and macOS Certificate Validation packetstorm.news/files/234187 #advisory

  4. Check out my latest article: “Teaching the 5 Dynamics of Goal Setting - A lesson I first learned as a cadet at the Air Force Academy”

    wfryer.substack.com/p/teaching

    #Goals #GoalSetting #advisory #AI #visualization #Claude #Gemini

  5. Bouncy Castle Patches Identity Binding Vulnerability in Messaging Layer Security Implementation

    Bouncy Castle for Java patched a critical identity binding vulnerability (CVE-2026-71885) in its Messaging Layer Security implementation that allows attackers to spoof user identities and decrypt private group messages.

    **If your apps or servers use Bouncy Castle for Java (including Android apps and enterprise Java frameworks), update to version 1.86 or later as soon as possible, because attackers can impersonate users and read secure group messages. Ask your developers to check that their apps properly verify certificates and identities all the way back to a trusted source.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  6. Fortra Patches Command Injection Flaw in BoKS Core PAM

    Fortra fixed a command injection vulnerability (CVE-2026-9862) in its BoKS Core PAM that allows unauthenticated remote code execution. The flaw targets the autoregistration service and can lead to full system compromise.

    **If you use Fortra BoKS Core 8.1 or 9.0, apply Fortra's security update ASAP. Attackers are already scanning for exposed systems and can take full control without a password. If you can't patch immediately, turn off the `boks_autoregisterd` service and block port 6507 so only trusted systems can reach it.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  7. ASUS Patches Critical Vulnerabilities in Router Firmware Triggered by Malicious VPN Files

    ASUS patched two vulnerabilities (CVE-2026-14157 and CVE-2026-13313) in its router firmware that allow authenticated attackers to execute arbitrary commands and gain root privileges via malicious VPN configuration files or active debug code.

    **If you have an ASUS router, update its firmware ASAP from the official ASUS support page, and make sure its admin page can only be reached from your trusted internal network, never from the internet. Only import VPN configuration files from providers you trust, and if your router is on ASUS's end-of-life list, plan to replace it since it will not be patched.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

  8. Critical Capacitor Flaw Allows Malicious Links to Hijack Mobile App Data and Native Features

    Capacitor patched a critical vulnerability (CVE-2026-103922) that allows malicious links to load attacker-controlled content within a mobile app's trusted origin. This flaw enables unauthorized access to sensitive user data, authentication tokens, and native device features through Capacitor plugins.

    **If you build mobile apps with Capacitor, update to a patched version (6.2.2, 7.6.9, 8.3.5, 8.4.3 or 8.5.1), then rebuild your Android and iOS apps and push the new versions to users. Updating the package alone doesn't protect anyone. If you can't update, block navigation to the internal interceptor path with a custom plugin, and rebuild the apps. Prioritize apps that show chat messages, feeds or other user content first.**
    #cybersecurity #infosec #advisory #vulnerability
    beyondmachines.net/event_detai

Share on Mastodon

Enter the server where you have an account.