#exploit — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #exploit, aggregated by home.social.
-
QEMU 10.2.1 hv-syndbg Out-Of-Bounds Write https://packetstorm.news/files/228710 #exploit
-
Roundcube 1.7.1 Cross Site Scripting https://packetstorm.news/files/228709 #exploit
-
Budibase 3.41.2 Missing Authorization https://packetstorm.news/files/228708 #exploit
-
WooCommerce Subscriptions 9.0.0 Remote Code Execution https://packetstorm.news/files/228707 #exploit
-
Microsoft Windows Kerberos Privilege Escalation https://packetstorm.news/files/228706 #exploit
-
NetView Pro 4.2 Remote Code Execution https://packetstorm.news/files/228705 #exploit
-
The Dutch said we are under attack!
Vulnerability giving attackers full control of Macs is under active exploitation
-
The Dutch said we are under attack!
Vulnerability giving attackers full control of Macs is under active exploitation
-
Fabrik 4.6.7 Remote Code Execution https://packetstorm.news/files/228704 #exploit
-
AcyMailing 6.19.2 SQL Injection https://packetstorm.news/files/228703 #exploit
-
Gajim / KDE Plasma Konsole Remote Code Execution https://packetstorm.news/files/228702 #exploit
-
Gajim / KDE Plasma Konsole Remote Code Execution https://packetstorm.news/files/228702 #exploit
-
Böse #ScreenSharing-Lücke in #macOS: #Exploit aus Apples Patch gebaut | Mac & i https://www.heise.de/news/Boese-Screen-Sharing-Luecke-in-macOS-Exploit-aus-Apples-Patch-gebaut-11411035.html #Apple :apple_inc: #Patchday #RemoteControl
-
Böse #ScreenSharing-Lücke in #macOS: #Exploit aus Apples Patch gebaut | Mac & i https://www.heise.de/news/Boese-Screen-Sharing-Luecke-in-macOS-Exploit-aus-Apples-Patch-gebaut-11411035.html #Apple :apple_inc: #Patchday #RemoteControl
-
Dovecot 2.4.0 SQL Injection / Authentication Bypass https://packetstorm.news/files/228614 #exploit
-
Webmin Help Template Authenticated Remote Code Execution https://packetstorm.news/files/228613 #exploit
-
Marimo 0.22.x Terminal WebSocket Authentication Bypass https://packetstorm.news/files/228606 #exploit
-
n8n 2.32.0 Token Exchange Authentication Bypass https://packetstorm.news/files/228599 #exploit
-
YOP Poll 7.0.5 Vote Restriction Bypass https://packetstorm.news/files/228592 #exploit
-
GoDAM 1.12.2 Unauthenticated Shell Upload https://packetstorm.news/files/228589 #exploit
-
Microsoft Windows Cross Device Service Local Privilege Escalation https://packetstorm.news/files/228583 #exploit
-
Google Chrome 148.0.7778.215 ANGLE WebGL Fuzzing https://packetstorm.news/files/228580 #exploit
-
Microsoft Configuration Manager 2603 Remote Code Execution https://packetstorm.news/files/228576 #exploit
-
Online Food Ordering System 1.0 Shell Upload https://packetstorm.news/files/228489 #exploit
-
Sicherheitslücken: Angreifer können Wachdienst von #ClamAV stören | Security https://www.heise.de/news/Sicherheitsluecken-Angreifer-koennen-Wachdienst-von-ClamAV-stoeren-11409730.html #exploit #Patchday
-
Sicherheitslücken: Angreifer können Wachdienst von #ClamAV stören | Security https://www.heise.de/news/Sicherheitsluecken-Angreifer-koennen-Wachdienst-von-ClamAV-stoeren-11409730.html #exploit #Patchday
-
Novo exploit ShieldBreak é capaz de contornar a correção do Microsoft Defender com 100% de eficácia, afetando sistemas com Windows 11 25H2 e Windows Server 2025. A ferramenta foi publicada no ProjectNightCrawler. 🚨
-
Novo exploit ShieldBreak é capaz de contornar a correção do Microsoft Defender com 100% de eficácia, afetando sistemas com Windows 11 25H2 e Windows Server 2025. A ferramenta foi publicada no ProjectNightCrawler. 🚨
-
Google Threat Intelligence head: Thanks to AI, “more zero-days than ever before”
Bug bounty programs are flooded with reports, while users and companies face AI attacks. The security landscape is changing rapidly, says Sandra Joyce.
#Google #GoogleGemini #HardwareHacking #IT #KünstlicheIntelligenz #Security #Exploit #news
-
Google Threat Intelligence head: Thanks to AI, “more zero-days than ever before”
Bug bounty programs are flooded with reports, while users and companies face AI attacks. The security landscape is changing rapidly, says Sandra Joyce.
#Google #GoogleGemini #HardwareHacking #IT #KünstlicheIntelligenz #Security #Exploit #news
-
VMware vCenter: Attackers establish a foothold via path traversal vulnerability
A path traversal vulnerability in VMware vCenter Syslog Server, disclosed in late July, is being used by attackers to break in and establish a foothold.
#Cyberangriff #Exploit #IT #Security #Sicherheitslücken #Updates #Virtualisierung #news
-
VMware vCenter: Attackers establish a foothold via path traversal vulnerability
A path traversal vulnerability in VMware vCenter Syslog Server, disclosed in late July, is being used by attackers to break in and establish a foothold.
#Cyberangriff #Exploit #IT #Security #Sicherheitslücken #Updates #Virtualisierung #news
-
VMware vCenter: Angreifer nisten sich durch Path-Traversal-Lücke ein
Eine Ende Juli bekannt gewordene Path-Traversal-Lücke in VMware vCenter Syslog Server dient Angreifern zum Einbrechen und Einnisten.
#Cyberangriff #Exploit #IT #Security #Sicherheitslücken #Updates #news
-
VMware vCenter: Angreifer nisten sich durch Path-Traversal-Lücke ein
Eine Ende Juli bekannt gewordene Path-Traversal-Lücke in VMware vCenter Syslog Server dient Angreifern zum Einbrechen und Einnisten.
#Cyberangriff #Exploit #IT #Security #Sicherheitslücken #Updates #news
-
Telaeris XPressEntry 3.7.7454 SQL Injection / Remote Command Execution https://packetstorm.news/files/228484 #exploit
-
Plixer Scrutinizer 19.7.0 SQL Injection / Remote Command Execution https://packetstorm.news/files/228483 #exploit
-
Output Messenger Server 2.0.x Remote Code Execution https://packetstorm.news/files/228482 #exploit
-
Cisco warns of attacks on Secure Firewall Adaptive Security Appliance
Attackers are currently causing Cisco Secure Firewall Adaptive Security Appliance to crash after attacks. A security patch is available.
#Cyberangriff #Exploit #IT #Security #Sicherheitslücken #Updates #news
-
Cisco warnt vor Attacken auf Secure Firewall Adaptive Security Appliance
Derzeit lassen Angreifer Cisco Secure Firewall Adaptive Security Appliance nach Attacken abstürzen. Ein Sicherheitspatch ist verfügbar.
#Cyberangriff #Exploit #IT #Security #Sicherheitslücken #Updates #news
-
Microsoft Defender enfrenta novo exploit ShieldBreak que contorna correção da empresa. Um novo exploit de dia zero, chamado ShieldBreak, foi tornado público após a atualização de segurança de agosto de 2026 da Microsoft, permitindo obter privilégios máximos do sistema (SYSTEM) em ambientes atualizados. 🚨
-
Nasty screen sharing vulnerability in macOS: Exploit built from Apple's patch
Users of Apple's practical screen sharing function on Mac must update their operating system. An exploit could be developed quickly.
-
Böse Screen-Sharing-Lücke in macOS: Exploit aus Apples Patch gebaut
Wer Apples praktische Bildschirm-teilen-Funktion auf dem Mac nutzt, muss sein Betriebssystem aktualisieren. Ein Exploit ließ sich schnell entwickeln.
-
Patchday: Attackers target Windows and gain system privileges
Microsoft addresses around 400 security issues in Azure, Office, Windows & more. Several vulnerabilities are considered critical.
#Cyberangriff #Exploit #IT #Microsoft #Security #Sicherheitslücken #Updates #Windows #news
-
Patchday: Angreifer attackieren Windows und verschaffen sich System-Rechte
Microsoft kümmert sich um rund 400 Sicherheitsprobleme in Azure, Office, Windows & Co. Mehrere Lücken gelten als kritisch.
#Cyberangriff #Exploit #IT #Microsoft #Security #Sicherheitslücken #Updates #Windows #news
-
QEMU Guest Agent 11.0.3 Local Privilege Escalation https://packetstorm.news/files/228351 #exploit
-
Ein Modder hat die Sperren des Cloud-Gaming-Dienstes #GeForceNow von #Nvidia ausgehebelt. Statt nur zu spielen, entsperrte er den zugrundeliegenden vollwertigen #Windows-#Desktop. #Exploit https://winfuture.de/news,160526.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
This bloke asked OpenClaw to book him into a gym class. In its effort to please, OpenClaw found an exploit in the booking system, hacked the waiting list and booted off the person ahead of him in the queue! 😂
https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986
-
Patch now! Admin attacks on Metabase observed
Attackers are currently exploiting a critical security vulnerability in the business intelligence platform Metabase. Admins must act now.
#Cyberangriff #Exploit #IT #Patchday #Security #Sicherheitslücken #Updates #news
-
Jetzt patchen! Admin-Attacken auf Metabase beobachtet
Angreifer nutzen zurzeit eine kritische Sicherheitslücke in der Business-Intelligence-Plattform Metabase aus. Admins müssen jetzt handeln.
#Cyberangriff #Exploit #IT #Patchday #Security #Sicherheitslücken #Updates #news
-
Google-Threat-Intelligence-Chefin: Dank KI „mehr Zero-Days als je zuvor“ | heise online https://www.heise.de/hintergrund/Google-Threat-Intelligence-Chefin-Dank-KI-mehr-Zero-Days-als-je-zuvor-11400371.html #ArtificialIntelligence #AI #CyberCrime #exploit #ZeroDay #0day
-
Zapscape, CVE-2026-64561, a KVM x86 use after free in shadow MMU emulation. Requires nested virtualization enabled, and an AMD or Intel Ice-Lake-SP+ CPU. Apparently, without nested virtualization on, it doesn't apply.
A tenant with root inside their own VM guest can escalate to root on the host. On a host that doesn't run VMs for tenants, an attacker (or a compromised website/process) can spin up a throwaway guest of their own and attack the host kernel from inside it. So even if you don't provide VMs, it isn't okay to skip if KVM/nested virt is enabled.
Released fix along with SCTPhantom fix.
-
I'm not at defcon. So...
SCTPhantom, CVE-2026-64564, yet another "AI Found" kernel vuln, this time with coordinated (responsible) disclosure! It is a use-after-free bug in the Linux kernel's SCTP (Stream Control Transmission Protocol) ASCONF (Address Configuration Change) handling. Unprivileged local user to root, with container escape to the host in some configurations. The upside is that since it was a coordinated disclosure, fixes are out and have been backported to earlier kernel versions.
-
Google-Threat-Intelligence-Chefin: Dank KI „mehr Zero-Days als je zuvor“
Bug-Bounty-Programme werden mit Fehlerberichten geflutet, User und Firmen leiden unter KI-Angriffen: Der Security-Bereich ändert sich rasant, sagt Sandra Joyce.
#Google #GoogleGemini #HardwareHacking #IT #KünstlicheIntelligenz #Security #Exploit #news
-
Auf der Black Hat haben Forscher von Google Project Zero gezeigt, wie sich ein Pixel 10 ohne Nutzerinteraktion kompromittieren lässt. Die vorgestellte Exploit-Kette führt von einem eingehenden Inhalt bis zur vollständigen Kontrolle mit Root-Rechten.
https://blackhat.com/us-26/briefings/schedule/#a-0-click-exploit-chain-for-the-pixel-10-53404
1/2
-
Woah this is neat. Pivot an Oracle SQL injection to OS command injection (without xp_commandshell, obviously).
https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html
-
This is fun. A Chinese company that makes fairly generic WiFi routers and sells them under its own (multiple) brands as well as white-labelling them for many other companies to sell as "theirs", has shipped a backdoor on what appears to be every version of every model they've sold.
https://www.vulncheck.com/blog/zbt-endlessdoors
The backdoor itself is also laughably insecure, easily taken over by anyone who can intercept packets between the router and its command-and-control server, or who can cause the hardcoded domain names it used to resolve to an IP address under their control. TL;DR: this is very easy to exploit.
It is a deliberate remote root backdoor.
The company says "oh no, there's no security issue, you misunderstand" to the researcher that found this. However, they've taken all their downloadable firmware images offline to be updated for the security issue their PR people say doesn't exist.
And it is definitely, 100% deliberate and done in bad faith. The backdoor processes deliberately mislabel themselves as `kworker` processes to try to make anyone who sees them think they are Linux built-in kernel threads.
Worth a read.
#BackDoor #security #exploit #root #Chinesium #trust #network #hardware