#nttdata — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #nttdata, aggregated by home.social.
-
NTT DATA awarded Golden Certificate by SAP as Global Operations Partner, reflecting the scale of its Global Managed Services expertise
BIELEFELD, Germany, Aug. 13, 2026 /PRNewswire/ — NTT DATA, a global leader in AI, digital business and technology…
#Germany #DE #Europe #EU #Europa #SAP #businessandtechnologyservices #BusinessSolutions #globalleader #globaloperations #NTTDATA #sap #SAPHANA #SAPsecurity
https://www.europesays.com/germany/71627/ -
🚨 XSS2shell (CVE-2026-64638) has been identified as a notable vulnerability.
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.
This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
Discovered and responsibly disclosed by the team at pwn.ai.
ℹ️ Additional details on ZEN SecDB https://secdb.nttzen.cloud/updates/267dffcb-04e8-4ba6-9c9e-2305d1d11b59/xss2shell-vulnerability
#infosec #xss2shell #wordpress #xss #rce
#nttdata #zen #secdb -
🚨 XSS2shell (CVE-2026-64638) has been identified as a notable vulnerability.
WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen.
Via a specially crafted malicious third-party website hosted by an attacker, it is possible for this to be escalated to an RCE vulnerability with conditions outside of the attackers control. This requires successful social engineering of and explicit interaction by the target victim.
This issue affects all versions of WordPress. Version 7.0.3 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
Discovered and responsibly disclosed by the team at pwn.ai.
ℹ️ Additional details on ZEN SecDB https://secdb.nttzen.cloud/updates/267dffcb-04e8-4ba6-9c9e-2305d1d11b59/xss2shell-vulnerability
#infosec #xss2shell #wordpress #xss #rce
#nttdata #zen #secdb -
NTT Data Group expects to spend at least $9 billion through 2033 to quadruple computing capacity to 1 gigawatt to address a surge in demand from companies seeking to catch up in artificial intelligence in Japan. https://www.japantimes.co.jp/business/2026/08/04/companies/ntt-data-spending-japan-data-center/?utm_medium=Social&utm_source=mastodon #business #companies #nttdata #ntt #bigdata #datacenters #investmentsz #ai
-
NTT Data Group expects to spend at least $9 billion through 2033 to quadruple computing capacity to 1 gigawatt to address a surge in demand from companies seeking to catch up in artificial intelligence in Japan. https://www.japantimes.co.jp/business/2026/08/04/companies/ntt-data-spending-japan-data-center/?utm_medium=Social&utm_source=mastodon #business #companies #nttdata #ntt #bigdata #datacenters #investmentsz #ai
-
NTT Data Group expects to spend at least $9 billion through 2033 to quadruple computing capacity to 1 gigawatt to address a surge in demand from companies seeking to catch up in artificial intelligence in Japan. https://www.japantimes.co.jp/business/2026/08/04/companies/ntt-data-spending-japan-data-center/?utm_medium=Social&utm_source=mastodon #business #companies #nttdata #ntt #bigdata #datacenters #investmentsz #ai
-
NTT Data Group expects to spend at least $9 billion through 2033 to quadruple computing capacity to 1 gigawatt to address a surge in demand from companies seeking to catch up in artificial intelligence in Japan. https://www.japantimes.co.jp/business/2026/08/04/companies/ntt-data-spending-japan-data-center/?utm_medium=Social&utm_source=mastodon #business #companies #nttdata #ntt #bigdata #datacenters #investmentsz #ai
-
🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
xfs: resample the data fork mapping after cycling ILOCK
RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access.
ℹ️ Additional details on ZEN SecDB https://secdb.nttzen.cloud/updates/1d26eb14-ce27-4846-a8ce-bae087fb1e46/refluxfs-vulnerability
#infosec #refluxfs #linux #kernel #xfs #lpe
#nttdata #zen #secdb -
🚨 RefluXFS (CVE-2026-64600) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
xfs: resample the data fork mapping after cycling ILOCK
RefluXFS is a local privilege escalation vulnerability in the Linux kernel's XFS filesystem copy-on-write path. It allows local users to overwrite protected files and gain root access.
ℹ️ Additional details on ZEN SecDB https://secdb.nttzen.cloud/updates/1d26eb14-ce27-4846-a8ce-bae087fb1e46/refluxfs-vulnerability
#infosec #refluxfs #linux #kernel #xfs #lpe
#nttdata #zen #secdb -
Mitsubishi Materials, BHP launch Chile-to-Japan low-GHG copper cable pilot
KEY POINTSMitsubishi Materials and BHP start a pilot for copper cable using a mass-balance credit model across the…
#EuropeSays #Japan #JP #AmazonJapan #BHP #coppercable #Escondida #ISO22095 #Japanese #mass-balancecreditmodel #MitsubishiMaterials #NTTDATA
https://www.europesays.com/japan/62379/ -
🚨 wp2shell affects multiple vulnerabilities (CVE-2026-63030, CVE-2026-60137).
- CVE-2026-63030 (HIGH) - WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
- CVE-2026-60137 (CRITICAL) - WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryRunning WordPress? Check your versions and patch to 6.8.6 / 6.9.5 / 7.0.2. If you can't patch immediately, apply the mitigations in the meantime.
ℹ️ Additional information on ZEN SecDB
https://secdb.nttzen.cloud/updates/a5a57351-ee12-401e-89a9-eca20d3ba7af/wp2shell-vulnerability#infosec #wordpress #rce #sqlinjection #cve202663030 #cve202660137
#nttdata #zen #secdb #vulnerability_intelligence -
🚨 wp2shell affects multiple vulnerabilities (CVE-2026-63030, CVE-2026-60137).
- CVE-2026-63030 (HIGH) - WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
- CVE-2026-60137 (CRITICAL) - WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryRunning WordPress? Check your versions and patch to 6.8.6 / 6.9.5 / 7.0.2. If you can't patch immediately, apply the mitigations in the meantime.
ℹ️ Additional information on ZEN SecDB
https://secdb.nttzen.cloud/updates/a5a57351-ee12-401e-89a9-eca20d3ba7af/wp2shell-vulnerability#infosec #wordpress #rce #sqlinjection #cve202663030 #cve202660137
#nttdata #zen #secdb #vulnerability_intelligence -
🚨 wp2shell affects multiple vulnerabilities (CVE-2026-63030, CVE-2026-60137).
- CVE-2026-63030 (HIGH) - WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
- CVE-2026-60137 (CRITICAL) - WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryRunning WordPress? Check your versions and patch to 6.8.6 / 6.9.5 / 7.0.2. If you can't patch immediately, apply the mitigations in the meantime.
ℹ️ Additional information on ZEN SecDB
https://secdb.nttzen.cloud/updates/a5a57351-ee12-401e-89a9-eca20d3ba7af/wp2shell-vulnerability#infosec #wordpress #rce #sqlinjection #cve202663030 #cve202660137
#nttdata #zen #secdb #vulnerability_intelligence -
🚨 wp2shell affects multiple vulnerabilities (CVE-2026-63030, CVE-2026-60137).
- CVE-2026-63030 (HIGH) - WordPress < 7.0.2 - REST API batch-route confusion and SQL injection issue leading to Remote Code Execution
- CVE-2026-60137 (CRITICAL) - WordPress < 7.0.2 - Facilitated SQL Injection via author__not_in in WP_QueryRunning WordPress? Check your versions and patch to 6.8.6 / 6.9.5 / 7.0.2. If you can't patch immediately, apply the mitigations in the meantime.
ℹ️ Additional information on ZEN SecDB
https://secdb.nttzen.cloud/updates/a5a57351-ee12-401e-89a9-eca20d3ba7af/wp2shell-vulnerability#infosec #wordpress #rce #sqlinjection #cve202663030 #cve202660137
#nttdata #zen #secdb #vulnerability_intelligence -
Triumph Modular builds the future with SAP
SAP offers a range of ERP solutions designed for functionalities, infrastructures and business sizes. Having limited experience with…
#Germany #DE #Europe #EU #Europa #SAP #Acquisition #businessintegration #ERPmigration #modularbuildings #NTTDATA #sap #tecnofast #triumphmodular
https://www.europesays.com/germany/48711/ -
🚨 Bad Epoll (CVE-2026-46242) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
eventpoll: fix ep_remove struct eventpoll / struct file UAF
ℹ️ Additional information on ZEN SecDB:
- BadEpoll: https://secdb.nttzen.cloud/updates/79198418-b310-4e40-80cd-d98ba3da0b2a/bad-epoll-vulnerability
- CVE details, sightings and advisories: https://secdb.nttzen.cloud/cve/detail/CVE-2026-46242
-
🚨 Bad Epoll (CVE-2026-46242) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
eventpoll: fix ep_remove struct eventpoll / struct file UAF
ℹ️ Additional information on ZEN SecDB:
- BadEpoll: https://secdb.nttzen.cloud/updates/79198418-b310-4e40-80cd-d98ba3da0b2a/bad-epoll-vulnerability
- CVE details, sightings and advisories: https://secdb.nttzen.cloud/cve/detail/CVE-2026-46242#InfoSec #BadEpoll #CVE202646242 #Linux #Kernel
#NTTDATA #Zen #SecDB #VulnerabilityIntelligence #Security -
🚨 Bad Epoll (CVE-2026-46242) has been identified as a notable vulnerability.
In the Linux kernel, the following vulnerability has been resolved:
eventpoll: fix ep_remove struct eventpoll / struct file UAF
ℹ️ Additional information on ZEN SecDB:
- BadEpoll: https://secdb.nttzen.cloud/updates/79198418-b310-4e40-80cd-d98ba3da0b2a/bad-epoll-vulnerability
- CVE details, sightings and advisories: https://secdb.nttzen.cloud/cve/detail/CVE-2026-46242#InfoSec #BadEpoll #CVE202646242 #Linux #Kernel
#NTTDATA #Zen #SecDB #VulnerabilityIntelligence #Security -
Nur 20 % der Versicherer nutzen KI produktiv, obwohl Cyberrisiken und ungedeckte Schäden massiv steigen. KI-gestützte Modelle könnten Kosten um bis zu 35 % senken – die Branche steht am Wendepunkt.
#Aktuell #Anwendung #FinTech #FintechStudie #InsurTech #KünstlicheIntelligenz #NTTData #Audio
https://www.it-finanzmagazin.de/ntt-studie-nur-jeder-fuenfte-versicherer-hat-ki-...
https://www.it-finanzmagazin.de/ntt-studie-nur-jeder-fuenfte-versicherer-hat-ki-produktiv-im-einsatz-246934/?fsp_sid=35431 -
🚨 DirtyClone (CVE-2026-43503)
In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: propagate shared-frag marker through frag-transfer helpers
ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/updates/9a1828d5-6607-419b-b475-622a6c135aae/dirtyclone-vulnerability
#nttdata #zen #secdb
#infosec #dirtyclone #linux #lpe #cve202643503 -
🚨 DirtyClone (CVE-2026-43503)
In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: propagate shared-frag marker through frag-transfer helpers
ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/updates/9a1828d5-6607-419b-b475-622a6c135aae/dirtyclone-vulnerability
#nttdata #zen #secdb
#infosec #dirtyclone #linux #lpe #cve202643503 -
https://www.europesays.com/ch/93075/ Sabadell-Zurich modernizes applications #agility #ApplicationModernization #AWS #CaseStudy #CostReduction #DigitalApplications #DigitalPlatform #NttData #SabadellZurich #Zürich
-
Scalable GenAI platform for the BMW Group
As the implementation partner, NTT DATA supported the project through all phases – from architecture consulting and implementation…
#Germany #DE #Europe #EU #Europa #BMW #AIadoption #BMWGroup #enterprisegenai #genaiplatform #Governance #NTTDATA #organization-wideai #scalablegenai
https://www.europesays.com/germany/44306/ -
Scalable GenAI platform for the BMW Group
As the implementation partner, NTT DATA supported the project through all phases – from architecture consulting and implementation…
#Germany #DE #Europe #EU #Europa #BMW #AIadoption #BMWGroup #enterprisegenai #genaiplatform #Governance #NTTDATA #organization-wideai #scalablegenai
https://www.europesays.com/germany/43769/ -
Lumileds lights the way with world-class SAP deployment
The Lumileds team reviewed proposals from leading IT solutions providers to undertake Project STAR. When it came to…
#Germany #DE #Europe #EU #Europa #SAP #globaldeployment #lumileds #NTTDATA #Philips #sap #sapdeployment #SAPERP #sapseparation #treasurysystems
https://www.europesays.com/germany/43767/ -
Pathlock Partners with NTT DATA Business Solutions to Deliver Managed SAP Cybersecurity Services Worldwide
Alliance combines Pathlock’s innovative technology with NTT DATA Business Solutions’ managed services expertise to address growing demand for…
#Germany #DE #Europe #EU #Europa #SAP #BusinessSolutions #cybersecurity #managedservices #NTTDATA #Organizations #sap #SAPsecurity #SAPsystems #SecurityOperationsCenter
https://www.europesays.com/germany/40252/ -
Pathlock Partners with NTT DATA Business Solutions to Deliver Managed SAP Cybersecurity Services Worldwide
Alliance combines Pathlock’s innovative technology with NTT DATA Business Solutions’ managed services expertise to address growing demand for…
#Germany #DE #Europe #EU #Europa #SAP #BusinessSolutions #cybersecurity #managedservices #NTTDATA #Organizations #sap #SAPsecurity #SAPsystems #SecurityOperationsCenter
https://www.europesays.com/germany/37602/ -
Japan’s NTT DATA, Google Cloud to jointly scale enterprise AI deployment
Japan’s NTT DATA and Google Cloud will collaborate help enterprises move from AI experimentation to large-scale deployment of…
#EuropeSays #Japan #JP #AI #GoogleCloud #Nihon #NTTDATA
https://www.europesays.com/japan/37619/ -
🚨 CVE-2026-45585 (YellowKey)
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices.
We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available.ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-45585
#nttdata #zen #secdb #infosec
#yellowkey #microsoft #bitlocker #cve202645585 -
🚨 CVE-2026-45585 (YellowKey)
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices.
We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available.ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-45585
#nttdata #zen #secdb #infosec
#yellowkey #microsoft #bitlocker #cve202645585 -
🚨 CVE-2026-45585 (YellowKey)
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coordinated vulnerability best practices.
We are issuing this CVE to provide mitigation guidance that can be implemented to protect against this vulnerability until the security update is made available.ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-45585
#nttdata #zen #secdb #infosec
#yellowkey #microsoft #bitlocker #cve202645585 -
🚨 CVE-2026-31635 (DirtyDecrypt / DirtyCBC)
rxrpc: fix oversized RESPONSE authenticator length check
rxgk_verify_response() decodes auth_len from the packet and is supposed
to verify that it fits in the remaining bytes. The existing check is
inverted, so oversized RESPONSE authenticators are accepted and passed
to rxgk_decrypt_skb(), which can later reach skb_to_sgvec() with an
impossible length and hit BUG_ON(len).ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-31635
#nttdata #zen #secdb #infosec
#dirtydecrypt #dirtycbc #linux #kernel #lpe #cve202631635 -
🚨 CVE-2026-31635 (DirtyDecrypt / DirtyCBC)
rxrpc: fix oversized RESPONSE authenticator length check
rxgk_verify_response() decodes auth_len from the packet and is supposed
to verify that it fits in the remaining bytes. The existing check is
inverted, so oversized RESPONSE authenticators are accepted and passed
to rxgk_decrypt_skb(), which can later reach skb_to_sgvec() with an
impossible length and hit BUG_ON(len).ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-31635
#nttdata #zen #secdb #infosec
#dirtydecrypt #dirtycbc #linux #kernel #lpe # cve202631635 -
🚨 CVE-2026-42945 (NGINX Rift)
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-42945
#nttdata #zen #secdb #infosec
#nginxrift #cve202642945 #nginx -
🚨 CVE-2026-42945 (NGINX Rift)
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, for systems with Address Space Layout Randomization (ASLR ) disabled, code execution is possible. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-42945
#nttdata #zen #secdb #infosec
#nginxrift #cve202642945 #nginx -
🚨 CVE-2026-46333 (ssh-keysign-pwn)
In the Linux kernel, the following vulnerability has been resolved:
ptrace: slightly saner 'get_dumpable()' logic
The 'dumpability' of a task is fundamentally about the memory image of
the task - the concept comes from whether it can core dump or not - and
makes no sense when you don't have an associated mm.And almost all users do in fact use it only for the case where the task
has a mm pointer.But we have one odd special case: ptrace_may_access() uses 'dumpable' to
check various other things entirely independently of the MM (typically
explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for
threads that no longer have a VM (and maybe never did, like most kernel
threads).It's not what this flag was designed for, but it is what it is.
The ptrace code does check that the uid/gid matches, so you do have to
be uid-0 to see kernel thread details, but this means that the
traditional "drop capabilities" model doesn't make any difference for
this all.Make it all make a bit more sense by saying that if you don't have a
MM pointer, we'll use a cached "last dumpability" flag if the thread
ever had a MM (it will be zero for kernel threads since it is never
set), and require a proper CAP_SYS_PTRACE capability to override.ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-46333
#nttdata #zen #secdb #infosec
#sshkeysignpwn #cve202646333 #linux #kernel -
🚨 CVE-2026-46333 (ssh-keysign-pwn)
In the Linux kernel, the following vulnerability has been resolved:
ptrace: slightly saner 'get_dumpable()' logic
The 'dumpability' of a task is fundamentally about the memory image of
the task - the concept comes from whether it can core dump or not - and
makes no sense when you don't have an associated mm.And almost all users do in fact use it only for the case where the task
has a mm pointer.But we have one odd special case: ptrace_may_access() uses 'dumpable' to
check various other things entirely independently of the MM (typically
explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for
threads that no longer have a VM (and maybe never did, like most kernel
threads).It's not what this flag was designed for, but it is what it is.
The ptrace code does check that the uid/gid matches, so you do have to
be uid-0 to see kernel thread details, but this means that the
traditional "drop capabilities" model doesn't make any difference for
this all.Make it all make a bit more sense by saying that if you don't have a
MM pointer, we'll use a cached "last dumpability" flag if the thread
ever had a MM (it will be zero for kernel threads since it is never
set), and require a proper CAP_SYS_PTRACE capability to override.ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-46333
#nttdata #zen #secdb #infosec
#sshkeysignpwn #cve202646333 #linux #kernel -
🚨 CVE-2026-46333 (ssh-keysign-pwn)
In the Linux kernel, the following vulnerability has been resolved:
ptrace: slightly saner 'get_dumpable()' logic
The 'dumpability' of a task is fundamentally about the memory image of
the task - the concept comes from whether it can core dump or not - and
makes no sense when you don't have an associated mm.And almost all users do in fact use it only for the case where the task
has a mm pointer.But we have one odd special case: ptrace_may_access() uses 'dumpable' to
check various other things entirely independently of the MM (typically
explicitly using flags like PTRACE_MODE_READ_FSCREDS). Including for
threads that no longer have a VM (and maybe never did, like most kernel
threads).It's not what this flag was designed for, but it is what it is.
The ptrace code does check that the uid/gid matches, so you do have to
be uid-0 to see kernel thread details, but this means that the
traditional "drop capabilities" model doesn't make any difference for
this all.Make it all make a bit more sense by saying that if you don't have a
MM pointer, we'll use a cached "last dumpability" flag if the thread
ever had a MM (it will be zero for kernel threads since it is never
set), and require a proper CAP_SYS_PTRACE capability to override.ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-46333
#nttdata #zen #secdb #infosec
#sshkeysignpwn #cve202646333 #linux #kernel -
🚨 CVE-2026-45185 (Dead.Letter)
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-45185
#nttdata #zen #secdb #infosec
#deadletter #cve202645185 #exim #gnutls -
🚨 CVE-2026-45185 (Dead.Letter)
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-45185
#nttdata #zen #secdb #infosec
#deadletter #cve202645185 #exim #gnutls -
🚨 CVE-2026-45185 (Dead.Letter)
Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a client sends a TLS close_notify mid-body during a CHUNKING transfer, followed by a final cleartext byte on the same TCP connection. This can lead to heap corruption. An unauthenticated network attacker exploiting this vulnerability could execute arbitrary code.
ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-45185
#nttdata #zen #secdb #infosec
#deadletter #cve202645185 #exim #gnutls -
🚨 CVE-2026-43284 (Dirty Frag)
In the Linux kernel, the following vulnerability has been resolved:
xfrm: esp: avoid in-place decrypt on shared skb frags
MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP
marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),
so later paths that may modify packet data can first make a private
copy. The IPv4/IPv6 datagram append paths did not set this flag when
splicing pages into UDP skbs.That leaves an ESP-in-UDP packet made from shared pipe pages looking
like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW
fast path for uncloned skbs without a frag_list and decrypts in place
over data that is not owned privately by the skb.Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching
TCP. Also make ESP input fall back to skb_cow_data() when the flag is
present, so ESP does not decrypt externally backed frags in place.
Private nonlinear skb frags still use the existing fast path.This intentionally does not change ESP output. In esp_output_head(),
the path that appends the ESP trailer to existing skb tailroom without
calling skb_cow_data() is not reachable for nonlinear skbs:
skb_tailroom() returns zero when skb->data_len is nonzero, while ESP
tailen is positive. Thus ESP output will either use the separate
destination-frag path or fall back to skb_cow_data().ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-43284
#nttdata #zen #secdb #infosec
#dirtyfrag #cve202643284 #linux #kernel -
🚨 CVE-2026-43284 (Dirty Frag)
In the Linux kernel, the following vulnerability has been resolved:
xfrm: esp: avoid in-place decrypt on shared skb frags
MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP
marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),
so later paths that may modify packet data can first make a private
copy. The IPv4/IPv6 datagram append paths did not set this flag when
splicing pages into UDP skbs.That leaves an ESP-in-UDP packet made from shared pipe pages looking
like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW
fast path for uncloned skbs without a frag_list and decrypts in place
over data that is not owned privately by the skb.Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching
TCP. Also make ESP input fall back to skb_cow_data() when the flag is
present, so ESP does not decrypt externally backed frags in place.
Private nonlinear skb frags still use the existing fast path.This intentionally does not change ESP output. In esp_output_head(),
the path that appends the ESP trailer to existing skb tailroom without
calling skb_cow_data() is not reachable for nonlinear skbs:
skb_tailroom() returns zero when skb->data_len is nonzero, while ESP
tailen is positive. Thus ESP output will either use the separate
destination-frag path or fall back to skb_cow_data().ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-43284
#nttdata #zen #secdb #infosec
#dirtyfrag #cve202643284 #linux #kernel -
🚨 CVE-2026-43284 (Dirty Frag)
In the Linux kernel, the following vulnerability has been resolved:
xfrm: esp: avoid in-place decrypt on shared skb frags
MSG_SPLICE_PAGES can attach pages from a pipe directly to an skb. TCP
marks such skbs with SKBFL_SHARED_FRAG after skb_splice_from_iter(),
so later paths that may modify packet data can first make a private
copy. The IPv4/IPv6 datagram append paths did not set this flag when
splicing pages into UDP skbs.That leaves an ESP-in-UDP packet made from shared pipe pages looking
like an ordinary uncloned nonlinear skb. ESP input then takes the no-COW
fast path for uncloned skbs without a frag_list and decrypts in place
over data that is not owned privately by the skb.Mark IPv4/IPv6 datagram splice frags with SKBFL_SHARED_FRAG, matching
TCP. Also make ESP input fall back to skb_cow_data() when the flag is
present, so ESP does not decrypt externally backed frags in place.
Private nonlinear skb frags still use the existing fast path.This intentionally does not change ESP output. In esp_output_head(),
the path that appends the ESP trailer to existing skb tailroom without
calling skb_cow_data() is not reachable for nonlinear skbs:
skb_tailroom() returns zero when skb->data_len is nonzero, while ESP
tailen is positive. Thus ESP output will either use the separate
destination-frag path or fall back to skb_cow_data().ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-43284
#nttdata #zen #secdb #infosec
#dirtyfrag #cve202643284 #linux #kernel -
🚨 CVE-2026-31431 (Copy Fail)
In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the copying of the associated data.
There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-31431
#nttdata #zen #secdb #infosec
#copyfail #cve202631431 #linux #kernel -
🚨 CVE-2026-31431 (Copy Fail)
In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the copying of the associated data.
There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-31431
#nttdata #zen #secdb #infosec
#copyfail #cve202631431 #linux #kernel -
🚨 CVE-2026-41651 (Pack2TheRoot)
PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5.
ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-41651
#nttdata #zen #secdb #infosec
#pack2theroot #cve2026411651 #packagekit #toctou -
🚨 CVE-2026-41651 (Pack2TheRoot)
PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5.
ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-41651
#nttdata #zen #secdb #infosec
#pack2theroot #cve2026411651 #packagekit #toctou -
🚨 CVE-2026-41651 (Pack2TheRoot)
PackageKit vulnerable to TOCTOU Race on Transaction Flags leads to arbitrary package installation as root
PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. This is patched in version 1.3.5.
ℹ️ Additional info on ZEN SecDB https://secdb.nttzen.cloud/cve/detail/CVE-2026-41651
#nttdata #zen #secdb #infosec
#pack2theroot #cve2026411651 #packagekit #toctou -
https://www.europesays.com/ie/447883/ NTT DATA Merchants in Malaysia Can Now Accept Payments with iPhone #Apple #Éire #IE #Ireland #Mobile #NTTDATA #NTTDATAPaymentServices #Technology
-
https://www.europesays.com/uk/910739/ NTT DATA Merchants in Malaysia Can Now Accept Payments with iPhone #Apple #Mobile #NttData #NTTDATAPaymentServices #Technology #UK #UnitedKingdom
-
NTT Global Data Centers, the world's third-largest data center provider outside of China, is working to double its capacity to meet the rising demand for the critical digital infrastructure amid an AI boom. https://www.japantimes.co.jp/business/2026/03/19/companies/ntt-data-centers-double-ai/?utm_medium=Social&utm_source=mastodon #business #companies #nttdata #ai
-
NTT Global Data Centers, the world's third-largest data center provider outside of China, is working to double its capacity to meet the rising demand for the critical digital infrastructure amid an AI boom. https://www.japantimes.co.jp/business/2026/03/19/companies/ntt-data-centers-double-ai/?utm_medium=Social&utm_source=mastodon #business #companies #nttdata #ai
-
NTT Global Data Centers, the world's third-largest data center provider outside of China, is working to double its capacity to meet the rising demand for the critical digital infrastructure amid an AI boom. https://www.japantimes.co.jp/business/2026/03/19/companies/ntt-data-centers-double-ai/?utm_medium=Social&utm_source=mastodon #business #companies #nttdata #ai
-
NTT Global Data Centers, the world's third-largest data center provider outside of China, is working to double its capacity to meet the rising demand for the critical digital infrastructure amid an AI boom. https://www.japantimes.co.jp/business/2026/03/19/companies/ntt-data-centers-double-ai/?utm_medium=Social&utm_source=mastodon #business #companies #nttdata #ai
-
NTT DATA launches GCC Innovation Acceleration Program to help global companies set up innovation hubs in India. The program targets 50+ companies over three years, tapping into India's talent pool. India's GCC ecosystem aims for 110 billion USD by 2030. https://indiatechnologynews.in/ntt-data-launches-gcc-innovation-acceleration-program-to-support-innovation-creation-by-global-companies/ #India #Tech #ITServices #NTTDATA
-
NTT DATA launches GCC Innovation Acceleration Program to help global companies set up innovation hubs in India. The program targets 50+ companies over three years, tapping into India's talent pool. India's GCC ecosystem aims for 110 billion USD by 2030. https://indiatechnologynews.in/ntt-data-launches-gcc-innovation-acceleration-program-to-support-innovation-creation-by-global-companies/ #India #Tech #ITServices #NTTDATA
-
NTT DATA launches GCC Innovation Acceleration Program to help global companies set up innovation hubs in India. The program targets 50+ companies over three years, tapping into India's talent pool. India's GCC ecosystem aims for 110 billion USD by 2030. https://indiatechnologynews.in/ntt-data-launches-gcc-innovation-acceleration-program-to-support-innovation-creation-by-global-companies/ #India #Tech #ITServices #NTTDATA
-
https://winbuzzer.com/2026/03/02/nvidia-open-30b-telco-ai-model-autonomous-networks-xcxwbn/
NVIDIA Opens 30B Telco AI Model for Autonomous Networks
#AI #NVIDIA #AgenticAI #AIAgents #OpenSourceAI #AIInfrastructure #EnterpriseAI #Nemotron #Telecom #NTTDATA #GSMA #CassavaTechnologies #TelenorGroup #AdaptkeyAI #AutonomousNetworks #AIModels
-
https://winbuzzer.com/2026/03/02/nvidia-open-30b-telco-ai-model-autonomous-networks-xcxwbn/
NVIDIA Opens 30B Telco AI Model for Autonomous Networks
#AI #NVIDIA #AgenticAI #AIAgents #OpenSourceAI #AIInfrastructure #EnterpriseAI #Nemotron #Telecom #NTTDATA #GSMA #CassavaTechnologies #TelenorGroup #AdaptkeyAI #AutonomousNetworks #AIModels