home.social

#securityvulnerabilities — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securityvulnerabilities, aggregated by home.social.

  1. Two recent #Linux kernel vulnerabilities have been disclosed:
    ➡️ Copy Fail (CVE-2026-31431)
    ➡️ Dirty Frag (CVE-2026-43284 & CVE-2026-43500)

    Both vulnerabilities exploit flaws in the page cache via different subsystems, necessitating immediate patching by affected organizations.

    More details on #InfoQ ➡️ bit.ly/4dHOx47

    #DevOps #SecurityVulnerabilities

  2. An attacker purchased the entire Essential Plugin portfolio - 30+ WordPress plugins with ~400k installs - on Flippa.

    ➡️ First code commit introduced a PHP deserialization backdoor
    ➡️ Dormant for 8 months
    ➡️ Activated in April 2026, injecting cloaked SEO spam across thousands of sites.
    ➡️ WordPress shut down all 31 plugins in a single day

    Find out more: bit.ly/4u9pJb9

    #InfoQ #SoftwareDevelopment #SecurityVulnerabilities

  3. Log4Shell - Spring4Shell - The XZ Backdoor

    These aren't just headlines - they are wake-up calls! As the software ecosystem grows more complex, the question remains: Are we ready for the next #CyberSecurity crisis?

    In this #InfoQ video, Soroosh Khodami shares practical strategies to secure your development lifecycle, whether you're a lean startup or a global enterprise.

    🎬 Watch now: bit.ly/4cq4DxN

    📄 #transcript included

    #SoftwareSecurity #SecurityVulnerabilities

  4. Log4Shell - Spring4Shell - The XZ Backdoor

    These aren't just headlines - they are wake-up calls! As the software ecosystem grows more complex, the question remains: Are we ready for the next #CyberSecurity crisis?

    In this #InfoQ video, Soroosh Khodami shares practical strategies to secure your development lifecycle, whether you're a lean startup or a global enterprise.

    🎬 Watch now: bit.ly/4cq4DxN

    📄 #transcript included

    #SoftwareSecurity #SecurityVulnerabilities

  5. Docker launches #DockerHardenedImages (DHI) – a security-focused set of base images designed to cut vulnerabilities by up to 95%.

    Using a #distroless approach, DHI removes unnecessary components, supports automatic patching, and remains compatible with existing Dockerfiles.

    🔎 More on #InfoQ: bit.ly/4nfy3TB

    #DevOps #SecurityVulnerabilities #Docker

  6. Went on @trtworld over the weekend to provide live commentary on the Crowdstrike global IT outage on the Newshour programme and explain why it isn't an easy fix, as well as why we really should be looking at Microsoft to make changes in order to avoid this happening again. Thanks for the chat Maria Ramos!

    Here's a clip from the segment, you can watch the full video here 📹:
    youtube.com/watch?v=NNDg52RPhM

    #Crowdstrike #Crowdstrikeoutage #Microsoft #IToutage #bigtech #kernel #cybersecurity #securityvulnerabilities #technologynews