home.social

#securityvulnerability — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securityvulnerability, aggregated by home.social.

fetched live
  1. 🚨BREAKING: Ruby 4.0 can now turn your innocent code into a ticking time bomb of chaos with just one magic call to Marshal.load! 🤯 Because clearly, what we all needed was another universal #RCE #deserialization gadget chain to add some spice to our daily developer anxiety. 🎉 #InnovationAtItsFinest
    elttam.com/blog/ruby-4-0-unive #Ruby4 #developeranxiety #securityvulnerability #HackerNews #ngated

  2. A legacy SQL injection almost reached production until an internal security competition gave a developer permission to test beyond the release scope. hackernoon.com/the-security-bu #securityvulnerability

  3. The Security Interest Group has published the first draft of a Group Note titled W3C Standards Vulnerability Disclosure & Handling Process and Policy. This document defines how to report suspected security vulnerabilities in W3C standards and specifications (technical reports), so that issues can be triaged, confirmed, and resolved through the appropriate W3C processes.
    w3.org/news/2026/group-note-dr
    #WebStandards #SecurityVulnerability

  4. [en] Serious security vulnerabilities in cloud-based password managers : #Bitwarden, #Lastpass, #Dashlane

    The research team of Prof. Paterson found cryptographic technologies from the 90s. "We were surprised by the severity of the security vulnerabilities".

    In most cases, the researchers were able to gain access to the passwords – and even make changes to them.

    ethz.ch/en/news-and-events/eth

    Aside from this research paper, recommended password managers often include #KeePassXC and/or #KeePassDX for Android or #KeePassium for iOS. Also, it's usually a good idea to store only accounts and passwords that are really necessary on the go, especially on mobile devices.

    #password #passwordmanager #cloudbased #security #ictsecurity #securityvulnerability #ethz

  5. 🚨Critical security vulnerability (CVSS 10.0) discovered in Pterodactyl Panel! Attackers can execute code without authentication. Game server admins must update to v1.11.11 immediately to prevent compromise.

    #SecurityLand #CyberWatch #Cybersecurity #GameServers #Pterodactyl #SecurityVulnerability #CVSS

    security.land/critical-securit

  6. Critical security flaws discovered in VMware core products including vCenter Server and ESXi. Vulnerabilities could allow command execution and service disruption. Updates available now to protect your infrastructure.

    #SecurityLand #CyberWatch #Broadcom #VMware #Vulnerability #PatchNow #SecurityVulnerability #Technology

    Read More: security.land/multiple-securit