home.social

#securityvulnerability — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #securityvulnerability, aggregated by home.social.

fetched live
  1. 🚨BREAKING: Ruby 4.0 can now turn your innocent code into a ticking time bomb of chaos with just one magic call to Marshal.load! 🤯 Because clearly, what we all needed was another universal #RCE #deserialization gadget chain to add some spice to our daily developer anxiety. 🎉 #InnovationAtItsFinest
    elttam.com/blog/ruby-4-0-unive #Ruby4 #developeranxiety #securityvulnerability #HackerNews #ngated

  2. 🚨BREAKING: Ruby 4.0 can now turn your innocent code into a ticking time bomb of chaos with just one magic call to Marshal.load! 🤯 Because clearly, what we all needed was another universal #RCE #deserialization gadget chain to add some spice to our daily developer anxiety. 🎉 #InnovationAtItsFinest
    elttam.com/blog/ruby-4-0-unive #Ruby4 #developeranxiety #securityvulnerability #HackerNews #ngated

  3. A legacy SQL injection almost reached production until an internal security competition gave a developer permission to test beyond the release scope. hackernoon.com/the-security-bu #securityvulnerability

  4. A legacy SQL injection almost reached production until an internal security competition gave a developer permission to test beyond the release scope. hackernoon.com/the-security-bu #securityvulnerability

  5. The Security Interest Group has published the first draft of a Group Note titled W3C Standards Vulnerability Disclosure & Handling Process and Policy. This document defines how to report suspected security vulnerabilities in W3C standards and specifications (technical reports), so that issues can be triaged, confirmed, and resolved through the appropriate W3C processes.
    w3.org/news/2026/group-note-dr
    #WebStandards #SecurityVulnerability

  6. The Security Interest Group has published the first draft of a Group Note titled W3C Standards Vulnerability Disclosure & Handling Process and Policy. This document defines how to report suspected security vulnerabilities in W3C standards and specifications (technical reports), so that issues can be triaged, confirmed, and resolved through the appropriate W3C processes.
    w3.org/news/2026/group-note-dr
    #WebStandards #SecurityVulnerability

  7. The OpenClaw autonomous AI agent has achieved explosive growth, but its rapid rise has triggered a major security crisis. China's MIIT and CNCERT have issued urgent warnings following the discovery of over 40,000 exposed instances of the software online. The highest density of these exposed instances was located in China, followed by the US and Singapore.

    Read More: security.land/china-openclaw-a

    #SecurityLand #GeoSphere #China #OpenClaw #AI #SecurityVulnerability #CVE

  8. [en] Serious security vulnerabilities in cloud-based password managers : #Bitwarden, #Lastpass, #Dashlane

    The research team of Prof. Paterson found cryptographic technologies from the 90s. "We were surprised by the severity of the security vulnerabilities".

    In most cases, the researchers were able to gain access to the passwords – and even make changes to them.

    ethz.ch/en/news-and-events/eth

    Aside from this research paper, recommended password managers often include #KeePassXC and/or #KeePassDX for Android or #KeePassium for iOS. Also, it's usually a good idea to store only accounts and passwords that are really necessary on the go, especially on mobile devices.

    #password #passwordmanager #cloudbased #security #ictsecurity #securityvulnerability #ethz

  9. 2025 cyber recap: React2Shell hit CVSS 10.0, the first AI attack emerged, but only 23% paid ransoms. Law enforcement seized $320M across 20 operations. 2025 pushed cybersecurity to its limits. Our analysis covers top data breaches, critical vulnerabilities, and what 2026 demands.

    Read More: security.land/2025-cybersecuri

    #SecurityLand #News #YearInReview #Cybersecurity #InfoSec #ThreatIntelligence #Ransomware #AI #DataBreach #CyberDefense #CISO #SecurityVulnerability #LawEnforcement #LEA #Government

  10. Analysis of CVE-2025-14733, a critical WatchGuard Firebox security vulnerability. Learn why unauthenticated RCE persists even after deleting vulnerable VPN configurations.

    #SecurityLand #CyberWatch #ZeroDay #Watchguard #SecurityVulnerability #Firewall #CVE

    Read More: security.land/watchguard-cve-2

  11. Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 25-03 after threat actors exploited Cisco ASA zero-days, including RCE and privilege escalation flaws. The agency praised quick reporting and mandates urgent patching — once again showing U.S. cyber defense leadership in transparency and rapid response.

    #SecurityLand #CyberWatch #CISA #Cisco #ZeroDay #RCE #PrivilegeEscalation #SecurityVulnerability

    Read More: security.land/cisa-orders-agen

  12. Imagine opening a project and realizing hidden code was executed without your consent. A simple setting in Cursor AI Editor is letting developers become unwitting hosts for malicious code. How safe is your workspace?

    thedefendopsdiaries.com/unders

    #cursorai
    #securityvulnerability
    #autorunrisk
    #cybersecurity
    #infosec

  13. 🚨Critical security vulnerability (CVSS 10.0) discovered in Pterodactyl Panel! Attackers can execute code without authentication. Game server admins must update to v1.11.11 immediately to prevent compromise.

    #SecurityLand #CyberWatch #Cybersecurity #GameServers #Pterodactyl #SecurityVulnerability #CVSS

    security.land/critical-securit

  14. Critical security flaws discovered in VMware core products including vCenter Server and ESXi. Vulnerabilities could allow command execution and service disruption. Updates available now to protect your infrastructure.

    #SecurityLand #CyberWatch #Broadcom #VMware #Vulnerability #PatchNow #SecurityVulnerability #Technology

    Read More: security.land/multiple-securit