#securityvulnerability — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #securityvulnerability, aggregated by home.social.
-
🚨BREAKING: Ruby 4.0 can now turn your innocent code into a ticking time bomb of chaos with just one magic call to Marshal.load! 🤯 Because clearly, what we all needed was another universal #RCE #deserialization gadget chain to add some spice to our daily developer anxiety. 🎉 #InnovationAtItsFinest
https://www.elttam.com/blog/ruby-4-0-universal-rce-deserialization-gadget-chain #Ruby4 #developeranxiety #securityvulnerability #HackerNews #ngated -
A legacy SQL injection almost reached production until an internal security competition gave a developer permission to test beyond the release scope. https://hackernoon.com/the-security-bug-that-almost-shipped #securityvulnerability
-
The Security Interest Group has published the first draft of a Group Note titled W3C Standards Vulnerability Disclosure & Handling Process and Policy. This document defines how to report suspected security vulnerabilities in W3C standards and specifications (technical reports), so that issues can be triaged, confirmed, and resolved through the appropriate W3C processes.
https://www.w3.org/news/2026/group-note-draft-w3c-standards-vulnerability-disclosure-handling-process-and-policy/
#WebStandards #SecurityVulnerability -
#Notepad++ 8.9.6.2 has been released ( #NotepadPlusPlus / #TextEditor / #FileEditor / #SourceCodeEditor / #Scintilla / #CVE / #SecurityVulnerability ) https://notepad-plus-plus.org/
-
#Exim 4.99.4 has been released ( #SMTP / #SimpleMailTransferProtocol / #Mail / #MailServer / #MTA / #MailTransportAgent / #MessageTransferAgent / #CVE / #SecurityVulnerability ) https://exim.org/
-
#nginx 1.31.1 (dev) has been released ( #http / #http2 / #http3 / #httpd / #Web / #Webserver / #TLS / #TLS13 / #CVE / #SecurityVulnerability ) https://nginx.org/
-
#nginx 1.30.2 has been released ( #http / #http2 / #http3 / #httpd / #Web / #Webserver / #TLS / #TLS13 / #CVE / #SecurityVulnerability ) https://nginx.org/
-
#Unbound 1.25.1 has been released ( #DNS / #DNSOverTLS / #DNSOverHTTPS / #DNSSEC / #NLnetLabs / #CVE / #SecurityVulnerability ) https://unbound.net/
-
#Roundcube 1.6.16 ( #LTS ) has been released ( #Webmail / #Mail / #IMAP / #SMTP / #LDAP / #Managesieve / #PHP / #MariaDB / #MySQL / #PostgreSQL / #SQLite / #OracleDB / #MSSQL / #LongTermSupport / #CVE / #SecurityVulnerability ) https://roundcube.net/
-
#Roundcube 1.7.1 (stable) has been released ( #Webmail / #Mail / #IMAP / #SMTP / #LDAP / #Managesieve / #PHP / #MariaDB / #MySQL / #PostgreSQL / #SQLite / #OracleDB / #MSSQL / #CVE / #SecurityVulnerability ) https://roundcube.net/
-
Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root
https://fed.brid.gy/r/https://nerds.xyz/2026/04/copy-fail-linux-root-exploit/
-
via @dotnet : .NET 10.0.7 Out-of-Band Security Update
https://ift.tt/M4BdDGe
#dotnet #dotnet10 #dotnetcore #AspNetCore #DataProtection #SecurityUpdate #OutOfBand #OOB #CVE202640372 #SecurityVulnerability #Decryption #HMAC #Encryption #ReleaseNotes #Downloads #SD… -
“ClawJacked” Vulnerability Allows Malicious Websites to Take Control of OpenClaw
-
Notepad++’s New Update System is “Robust and Effectively Unexploitable”
-
[en] Serious security vulnerabilities in cloud-based password managers : #Bitwarden, #Lastpass, #Dashlane
The research team of Prof. Paterson found cryptographic technologies from the 90s. "We were surprised by the severity of the security vulnerabilities".
In most cases, the researchers were able to gain access to the passwords – and even make changes to them.
Aside from this research paper, recommended password managers often include #KeePassXC and/or #KeePassDX for Android or #KeePassium for iOS. Also, it's usually a good idea to store only accounts and passwords that are really necessary on the go, especially on mobile devices.
#password #passwordmanager #cloudbased #security #ictsecurity #securityvulnerability #ethz
-
Bluetooth Exploit Leaves Hundreds of Millions of Accessories Vulnerable to Full Takeover
-
Trail of Bits Exposes Vulnerabilities in Agentic Browsers, Compares to Cross-Site Scripting
-
Smart toilet camera misleads customers on end-to-end-encryption
-
#nginx 1.29.1 (dev) has been released (#http / #http2 / #http3 / #httpd / #Web / #Webserver / #TLS / #TLS13 / #CVE / #SecurityVulnerability) https://nginx.org/
-
#ApacheHTTPd 2.4.65 has been released (#Web / #Webserver / #http2 / #httpd / #Apache / #HTTPServer / #TLS13 / #ApacheSoftwareFoundation / #ASF / #CVE / #SecurityVulnerability) https://httpd.apache.org/
-
#ApacheHTTPd 2.4.64 has been released (#Web / #Webserver / #http2 / #httpd / #Apache / #HTTPServer / #TLS13 / #ApacheSoftwareFoundation / #ASF / #CVE / #SecurityVulnerability) https://httpd.apache.org/
-
@oliweb ah bah voilà pourquoi je n'ai jamais fait confiance ni à #Google #GAFAM ni au mots de passe d'application
#Gmail #FailleSécurité #faille_sécurité #faille_de_sécurité #SecurityBreach #SecurityVulnerability
-
🚨Critical security vulnerability (CVSS 10.0) discovered in Pterodactyl Panel! Attackers can execute code without authentication. Game server admins must update to v1.11.11 immediately to prevent compromise.
#SecurityLand #CyberWatch #Cybersecurity #GameServers #Pterodactyl #SecurityVulnerability #CVSS
-
Zero-Click Flaw in Microsoft Copilot Illustrates AI Agent, RAG Risks – Source: securityboulevard.com https://ciso2ciso.com/zero-click-flaw-in-microsoft-copilot-illustrates-ai-agent-rag-risks-source-securityboulevard-com/ #SecurityBoulevard(Original) #rssfeedpostgeneratorecho #securityvulnerability #ThreatIntelligence #CyberSecurityNews #SecurityAwareness #SecurityBoulevard #microsoftcopilot #AIagentsecurity #Identity&Access #NetworkSecurity #vulnerabilities #MobileSecurity #SocialFacebook #RAGAI
-
Critical security flaws discovered in VMware core products including vCenter Server and ESXi. Vulnerabilities could allow command execution and service disruption. Updates available now to protect your infrastructure.
#SecurityLand #CyberWatch #Broadcom #VMware #Vulnerability #PatchNow #SecurityVulnerability #Technology
-
ETH Zurich researchers discover new security vulnerability in Intel processors
#HackerNews #ETHZurich #IntelProcessors #SecurityVulnerability #Cybersecurity #ResearchNews #TechNews