#securityvulnerability — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #securityvulnerability, aggregated by home.social.
-
🚨BREAKING: Ruby 4.0 can now turn your innocent code into a ticking time bomb of chaos with just one magic call to Marshal.load! 🤯 Because clearly, what we all needed was another universal #RCE #deserialization gadget chain to add some spice to our daily developer anxiety. 🎉 #InnovationAtItsFinest
https://www.elttam.com/blog/ruby-4-0-universal-rce-deserialization-gadget-chain #Ruby4 #developeranxiety #securityvulnerability #HackerNews #ngated -
🚨BREAKING: Ruby 4.0 can now turn your innocent code into a ticking time bomb of chaos with just one magic call to Marshal.load! 🤯 Because clearly, what we all needed was another universal #RCE #deserialization gadget chain to add some spice to our daily developer anxiety. 🎉 #InnovationAtItsFinest
https://www.elttam.com/blog/ruby-4-0-universal-rce-deserialization-gadget-chain #Ruby4 #developeranxiety #securityvulnerability #HackerNews #ngated -
A legacy SQL injection almost reached production until an internal security competition gave a developer permission to test beyond the release scope. https://hackernoon.com/the-security-bug-that-almost-shipped #securityvulnerability
-
A legacy SQL injection almost reached production until an internal security competition gave a developer permission to test beyond the release scope. https://hackernoon.com/the-security-bug-that-almost-shipped #securityvulnerability
-
The Security Interest Group has published the first draft of a Group Note titled W3C Standards Vulnerability Disclosure & Handling Process and Policy. This document defines how to report suspected security vulnerabilities in W3C standards and specifications (technical reports), so that issues can be triaged, confirmed, and resolved through the appropriate W3C processes.
https://www.w3.org/news/2026/group-note-draft-w3c-standards-vulnerability-disclosure-handling-process-and-policy/
#WebStandards #SecurityVulnerability -
The Security Interest Group has published the first draft of a Group Note titled W3C Standards Vulnerability Disclosure & Handling Process and Policy. This document defines how to report suspected security vulnerabilities in W3C standards and specifications (technical reports), so that issues can be triaged, confirmed, and resolved through the appropriate W3C processes.
https://www.w3.org/news/2026/group-note-draft-w3c-standards-vulnerability-disclosure-handling-process-and-policy/
#WebStandards #SecurityVulnerability -
#Notepad++ 8.9.6.2 has been released ( #NotepadPlusPlus / #TextEditor / #FileEditor / #SourceCodeEditor / #Scintilla / #CVE / #SecurityVulnerability ) https://notepad-plus-plus.org/
-
#Notepad++ 8.9.6.2 has been released ( #NotepadPlusPlus / #TextEditor / #FileEditor / #SourceCodeEditor / #Scintilla / #CVE / #SecurityVulnerability ) https://notepad-plus-plus.org/
-
#Exim 4.99.4 has been released ( #SMTP / #SimpleMailTransferProtocol / #Mail / #MailServer / #MTA / #MailTransportAgent / #MessageTransferAgent / #CVE / #SecurityVulnerability ) https://exim.org/
-
#Exim 4.99.4 has been released ( #SMTP / #SimpleMailTransferProtocol / #Mail / #MailServer / #MTA / #MailTransportAgent / #MessageTransferAgent / #CVE / #SecurityVulnerability ) https://exim.org/
-
#nginx 1.31.1 (dev) has been released ( #http / #http2 / #http3 / #httpd / #Web / #Webserver / #TLS / #TLS13 / #CVE / #SecurityVulnerability ) https://nginx.org/
-
#nginx 1.31.1 (dev) has been released ( #http / #http2 / #http3 / #httpd / #Web / #Webserver / #TLS / #TLS13 / #CVE / #SecurityVulnerability ) https://nginx.org/
-
#nginx 1.30.2 has been released ( #http / #http2 / #http3 / #httpd / #Web / #Webserver / #TLS / #TLS13 / #CVE / #SecurityVulnerability ) https://nginx.org/
-
#nginx 1.30.2 has been released ( #http / #http2 / #http3 / #httpd / #Web / #Webserver / #TLS / #TLS13 / #CVE / #SecurityVulnerability ) https://nginx.org/
-
#Unbound 1.25.1 has been released ( #DNS / #DNSOverTLS / #DNSOverHTTPS / #DNSSEC / #NLnetLabs / #CVE / #SecurityVulnerability ) https://unbound.net/
-
#Unbound 1.25.1 has been released ( #DNS / #DNSOverTLS / #DNSOverHTTPS / #DNSSEC / #NLnetLabs / #CVE / #SecurityVulnerability ) https://unbound.net/
-
#Roundcube 1.6.16 ( #LTS ) has been released ( #Webmail / #Mail / #IMAP / #SMTP / #LDAP / #Managesieve / #PHP / #MariaDB / #MySQL / #PostgreSQL / #SQLite / #OracleDB / #MSSQL / #LongTermSupport / #CVE / #SecurityVulnerability ) https://roundcube.net/
-
#Roundcube 1.6.16 ( #LTS ) has been released ( #Webmail / #Mail / #IMAP / #SMTP / #LDAP / #Managesieve / #PHP / #MariaDB / #MySQL / #PostgreSQL / #SQLite / #OracleDB / #MSSQL / #LongTermSupport / #CVE / #SecurityVulnerability ) https://roundcube.net/
-
#Roundcube 1.7.1 (stable) has been released ( #Webmail / #Mail / #IMAP / #SMTP / #LDAP / #Managesieve / #PHP / #MariaDB / #MySQL / #PostgreSQL / #SQLite / #OracleDB / #MSSQL / #CVE / #SecurityVulnerability ) https://roundcube.net/
-
#Roundcube 1.7.1 (stable) has been released ( #Webmail / #Mail / #IMAP / #SMTP / #LDAP / #Managesieve / #PHP / #MariaDB / #MySQL / #PostgreSQL / #SQLite / #OracleDB / #MSSQL / #CVE / #SecurityVulnerability ) https://roundcube.net/
-
Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root
https://fed.brid.gy/r/https://nerds.xyz/2026/04/copy-fail-linux-root-exploit/
-
via @dotnet : .NET 10.0.7 Out-of-Band Security Update
https://ift.tt/M4BdDGe
#dotnet #dotnet10 #dotnetcore #AspNetCore #DataProtection #SecurityUpdate #OutOfBand #OOB #CVE202640372 #SecurityVulnerability #Decryption #HMAC #Encryption #ReleaseNotes #Downloads #SD… -
via @dotnet : .NET 10.0.7 Out-of-Band Security Update
https://ift.tt/M4BdDGe
#dotnet #dotnet10 #dotnetcore #AspNetCore #DataProtection #SecurityUpdate #OutOfBand #OOB #CVE202640372 #SecurityVulnerability #Decryption #HMAC #Encryption #ReleaseNotes #Downloads #SD… -
The OpenClaw autonomous AI agent has achieved explosive growth, but its rapid rise has triggered a major security crisis. China's MIIT and CNCERT have issued urgent warnings following the discovery of over 40,000 exposed instances of the software online. The highest density of these exposed instances was located in China, followed by the US and Singapore.
Read More: https://www.security.land/china-openclaw-ai-security-alert-cve-2025-11251/
#SecurityLand #GeoSphere #China #OpenClaw #AI #SecurityVulnerability #CVE
-
“ClawJacked” Vulnerability Allows Malicious Websites to Take Control of OpenClaw
-
“ClawJacked” Vulnerability Allows Malicious Websites to Take Control of OpenClaw
-
Notepad++’s New Update System is “Robust and Effectively Unexploitable”
-
Notepad++’s New Update System is “Robust and Effectively Unexploitable”
-
[en] Serious security vulnerabilities in cloud-based password managers : #Bitwarden, #Lastpass, #Dashlane
The research team of Prof. Paterson found cryptographic technologies from the 90s. "We were surprised by the severity of the security vulnerabilities".
In most cases, the researchers were able to gain access to the passwords – and even make changes to them.
Aside from this research paper, recommended password managers often include #KeePassXC and/or #KeePassDX for Android or #KeePassium for iOS. Also, it's usually a good idea to store only accounts and passwords that are really necessary on the go, especially on mobile devices.
#password #passwordmanager #cloudbased #security #ictsecurity #securityvulnerability #ethz
-
Bluetooth Exploit Leaves Hundreds of Millions of Accessories Vulnerable to Full Takeover
-
Bluetooth Exploit Leaves Hundreds of Millions of Accessories Vulnerable to Full Takeover
-
Trail of Bits Exposes Vulnerabilities in Agentic Browsers, Compares to Cross-Site Scripting
-
Trail of Bits Exposes Vulnerabilities in Agentic Browsers, Compares to Cross-Site Scripting
-
2025 cyber recap: React2Shell hit CVSS 10.0, the first AI attack emerged, but only 23% paid ransoms. Law enforcement seized $320M across 20 operations. 2025 pushed cybersecurity to its limits. Our analysis covers top data breaches, critical vulnerabilities, and what 2026 demands.
Read More: https://www.security.land/2025-cybersecurity-year-in-review/
#SecurityLand #News #YearInReview #Cybersecurity #InfoSec #ThreatIntelligence #Ransomware #AI #DataBreach #CyberDefense #CISO #SecurityVulnerability #LawEnforcement #LEA #Government
-
Analysis of CVE-2025-14733, a critical WatchGuard Firebox security vulnerability. Learn why unauthenticated RCE persists even after deleting vulnerable VPN configurations.
#SecurityLand #CyberWatch #ZeroDay #Watchguard #SecurityVulnerability #Firewall #CVE
Read More: https://www.security.land/watchguard-cve-2025-14733-critical-vulnerability-analysis/
-
Ivanti Endpoint Manager faces four security vulnerabilities, including a critical 9.6 CVSS flaw. Updates now available for EPM users.
#SecurityLand #CyberWatch #SecurityVulnerability #Ivanti #EPM #CVSS #CVE #XSS
Read More: https://www.security.land/critical-flaws-ivanti-epm-endpoint-management/
-
Smart toilet camera misleads customers on end-to-end-encryption
-
Smart toilet camera misleads customers on end-to-end-encryption
-
Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 25-03 after threat actors exploited Cisco ASA zero-days, including RCE and privilege escalation flaws. The agency praised quick reporting and mandates urgent patching — once again showing U.S. cyber defense leadership in transparency and rapid response.
#SecurityLand #CyberWatch #CISA #Cisco #ZeroDay #RCE #PrivilegeEscalation #SecurityVulnerability
Read More: https://www.security.land/cisa-orders-agencies-to-mitigate-cisco-asa-zero-day-exploitation/
-
A critical RCE vulnerability in Control Web Panel (CVE-2025-48703) allows remote command execution. Patch to version 0.9.8.1205 immediately.
#SecurityLand #CyberWatch #SecurityVulnerability #RCE #CVE #CWP #ControlWebPanel
Read More: https://www.security.land/critical-rce-vulnerability-found-in-control-web-panel/
-
Cisco has disclosed 13 IOS and IOS XE vulnerabilities, including CVE-2025-20352, which is already being exploited. Immediate updates are strongly advised.
#SecurityLand #CyberWatch #Cisco #SecurityVulnerability #CVE #PatchNow
Read More: https://www.security.land/cisco-releases-security-advisories-for-ios-and-ios-xe-vulnerabilities/
-
Imagine opening a project and realizing hidden code was executed without your consent. A simple setting in Cursor AI Editor is letting developers become unwitting hosts for malicious code. How safe is your workspace?
https://thedefendopsdiaries.com/understanding-the-security-risks-in-cursor-ai-editor/
#cursorai
#securityvulnerability
#autorunrisk
#cybersecurity
#infosec -
Plex users, listen up! A critical flaw in versions 1.41.7.x to 1.42.0.x could put your media at risk. Plex just emailed a must-do update. Are you securing your library?
#plexmediaserver
#securityvulnerability
#cybersecurity
#softwareupdate
#dataprotection -
#nginx 1.29.1 (dev) has been released (#http / #http2 / #http3 / #httpd / #Web / #Webserver / #TLS / #TLS13 / #CVE / #SecurityVulnerability) https://nginx.org/
-
#ApacheHTTPd 2.4.65 has been released (#Web / #Webserver / #http2 / #httpd / #Apache / #HTTPServer / #TLS13 / #ApacheSoftwareFoundation / #ASF / #CVE / #SecurityVulnerability) https://httpd.apache.org/
-
#ApacheHTTPd 2.4.64 has been released (#Web / #Webserver / #http2 / #httpd / #Apache / #HTTPServer / #TLS13 / #ApacheSoftwareFoundation / #ASF / #CVE / #SecurityVulnerability) https://httpd.apache.org/
-
@oliweb ah bah voilà pourquoi je n'ai jamais fait confiance ni à #Google #GAFAM ni au mots de passe d'application
#Gmail #FailleSécurité #faille_sécurité #faille_de_sécurité #SecurityBreach #SecurityVulnerability
-
🚨Critical security vulnerability (CVSS 10.0) discovered in Pterodactyl Panel! Attackers can execute code without authentication. Game server admins must update to v1.11.11 immediately to prevent compromise.
#SecurityLand #CyberWatch #Cybersecurity #GameServers #Pterodactyl #SecurityVulnerability #CVSS
-
Zero-Click Flaw in Microsoft Copilot Illustrates AI Agent, RAG Risks – Source: securityboulevard.com https://ciso2ciso.com/zero-click-flaw-in-microsoft-copilot-illustrates-ai-agent-rag-risks-source-securityboulevard-com/ #SecurityBoulevard(Original) #rssfeedpostgeneratorecho #securityvulnerability #ThreatIntelligence #CyberSecurityNews #SecurityAwareness #SecurityBoulevard #microsoftcopilot #AIagentsecurity #Identity&Access #NetworkSecurity #vulnerabilities #MobileSecurity #SocialFacebook #RAGAI
-
Critical security flaws discovered in VMware core products including vCenter Server and ESXi. Vulnerabilities could allow command execution and service disruption. Updates available now to protect your infrastructure.
#SecurityLand #CyberWatch #Broadcom #VMware #Vulnerability #PatchNow #SecurityVulnerability #Technology
-
ETH Zurich researchers discover new security vulnerability in Intel processors
#HackerNews #ETHZurich #IntelProcessors #SecurityVulnerability #Cybersecurity #ResearchNews #TechNews