24h | 7d | 30d

Overview

  • Google
  • Android

01 Jun 2026
Published
03 Jun 2026
Updated

CVSS
Pending
EPSS
0.40%

Description

In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

Statistics

  • 10 Posts
  • 2 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

Android-Sicherheitsupdates Juni 2026: Kritische Schwachstellen adressiert
Google hat im Juni 2026 Sicherheitspatches für Android veröffentlicht, die 124 Schwachstellen schließen, darunter die aktiv ausgebeutete Lücke CVE-2025-48595 in der Android-Framework-Komponente. Betroffen sind Geräte mit Android 14 oder höher, wobei 18 weitere kritische Vulnerabilitäten ebenfalls behoben wurden.

source.android.com/docs/securi

#AndroidPatchDay #infosec #Android #up2date

  • 1
  • 0
  • 0
  • 21h ago
Profile picture fallback

Aggiornamenti Android giugno 2026: corretta una zero-day già sfruttata in attacchi mirati


@informatica
Google rilascia il bollettino di sicurezza Android per il mese di giugno 2026 con patch per 124 vulnerabilità, tra cui la zero-day CVE-2025-48595 già attivamente sfruttata. Ecco l'analisi tecnica e le contromisure per aziende e

  • 1
  • 0
  • 0
  • 1h ago
Profile picture fallback

Google June 2026 Android Update Patches 124 Flaws, One Actively Exploited

**Critical Alert:** A severe vulnerability (CVE-2025-48595) has been identified and requires immediate attention from security teams worldwide.

## The Details

securitycyber.uk

Resources: securitycyber.uk | hackthebox.com

  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback

PLEASE PATCH YOUR ANDROID DEVICES WITH JUNE’S PATCHES!

June 2026 Android security update fixes 124 vulnerabilities, headlined by a major zero-day flaw tracked as CVE-2025-48595. This zero-day allows attackers to gain unauthorized code execution capabilities on the underlying operating system.

bleepingcomputer.com/news/secu

  • 0
  • 0
  • 0
  • 17h ago

Bluesky

Profile picture fallback
Google patched 124 Android flaws, including zero-day CVE-2025-48595, a privilege escalation bug in Android Framework linked to limited targeted attacks. #Android #ZeroDay #CVE2025
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
June 2026 Android patches address 124 vulnerabilities, including CVE-2025-48595, a high-severity Framework privilege-escalation flaw under limited targeted exploitation.
  • 0
  • 0
  • 1
  • 20h ago
Profile picture fallback
Google has patched a critical Android flaw under active exploitation, identified as CVE-2025-48595. The vulnerability allows local privilege escalation without […]
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
~Cisa~ CISA added CVE-2022-0492 (Linux) and CVE-2025-48595 (Android) to the KEV catalog. - IOCs: CVE-2022-0492, CVE-2025-48595 - #CISA #KEV #threatintel
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
CISAが既知の悪用された脆弱性2件をカタログに追加 CISA Adds Two Known Exploited Vulnerabilities to Catalog #CISA (Jun 2) CVE-2022-0492 Linuxカーネルの不適切な認証の脆弱性 CVE-2025-48595 Androidフレームワークの整数オーバーフローの脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Oracle Corporation
  • WebLogic Server

16 Jul 2024
Published
02 Jun 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
89.65%

Description

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Statistics

  • 8 Posts
  • 14 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

CISA Adds Oracle WebLogic CVE-2024-21182 to KEV Catalog as Active Exploitation Confirmed — Patch by June 4
#CyberSecurity
securebulletin.com/cisa-adds-o

  • 5
  • 0
  • 0
  • 8h ago
Profile picture fallback

Una amenaza oculta en HTTP/2 revela vulnerabilidades críticas después de 14 años, mientras una orden ejecutiva impulsa la innovación segura en IA; Visual Studio Code expone tokens de GitHub, hackers rusos explotan WinRAR, y ransomware con IA evade defensas avanzadas, todo en un contexto donde Oracle WebLogic requiere parche urgente y Microsoft Exchange enfrenta fallos técnicos. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 03/06/26 📆 |====

🔎 NUEVO DESCUBRIMIENTO EN HTTP/2: UNA AMENAZA OCULTA

Hace 14 años se mejoró la compresión de encabezados HTTP para optimizar la velocidad, pero ahora se ha revelado un ataque sofisticado que pasó desapercibido en su momento. Esta vulnerabilidad en HTTP/2 podría comprometer la integridad del tráfico web, subrayando la importancia de revisar y actualizar protocolos críticos. Profundiza en cómo este fallo impacta la seguridad y qué medidas se recomiendan para proteger tus sistemas. Descubre más detalles sobre este hallazgo y sus implicaciones aquí 👉 djar.co/ZDn9w

🤖 ORDEN EJECUTIVA DE LA CASA BLANCA PARA IMPULSAR LA INNOVACIÓN EN IA Y SU SEGURIDAD

La administración estadounidense ha lanzado una directiva enfocada en promover el desarrollo seguro y responsable de la inteligencia artificial avanzada. Este documento establece pautas para proteger infraestructuras críticas y fomentar la innovación sin comprometer la privacidad ni la ciberseguridad. Entender esta iniciativa es clave para organizaciones y profesionales que trabajan con IA o dependen de ella para sus operaciones. Conoce el análisis completo y cómo puede afectar el panorama tecnológico 👉 djar.co/HN5L

🛠️ VULNERABILIDAD CRÍTICA EN VISUAL STUDIO CODE PONE EN RIESGO TOKENS DE GITHUB

Un fallo en Visual Studio Code permite a los atacantes robar tokens de autenticación de GitHub con un solo clic, poniendo en jaque la seguridad de repositorios y proyectos. Esta vulnerabilidad expone a desarrolladores a la pérdida de código fuente y la posibilidad de inserción de malware. Se recomienda actualizar el IDE y revisar las políticas de acceso para minimizar riesgos. Infórmate sobre cómo proteger tus credenciales y evitar este tipo de ataques aquí 👉 djar.co/pu1P

🇷🇺 HACKERS RUSOS EXPLOTAN FALLO EN WINRAR PARA ROBAR INFORMACIÓN SENSIBLE

Un grupo de cibercriminales ha utilizado un payload HTML llamado GammaPhish para iniciar una cadena de ataques que descargan códigos maliciosos en VBScript y comprometen datos corporativos. Esta amenaza demuestra la sofisticación en vectores de ataque que combinan ingeniería social y explotación de vulnerabilidades en software común. Aprende a identificar estos ataques y fortalecer tus defensas ante esta amenaza activa. Más información y recomendaciones disponibles 👉 djar.co/GgJLqg

🧠 IA AL SERVICIO DEL RANSOMWARE: AUTOMATIZACIÓN PARA EVADIR EDR Y EXPLORAR ACTIVE DIRECTORY

Se ha detectado un toolkit de ransomware que utiliza inteligencia artificial para automatizar la evasión de soluciones de detección y respuesta (EDR) y el reconocimiento en Active Directory. Esto representa un salto en la eficacia de ataques dirigidos a infraestructuras empresariales, incrementando el riesgo de brechas graves. Es vital implementar controles avanzados y monitoreo constante para contrarrestar estas amenazas inteligentes. Descubre cómo actúa esta amenaza y cómo prepararte 👉 djar.co/eg3q

📧 PROBLEMAS EN MICROSOFT EXCHANGE ONLINE AFECTAN ENVÍO Y RECEPCIÓN DE CORREOS

Usuarios en Norteamérica y Alemania experimentan retrasos y errores en el servicio de correo electrónico de Microsoft Exchange Online debido a una falla técnica que la compañía está resolviendo. Esta interrupción impacta la comunicación empresarial y puede afectar flujos críticos de trabajo. Mantente informado sobre el estado de la solución y recomendaciones para mitigar el impacto temporal. Consulta la actualización oficial y consejos aquí 👉 djar.co/h1hHi

⚠️ VULNERABILIDAD CVE-2024-21182 EN ORACLE WEBLOGIC CON EXPLOTACIÓN ACTIVA

La falla CVE-2024-21182, que afecta Oracle WebLogic, ha sido incluida en el catálogo KEV tras confirmarse ataques en entornos reales. Esta vulnerabilidad crítica requiere parcheo urgente, especialmente en entornos federales, antes del 4 de junio de 2026, para evitar compromisos graves. Se aconseja a los administradores priorizar su corrección y revisar medidas de seguridad complementarias. Infórmate sobre cómo proteger tus sistemas y los riesgos asociados 👉 djar.co/yCakp

  • 3
  • 3
  • 0
  • 5h ago

Bluesky

Profile picture fallback
CISA added Oracle WebLogic CVE-2024-21182 to its KEV Catalog after active exploitation. The flaw allows unauthenticated network attacks that can expose data or server control. #OracleWebLogic #CISA #USA
  • 0
  • 2
  • 0
  • 10h ago
Profile picture fallback
CISA added CVE-2024-21182 to its exploited list. The Oracle WebLogic Server flaw affects versions 12.2.1.4.0 and 14.1.1.0.0, enabling remote unauthenticated attacks. #OracleWebLogic #CISA #Oracle
  • 0
  • 1
  • 0
  • 23h ago
Profile picture fallback
CISA added CVE-2024-21182 in Oracle WebLogic Server to the KEV Catalog due to evidence of active exploitation, requiring FCEB remediation by June 4, 2026.
  • 0
  • 0
  • 0
  • 21h ago
Profile picture fallback
Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation #cybersecurity #hacking #news #infosec #security #technology #privacy thehackernews.com/20...
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
Oracle WebLogicの脆弱性CVE-2024-21182が、実際の攻撃後にKEVカタログに追加されました Oracle WebLogic CVE-2024-21182 Added to KEV Catalog After Active Exploitation #HackerNews (Jun 2) thehackernews.com/2026/06/orac...
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
2年前に修正されたOracleの脆弱性が攻撃で悪用される 米CISAが警告(CVE-2024-21182) | Codebook|Security News https://codebook.machinarecord.com/threatreport/silobreaker-cyber-alert/45906/
  • 0
  • 0
  • 0
  • 11h ago

Overview

  • win.rar GmbH
  • WinRAR

08 Aug 2025
Published
26 Feb 2026
Updated

CVSS v4.0
HIGH (8.4)
EPSS
8.34%

Description

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

Statistics

  • 5 Posts
  • 7 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

✨ Gamaredon sfrutta CVE-2025-8088 in WinRAR per distribuire GammaWorm e GammaSteel contro l’Ucraina
#CyberSecurity
insicurezzadigitale.com/gamare

@informatica

  • 6
  • 0
  • 0
  • 2h ago
Profile picture fallback

Gamaredon sfrutta CVE-2025-8088 in WinRAR per distribuire GammaWorm e GammaSteel contro l’Ucraina

Sekoia documenta una campagna di gennaio 2026 del gruppo APT russo Gamaredon: sfruttando CVE-2025-8088 in WinRAR, gli operatori dell'FSB distribuiscono GammaPhish, GammaLoad, GammaWorm e GammaSteel contro target governativi e militari ucraini. La catena usa Telegram come dead drop resolver per il C2 e NTFS Alternate Data Streams per l'evasione, con esfiltrazione finale verso AWS S3.

insicurezzadigitale.com/gamare

  • 1
  • 0
  • 1
  • 3h ago

Bluesky

Profile picture fallback
WinRAR: hacker russi sfruttano vecchia vulnerabilità per rubare dati La vulnerabilità CVE-2025-8088 di WinRAR continua a essere sfruttata da gruppi russi... https://www.ilsoftware.it/winrar-hacker-russi-sfruttano-vecchia-vulnerabilita-per-rubare-dati/
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
Gamaredon sfrutta CVE-2025-8088 in WinRAR per distribuire GammaWorm e GammaSteel contro l’Ucraina il blog: insicurezzadigitale.com/gamaredon-sf... #cybersecurity #apt #backdoor #cyberwar #fsb #gamaredon #infosec #malware #russia #ukraine #winrar
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Verizon
  • VoLTE

02 Jun 2026
Published
03 Jun 2026
Updated

CVSS
Pending
EPSS
0.02%

KEV

Description

SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec integrity protection (missing Security-Client/Security-Server headers and ESP traffic), which allows an on-path attacker to compromise confidentiality, integrity, and authenticity of VoLTE signaling via passive monitoring and active manipulation of unsecured SIP messages over the radio and core network.

Statistics

  • 1 Post
  • 63 Interactions

Last activity: 19 hours ago

Fediverse

Profile picture fallback

:dumpster_fire_gif: :blobcatpopcorn: :dumpster_fire_gif:

kb.cert.org/vuls/id/615987

CVE-2026-10629
Verizon IMS deployments were observed transmitting SIP signaling without integrity protection. REGISTER exchanges lacked Security-Client, Security-Server, and Security-Verify headers, and no ESP-encapsulated SIP traffic was detected during subsequent signaling such as INVITE, MESSAGE, BYE, and UPDATE. This pattern persisted across devices, operating systems, and network conditions, indicating a deliberate network configuration rather than a transient issue.

Per 3GPP TS 33.203 and GSMA IR.92, SIP signaling between the UE and P-CSCF must be protected using IPsec ESP following IMS AKA authentication, with negotiation occurring during registration. The absence of this protection allows attackers to manipulate SIP signaling undetected, enabling call hijacking, spoofing, denial-of-service, and misrouting of emergency calls.

Verizon initially acknowledged the issue and stated that integrity support would be available upon request and extended broadly later in the year. However, the company has since ceased participation in coordination, including follow-up discussions and draft review, and has not provided verifiable evidence of mitigation. As remediation remains unconfirmed, this disclosure proceeds to inform users of an ongoing security exposure.

Independent verification would require observation of successful SIP security negotiation, ESP-protected traffic, or official confirmation from Verizon.

  • 31
  • 32
  • 0
  • 19h ago

Overview

  • kernel

03 Mar 2022
Published
03 Jun 2026
Updated

CVSS
Pending
EPSS
26.34%

Description

A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.

Statistics

  • 4 Posts

Last activity: 3 hours ago

Fediverse

Profile picture fallback

Deep-Dive Technical Briefing: Weaponization of CVE-2022-0492 highlights severe structural exposures within Linux Kernel cgroups v1 release_agent hooks. Read our exhaustive architectural analysis detailing exact memory space exploit mechanics and full Kubernetes user namespace mitigation steps. thecybermind.co/asi6

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
CVE-2022-0492 enables container escapes and privilege escalation via cgroups v1 improper authentication, allowing host-root execution through release_agent manipulation.
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
~Cisa~ CISA added CVE-2022-0492 (Linux) and CVE-2025-48595 (Android) to the KEV catalog. - IOCs: CVE-2022-0492, CVE-2025-48595 - #CISA #KEV #threatintel
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
CISAが既知の悪用された脆弱性2件をカタログに追加 CISA Adds Two Known Exploited Vulnerabilities to Catalog #CISA (Jun 2) CVE-2022-0492 Linuxカーネルの不適切な認証の脆弱性 CVE-2025-48595 Androidフレームワークの整数オーバーフローの脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • themeum
  • Kirki – Freeform Page Builder, Website Builder & Customizer

02 Jun 2026
Published
02 Jun 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.12%

KEV

Description

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0.6. This is due to the plugin accepting an arbitrary email address when a username is used in the password reset request. This makes it possible for unauthenticated attackers to send a password reset link for any user registered on the site to their own email address.

Statistics

  • 3 Posts
  • 5 Interactions

Last activity: 2 hours ago

Bluesky

Profile picture fallback
Hackers are exploiting a critical privilege escalation vulnerability (CVE-2026-8206) in the Kirki plugin for WordPress to take over any user account, including those belonging to administrators.
  • 1
  • 3
  • 0
  • 18h ago
Profile picture fallback
Defiant warns of flaws in Kirki and Burst Statistics WordPress plugins that could let unauthenticated attackers reset admin passwords or impersonate admins via REST API, risking full site compromise. #Kirki #BurstStatistics #CVE20268206
  • 0
  • 1
  • 0
  • 2h ago
Profile picture fallback
Critical Kirki flaw CVE-2026-8206 lets unauthenticated attackers hijack WordPress admin accounts by redirecting password resets. Wordfence blocked 222+ attempts in 24 hours. #WordPress #Kirki #CVE20268206
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • danny-avila
  • LibreChat

02 Jun 2026
Published
03 Jun 2026
Updated

CVSS v3.1
CRITICAL (9.6)
EPSS
0.03%

KEV

Description

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders against the server's process.env during Zod schema validation of user-supplied MCP server URLs. Any authenticated user can create a malicious MCP server configuration with a URL pointing to an attacker-controlled domain containing environment variable references, causing the LibreChat server to connect to the attacker's server and transmit critical secrets such as CREDS_KEY, CREDS_IV, JWT_SECRET, and MONGO_URI in the request URL. This enables full compromise of the installation's cryptographic materials and database credentials without requiring administrative privileges. This is patched in version 0.8.4-rc1.

Statistics

  • 2 Posts

Last activity: 7 hours ago

Fediverse

Profile picture fallback

🔒 CVE-2026-32625 (CRITICAL): LibreChat < 0.8.4-rc1 lets any authenticated user exfiltrate secrets via crafted MCP server URLs. Upgrade ASAP to avoid full compromise of keys & DB creds. More: radar.offseq.com/threat/cve-20

  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback

CVE-2026-32625 - Critical information disclosure in LibreChat. MCP server leaks process.env via Zod validation. CVSS 9.6. Authenticated users can exfiltrate sensitive data. No patch available. Disable MCP or restrict access immediately. #CVE #LibreChat #infosec

valtersit.com/cve/CVE-2026-326

  • 0
  • 0
  • 0
  • 7h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 2 Posts

Last activity: 4 hours ago

Fediverse

Profile picture fallback
Partage, veille et lecture : Codex Discovered a Hidden HTTP/2 Bomb https://blog.calif.io/p/codex-discovered-a-hidden-http2-bomb Une nouvelle CVE toute mimi encore : CVE-2026-49975. #Shaarli https://dryusdan.link/shaare/6_czRA
  • 0
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
HTTP/2 BOMB CVE-2026-49975 an assymmetric Denial of Service originated from the RFC an attacker can send a compresed request that when uncompressed on the server side consumes 32GB memory. apache, nginx patch now. IIS, others still no patch. blog.calif.io/p/codex-disc...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Microsoft
  • Windows Server 2012

12 May 2026
Published
02 Jun 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.10%

KEV

Description

Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.

Statistics

  • 2 Posts

Last activity: 9 hours ago

Fediverse

Bluesky

Profile picture fallback
CRITICAL: Microsoft’s May 2026 Patch Tuesday Unleashes 138 CVEs – CVE-2026-41089 Actively Exploited (CVSS 98) – Patch NOW! + Video Introduction: Microsoft’s May 2026 security update is one of the largest in the company’s history, addressing 138 new CVEs including a rare CVSS 10 vulnerability in…
  • 0
  • 0
  • 0
  • 17h ago

Overview

  • F5
  • NGINX Plus

13 May 2026
Published
21 May 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.90%

KEV

Description

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Statistics

  • 1 Post
  • 8 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

CVE-2026-42945 (NGINX Rift): vulnerabilità critica attivamente sfruttata — aggiornare subito
#tech
spcnet.it/cve-2026-42945-nginx
@informatica

  • 8
  • 0
  • 0
  • 1h ago
Showing 1 to 10 of 45 CVEs